Eonquest
Privacy Policy

Eonquest Privacy Policy

Last updated: 26 August 2026

Eonquest has not launched yet — expected around early November 2026. This document is published ahead of the launch and takes effect when the app becomes available.

This policy explains what personal data the Eonquest mobile app (“Eonquest”, “the app”) collects, why, who it is shared with, and the choices and rights you have. It applies to the app and its backend service. It does not cover third-party services that have their own privacy policies, which are linked below.

Who is responsible for your data

The data controller for Eonquest is SG Software Development (Szymon Gaweł), based in Poland. For any privacy question or request, contact eonquest@sgsoftware.pl.

What we collect and why

We collect only what the app needs to work. We do not sell personal data, and we do not use your content or activity to train AI models.

DataWhyLegal basis (GDPR Art. 6)
Email addressAccount identity, sign-in, account-related messagesPerformance of a contract — Art. 6(1)(b)
Display namePersonalising the appArt. 6(1)(b)
Password (stored only as a salted hash)Securing email/password accountsArt. 6(1)(b)
Sign-in provider identifier (Google or Apple subject ID) when you use social loginLetting you sign in with that providerArt. 6(1)(b)
Time zoneReleasing the daily quest at 6:00 in your local timeArt. 6(1)(b)
Quest activity — claims, completions, 1–5 ratings, streaks, badges, category selectionsProviding the core service and tracking your progressArt. 6(1)(b)
Text you type to create a custom interest categoryGenerating a category and quests, and moderating that input for safetyArt. 6(1)(b) and our legitimate interest in keeping the service safe — Art. 6(1)(f)
Subscription tier and status; purchase events from the stores / RevenueCatGranting paid features and reconciling subscriptionsArt. 6(1)(b)
Push notification tokenSending the daily quest reminder you opted intoConsent — Art. 6(1)(a)
Advertising and device identifiers (Free tier only — see Advertising)Showing ads that fund the free tierConsent — Art. 6(1)(a) in the EEA/UK
IP address, request metadata and server logsSecurity, rate-limiting, abuse prevention and debuggingLegitimate interest — Art. 6(1)(f)

If you sign in with Apple and choose to hide your email, Apple gives us a private relay address instead of your real one; email we send to it is forwarded by Apple.

AI-generated content

Quests and custom categories are produced by an automated system using Anthropic’s Claude API. When you create a custom category, the text you type is sent to Anthropic to generate the category and its quests and to screen the input for offensive, dangerous or illegal content. Minimal, non-identifying context (such as a category name and recent quest titles, to avoid repetition) is sent when generating a quest. We do not send your email, name or account identifiers to Anthropic. Anthropic processes this data as our service provider and, under its commercial terms, does not use it to train its models. Please do not enter other people’s personal data as category input.

Advertising (free tier)

Eonquest shows banner ads to users on the free tier only, through Google AdMob. Paid subscribers see no ads and no ad SDK activity. Where required (EEA, UK and similar), the app asks for your consent before any personalised advertising and before an advertising identifier is used; you can change this choice later in your device settings. Depending on your consent, AdMob may process an advertising ID, IP address, and ad-interaction data to select and measure ads. See Google’s advertising policy.

Who we share data with

We share data only with service providers that help us run Eonquest, each under a data processing agreement, and with the app stores for payments. These are:

ProviderPurposeLocation
Anthropic, PBCGenerating and moderating quests and custom categoriesUSA
RevenueCat, Inc.Managing and validating subscriptions (uses a random app-user ID, not your email)USA
Google (AdMob)Serving and measuring ads to free-tier usersUSA / global
Google & AppleSign-in (if you use it) and subscription payment processing; we never receive card detailsUSA / global
Expo (650 Industries, Inc.)Delivering push notificationsUSA
Railway / hosting providerRunning the backend and its PostgreSQL databaseEU / USA region

We may also disclose data where required by law, or to establish, exercise or defend legal claims. If the service is ever transferred to another operator, we will require them to honour this policy and will notify you in the app.

International transfers

Some providers listed above are located in the United States. Where personal data is transferred outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Contact us for more detail on the safeguards used for a specific provider.

How long we keep data

  • Account and activity data — kept while your account exists. When you delete your account, this data is permanently erased, cascading to your quests, ratings, rerolls, category selections, push token and session tokens, normally within 30 days.
  • Purchase and subscription-event records — kept for up to 24 months for financial reconciliation, tax and dispute handling, then deleted or anonymised.
  • Server logs — typically 30–90 days.
  • Backups — deleted data also disappears from backups on the backup rotation cycle, within about 35 days.

Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable form, and withdraw any consent at any time (without affecting processing already carried out). You can delete your account and its data directly in the app (Settings → Delete account) or via the deletion page. For any other request, email eonquest@sgsoftware.pl.

If you believe we have handled your data unlawfully, you may lodge a complaint with your local supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

Security

Passwords are stored only as salted hashes. Data is encrypted in transit with TLS. Sign-in uses short-lived access tokens with rotating refresh tokens, and tokens are held in the device’s secure storage (Keychain / Keystore). Access to production systems is limited to what is needed to operate the service. No system is perfectly secure, but we take reasonable measures to protect your data.

Children

Eonquest is not directed to children under 13, or under the minimum age of digital consent in your country (up to 16 in parts of the EU). We do not knowingly collect data from children below that age. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy. The “Last updated” date at the top always reflects the current version, and we will notify you in the app or by email of material changes before they take effect.

Contact

SG Software Development (Szymon Gaweł)eonquest@sgsoftware.pl