LifeQuest — Privacy Policy
Last updated: 2026-07-27 Effective date: 2026-07-12
LifeQuest ("we", "us", "the app") is a gamified productivity mobile app developed and operated by Bohdan ("the developer"), an individual based in Norway. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data under the EU General Data Protection Regulation (GDPR) and equivalent Norwegian data protection law.
By using LifeQuest you acknowledge this policy. If you don't agree, please don't create an account.
1. Data Controller
The data controller for the purposes of GDPR is:
Bohdan (individual developer, Norway) Contact: support@lifequestapps.com
2. Data we collect
2.1 Account information
When you create an account we collect:
- Email address — used as your login identifier and for account-related service messages
- Display name — shown on your profile and in shared/social features
- Password (stored only as a bcrypt hash — we never see or store your plaintext password)
- Avatar — either a picked ID from our built-in avatar set, or an optional photo you upload
2.2 Activity data
When you use the app we store activity you create:
- Habits you define, your habit logs (date + status), streaks
- Tasks / todos and daily card entries
- Focus sessions — start/end time, duration, type, optional review notes
- Workouts — sessions you log, body part / exercise tags
- Quests / achievements / XP / coins earned through normal app use
- Friends / squads / challenges — connections you initiate or accept, weekly aggregated activity
- Moderation records — user blocks and abuse reports you create or that are filed about you
2.3 Device & technical data
- Device type, OS version, app version — to ensure the app works correctly
- Push notification token — only if you grant notification permission; used to send focus-timer / streak / daily-reminder notifications
- IP address — briefly processed at the API layer for authentication and rate-limiting; not stored beyond request logs (kept ≤ 30 days for security purposes)
2.4 Data we do not collect
- We do not collect your location
- We do not track you across other apps or websites
- We do not collect contacts, microphone, or camera data
- We do not collect biometric data
- We do not sell or share your personal data with advertisers or data brokers
- The app contains no third-party advertising SDKs
- The app contains no third-party analytics SDKs
3. Legal basis for processing (GDPR Article 6)
- Performance of a contract (Art. 6(1)(b)) — account creation and app functionality (habits, focus, todos, etc.)
- Legitimate interest (Art. 6(1)(f)) — service security, fraud prevention, abuse moderation
- Consent (Art. 6(1)(a)) — push notifications, optional avatar photo upload
You can withdraw consent at any time by revoking permissions in your device settings, or by deleting your account.
4. How we use your data
We use the data above strictly to:
- Provide the service — store your habits, render your dashboard, calculate XP/levels/streaks
- Enable social features — show your weekly leaderboard rank, squad standings, challenge progress (only data you explicitly share by joining a friend / squad / challenge)
- Send notifications you opt into — focus session ending, streak-at-risk reminders, daily bonus
- Enforce our Terms of Use — process reports and blocks, prevent abuse
- Communicate about the service — service announcements (rare) and security notices
We do not:
- Sell your data to third parties
- Use your data to train AI models
- Show ads based on your data
- Cross-reference your data with external profiles
5. Where your data is stored
Your data is stored on managed cloud infrastructure hosted in the European Economic Area (EEA):
- Database: PostgreSQL hosted on Neon (https://neon.tech) — region: Frankfurt, Germany (EU)
- Application server: Node.js hosted on Render (https://render.com) — region: Frankfurt, Germany (EU)
Your data does not leave the EEA in the normal course of operation. If we ever need to transfer data outside the EEA (for example, during migration), we will use appropriate safeguards (Standard Contractual Clauses) as required by GDPR.
6. Data sharing
We share data only in these limited cases:
- Other users you connect with: when you accept a friend, join a squad, or create a challenge, those users can see your display name, avatar, weekly XP totals, and high-level activity counts (e.g., habit completions this week). They never see your individual habit names, todo titles, notes, journal content, or focus session names.
- Service providers (processors): Neon and Render process data on our behalf under their own GDPR-compliant data processing agreements.
- Legal compliance: if required by valid legal process or to protect rights, property, or safety.
We never share data with advertisers, data brokers, or for marketing purposes.
7. Your rights under GDPR
You have the following rights regarding your personal data:
- Right of access — see everything you've created inside the app; request a full JSON export by emailing us
- Right to rectification — edit your name, avatar, email, habits, etc. directly in app
- Right to erasure ("right to be forgotten") — from Account → Delete account permanently. This permanently removes your profile and all associated data. The action is immediate and irreversible.
- Right to data portability — request a machine-readable JSON export of your data at any time
- Right to object — object to processing based on legitimate interest by contacting us
- Right to withdraw consent — revoke notification permission in device settings; delete your account
- Right to lodge a complaint — with the Norwegian Data Protection Authority (Datatilsynet, https://www.datatilsynet.no) or the supervisory authority in your EU country of residence
We will respond to any rights request within 30 days.
8. Data retention
- Active accounts: we keep your data as long as your account exists
- Deleted accounts: when you delete your account, all personal data is purged from our operational database immediately. Automated backups may retain deleted data for up to 30 additional days before rotation, after which it is unrecoverable.
- Server request logs (IP addresses, timestamps): kept up to 30 days for security purposes, then deleted.
- Abuse reports: retained for 12 months to enforce our Terms and detect repeat offenders, then anonymized.
9. Children
LifeQuest is not intended for users under 13. If you are under 16 (or the minimum age of digital consent in your country of residence), you may only use the app with the consent of a parent or legal guardian, as required by GDPR Article 8. We do not knowingly collect data from children below the applicable age. If you believe a child has created an account, contact us and we will delete it.
10. Security
- Passwords are hashed using bcrypt and never stored or transmitted in plaintext
- All API traffic is encrypted in transit using HTTPS/TLS 1.2+
- Authentication uses signed JWT tokens with short lifetimes stored in the device's secure enclave (iOS Keychain / Android Keystore via Expo SecureStore)
- Database access is restricted to the application server via network-level rules
- Sensitive fields (passwords) are never included in API responses
No system is perfectly secure. If you discover a vulnerability, please report it responsibly to the contact below.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via in-app notice or email. The "Last updated" date at the top of this document reflects the most recent change. Continued use of the app after changes indicates acceptance of the updated policy.
12. Contact
For privacy questions, data export, deletion requests, or general questions:
Email: support@lifequestapps.com Developer: Bohdan (Norway) App name: LifeQuest Bundle ID (iOS): com.bohdan.lifequest Package (Android): com.bohdan.lifequest
You may also contact the Norwegian Data Protection Authority (Datatilsynet) at https://www.datatilsynet.no or your local EU supervisory authority.
This document is provided in good faith and is not legal advice.