QUEST ยท PRIVACY

Quest Privacy Policy

Effective date: July 10, 2026

Quest is an interactive story application published by Indieloper. This policy explains how Quest handles data when you use the mobile app.

Summary

Quest uses a private Firebase guest profile to save and continue stories without asking for your name, email address, or social login. Story context is processed by a server-selected AI provider to generate and pre-generate scenes. Quest does not show third-party ads and does not use analytics or advertising SDKs.

You can permanently delete the guest profile and its cloud data from Settings โ†’ Your data.

Data we process

Quest may process:

Quest does not ask for your name, email address, phone number, contacts, precise location, payment details, advertising identifier, photos, microphone, or camera access.

How data is used

We use data only to:

Firebase

Quest uses Google Firebase Authentication, Cloud Functions, and Cloud Firestore.

Production Firebase and Firestore resources are hosted in United States regions. Google processes data under its own terms and privacy commitments.

AI generation providers

Quest's server can use Cerebras, OpenAI, Google's Gemini API, OpenRouter, or another administrator-configured OpenAI-compatible API, depending on the generation configuration assigned to the guest profile. The selected provider receives the relevant story theme or action and the server-owned context needed to generate, pre-generate, repair, or safety-check a scene. Pre-generation may process the current scene and its four available choices before you select one.

The mobile app sends only defined story API fields; it never sends or receives hidden prompts, provider credentials, private story memory, or model settings. A pseudonymous service reference may accompany a provider request for safety and abuse protection; it is not your name or email address. AI providers do not receive your Firebase credential from Quest.

On-device storage

Quest keeps an encrypted-by-platform app sandbox cache of settings and stories so saved content can be opened when the network is unavailable. The app also stores a short-lived idempotency record so a retried choice is not generated twice. Removing the app or clearing its storage may remove this cache and access to the guest profile.

Stories imported from an earlier app version stay only on the device as read-only history and are not uploaded automatically.

Retention

Firestore time-to-live deletion is asynchronous, so expired records can remain for a short period after their expiry time.

Deletion and choices

You may withdraw story-generation permission in Settings. This stops new cloud reads and generation; cached stories remain readable and account deletion remains available.

To delete everything, use Settings โ†’ Your data โ†’ Delete profile and all data. Quest immediately blocks new writes for that profile and schedules durable deletion of its stories, reports, and guest authentication account. Local data is then cleared from the device.

Individual stories can also be deleted from their story menu.

Content reports

When you submit a report, the server verifies that the referenced story belongs to your guest profile and selects only the relevant excerpt. Reports are rate-limited, stored separately, and available only to authorized service operators.

Security

Quest uses HTTPS in production, Firebase ID-token verification, tenant-isolated Firestore paths, replay-resistant mutations, default-deny Firestore rules, rate limits, and Secret Manager for AI-provider credentials. No system can be guaranteed perfectly secure, but we limit collection and access to what the service needs.

Children

Quest is designed for users aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

International processing

Quest production services are operated in United States regions. If you use Quest from another country, data is transferred to and processed in the United States.

Changes

We may update this policy when the product or its processors change. The effective date at the top identifies the current version. If a change requires renewed consent, the app will ask before new story generation.

Contact

For privacy questions or deletion support, contact alphamikle@gmail.com.