Privacy Policy

Last updated: January 29, 2026

Your family's privacy matters to us. This policy explains what data we collect, how we use it, and how we protect it — especially for children.

1. Who We Are

Family Quest ("we", "us", "our") is a family task management platform operated at ourfamilyquest.com. We help families organize chores and responsibilities through gamification — coins, levels, badges, and rewards.

2. Data We Collect

We collect different data from parents/guardians and children:

From Parents/Guardians

  • Email address (for account login and communication)
  • Name (for display within the family)
  • Password (stored securely with encryption)
  • Language preference
  • Device tokens (for push notifications, if enabled)

From Children (Created by Parents)

  • First name (chosen by parent)
  • Age (for age-appropriate features)
  • Avatar selection (from predefined options)
  • PIN code (for kid login — stored encrypted)
  • Task completion data (within the family context)
  • Coin balances and redemption history
  • Level, XP, badge, and streak data

We do NOT collect from children: email addresses, phone numbers, physical addresses, photos (unless parent enables photo proof for specific tasks), location data, or any data used for advertising.

3. How We Use Data

  • Providing the Family Quest service (task management, rewards, gamification)
  • Authenticating users (parent login, kid PIN login)
  • Sending push notifications (task approvals, rewards, etc.)
  • Improving the service and fixing bugs
  • Communicating with parents about account-related matters

4. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process data based on:

  • Contractual necessity — to provide the service you signed up for
  • Parental consent — for processing children's data (Article 8, GDPR-K)
  • Legitimate interest — for security, fraud prevention, and service improvement

5. Children's Privacy (COPPA & GDPR-K)

We are committed to protecting children's privacy. Family Quest is designed so that parents create and manage child accounts. Children do not directly provide personal information to us — all child data is entered and controlled by their parent or guardian. We do not engage in behavioral advertising to children. We do not share children's data with third parties for marketing purposes.

For more details, see our Children's Privacy.

6. Data Sharing

We do not sell your data. We share data only with:

  • Hosting provider (Hetzner Cloud, Germany) — for running the service
  • Email service provider — for transactional emails to parents
  • Push notification service (Apple/Google) — for delivering notifications

We never sell, rent, or trade personal data to third parties for marketing or advertising purposes.

7. Data Retention

We retain account data for as long as the account is active. When a parent deletes their account or removes a child, we delete the associated personal data within 30 days. Anonymized usage statistics may be retained for service improvement.

8. Your Rights

Under GDPR, Israeli Privacy Protection Law, and other applicable regulations, you have the right to:

  • Access your data and your children's data
  • Correct inaccurate data
  • Delete your account and all associated data
  • Export your data in a portable format
  • Restrict or object to certain processing
  • Withdraw consent at any time

To exercise these rights, contact us at privacy@ourfamilyquest.com.

9. Israeli Privacy Protection Law

In compliance with the Israeli Protection of Privacy Law, 5741-1981, and its regulations, we maintain appropriate security measures for personal data. Israeli residents have the right to access, correct, and delete their personal information. We do not transfer personal data outside of Israel/EU without adequate protection measures.

10. Data Security

We implement industry-standard security measures including encrypted passwords, HTTPS for all connections, encrypted database connections, and regular security reviews. However, no system is 100% secure, and we cannot guarantee absolute security.

11. Third-Party Services

Our infrastructure uses:

  • Hetzner Cloud (Germany/Finland) — server hosting
  • PostgreSQL — database (self-hosted)
  • Redis — caching and background jobs (self-hosted)
  • Sidekiq — background job processing (self-hosted)
  • Apple Push Notification Service / Firebase Cloud Messaging — push notifications

12. Changes to This Policy

We may update this policy from time to time. We will notify parents via email of any material changes, especially those affecting children's data. The effective date at the top will be updated.

13. Contact Us

For privacy-related questions, data requests, or concerns:

privacy@ourfamilyquest.com

IMPORTANT: This privacy policy is an AI-generated draft provided for informational purposes. It must be reviewed and approved by a qualified legal professional before being relied upon. It does not constitute legal advice.