Privacy Policy
This Privacy Policy explains how Ascend Quests ("Ascend Quests," "the app," "we," "us") collects, uses, stores and protects information when you use the Ascend Quests mobile application and the website at ascendquests.com ("the Site"). It applies to all current versions and platforms of the app.
1. Identity of the controller
Ascend Quests is developed and operated by an independent developer based in the Czech Republic. As an individual developer, no separate company name, registered business address or company number exists to disclose. You can reach the developer using the contact details in Section 23 below.
2. Contact
For any question about this policy, your data, or to exercise any of the rights described below, email ascendhelps@gmail.com. This inbox is monitored by the developer.
3. Scope
This policy covers all versions of the Ascend Quests app across platforms (Android and iOS, once published) and the ascendquests.com website, including the account deletion page.
4. What data is collected
What is collected depends entirely on how you use Ascend Quests. We state plainly, category by category, what stays on your device and what (if anything) reaches a server.
If you play without an account (guest mode — the default)
- Nothing is sent anywhere. All data — your hero (name, level, XP, streaks, titles, avatar), quest history, daily and weekly analytics, an on-device error log, and any custom avatar or background images you add — is stored only in your device's local storage (
localStorage/IndexedDB). - No account or sign-up is required to use the app.
If you create an optional account
- Your email address and a password (see Section 14 for how the password itself is handled).
- Your account's internal user ID.
- A synced copy of a limited, allow-listed set of your hero's score and progress fields — things like your hero name and title, level, XP, streak, Flame Shields, unlocked titles and badges, category progress, your chosen avatar, and account/onboarding status. The full technical list is enforced server-side so it cannot silently grow.
- Your country, but only if you explicitly choose one — it is never inferred from your IP address, GPS, or device locale.
Regardless of account status, the following are never uploaded: your quest history, daily XP log, weekly and monthly reports, focus history, and any custom avatar or background image you upload. Those stay device-local, permanently.
5. Why each type is collected
- Email and password — to let you sign in and recover access to an optional account.
- Synced score/progress fields — so your level, XP, streak and title are consistent if you use the app on more than one device.
- Country (if chosen) — to personalize country-specific content you explicitly opt into.
- Local-only analytics (if you opt in) — to help us understand, in aggregate on your own device today, which parts of the app you actually use.
- Local error log — to help diagnose crashes and bugs if you choose to report one to us.
6. Legal basis (EU)
- Contract — processing your email, password and synced progress is necessary to provide the optional account and sync feature you requested.
- Consent — local analytics collection is opt-in and relies on your explicit consent, which you can withdraw at any time.
- Legitimate interest — limited technical processing (such as the security and abuse-prevention measures described in Section 18) relies on our legitimate interest in keeping the service secure and available.
7. How data is collected
Directly from you (account sign-up, choosing a country, typing your hero name). Automatically by the app for the on-device analytics and error log described above, only once you opt in. We do not currently receive any data automatically from Apple or Google (such as platform age signals) — Ascend Quests is not yet listed in either store.
8. Storage and location
- On-device: guest-mode data, quest history, analytics, error log, and any custom images — stored locally on your device only, never transmitted.
- Server-side (optional account only): your account record and the synced score/progress fields listed in Section 4, hosted with Supabase in the EU (Frankfurt, Germany).
- Data in transit is encrypted (TLS). Data at rest is encrypted by our database provider. See Section 18 for more on security.
9. Third parties and processors
We use a small number of processors, each acting only on our instructions and bound by their own data processing terms. Consistent with Apple's requirement, we confirm that each of the processors below provides the same or equal protection of your data as required by this policy.
| Processor | Purpose | What it receives | Region |
|---|---|---|---|
| Supabase | Database and authentication for optional accounts | Email, hashed password, account ID, synced score/progress fields | EU (Frankfurt, Germany) |
| Amazon Web Services (Amazon SES) | Sending transactional emails only — sign-up confirmation codes, password-reset codes, account-deletion confirmations | Your email address and the transactional message content | EU (Frankfurt, Germany); contracting entity Amazon Web Services EMEA SARL, Luxembourg |
| Cloudflare | Hosting and DNS for ascendquests.com | Technical request data (such as IP address) needed to deliver and protect the website | Global network; request routing |
10. Analytics
In-app analytics are opt-in and off by default. You're asked during onboarding, and you can change your choice any time in Settings → Privacy. When on, events are recorded only on your device (capped at 500 events) and are not sent anywhere today. Turning analytics off immediately deletes everything already recorded on your device. There is no cross-app or cross-site tracking, and no advertising identifiers are used.
11. Advertising
Ascend Quests does not show ads and does not use any advertising network, advertising identifier, or ad-based tracking.
12. AI
Ascend Quests does not use any third-party AI provider to process your personal data.
13. Account data
Creating an account is entirely optional. Guest mode — the default — requires no account and no email. If you do create an account, it links an email and password to your existing local hero so your score and progress can sync; see Section 4 for exactly what is and is not synced.
14. User rights
Depending on your location, you may have the right to access, correct (rectify), delete (erase), restrict, or receive a copy of (port) your personal data, to object to certain processing, and to withdraw consent at any time. You can exercise any of these rights by emailing ascendhelps@gmail.com. In addition:
- Access / portability: the app includes an in-app "Export My Data" feature (Settings) that generates a full JSON export of your hero data at any time, with no request needed.
- Erasure: see Section 16, Data deletion.
- Complaints: if you are in the Czech Republic or elsewhere in the EU, you may lodge a complaint with your local supervisory authority. In the Czech Republic this is the Úřad pro ochranu osobních údajů (ÚOOÚ), www.uoou.cz.
15. Data deletion
You can delete your Ascend Quests account and all associated data at any time, in two ways:
- In the app: Settings → Delete Account → type
DELETEto confirm. - On the web, without the app or a working sign-in: ascendquests.com/delete-account/. If you can sign in, the page deletes your account immediately. If you can't, enter the email on your account and follow the confirmation link we send.
Uninstalling the app alone does not delete a server-side account — use one of the methods above. Deleting a guest-mode hero (no account) is done entirely on-device by clearing the app's data, since nothing about it exists anywhere else.
16. Data retention
| Data category | Retained while | Deleted |
|---|---|---|
| Account profile, synced score/progress | Account is active | Within 30 days of account deletion |
| Uploaded avatar / background images (guest mode; never uploaded for account sync) | Stored only on your device | When you delete the app's local data |
| Database backups | Normal backup rotation | Within 90 days of account deletion |
| Local analytics events (opt-in) | Capped at 500 most recent events | Immediately, when you turn analytics off |
| Local error log | Capped at 100 most recent entries | When you clear the app's local data |
We do not keep a general "as long as necessary" retention period for account data — the 30-day and 90-day windows above are the concrete commitment.
17. Security
- Data in transit is protected with TLS encryption.
- Data at rest is encrypted by our database provider.
- Database access is locked down with row-level security and no public data API — your data isn't queryable by other users.
- Passwords are hashed by our authentication provider; we never see or store a plaintext password.
- If a data breach affecting your personal data ever occurs, we are committed to notifying affected users and the relevant supervisory authority as required by applicable law.
18. International transfers
Your data is stored in the EU (Frankfurt, Germany). Where a processor listed in Section 9 may process data outside the European Economic Area, that transfer relies on the European Commission's Standard Contractual Clauses, as provided for in that provider's own data processing terms. You can request a copy of the relevant safeguards by emailing ascendhelps@gmail.com.
19. Children's privacy
Ascend Quests is not directed at children and requires you to confirm during onboarding that you are 13 years of age or older. We do not knowingly collect personal data from anyone under 13. If we become aware that we have inadvertently collected data from a child under 13, we will delete it promptly. A parent or guardian who believes their child has provided us with personal data can contact ascendhelps@gmail.com to request its removal.
20. California / US state privacy rights
We do not sell or share personal information, as those terms are defined under the CCPA/CPRA and similar state laws (Virginia, Colorado, Connecticut, Utah, and others). We collect only the categories of data described in Section 4. If you are a resident of a US state with its own privacy law, you may have the right to know what personal information we hold about you, to request its deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. You (or an authorized agent acting on your behalf) can exercise these rights by emailing ascendhelps@gmail.com.
21. Cookies
Neither the Ascend Quests website nor the app uses cookies or web beacons. The app uses localStorage/IndexedDB on your device, as described throughout this policy.
22. Changes to this policy
If we make a material change to this policy — particularly any change to what we collect — we will update the effective date above and, where the change affects consent you already gave (such as analytics), re-prompt you for that consent in the app. We encourage you to review this page periodically.
23. Contact
Ascend Quests is developed and operated by an independent developer based in the Czech Republic. For any question about this policy or your data, email ascendhelps@gmail.com.