Privacy Policy – Urban Quest
Effective Date: September 15, 2026
This Privacy Policy describes how Blue Pelican Digital LLC (“we,” “us,” or “our”) collects, uses, and shares information when you use our mobile application Urban Quest (the “App”) and our creator website, together the “Service”. Urban Quest is a location-based interactive storytelling experience that uses GPS to guide you through real-world locations.
The App is available on iOS in approximately 171 territories, including the European Economic Area and the United Kingdom. This policy is intended to meet Apple App Store privacy and location disclosure requirements, Google Play data-safety requirements, the EU and UK General Data Protection Regulation, and California privacy law.
If you only want the short version: we collect what we need to run a GPS game and pay our creators, we do not sell your location, uploaded media is public by design for as long as it is stored, and most of it is deleted when you delete your account, and you can delete your account at any time — Section 6 explains exactly what that does and does not remove.
1. Information We Collect
a. Account Information
You can browse quests without an account. You need an account to start a quest, buy a quest, or create one. You can create an account in three ways:
- Sign in with Apple or Sign in with Google — we receive the account identifier the provider gives us (a subject ID), your email address, your name, and your profile picture, where the provider supplies them.
- Email and password — we store your email address and a cryptographically hashed version of your password (scrypt). We never store your password in readable form and we cannot recover it for you.
You may also set a display name, avatar, and — if you publish quests — a creator profile with a short bio.
You cannot currently change the email address on your account from inside the App. If it needs to be corrected, email us at support@urbanquestapp.com and we will change it for you.
At sign-up we ask for your date of birth on a neutral age screen. It is used to confirm you meet the App’s minimum age of 13; we do not create an account for anyone under 13. We store the result of that check (a yes/no flag), not your date of birth. See Section 9.
b. Location Information (Required for Core Functionality)
The App collects precise location information (GPS) to enable its core functionality.
We use your location to:
- Guide you through story locations and real-world stops
- Detect when you arrive at a waypoint and unlock the story content tied to it
- Keep your progression through a quest accurate
While you are actively playing a quest leg, the App keeps reading your location after you switch away from it, so it can detect arrival at a waypoint and alert you even when the App is not open. On iOS this uses the “Always” location permission. On Android, version 2.1 and later run a foreground service with a permanent notification for the length of the leg and do not request background location at all; version 2.0, which is the release still available on Google Play at the time of writing, uses Android’s background-location permission for the same purpose. This stops when the quest leg ends, and outside an active quest the App reads your location only while it is in the foreground. We never receive this gameplay location stream — your position is compared with the next waypoint on your own device. The map screens do show your position on a map, which means the map provider named in Section 4 receives it in order to draw the tiles.
Your precise location is used for gameplay proximity only. We do not sell it and we do not share it with advertisers.
If you do not allow location access, the App will not function as intended.
c. Content You Create and Upload
If you create content with our creator tools, we collect and store it so we can make it available to players. This includes:
- Quest titles, descriptions, scene scripts, questions, and answer choices
- Cover images, scene images, audio, and video you upload
- Your creator profile name, avatar, and bio
By submitting content, you grant us the licenses described in our Terms & Conditions.
Please read this before you upload anything. Media files you upload (images, audio, and video) are stored in a cloud storage bucket that is publicly readable by anyone who has the file’s web address. Access to that file is not restricted by our app permissions. This means that even if a quest is unlisted, in draft, or never published, the media inside it should be treated as public — a person who obtains or guesses the URL can open it. Deleting a waypoint, a quest, or your account also removes the files it held from storage, unless another record still points at the same file — see Section 6 for the exceptions. Do not upload anything you would not be willing to publish, and do not include other people’s private information, faces, or documents in uploaded media.
d. Scouted Waypoints
Our creator scouting tools let you capture a candidate location while you are standing in it. When you do, we collect the GPS coordinates of that point, together with any photos, video, or audio you record there and any notes you add. Unlike the location the App uses during play, these coordinates are sent to our servers and stored under your account, and they stay there until you delete the waypoint or your account. Scouted waypoints are used to help you build quests. The media you capture is stored in the same publicly readable bucket described in Section 1(c).
If you build a quest from a scouted point and publish it, that point’s coordinates become part of the published quest — they are shown to players on the quest’s map, and for a free quest anyone can retrieve them. Published quests are kept when you delete your account (Section 6), so those coordinates are kept too. Scout places you are willing to send other people to, and not your home or anywhere else you would not publish.
e. Device Permissions the App Requests
To let you capture and attach media, the App asks your device for access to the camera, the microphone, and your photo library, in addition to location. We use each of these only when you actively use a feature that needs it — taking a photo or video for a waypoint, recording an audio note, or choosing an existing image or video to attach. You can grant or revoke any of them in your device settings; declining them does not stop you playing quests, but you will not be able to capture or attach that kind of media.
f. Reviews, Ratings, and Feedback
We collect the reviews and star ratings you submit for quests, and the messages you send us through the in-app feedback form. Reviews and ratings are shown to other users and are associated with your display name. Feedback messages are not published; we use them to fix problems and improve the App, and they are associated with your account so we can reply. Feedback messages are deleted when you delete your account — see Section 6.
g. Reports and Blocks
If you report a quest or a review, we store the reason you selected, any free-text details you write (up to 1,000 characters), what you reported, and the fact that you filed it. If you block another user, we store that block. We keep both so our moderation team can act on them, keep a record of what was decided, and identify repeat or abusive reporting.
Because other users can report content too, reports written about you by other people are stored and kept as well, including the free text they wrote. Reports are retained after account deletion and after moderation is complete; blocks are deleted when either the blocking or the blocked account is deleted — see Section 5.
h. Push Notifications
If you allow notifications, we store the push notification token your device issues. We use it for two things:
- Creator notifications — telling you about quests you submitted, for example that a quest of yours has been approved and is live.
- Announcements to everyone — occasionally we send a single message to every device registered with the App, composed by us. These are service and product announcements — for example, that a new feature or the Premium subscription has launched. This is an announcement channel, not a personalized one: the message is the same for everyone and is not based on anything we know about you.
The “you have arrived” alert is not a push notification. It is generated by the App on your own device when it detects that you have reached a waypoint. It does not use your push token and it does not involve our servers.
You can turn notifications off at any time in your device settings, and you will stop receiving them. Turning them off does not delete the stored token. The token is removed when you sign out of that device inside the App, when you delete your account, or when the push service tells us on a later send that the device is no longer registered. See Sections 5 and 6.
i. Usage, Server, and Diagnostic Data
We automatically collect limited technical information, including:
- App interactions and story progress
- Device type and operating system
- IP addresses recorded in our server logs, along with the requests your device makes to our servers
- Server-side error reports. These are generated on our servers when something goes wrong. An error report may contain the request path, any query parameters on it, and your IP address. It does not contain the request body, your authorization credentials, or your cookies — we strip those before the report is sent. We do not run a crash-reporting or performance-monitoring SDK of our own inside the App, and we do not collect performance traces of our own. The Google Mobile Ads SDK we bundle to serve ads does, however, collect crash data, performance data, and other diagnostic data about the App and send it to Google, as Google declares in that SDK’s own privacy manifest. Google states that this data is not linked to your identity, and it does not reach us. See Section 1(j).
We use this to keep the Service running, secure, and debuggable.
j. Advertising and the Advertising Identifier
Free quests are supported by ads served through Google AdMob. Ads appear only on free quests, as a single interstitial when you finish a quest; Premium subscribers see no ads at all. To request and measure these ads, the App and AdMob may access your device’s advertising identifier (the IDFA on iOS or the Advertising ID on Android), along with limited device and usage information. Google’s ad SDK also collects crash data, performance data, and other diagnostic data about the App for Google, which Google declares as not linked to your identity. The ad SDK starts when the App starts, so this applies to every install — including Premium subscribers, who are never shown an ad.
On iOS, we ask for your permission through Apple’s App Tracking Transparency (ATT) prompt before any tracking takes place. In the European Economic Area and the United Kingdom, we present a Google User Messaging Platform (UMP) consent form. If you decline, you will still see ads, but they will be non-personalized (less relevant).
Where personalized ads are served, Google may use the advertising identifier to link what you do in Urban Quest with what you do in other apps and websites in order to choose the ads you see. That is what the iOS tracking prompt is asking about.
These prompts appear the first time you open the App — before you sign in and before you play anything — and Google’s advertising component starts up at the same time. This happens for every user, including Premium subscribers, who are never shown an ad.
How to change your ad choices later depends on where you are:
- In the EEA and the UK, open Profile → Ad Privacy in the App to reopen the consent form and change your answer. You need to be signed in to reach that screen; if you are signed out, use your device’s advertising-identifier settings instead.
- Everywhere else, there is no in-app control. The iOS tracking prompt is shown once and cannot be reopened; to change that answer, go to iOS Settings → Privacy & Security → Tracking. On Android, use your device’s advertising-ID settings.
We do not share your precise (GPS) location with advertisers; AdMob may infer your approximate location from your IP address as described in Google’s policies. Players who subscribe to Premium do not see ads. For more information, see Google’s Privacy Policy at policies.google.com/privacy and “How Google uses information from sites or apps that use our services.”
k. Our Own Record of Ads You Were Shown
Separately from what AdMob receives, we keep our own record on our servers of each ad shown to you. Each record contains your account identifier, the quest and (where applicable) the scene you were in, the store your app came from (iOS or Android), and the time. We keep this because creator ad earnings are allocated in proportion to the ad impressions their quests generated, and because it lets us detect inflated or fraudulent impression counts.
This record is not deleted when you delete your account — but the account identifier is removed from it at that point, so what survives no longer identifies you. It is not shared with advertisers.
2. How We Use Your Information
We use collected information to:
- Operate and provide the App’s core features
- Deliver location-based story content and detect waypoint arrival
- Authenticate sign-in and maintain your account
- Publish, distribute, and moderate creator content, and act on reports and blocks
- Process purchases and subscriptions, verify store receipts, and calculate and pay creator earnings
- Count ad impressions so creator ad revenue can be allocated, and detect manipulated counts
- Send creators notifications about quests they submitted, and occasional service or product announcements to all devices
- Provide customer support and respond to your feedback
- Improve performance, reliability, and usability, and investigate errors
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with legal, tax, and accounting requirements
We do not use your account information or your precise (GPS) location to target ads. Free quests display ads served by Google AdMob using your device’s advertising identifier, as described in Section 1(j) and subject to your ATT and consent choices.
3. Payments, Subscriptions, and Creator Payouts
Purchases. In-app purchases and subscriptions are sold by the app store you downloaded the App from, and that store is the merchant of record for every transaction — Apple through the App Store, and Google Play where the App is distributed on Android. You buy from the store, not from us and not from the creator of a quest.
We never receive, collect, or store your card number or full payment details. Your payment information is handled by the app store you bought from, under its own privacy policy.
Receipt checking. We use RevenueCat to check store receipts with the app store and to manage your Premium subscription status. Your access to individual paid quests is recorded and controlled by us, on our own servers.
RevenueCat is configured anonymously: it does not receive your Urban Quest user ID, your name, or your email address. It does receive store transaction and receipt data, and — like any mobile SDK — basic device and app information from your device, such as a device identifier, device model and operating system, app version, locale and country, and the IP address your request comes from. RevenueCat does not bill you and does not issue refunds.
Automated receipt verification. We check purchase receipts with the store, both at the time of purchase and afterwards. If the store reports that a purchase has been refunded or cancelled, access to that purchase is removed automatically, without a person reviewing it first, and we may also remove access automatically where a receipt cannot be confirmed with the store. If you believe this happened in error, email support@urbanquestapp.com and a person will look at it. See Section 7.
Refunds. We do not process refunds. All refund requests are handled by the store you bought from — Apple at reportaproblem.apple.com, and Google Play for Android purchases at play.google.com/store/account/orderhistory.
Creator payouts. If you receive creator payouts, payouts are processed by Stripe through Stripe Connect Express. During onboarding you enter into Stripe’s Connected Account Agreement directly with Stripe, and you provide your identity, tax, and banking information directly to Stripe under its own privacy policy (stripe.com/privacy). We do not collect or store your bank details or your government identification. On our side we store only a reference to your Stripe account, its onboarding status, and the amounts we transfer to you. We send Stripe your email address, the transfer amounts, and our internal account identifier for you.
4. Data Sharing and Service Providers
We do not sell your personal information for money, and we do not sell or share your precise location.
We use the service providers below to run the Service. Each one receives only what it needs for its stated purpose, and each is bound by its own agreement and privacy policy.
Accounts and sign-in
- Apple — receives and verifies your Sign in with Apple request; returns your account identifier and, if you allow it, your email and name. Why: authentication.
- Google — receives and verifies your Sign in with Google request; returns your account identifier, email, name, and profile picture. Why: authentication.
Purchases and money
- Apple / Google Play — merchant of record for in-app purchases and subscriptions; they hold your payment details, not us. Why: billing, refunds, and cancellations.
- RevenueCat — receives store transaction and receipt data, plus basic device and app information and the IP address of the request, from its SDK on your device. Our servers additionally send RevenueCat the store’s transaction identifier for a purchase, so we can confirm the purchase is genuine and has not been refunded. It does not receive your Urban Quest user ID, name, or email address from us. Why: checking receipts with the store and managing Premium status.
- Stripe — for creators only: receives your email address, your transfer amounts, and our internal account identifier for you, and collects your identity, tax, and bank details directly from you. Why: paying creator earnings.
Advertising
- Google AdMob and the Google User Messaging Platform (UMP) — receive your device’s advertising identifier, ad event data, and an approximate location inferred from your IP address. Google’s own privacy manifests for these SDKs also declare that they collect crash data, performance data, and other diagnostic data about the App, not linked to your identity; that data goes to Google and not to us. Why: serving and measuring ads in free quests, and recording your consent choice. In the EEA and UK, personalized ads are served only if you consent through the UMP form; if you refuse, ads are non-personalized. Outside the EEA and UK we do not ask for a separate advertising consent and ad requests are personalized by default — on iOS, subject to the App Tracking Transparency choice described in Section 1(j).
Hosting, storage, and diagnostics
- Railway — hosts our servers and database; its systems process everything you send us, including application logs containing IP addresses. Why: running the Service.
- Netlify — hosts our creator website. Netlify receives the IP address, browser user agent, and requested page of everyone who visits that site. Why: serving the creator website.
- Bluehost — hosts urbanquestapp.com, the website this policy is published on, together with our support page and our account-deletion page. Bluehost, and the content-delivery layer it operates in front of that site, receive the IP address, browser user agent, and requested page of everyone who visits it. Why: serving our public website.
- Cloudflare R2 — stores all uploaded media (images, audio, video), and separately holds our disaster-recovery database replicas. The media storage is publicly readable by URL — see the notice in Section 1(c). Files are removed from it when the content or the account that holds them is deleted, unless another record still points at the same file. The database replicas live in a separate, private bucket that is not publicly readable, and are retained for 72 hours before being overwritten. Why: storing and delivering media, and disaster recovery.
- Sentry — receives server-side error reports. We remove authorization and cookie headers and the entire request body before a report is sent, and we redact WebSocket credentials from URLs. Error reports may still contain the request path, any query parameters on it, and your IP address. Why: finding and fixing server errors. Sentry receives errors only — performance tracing is switched off — and we run no Sentry or other crash-reporting SDK of our own inside the mobile App. The crash, performance, and diagnostic data collected by the bundled Google Mobile Ads SDK goes to Google, not to Sentry; see the Advertising entry above and Section 1(i).
Messaging
- Resend — receives your email address when we send you a password-reset email. It also receives, in the internal notices our system emails to our own support address so a submission or a report is not missed: your display name; the title of a quest you submit for review or that someone reports, together with the details you entered for it — including the city, which is free text you type yourself, plus its price, its scene count and whether it is unlisted — and whether the submission is a first submission or a resubmission, including whether that resubmission follows a rejection, follows an approval, or is of a quest that is live with unreviewed edits; the reason category the reporter picked from our list (for example “Harassment or bullying”), which is another person’s classification of you or your content and which appears in the notice’s subject line as well as its body; the free-text description a reporter writes when reporting content (which is whatever that person chose to type, and can therefore mention other people); a short label identifying what was reported — for a reported review, its star rating and the title of the quest it is on; for a reported scene, the title of the quest it belongs to and its position in that quest (for example “Scene 2 of …”); for a reported quest, whether that quest is a draft, published, or archived; for a report about a person, that person’s display name; and the internal record identifier of the reported item — for a report about a person, that identifier is our own account id for them. The daily summary of what is waiting also carries, for each quest in it, how long it has been waiting or how long ago it was edited, whether it is public right now, and whether its scene media is missing, and, for each open report, the reason category, what kind of thing was reported and how long it has been open. We never put your email address in those notices. It is not used for marketing. Why: transactional and internal operational email.
- Expo push notification service — receives your device’s push token and the notification content, and passes the notification on to Apple’s Push Notification service for delivery to your device. On the Android release of the App, the same notification is passed to Google’s Firebase Cloud Messaging instead. Why: delivering creator notifications and the occasional all-device announcement described in Section 1(h).
Content generation tools
- Anthropic (Claude) — receives quest text (titles, descriptions, scene scripts, questions, and answer choices) when we produce an adapted edition of a quest for another city, or when we use our internal story-writing tool. This is administrator-initiated and is not triggered by ordinary play. Why: drafting and adapting quest text.
- Replicate — receives scene script text to generate narration audio. Why: text-to-speech narration.
Maps, places, and fonts
- Apple (MapKit) — on iOS, the maps inside the App are rendered by Apple. Your device requests map tiles from Apple for the area you are viewing. Why: showing the map in the App.
- Google Maps Platform — on our creator website, your browser requests map tiles and sends the text you type into place search. On the Android release of the App, the in-app maps are also rendered by Google Maps, so your device requests map tiles from Google for the area you are viewing. Why: showing maps and letting creators find and place waypoints.
- OpenStreetMap (Nominatim and Overpass) — receives the coordinates of a quest’s first waypoint, and city names, when we work out or refresh the city label for that quest. It also receives what you type into the “Search a city, address, or landmark” box in the mobile app’s quest browser, so it can suggest matching places. We send the text to OpenStreetMap to get those suggestions and we do not store what you typed. This happens for draft quests as well as published ones: adding, moving, or removing the first waypoint far enough from the quest’s stored start point triggers the lookup. Why: naming and locating quests.
- Google Fonts — our creator website loads its typefaces from Google’s font service, so visiting the creator website sends your IP address and browser user agent to Google on page load. This does not apply to the mobile App. Why: website typography.
We may also disclose information:
- For legal compliance — if required by law, regulation, or valid legal process, or to protect our rights, users, or the public.
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this policy.
Depending on where you live, allowing personalized advertising may be considered a “sale” or “sharing” of personal information under laws such as the California Consumer Privacy Act. You can opt out at any time: in the EEA and UK through Profile → Ad Privacy in the App (you must be signed in to reach it; if you are signed out, use your device’s advertising-identifier settings); elsewhere through iOS Settings → Privacy & Security → Tracking or your Android advertising-ID settings. See Section 1(j).
5. Data Retention
We keep information for different lengths of time depending on what it is.
- Account record (identifiers, email, display name, hashed password) — kept while your account exists. When you delete your account, the record is anonymized rather than removed, as described in Section 6.
- Location during play — compared with the next waypoint on your own device and never sent to us. We do not receive, build, or keep any history of your movements.
- Scouted waypoint coordinates — the precise coordinates you capture with the creator scouting tools are stored on our servers under your account for as long as the account exists, and are deleted when you delete your account. If you place one of those points into a quest and publish it, the coordinates are copied into the quest and are kept with the published quest, which survives deletion of your account — see Sections 1(d) and 6.
- Quest progress and completion history — stored on the purchase record for each quest, and deleted with that record when you delete your account.
- Published quests — kept for as long as the quest is published, because other players’ history and reviews depend on it. If you delete your account, the quest itself is kept but stops appearing in the App’s public browse listings; it still resolves for players who already hold access or have a direct link. See Section 6.
- Uploaded media files (images, audio, video, including scouted-waypoint captures and media in draft quests) — deleted from storage together with the record that holds them, unless another record still points at the same file. Deleting your account removes your profile picture and the media inside your scouted waypoints and your draft and archived quests; media inside quests you published stays, because the published quest stays. Removal is best effort: if our storage provider is unavailable at that moment the deletion still completes and the file is left behind. While a file is stored, it is reachable by its URL — see Section 1(c) and Section 6.
- Draft quests and scouted waypoints — the database records are kept while your account exists and are deleted when you delete your account, together with the media files attached to them.
- Reviews and ratings — kept while your account exists; deleted when you delete your account.
- In-app feedback messages — kept while your account exists; deleted when you delete your account.
- Moderation reports — retained indefinitely, including after the report is resolved and after either party deletes their account. This includes reports other users filed about you and the free text they wrote. We keep them as the record of moderation decisions and to identify repeat abuse. User blocks are deleted when either the blocking or the blocked account is deleted.
- Ad-impression records (which ads you were shown, and when) — retained for creator revenue accounting and fraud detection, including after account deletion; the link to your account is removed at deletion, so the surviving record no longer identifies you.
- Push notification tokens — kept until you sign out of that device in the App, until you delete your account, or until the push service reports on a later send that the device is no longer registered.
- Server logs, including IP addresses, and error reports — kept for a limited period for security, abuse investigation, and debugging, then rotated out.
- Purchase and entitlement records — kept while your account exists so we know what you can play; deleted on account deletion. The underlying financial and ledger records (transactions, earnings, payouts, refunds) are retained separately for as long as tax and accounting law requires, even after deletion.
- Backups — our database is continuously replicated for disaster recovery. Replicas are kept on a rolling 72-hour window and are then overwritten, so copies of deleted data may persist for up to 72 hours after deletion.
Where we are required to keep something by law, or need it to resolve a dispute or prevent fraud, we keep the minimum necessary for that purpose and nothing more.
6. Your Privacy Choices and Account Deletion
You may:
- Enable or disable location access at any time in your device settings. Disabling it will prevent the App from delivering its core experience.
- Enable or disable camera, microphone, and photo-library access at any time in your device settings.
- Turn push notifications off at any time in your device settings. You will stop receiving them; the stored token is removed when you sign out of that device in the App, or when the push service reports the device as unregistered.
- Change your advertising choices. In the EEA and UK, open Profile → Ad Privacy in the App to reopen the consent form. Elsewhere there is no in-app control: use iOS Settings → Privacy & Security → Tracking, or your Android advertising-ID settings. The iOS tracking prompt appears only once and cannot be reopened.
- Correct your own profile in the App. Your display name, bio, and listed genres can be changed at any time under Profile → Edit Profile. Your email address and profile picture are not editable in the App — see Section 1(a).
- Request access to a copy of your personal information, or ask us to correct something you cannot change yourself, by emailing support@urbanquestapp.com. We assemble these by hand — see “Getting a copy of your data” below.
We send transactional email only — for example, password resets. We do not send marketing email. We do occasionally send a push announcement to every device, which may include product news such as a feature or subscription launch; turning off notifications in your device settings stops these. See Section 1(h).
Getting a copy of your data
We do not currently have a self-service export tool. If you ask, we assemble your data by hand from our systems and send it to you in a commonly used format. Email support@urbanquestapp.com from the address on your account and tell us what you want. We will respond within one month.
How to delete your account
You have two routes, and both work:
- In the App — open your profile settings and choose Delete Account.
- On the web — see the step-by-step instructions at https://urbanquestapp.com/account-deletion/, which also cover you if you have already uninstalled the App. You can also email support@urbanquestapp.com with the subject line “Account Deletion Request” from the email address on your account.
What deletion actually does
We want to be accurate about this rather than reassuring. Some of what follows is not flattering.
Your user record is anonymized, not erased. We overwrite the identifying fields — your email address, sign-in identifiers, display name, avatar, bio, and listed genres — with non-identifying placeholder values, and the account can no longer be signed into. We do this rather than deleting the row outright so that quests you published, and the play history and reviews other users built on them, do not break.
The anonymized record still contains the sign-in provider you used (Apple, Google, or email), the date the account was created, and the result of the 13+ age check. If you were a creator with payouts set up, the reference to your Stripe account and its onboarding status are cleared from our record when you delete. That does not delete the Stripe account itself: Stripe holds the identity, tax, and banking details you gave it directly and retains them under its own policy. Contact Stripe to have that account deleted, or ask us and we will make the request on your behalf.
Deleted from our database:
- Draft and archived quests, and their waypoints and scenes
- Scouted waypoint records, including the coordinates and the notes attached to them
- Reviews and ratings you submitted
- Your purchase and entitlement records
- The in-app feedback messages you sent us
- The push-notification registrations for every device signed in to your account
- Blocks in both directions — the users you blocked, and the users who blocked you
- Your narration usage counters
- Any outstanding password-reset tokens
NOT deleted — please read this part.
- Media inside quests you published. A quest you published survives your deletion (see below), and so does the media inside it — cover image, scene images, narration audio, and video. It stays reachable by URL.
- Media files another record still points at, or that we could not remove. Before removing a file we check whether anything else still references it — a city edition of your quest, a shared narration clip, or a surviving published quest — and if something does, the file stays. Removal is also best effort: if our storage provider is unavailable at that moment, your account deletion still completes and the file is left behind. Any file that survives for either reason remains reachable by anyone holding its URL (see Section 1(c)). If you believe a specific file should have been removed and has not been, email support@urbanquestapp.com with the subject line “Media Deletion” and tell us which ones; we will remove them by hand.
- Moderation reports — both those you filed and those filed about you, including the free text.
- Ad-impression records of which ads were shown, and when. The rows survive because creator ad earnings are allocated in proportion to them, but your account identifier is removed from them when you delete your account, so what remains no longer records which ads you were shown.
Kept, but no longer identifying you:
- Quests you already published, and the media inside them. The quest is retained and remains playable for anyone who already holds access or has a direct link, and the authorship no longer identifies you — but the quest is removed from the App’s public browse listings, because those listings exclude quests whose author has been deleted. Your reviews are not retained at all — they are deleted outright, as stated above.
Retained:
- Financial and ledger records — transactions, earnings, payouts, and refunds — which we keep for accounting and tax purposes. Any earned balance you are owed is not cancelled by deleting your account.
Deletion reaches some of our service providers, but not all. Deleting your account removes the stored files it held from our media host, and removes your push registrations, so the push notification service is never asked to reach your devices again. It does not send a deletion instruction to our error-reporting provider, RevenueCat, or Stripe. Data those providers hold is governed by their own retention policies and, where we have asked them to, their contractual commitments to us. If you need us to make a specific request to one of them, email support@urbanquestapp.com and we will do it by hand.
If you want a published quest taken down as well, say so in your deletion request and we will honour it where technically feasible.
Anonymization as a moderation outcome
If our moderation team bans an account for violating our content rules, the same identifying fields listed above are overwritten and every quest that account published is unpublished. This happens as a moderation decision, not at your request. A ban is not a deletion. None of the deletions described above are performed: the account’s quests, uploaded media files, reviews, purchase records, scouted waypoints, feedback messages, moderation reports, financial records, and any reference to a Stripe payout account are all retained — the last so that an earned balance can still be paid. A banned user who also wants their data deleted can ask us, and we will run the deletion described above.
7. Your Rights in the European Economic Area and the United Kingdom
This section applies if you are in the EEA, the UK, or Switzerland.
Who is responsible for your data. The data controller is Blue Pelican Digital LLC, 4523 Cloverdale Loop, Hixson, TN 37343, United States. You can reach us about any data protection matter at support@urbanquestapp.com.
Why we are allowed to process your data. Under the GDPR we must have a legal basis for each purpose. Ours are:
- Creating and maintaining your account, signing you in, and keeping your progress — performance of a contract (Article 6(1)(b)).
- Collecting your precise location while you play a quest, including while a quest leg is running and you have switched away from the App — performance of a contract (Article 6(1)(b)). This is not based on consent: matching your position against the next waypoint is the core mechanic of a location-based game and the only way we can deliver arrival-triggered content. Your position is compared with the waypoint on your own device and is not transmitted to us, so this basis covers the App’s use of the location your device gives it rather than any storage by us. You can refuse or withdraw the operating-system permission at any time: the App still opens, and a quest can still be advanced manually with the “I’m here” control, but we can no longer detect your arrival and the experience will not work as designed.
- Storing and publishing the content you create, and showing your reviews and ratings to other players — performance of a contract.
- Processing purchases and subscriptions, checking receipts, and determining your entitlements — performance of a contract.
- Calculating and paying creator earnings — performance of a contract, and compliance with a legal obligation for the tax and accounting elements.
- Sending creators notifications about quests they submitted — performance of a contract.
- Sending occasional service and product announcements to all devices — legitimate interests (Article 6(1)(f)) in telling users about the Service they use. You can stop these at any time by turning off notifications in your device settings, and you may object to this processing (see below).
- Serving personalized advertising and using your advertising identifier for it — consent (Article 6(1)(a)), collected through the Google UMP form and, on iOS, App Tracking Transparency. If you refuse or withdraw consent, you will still see ads, but non-personalized ones.
- Moderating content, handling reports and blocks, security, fraud prevention, abuse investigation, ad-impression accounting, and diagnostics — legitimate interests (Article 6(1)(f)) in keeping the Service safe, honest, and working. You may object to this processing (see below).
- Keeping financial and tax records — compliance with a legal obligation (Article 6(1)(c)).
Where your data goes. We are a United States company and our service providers are principally located in the United States. Your personal data is transferred to and processed in the United States, which is outside the EEA and the UK. Where a transfer safeguard is required, we rely on the mechanism our provider makes available — typically the European Commission’s Standard Contractual Clauses (and the UK Addendum), or the provider’s certification under the EU–U.S. Data Privacy Framework. You can ask us which mechanism applies to a particular provider.
Your rights. Subject to the conditions in the GDPR, you have the right to:
- Access the personal data we hold about you and receive a copy of it
- Rectify data that is inaccurate or incomplete
- Erase your data (“right to be forgotten”) — deleting your account anonymizes your account record and deletes your scouted waypoints and their coordinates, your draft and archived quests, your reviews, your purchase records, your feedback messages, your push registrations, and your blocks, and removes the stored media files those records pointed at unless a quest that survives deletion still uses the same file. Moderation reports, ad-impression records with your identifier removed, published quests, and financial records are retained. Section 6 sets out precisely what erasure does and does not remove today
- Restrict our processing in certain circumstances
- Object to processing we carry out on the basis of legitimate interests, including announcement pushes and moderation records, and to any direct marketing
- Data portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. We have no self-service export tool: email us and we will assemble the data by hand and send it to you within the response time below.
- Withdraw your consent at any time, for anything based on consent. Withdrawing consent does not affect processing that already took place. For advertising, open Profile → Ad Privacy in the App to reopen the Google consent form and change your answer; you may also use your device’s advertising-identifier settings. The iOS tracking prompt cannot be reopened — use iOS Settings → Privacy & Security → Tracking.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. There is one automated check you should know about: we check purchase receipts with the app store automatically, and if the store reports that a purchase has been refunded or cancelled, access to that purchase is withdrawn without a person reviewing it; we may also withdraw access automatically where a receipt cannot be confirmed with the store. If that happens and you think it is wrong, email support@urbanquestapp.com. A person will review the decision; restoring access is a manual operation on our side, so please allow us a few days to put it right. We make no other decisions of this kind — in particular, we do not profile you, and moderation decisions are made by a person.
To exercise any of these rights, email support@urbanquestapp.com from the address on your account. We will respond within one month, and will tell you if we need to extend that period as the GDPR permits. We will not charge you or treat you differently for exercising a right.
Complaints. If you think we have handled your data unlawfully, you have the right to lodge a complaint with your national data protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address it first, but you do not have to contact us before complaining.
8. California Residents
We provide the disclosures and rights in this section as a matter of policy, whether or not the California Consumer Privacy Act formally applies to a business of our size.
Categories of personal information we collect, using the CCPA’s own labels:
- Identifiers — sign-in identifiers, email address, display name, IP address, device identifiers, advertising identifiers, and push notification tokens
- Commercial information — purchases, subscriptions, entitlements, and creator earnings records
- Precise geolocation — GPS location during gameplay, which California law treats as sensitive personal information
- Internet or other electronic network activity — app interactions, quest progress, server request logs, ad event data, and our own record of which ads you were shown and when
- Audio, electronic, visual, or similar information — images, audio, and video you upload, and photos, video, and audio captured with scouted waypoints
- Other user-generated content — quest text, reviews and ratings, in-app feedback messages, and the content of moderation reports you file (and reports other users file about you)
- Professional or financial information — for creators only, collected directly by Stripe for payouts
We collect these for the purposes in Section 2, from you, from your device, and — in the case of moderation reports about you — from other users, and we disclose them to the service providers listed in Section 4.
Sensitive personal information. We use your precise location only to run the Service — to guide you between waypoints and detect arrival. We do not use or disclose it to infer characteristics about you, and we do not sell it.
Your rights. You may request to know what personal information we have collected about you and how we use and disclose it, to delete it, to correct inaccurate information, and to obtain a portable copy. You will not be discriminated against for making a request. Section 6 sets out what deletion does and does not remove today — in particular, moderation reports are retained, our ad-impression records are kept with your identifier removed, quests you published are retained but delisted, and financial records are kept for as long as tax law requires. Deletion does remove your scouted waypoints and their coordinates, your drafts, your reviews, your purchase records, your feedback messages and your push registrations, together with the stored media files those records pointed at, unless a surviving quest still uses the same file. If a specific file you care about survives because something else references it, email us and we will deal with it by hand. We have no self-service export tool; a portable copy is assembled by hand when you ask for one.
How to submit a request. Email support@urbanquestapp.com from the email address associated with your account, and tell us which right you are exercising. We verify requests by confirming control of that email address. An authorized agent may submit a request on your behalf with your written permission. Account deletion can also be completed directly in the App or by following the instructions at https://urbanquestapp.com/account-deletion/.
Advertising. Allowing personalized advertising may be treated as “sharing” personal information for cross-context behavioral advertising. You can opt out at any time. In California, as everywhere outside the EEA and UK, there is no in-app consent control — use iOS Settings → Privacy & Security → Tracking, or your Android advertising-ID settings, as described in Section 1(j). The iOS tracking prompt is shown once and cannot be reopened. We do not sell personal information for money. We do not currently operate a “Do Not Sell or Share My Personal Information” web link, and we do not currently process Global Privacy Control browser signals; the device-level controls above are the opt-out we support.
9. Children’s Privacy
The App is not intended for children under the age of 13 (or under the minimum age of digital consent required by law in your jurisdiction). When you sign up we ask for your date of birth on a neutral age screen and do not create an account for anyone under 13; we use it only to determine eligibility and we store only the yes/no result, not the date itself. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it as soon as practicable. If you believe a child has provided us personal information, contact us at support@urbanquestapp.com.
10. Security
We use reasonable administrative, technical, and physical safeguards to protect your information. Passwords are stored only as scrypt hashes, never in readable form. Our error-reporting pipeline removes authorization and cookie headers and the entire request body before an error report leaves our servers, and redacts WebSocket credentials from URLs; error reports may still contain the request path, its query parameters, and your IP address.
No system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your sign-in credentials secure.
Please note again that uploaded media is stored in publicly readable storage (Section 1(c)): for as long as a file is stored, anyone holding its address can open it. Deleting the content or the account that holds a file removes it, with the exceptions set out in Section 6. Security safeguards do not make an uploaded file private.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on our website or within the App with an updated effective date. Material changes will be announced through the App or by email where appropriate. Where a change requires your consent, we will ask for it before the change applies to you.
12. Contact Information
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Email: support@urbanquestapp.com
Mailing address: Blue Pelican Digital LLC, 4523 Cloverdale Loop, Hixson, TN 37343, United States
Apple App Store Disclosure Summary
- Location: precise location is used while the app is in use and in the background while you are actively playing a quest (so the app can detect arrival at a waypoint); background use stops when the quest leg ends. Arrival is decided on the device and that stream is not sent to our servers; the precise coordinates we do receive and store are the ones you capture yourself as scouted waypoints, which are linked to your account. Location powers the app’s core experience and is not used for advertising and is not sold.
- Contact info and identifiers: email address, name, and sign-in identifier from Apple/Google or from email sign-up; used for account, support, and app functionality, and linked to your identity.
- User content: quests, scene text, images, audio, and video you upload; reviews and ratings; in-app feedback messages; the content of moderation reports; photos, video, audio, and coordinates captured with scouted waypoints. Uploaded media is stored in publicly readable cloud storage; it is removed when the content or the account that holds it is deleted, unless another record still points at the same file.
- Device permissions: camera, microphone, and photo library, used only when you capture or attach media, in addition to location.
- Usage data and diagnostics: app interactions, quest progress, our own record of ads shown, server-side error reports, and IP addresses in server logs. Error reporting is server-side; we run no crash-reporting or performance-monitoring SDK of our own and collect no performance traces of our own. The bundled Google Mobile Ads SDK collects crash data, performance data, and other diagnostic data, which Google declares as not linked to your identity — this is why the App’s privacy manifest declares those three categories. See Section 1(i) and Section 1(j).
- Identifiers / advertising: free quests show ads through Google AdMob. With your App Tracking Transparency permission, your Device ID (IDFA) and Advertising Data may be used to track you across apps and websites for advertising. The ATT prompt is shown once; change your answer in iOS Settings → Privacy & Security → Tracking. Premium subscribers see no ads.
- Purchases: Apple is the merchant of record. We do not collect or store payment details. RevenueCat checks receipts and receives store transaction data plus basic device and app information from its SDK, with no user ID or email from us; it does not bill or refund.
- Maps: in-app maps on iOS are rendered by Apple MapKit.
Google Play Store Disclosure Summary
These disclosures describe the Android release currently in preparation.
- The App collects precise location data to enable core, user-facing functionality (location-based storytelling and navigation between story stops). Android version 2.1 and later do not request background location access —
ACCESS_BACKGROUND_LOCATIONis not in the 2.1 manifest. (Version 2.0, the release still available on Google Play at the time of writing, does request it; 2.1 replaces that with the foreground service described next.) While you are actively playing a quest leg, the App runs a location-typed foreground service, shown by a permanent “Urban Quest — Checking to see if you’ve arrived…” notification, so it can keep detecting arrival at a waypoint after you switch away from the app; the service and the notification both stop when the quest leg ends. Outside an active quest leg, location is used only while the App is open. Users are told at runtime why location access is required. - Your precise location is not sold, is not shared for advertising, and is not used for data brokering.
- Personal info collected: name, email address, and sign-in identifier (Apple, Google, or email sign-up). App activity: in-app actions, quest progress, and a record of ads shown. App info and performance: server-side error reports, plus the crash logs, performance data, and other diagnostics that the bundled Google Mobile Ads SDK collects and sends to Google. Device or other IDs: advertising identifier and push notification token. Photos, videos, audio, and other user content: quest media, scouted-waypoint captures, reviews, ratings, feedback messages, and moderation report content.
- Permissions: the App requests approximate and precise location (
ACCESS_COARSE_LOCATION,ACCESS_FINE_LOCATION) and, so it can keep detecting your arrival during a quest leg after you leave the app, the foreground-service permissions (FOREGROUND_SERVICE,FOREGROUND_SERVICE_LOCATION) — that service is the permanent “Checking to see if you’ve arrived…” notification. Version 2.1 and later do not request background location access (ACCESS_BACKGROUND_LOCATION); version 2.0, still available on Google Play at the time of writing, does. It also requests camera, microphone, and photo/media access for capturing and attaching waypoint media, and the advertising ID permission (com.google.android.gms.permission.AD_ID). - Free quests display ads through Google AdMob, which uses your device’s Advertising ID; consent is collected through the Google User Messaging Platform in the EEA and UK. You can reset or limit this identifier in your device settings. Premium subscribers see no ads.
- Data shared with third parties: your advertising identifier and ad event data are shared with Google AdMob for advertising, including personalized advertising — in the EEA and UK only where you consent through the Google User Messaging Platform, and by default elsewhere. The crash, performance and other diagnostic data the bundled Google Mobile Ads SDK collects is also sent to Google, which states it is not linked to your identity. No data is shared with data brokers, and your precise location is never shared for advertising. Section 4 lists every service provider that receives data and what each one receives.
- Maps: in-app maps on Android are rendered by Google Maps, so map tile requests for the area you are viewing go to Google.
- Data is encrypted in transit. Uploaded media, however, is stored in cloud storage that is publicly readable by URL — see Section 1(c).
- Data deletion: users can delete their account inside the App or by following the instructions at https://urbanquestapp.com/account-deletion/. Deletion anonymizes the account record and deletes drafts and archived quests, scouted waypoint records, reviews, purchase records, in-app feedback messages, push notification tokens and blocks, together with the stored media files those records held — unless another surviving record points at the same file. It does not delete moderation reports, our de-identified ad-impression records, or quests you already published, which are delisted rather than deleted. Deletion removes your files from our media host and removes your push registrations, but it is not passed on to our other service providers. Financial and ledger records are retained as required by law. See Section 6, which describes all of this in full.
- When the Android version is released, purchases and subscriptions will be sold by Google Play as merchant of record. We do not collect or store full payment details. Refunds are handled by Google Play.
This Privacy Policy is provided for informational purposes and does not constitute legal advice.