Legal
Privacy Policy
§1: Data controller
The data controller is [FOUNDER_NAME], sole trader (micro-entrepreneur), SIREN [SIREN], operating the QuestFable service. Full contact details: Legal notices.
GDPR contact point: privacy@questfable.app. No DPO is required (no large-scale processing of sensitive data), but a dedicated contact is designated.
§2: Data collected, purposes & legal bases
| Category | Data | Purpose | Legal basis (GDPR art. 6) | Retention |
|---|---|---|---|---|
| Account / identity | Email, Discord ID + avatar (if OAuth), display name | Create/manage account, authenticate | Contract performance (art. 6.1.b) | Lifetime of account; purged on deletion |
| Quest prompts (inputs) | Quest descriptions entered by the Owner | Generate quests | Contract performance | Lifetime of account; deletable |
| Quest outputs | IR/YAML of generated quests | Provide, manage, version quests | Contract performance | Lifetime of account |
| Server | Name, plugin+version, server IP (via fingerprint), heartbeat status | Link server, detect plugin, deploy | Contract performance | Lifetime of the link |
| Billing | Via Stripe: name, billing address, country, last 4 digits, history | Invoice, VAT, accounting | Contract + legal obligation (art. 6.1.c, invoices) | Invoices: 10 years (FR accounting law); rest: account lifetime |
| Plugin survey | Quest plugin choice (1st login) | Personalise, internal telemetry | Legitimate interest (art. 6.1.f) | Anonymised/aggregated |
| Technical logs | Application logs, errors (Sentry), requests | Security, debugging, anti-abuse | Legitimate interest (art. 6.1.f) | ≤ 30 days |
| Web analytics | Navigation events (PostHog EU, cookieless) | Measure conversion, improve the site | Legitimate interest (art. 6.1.f), cookieless, no blocking banner | Aggregated, ≤ 12 months |
| Moderation | Filtered content (input/output), rejected IRs | Safety, minor audience protection, API key protection | Legitimate interest + obligation | ≤ 30 days |
| Marketing emails | Email + opt-in status (waitlist, digest) | Inform, activate, retain | Consent (art. 6.1.a) for non-transactional | Until consent is withdrawn |
§3: No player data, ever
We collect no data about your players: no username, no IP address, no progression, no economy data, no TPS or server load. The Bridge transmits only the plugin version and a server fingerprint (server-side identifier) at the heartbeat, no player data whatsoever.
This means we never process data about third-party minors (your players) by proxy. The only user in our system is you, the server owner.
§4: Sub-processors & international transfers
We use the following sub-processors that may process personal data on our behalf:
| Sub-processor | Role | Location | Transfer safeguard |
|---|---|---|---|
| Anthropic | AI generation (prompts processing) | US | DPA + Standard Contractual Clauses (SCC); no-training contractual |
| Stripe | Payment, invoicing, VAT | US/IE (Stripe Payments Europe) | Stripe DPA + SCC |
| Railway | Backend hosting (Fastify + Postgres prod) | US/EU (region TBC) | Railway DPA: ⚠️ region under review (S7) |
| Resend | Transactional + lifecycle emails | US | Resend DPA + SCC |
| PostHog | Web analytics (cookieless) | EU (Frankfurt) | EU Cloud: no transfer |
| Sentry | Error monitoring | US (EU region option) | Sentry DPA + SCC; PII scrubbing active |
| Cloudflare | Anti-bot (Turnstile), backups (R2 EU bucket) | US (EU bucket for R2) | Cloudflare DPA + SCC; R2 EU bucket imposed |
| Upstash | Redis queue (BullMQ jobs, transient, no durable PII) | EU (Frankfurt) | Upstash DPA; EU region |
| Discord | OAuth (identify + email scopes only) | US | OAuth provider; minimal scopes |
DPAs will be signed before the first payment (S7 legal review, as required by CDC §11.3).
§5: AI & model training
The Service uses the Anthropic API (Claude models). Anthropic never trains on your inputs or outputs: this is contractually guaranteed in Anthropic's Commercial Terms (no-training). Anthropic retains API data for approximately 30 days for safety purposes.
Content is moderated at input and output to protect minor audiences. Zero Data Retention (ZDR) will be available on request in V2.
§6: Cookies & trackers
We minimise cookies to avoid requiring a consent banner. See our Cookies policy for the full inventory.
In summary: only a strictly necessary session cookie (Better Auth, httpOnly, exempt from consent) and cookieless PostHog analytics (no cross-site tracking, EU Cloud, exempt from consent under CNIL audience measurement exemption).
§7: Your GDPR rights & how to exercise them
Under the GDPR, you have the right to:
- Access your data (art. 15)
- Rectify inaccurate data (art. 16)
- Erasure ("right to be forgotten") (art. 17)
- Data portability (art. 20)
- Restriction of processing (art. 18)
- Object to processing based on legitimate interest (art. 21)
- Withdraw consent at any time (for consent-based processing)
Self-service: from your account settings you can export all your data (JSON: account, quest IRs, billing history) and delete your account (full purge, token revocation). Response time: within 1 month.
To exercise your rights or file a complaint: privacy@questfable.app. You may also lodge a complaint with the CNIL (French data protection authority).
§8: Security
All connections use TLS. server_token credentials are stored as SHA-256 hashes only, never in plain text. Secrets are stored in a vault, never in the Bridge binary. The Bridge writes only to the import/ directory (isolation guarantee).
§9: Minors
The Service is not directed at children under 16. We do not knowingly collect data from users under 16. If you believe a minor has provided data, contact privacy@questfable.app and we will delete it promptly.
Note: your players (who may be minors) are not our data subjects. We collect no data about them whatsoever (§3).
§10: Updates to this policy
This policy is versioned. Substantial changes will be notified by email before they take effect. The current version is always available at this URL.
Last updated: 2026-07-04.