Quest Privacy Policy
Effective date: July 10, 2026
Quest is an interactive story application published by Indieloper. This policy explains how Quest handles data when you use the mobile app.
Summary
Quest uses a private Firebase guest profile to save and continue stories without asking for your name, email address, or social login. Story context is processed by a server-selected AI provider to generate and pre-generate scenes. Quest does not show third-party ads and does not use analytics or advertising SDKs.
You can permanently delete the guest profile and its cloud data from Settings โ Your data.
Data we process
Quest may process:
- a randomly generated Firebase guest user identifier;
- a numbered story-generation cohort assigned to that guest for the profile lifetime. The configuration routed to the cohort may change for future quests, while each existing quest keeps its pinned revision;
- IP address, Firebase SDK/app and user-agent metadata, and short-lived authentication credentials processed for account access, request routing, security, and abuse prevention; Quest does not use IP addresses to infer location;
- themes, custom story ideas, choices, custom actions, generated scenes, goals, resources, endings, and story history;
- content-report reason, optional note, and a limited server-selected story excerpt;
- operational metadata such as request identifiers, response status, latency, and pseudonymous abuse-prevention counters.
Quest does not ask for your name, email address, phone number, contacts, precise location, payment details, advertising identifier, photos, microphone, or camera access.
How data is used
We use data only to:
- generate, save, display, and continue interactive stories;
- keep choices consistent with the current story state;
- pre-generate temporary candidate scenes for the four choices currently shown, reducing the wait after a choice;
- compare generation configurations across pseudonymous cohorts to improve story quality and reliability;
- protect the service from abuse and duplicate requests;
- review content reports and improve safety;
- diagnose service reliability without logging story text in routine operational logs.
Firebase
Quest uses Google Firebase Authentication, Cloud Functions, and Cloud Firestore.
- Firebase Authentication creates a private anonymous guest identifier.
- Cloud Functions operate the Quest REST service.
- Cloud Firestore stores the canonical story state, pseudonymous cohort assignment, temporary candidate scenes, and reports.
Production Firebase and Firestore resources are hosted in United States regions. Google processes data under its own terms and privacy commitments.
AI generation providers
Quest's server can use Cerebras, OpenAI, Google's Gemini API, OpenRouter, or another administrator-configured OpenAI-compatible API, depending on the generation configuration assigned to the guest profile. The selected provider receives the relevant story theme or action and the server-owned context needed to generate, pre-generate, repair, or safety-check a scene. Pre-generation may process the current scene and its four available choices before you select one.
The mobile app sends only defined story API fields; it never sends or receives hidden prompts, provider credentials, private story memory, or model settings. A pseudonymous service reference may accompany a provider request for safety and abuse protection; it is not your name or email address. AI providers do not receive your Firebase credential from Quest.
On-device storage
Quest keeps an encrypted-by-platform app sandbox cache of settings and stories so saved content can be opened when the network is unavailable. The app also stores a short-lived idempotency record so a retried choice is not generated twice. Removing the app or clearing its storage may remove this cache and access to the guest profile.
Stories imported from an earlier app version stay only on the device as read-only history and are not uploaded automatically.
Retention
- Stories remain until you delete an individual story, delete the guest profile, or the profile is removed under the inactive-account cleanup policy.
- Idempotency command records expire after approximately 24 hours.
- Unused pre-generated candidate scenes expire after approximately 24 hours and are deleted sooner when they become obsolete; Firestore time-to-live cleanup may complete later.
- Content reports expire after approximately 90 days.
- Completed deletion tombstones expire about 30 days after deletion. If cleanup is interrupted, the protective deletion record remains until cleanup succeeds, preventing late or replayed writes from restoring data.
- Routine cloud logs exclude story bodies and use the configured Google Cloud log-retention period.
- Inactive anonymous profiles are eligible for deletion after 12 months without story activity.
Firestore time-to-live deletion is asynchronous, so expired records can remain for a short period after their expiry time.
Deletion and choices
You may withdraw story-generation permission in Settings. This stops new cloud reads and generation; cached stories remain readable and account deletion remains available.
To delete everything, use Settings โ Your data โ Delete profile and all data. Quest immediately blocks new writes for that profile and schedules durable deletion of its stories, reports, and guest authentication account. Local data is then cleared from the device.
Individual stories can also be deleted from their story menu.
Content reports
When you submit a report, the server verifies that the referenced story belongs to your guest profile and selects only the relevant excerpt. Reports are rate-limited, stored separately, and available only to authorized service operators.
Security
Quest uses HTTPS in production, Firebase ID-token verification, tenant-isolated Firestore paths, replay-resistant mutations, default-deny Firestore rules, rate limits, and Secret Manager for AI-provider credentials. No system can be guaranteed perfectly secure, but we limit collection and access to what the service needs.
Children
Quest is designed for users aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
International processing
Quest production services are operated in United States regions. If you use Quest from another country, data is transferred to and processed in the United States.
Changes
We may update this policy when the product or its processors change. The effective date at the top identifies the current version. If a change requires renewed consent, the app will ask before new story generation.
Contact
For privacy questions or deletion support, contact alphamikle@gmail.com.