Quest is private by default. Your collection, your chases, your stories, and any values are visible only to you unless you explicitly share them. Quest never sells your personal information, never runs advertising against your collection, and never exports collector data to dealers or anyone else. The rest of this policy is the detail behind those sentences.
Email address, display name, and handle, collected at signup through our sign-in provider. Quest never sees or stores your password.
What you add: cards and items you record, quest names and definitions, photographs, written stories, voice notes, values you enter, and your collecting story if you choose to tell it. Your collecting story and the preferences drawn from it are private and used only to shape your own experience — they are never shown to other collectors.
If you join Quest by scanning a dealer's code, a referral marker is stored on your account so Quest knows which dealer introduced you. It is never displayed publicly, and it does not give the dealer access to your account or your collection. See Section 5.
Ordinary service logs (device type, browser, IP address, pages and features used) for security and debugging. This website runs no analytics and no trackers. The app uses Sentry for error monitoring: when something breaks, the error report includes technical context such as device, browser, and IP address — errors only, no session replay, no behavioral analytics. No advertising or cross-site tracking anywhere.
Quest processes no payments and stores no payment card details. Quest is not a marketplace and holds no funds.
Quest is for collectors 13 and older. We do not create accounts for, or knowingly collect personal information from, children under 13. If we learn we hold personal information from a child under 13, we delete it and close the account. If you believe a child under 13 has a Quest account, contact hello@collect.quest.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Only when you make it so:
The dealer program is built on a one-way rule: requests flow to dealers; your identity doesn't. If Quest routes a want — something you're chasing that a dealer may be able to supply — the dealer sees the request, not your name or your collection. Who you are is revealed only if and when you choose to engage. Dealers receive no lists, no exports, and no browsing access to collector data, ever.
Quest runs on a small set of processors, each receiving only what its function requires: sign-in (Clerk), database and file storage (Supabase), web hosting and delivery (Vercel), card recognition and checklist drafting (Anthropic), and error monitoring in the app (Sentry). Each is bound by its own data-protection terms; none may use your data for its own purposes.
Quest uses cookies for signing you in, for security, and — if you arrived through a dealer's code — a referral cookie so attribution survives signup. No advertising cookies, no cross-site trackers.
Your content is kept while your account is open. You may export your collection data at any time.
When you delete something, it is deleted. Delete a photo, a story, a voice note, a card, or your whole account, and the thing itself — the pixels, the audio, the words — is removed from our systems. What survives is the record that a change happened: your collection's history will still show that a photo was removed or an entry deleted, and that record is marked as exactly that — a record of a change, not the content. The history stays honest; the deleted thing is gone.
Replacing is different from deleting. When you swap a photo for a better one, the replacement is your choice to improve the record, not a request to erase it — Quest intends to keep the replaced image in deep archive as part of the card's history. [Implementation-status note, draft only — not a decision bracket: today the app deletes replaced images too; archive-on-replace is intended but not yet built (lib/actions/images.ts). This sentence must not take effect before the archive exists.]
Deletion completes within a reasonable period, except copies in routine backups (retained briefly) and records we must keep by law. Catalog corrections you contributed remain in the catalog — they describe cards, not you.
California collectors — and, as a matter of Quest policy, everyone: you have the right to know what personal information we hold about you, to have it deleted, to have it corrected, to receive a portable copy, and to opt out of the sale or sharing of personal information — noting that Quest does not sell or share personal information as California law defines those terms. You will never face retaliation for exercising any of these rights. To make a request, email hello@collect.quest; we may need to verify your identity before acting on it. California's privacy statutes do not yet legally apply to a company of Quest's size — we honor these rights anyway, because private-by-default is what this product is.
Global Privacy Control: we honor the GPC signal.
Where your data lives: your information is currently stored and processed in the United States, with the providers named in Section 6. Quest currently makes no transfers of your data out of the US — and if you use Quest from outside the United States, your information travels to and is stored on US servers. As Quest becomes available globally, this section will be updated with the transfer safeguards that apply.
Data in transit is encrypted; access to production systems is restricted; sign-in is handled by a dedicated identity provider. No service can promise perfect security — if a breach affects your personal information, we will notify you as the law requires.
Material changes are posted here with a new version number and effective date, with notice to account holders before they take effect.
Quest is operated by Quest Collect, Inc., a Delaware corporation. Reach us at hello@collect.quest, or by mail: [PO Box ___, Saratoga, CA 95070 — placeholder until the real box arrives].