Privacy Policy

Effective date: May 12, 2026

1. Introduction

Quest Backlog ("we", "us", or "our") is a social video game backlog tracker. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, mobile application, and related services (collectively, the "Services").

2. Information We Collect

2.1 Account Information

When you create an account, we collect your username, display name, email address, and password (stored as a secure hash). If you sign in with Google, we receive your Google subject ID, email, and name from Google's authentication service.

2.2 Profile Information

You may optionally provide a bio, profile avatar, game interests, platform preferences, and privacy settings. You control what is visible on your public profile through privacy settings.

2.3 Content You Create

We store the posts, comments, reviews, game statuses, ratings, hours played, and images you upload to the Services. Images are processed for moderation before being displayed.

2.4 Social Activity

We store your follows, blocks, likes, direct messages, and notifications to enable the social features of the platform.

2.5 Device and Technical Information

We collect push notification tokens (for mobile notifications), device platform (iOS/Android), and your IP address (for session security and rate limiting). We do not collect precise location data or access your contacts.

2.6 Cookies and Local Storage

We use essential cookies for authentication (session cookies) and a viewer hint cookie for UI state. We also store your theme, language, and feed preferences in local storage (web) or secure storage (mobile). We do not use tracking or advertising cookies.

3. How We Use Your Information

  • To provide and maintain the Services (profiles, feeds, search)
  • To enable social features (follows, posts, comments, messages)
  • To send transactional emails (verification, password reset)
  • To send push notifications (optional, for activity alerts)
  • To moderate content and enforce community guidelines
  • To prevent abuse, spam, and unauthorized access
  • To improve the platform based on usage patterns

4. Data Sharing and Third Parties

We do not sell your personal data. We share data only with the following service providers:

  • Google — For sign-in authentication (Google Sign-In) and push notification routing (Firebase Cloud Messaging on Android).
  • IGDB (via Twitch) — For game catalog data. No user data is shared; only search queries are sent.
  • Steam — Only when you choose to link your Steam account. We fetch your library, playtime, and achievement data with your consent.
  • Resend — For sending transactional emails (verification and password reset).
  • Cloudflare R2 — For storing uploaded images (avatars, post/comment images).
  • Expo — For push notification delivery on mobile devices.

5. Data Retention

We retain your data for as long as your account is active. You can delete your account at any time from Settings. Upon deletion, your personal data and content are removed from our systems within 30 days, except where retention is required by law or for legitimate security purposes.

6. Your Rights and Choices

  • Access and update — Edit your profile, posts, and settings at any time.
  • Privacy controls — Control who can message you, see your online presence, and discover you through game interests.
  • Block users — Block any user to stop all interaction and visibility.
  • Delete account — Permanently delete your account and all associated data from Settings.
  • Push notifications — Disable push notifications in your device settings or app settings.

7. Children's Privacy

Quest Backlog is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it.

8. Security

We use industry-standard security measures including encrypted connections (HTTPS), hashed passwords (scrypt), httpOnly session cookies, and access controls. However, no online service is 100% secure, and we cannot guarantee absolute security.

9. International Data Transfers

Your data may be stored and processed on servers located in the United States. By using the Services, you consent to this transfer.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by email. Continued use of the Services after changes constitutes acceptance.

11. Contact Us

If you have questions about this Privacy Policy or your data, please contact us at: [email protected]