Privacy Policy
App: Qvestit · Developer: Luca Belluso · Contact: contact@qvestit.com Last updated: 2026-09-23
This policy explains what data the app collects, why, who processes it, and how you can delete it. The app is made by one independent developer. We do not sell your data.
What we collect
| Data | Why | Where it lives |
|---|---|---|
| Email address and sign-in identity (email, Google or Apple sign-in) | To create and secure your account | Supabase (our backend) |
| Username, friend code, optional profile picture | Your profile, and so friends can find you | Supabase; the profile picture is stored as a public image link |
| Quests, completions, streaks, credits, Guilt-Free Cash settings and history, spending log | The core features of the app | Supabase |
| Friends, reactions and comments | Social features you choose to use | Supabase, visible to the friends involved |
| Time zone and reset hour | So days, weeks and reminders line up with your local time | Supabase |
| Push notification token and notification settings | To send the reminders you turn on | Supabase, sent via Expo's push service |
| Purchases (Prism packs and unlocks) | To deliver what you bought and handle refunds | RevenueCat and the app store; we see the transaction, never your card details |
| Prism balance and ad rewards | To credit Prisms you earned by watching an ad | Supabase |
| Ad identifier, device and ad interaction data, consent choice | To show rewarded ads and verify the reward | Google AdMob (see below) |
App usage limits (Android). If you create an app-usage quest and grant usage access, the app reads how long you used the apps you picked. Those minutes stay on your device. Only the names of the apps you chose to limit are saved with the quest.
We do not collect your location, contacts, or precise device identifiers beyond the advertising ID described below.
Ads
The app shows ads only when you tap Watch to earn Prisms. Ads come from Google AdMob. If you are in the EEA, UK or Switzerland, you are asked for consent before any ad is requested. You can decline and still get non-personalised ads. You can change your choice at any time from Ad privacy choices in the Get Prisms sheet. Google's use of data is described at https://policies.google.com/technologies/partner-sites.
Who processes your data
- Supabase: database, sign-in and file storage.
- Expo: app updates and push notification delivery.
- RevenueCat and Google Play / Apple App Store: purchases.
- Google AdMob: rewarded ads.
- Google or Apple: only if you sign in with them.
Each processes data under its own privacy policy. Some of them may process data outside your country, including in the United States.
Legal basis (EEA/UK users)
Running your account and the features you use is based on our contract with you. Ads and personalised advertising are based on your consent. Keeping purchase records is based on legal obligations.
How long we keep it
Until you delete your account. Purchase records the stores and RevenueCat keep follow their own retention rules and legal requirements.
Delete your account
In the app: Settings → Account → Delete account. This permanently deletes your account and everything stored with it in our backend. You can also email contact@qvestit.com and we will delete it for you.
Your rights
You can ask to access, correct, export or delete your data, or object to how it is used, by emailing contact@qvestit.com. If you are in the EEA or UK you can also complain to your local data protection authority.
Children
The app is not directed at children under 13 (under 16 in the EEA) and we do not knowingly collect their data.
Changes
If this policy changes, the new version is posted here with a new date.