Questify

Privacy Policy

Effective date: 2026-06-05 · Last updated: 2026-09-21 · Version 2.4

This Privacy Policy describes how Questify (“we”, “us”, “our”) collects, uses, shares, and protects information when you use the Questify mobile application (the “App”). We've written it to be readable. Where law requires technical legal terms, we use them; where it doesn't, we use plain English.

If you have questions, email privacy@usequestify.com.


1. Who we are

Questify is a hyperlocal marketplace where people post real-world quests (tasks, favors, errands) and others nearby accept and complete them. The App is operated by Vladimir Rakočević, a sole operator based in Montenegro (contact details in §14). Questify is not (yet) incorporated as a separate legal entity; the operator is the responsible data controller.

We act as the data controller for the personal information you provide while using the App.

2. What we collect, and why

We collect the minimum information needed to make the App work. Categories below, grouped by purpose.

2.1 Account and profile data

DataSourceWhy
Email addressYou (signup) or Apple/Google SSOAuthentication, account recovery, important notices
Display name (handle)YouPublic identifier so others can recognize you
Avatar imageYou (uploaded) or built-in selectionPublic identifier
Apple / Google user identifierApple / Google during SSOSign-in mechanism
Push notification token (FCM)Your deviceSending you notifications about quests and messages
Account creation date, last sign-inAutomaticAccount management, fraud prevention
Date of birth (month and year)You (age screen at sign-up)Confirming you meet our 18+ age requirement; evidencing the age check

2.2 Quest activity

DataWhy
Quests you post (title, description, category, photos, location)Operating the marketplace
Quests you accept, complete, or cancelOperating the marketplace, reputation
Chat messages and attachments inside quest chatsCommunication between participants
Ratings you give and receiveReputation system
Reports and disputes you file or are involved inSafety, moderation

2.3 Location

We use your location in two ways.

When you choose to share it — posting a quest with a location, filtering quests by distance on the map, or proving completion with a location proof.

And to tell you a favour has been posted nearby. While the app is open, once the map or board has already obtained a position, we store your most recent location on our servers, at most once every five minutes, so we can notify you when a new quest appears near you. This is a last-known position only: each update replaces the previous one, and we do not keep a history of where you have been.

We never access your location in the background or when the app is closed. Questify does not request the “always” location permission on either platform. You can stop location being stored at all by denying the location permission — the app remains usable, and you will simply not receive nearby-quest notifications. Your stored location is deleted when you delete your account.

2.4 Identity verification (optional)

Questify offers an optional ID check. It is not required to use the app, and declining it costs you nothing. The check is carried out by Didit (didit.me) — Didit Identity, Inc., Dover, Delaware, USA, our contracting entity, together with its EU affiliate Didit Identity Spain, S.L., Barcelona — an independent identity-verification provider acting as our processor, on its systems in the EU (Amazon Web Services, Ireland). The check page is operated by Didit even where it is shown under a Questify web address; Didit's own Verification Privacy Notice and End User Terms apply to the check and are linked from that page. Questify never handles the documents itself — the earlier in-app upload was withdrawn before launch precisely so that we would never hold identity documents or biometric data.

What Didit processes: a photo of your government-issued identity document, a short selfie video (a liveness and face-match check), and the identity fields it reads from the document (such as your name and date of birth). This is special category data under Article 9 GDPR. It is processed only with your explicit consent, which you give in the app — by ticking an unticked box on the consent sheet — before the check opens; we record which consent text you agreed to and when. Didit keeps the check data for one month and then deletes it (this is the retention we have configured on our account).

What Questify receives and stores: the outcome (passed / did not pass, or under review), Didit's session reference, the dates (when the check happened and when it lapses), and your consent record. We never receive or store your document, your date of birth, your selfie, any image, or any biometric template. Didit's check is configured to decline documents of anyone under 18, so a passed check also means the document showed an adult — but the date itself stays with Didit.

We give Didit a pseudonymous reference for your account (a keyed hash, not your user id) so it can notice the same document being used on two accounts; Didit cannot identify you from it.

What a passed check shows: an “ID checked · month year” mark on your profile, for 24 months, after which it lapses and you can check again. It means a document and a live face matched on that month — nothing more. It is not a guarantee of anyone's conduct.

2.5 Device and technical data

DataSourceWhy
Device model and operating system versionYour deviceCompatibility, debugging
App versionYour deviceCompatibility, debugging
Crash reports (anonymized stack traces, device class)Firebase CrashlyticsDiagnosing and fixing crashes
IP address (transient)Your networkRequired for any internet connection; not stored
App-open record (one row per day you open the App)Your device, sent to our own backendUnderstanding whether people keep using Questify — retention only
Anonymous screen counts (a running total per screen per day, with no link to you)Your device, sent to our own backendDeciding which parts of the App to improve and which to remove

We do not collect: contacts, photos outside of those you explicitly upload, calendar events, browsing history outside the App, advertising identifiers, biometric data, or your device's other apps.

Voice input. If you use the microphone button to dictate a quest, your speech is transcribed by your device's own operating system — Apple on iOS, Google on Android — under their privacy terms, not ours. Only the resulting text reaches Questify; we never receive or store the audio recording. The microphone is used on that one screen, only while you hold the button, and only if you grant the permission.

We do not use cookies (this is a native mobile app, not a website).

3. Legal basis for processing (GDPR)

We process your data on these legal bases:

ActivityLegal basis
Running your account, completing quests you initiatedContract — necessary to provide the service you signed up for
Confirming you are 18+ (date of birth at the age screen)Legitimate interest / legal obligation — preventing minors from using an adults-only service
Sending essential service notificationsContract
Optional ID check (Didit)Explicit consent (Art. 9 GDPR) — you opt in on the consent sheet; Didit processes the document and selfie as our processor and we receive only the outcome, a reference and the dates
Reputation system (ratings, trust score, cancellation flags)Legitimate interest — required for marketplace safety; balanced against your interests
Crash diagnosticsLegitimate interest — required to keep the App working
Optional marketing or promotional notificationsConsent — you opt in, and can withdraw at any time in Settings
Compliance with legal obligations (e.g. responding to court orders)Legal obligation

You can withdraw consent for any consent-based processing at any time. Withdrawal doesn't affect processing already done in reliance on your consent.

4. Who we share data with

We do not sell your personal data. Ever.

We share specific data with specific service providers acting as data processors on our behalf:

ProviderWhat they receivePurposeWhere they process it
Supabase (Supabase Inc., USA)Account data, quest data, messages, ratings — basically everythingBackend hosting, database, authentication, file storageOur Supabase project is hosted in the EU (Frankfurt, eu-central-1)
Firebase (Google LLC, USA)Push notification tokens, anonymized crash diagnosticsPush notification delivery, crash reportingUSA
AppleApple SSO identifierSign in with AppleUSA
GoogleGoogle SSO identifierSign in with GoogleUSA
Didit (didit.me) (only if you use the optional ID check)Your ID document photo, selfie video and the identity fields read from the document are processed on Didit's systems; we receive only the outcome, a session reference and the datesOptional ID checkEU (processing and storage on Amazon Web Services, Ireland); contracting entity Didit Identity, Inc. (USA) with EU affiliate Didit Identity Spain, S.L.; one-month retention

We also share data with other Questify users only as required by the marketplace function:

We may disclose data in response to lawful requests by public authorities, court orders, or legal process — and only after we've verified the request is valid.

5. International data transfers

Some of our processors (Firebase, Apple, Google) are based in the United States. When data is transferred outside your country, we rely on standard contractual clauses and the providers' own data-protection commitments to ensure protection equivalent to what applies in the EU.

Our primary database (Supabase) is hosted in Frankfurt, Germany. Most of your data never leaves the EU.

6. How long we keep your data

Data categoryRetention
Account profileWhile your account is active. On deletion, we immediately erase or irreversibly de-identify your profile — your email, name, phone and avatar are removed or scrubbed and your login is permanently severed — so the account can no longer identify you. Any residual backup copies roll off within 30 days.
Quest content (posts, completions, ratings)Active while your account is active. On deletion, content that is yours alone is removed or de-identified; where a Quest involved another user, a de-identified record (your name and avatar shown as “Deleted User”) may be retained so the other party keeps a complete record of their own activity.
Chat messages6 months from the message timestamp, or until the account is deleted, whichever is sooner.
ID check (Didit)We do not store your identity document, date of birth or biometric — only the outcome, Didit's session reference, the dates and your consent record. A passed check shows on your profile for 24 months; the record itself is kept while your account is active and is deleted when you delete your account, at which point we also ask Didit to delete its records for your sessions. Didit otherwise keeps check data for one month.
Crash diagnostics (Crashlytics)90 days per Firebase default.
Disputes and reportsWhile the account exists + 2 years post-deletion (legal records).
Auth logs (sign-in attempts)90 days.
Date of birth (age check)Month and year retained while your account is active, to evidence the 18+ check; removed on account deletion.

7. Your rights

You have these rights regarding your personal data:

To exercise any of these rights, email privacy@usequestify.com with the email address tied to your account. We respond within 30 days. We may ask for additional verification before acting on requests involving sensitive data (e.g. ID verification documents).

You can delete your account directly from the App: Profile → Edit Profile → Delete Account. Account deletion is irreversible.

8. Age requirement (18+)

Questify is an adults-only service. It is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18. We apply a neutral age screen at sign-up and store only your month and year of birth to evidence the check. If we discover that an account belongs to someone under 18, we block it and delete the associated personal data.

If you believe someone under 18 is using Questify or has provided us data, email privacy@usequestify.com and we'll act promptly.

9. Security

We take reasonable technical and organizational measures to protect your data:

No system is perfectly secure. If a data breach occurs that materially affects your rights, we'll notify you and the relevant authority within 72 hours of discovery, per applicable law.

10. Marketing and analytics

We do not currently run marketing campaigns through third-party advertising networks. We do not track you across other apps or websites.

If we add marketing notifications later, they'll require opt-in consent and you can disable them at any time in Settings.

We use Firebase Crashlytics for crash diagnostics only — never for advertising or behavioral tracking.

We keep two first-party usage measures, both on our own servers.

The first is the date of each day you open the App, stored against your account. It tells us how many people come back week to week. It records the day only — not what you looked at, tapped or searched — and it is deleted with the rest of your data when you delete your account.

The second is a set of anonymous counters. When a screen is opened, we add 1 to a running total for that screen on that day — for example, “map opened, 24 August: 137”. These counters hold nothing but a screen name, a date and a number. They contain no account identifier, no device identifier and no session identifier, so they cannot be traced back to you, cannot be joined to your account, and cannot be used to reconstruct what any individual did. There is nothing of yours in them, which is also why deleting your account does not change them. We use them to decide which parts of Questify to improve and which to remove.

Neither measure ever leaves our infrastructure, and neither is shared with any third party or advertiser.

11. Cookies and similar technologies

The Questify mobile app does not use browser cookies. We use device storage to:

You can clear this data at any time by uninstalling the App or signing out.

12. Automated decision-making

We don't use automated decision-making or profiling that produces legal effects on you. Specifically:

13. Changes to this Policy

When we make material changes to this Policy, we'll:

  1. Update the “Last updated” date at the top.
  2. Notify you in the App at next launch.
  3. For significant changes (new categories of data collected, new processors, new purposes), require you to acknowledge the update before continuing to use the App.

Minor clarifications (typo fixes, wording improvements) don't trigger notifications.

14. Contact

For any privacy question, request, complaint, or general inquiry:

Email: privacy@usequestify.com
Operator: Vladimir Rakočević, Montenegro (full postal address available on request; to be added before public launch)

We aim to respond within 5 business days; statutory rights requests are handled within 30 days.


This document is the canonical Privacy Policy for Questify. It is shipped inside the app and also available at this URL, which is declared in Settings → Legal → Privacy Policy.


Website and waitlist (usequestify.com)

This section covers the website at usequestify.com itself. It is a website-specific addendum and is not part of the canonical in-app Policy above.

The Policy above covers the Questify mobile App. The website also processes a small amount of data:

Your rights under §7 apply equally to waitlist data.