Privacy Notice
QuestKeep is in beta. We wrote this page ourselves and no lawyer has reviewed it. It describes honestly what QuestKeep does with data today, and it will change as the product does.
Last updated Aug 25, 2026
This page explains what QuestKeep does with your family's data, in plain words. Wittenberger Industries is the controller. We collect as little as we can, we do not advertise to you, and we run no trackers.
Who is responsible
QuestKeep is built and operated by Wittenberger Industries, registered in Romania, and we are the data controller for everything described here. Our registered company name and registration number (CUI) are available on request.
Contact is via in-app feedback from Family settings.
This describes a beta
QuestKeep is in beta, so this notice describes a moving product. Where something is planned rather than built, we say so instead of describing it as if it already worked.
What we hold about a guardian
The email address you sign in with, an identifier from our sign-in provider, your family's timezone and currency, and the settings you choose. If you write to us, we hold what you wrote.
We do not ask for your postal address, your phone number, or your date of birth.
What we hold about a child
A display name, an avatar picked from a small set of drawings we ship, and a PIN stored as a hash. That is all.
There is no email address, no phone number, no photo upload, and no contact detail for a child anywhere in QuestKeep. The PIN is hashed with argon2id and never stored as digits, and the cookie that keeps a child signed in on the family device carries internal identifiers only — never a name, an avatar, or a PIN.
Why we process it
To run the family's Keep: to sign a guardian in, to show each adventurer their quests and coins, to keep one family's data separate from every other family's, to send the few account messages QuestKeep sends, and to keep the service secure and working.
Our legal bases are the contract with the guardian for running the account, our legitimate interest in keeping the service secure, and consent where the law asks for it.
Children and parental consent
QuestKeep is designed to be set up by a parent or guardian for their own children. A child cannot create an account; a child's profile exists only because a guardian created it.
The guardian who holds the account is the one who consents to us handling their child's data, and can change or delete an adventurer profile at any time from the family settings.
No ads, no tracking
There is no advertising in QuestKeep, no behavioural profiling, and no third-party tracker or analytics SDK — not on the guardian surfaces and certainly not on the children's. We have not added an analytics product at all. If we ever add product analytics, it will be cookieless and privacy-first, and this page will say so before it ships.
Where your data lives
Your family's data is stored in the European Union, in Microsoft Azure's West Europe region, and the application runs in the EU as well.
If staff file a Feedback note internally, a short reference — the category and an opaque ticket id, not the message you wrote — may be stored in GitHub's engineering tracker in the United States.
Who processes it for us
Five processors handle data on our behalf today.
Microsoft Entra External ID handles guardian sign-in, password reset, and multi-factor authentication — children never touch it. Azure App Service runs the application. Azure Database for PostgreSQL stores your family's data. Azure Communication Services sends the account messages QuestKeep sends, which today means guardian invitations only. GitHub, Inc. holds a staff-only stub (category, ticket id, and app version) when an operator files a Feedback note to our private engineering tracker — the message itself stays in our EU database and is not posted there.
That is the whole list. If it grows, this page changes with it.
Payments
We are not charging anyone during the beta, so no payment data has been collected. When paid plans start, checkout will happen off our servers on the payment provider's own pages, so card numbers never reach QuestKeep — all we will see is whether a family's subscription is active. That provider will be named in the processor list above before it goes live.
How long we keep it
We keep a family's data while the account exists. Delete an adventurer profile and its profile data goes with it; delete the family account from Family settings and we remove it, including the Feedback message you sent. A non-message staff stub on GitHub may remain after that wipe; it cannot by itself identify the family once the ticket is gone. Some records — the coin ledger of an active family, or a security record — stay while they are still needed for the account to make sense, and account messages may sit in our email provider's logs for a short while.
Your rights
Under the GDPR you can ask for a copy of your family's data, ask us to correct it, ask us to delete it, object to how we use it, or complain to a supervisory authority. In Romania that authority is ANSPDCP.
These rights are yours by law today, whatever tooling we have built.
What you can do today
In the app right now a guardian can log every family device out remotely, reset a child's PIN, deactivate or delete an adventurer profile, and change the family's settings.
From Family settings a guardian can also download a copy of the family's data and delete the whole family account. That download is the data QuestKeep holds; it is not a dump of GitHub.
From Family settings a guardian can also send us a message.
Security
Guardian sign-in is handled by Microsoft Entra External ID, so we never see or store a guardian password. Child PINs are stored as argon2id hashes, with a lenient pause after repeated wrong guesses. Every family's rows are kept apart both in the application and by PostgreSQL row-level security in the database, and the application connects to that database as a restricted, non-owner role. Traffic runs over HTTPS.
No system is perfect and QuestKeep is in beta, so please do not keep anything in it that would hurt you to lose.
Changes to this notice
When QuestKeep changes what it does with data, we change this page and the date at the top. For a change that matters we will tell you in the app before it takes effect.