Privacy Policy
Last updated Invalid Date
This Privacy Policy describes how Questpad ("we," "us," or "our") handles information when you visit questpad.app (our marketing site), use app.questpad.app (the Questpad web application), or interact with features that connect the two — such as the embedded goal wizard.
By using Questpad, you agree to the practices described here. If you do not agree, please do not use the service.
What Questpad is
Questpad is a personal productivity web application for individuals. It is not designed for team collaboration, shared workspaces, or enterprise administration. This policy covers the marketing site and the signed-in product unless a section says otherwise.
Information we collect
Account information
When you create an account at app.questpad.app, we collect information you provide — typically an email address and a password (stored by our authentication provider as a secure credential, not as plain text). If you use a password-reset flow, we process your email address to send reset instructions.
Product data you create
When you use Questpad, we store the content you create and manage in the app, including:
- Goals, sections, and progress settings (checklist, quota, or milestone)
- Tasks, notes, schedules, time blocks, and recurrence settings
- Routines and how tasks are grouped
- Day-queue state (what appears on your daily focus list)
This data is associated with your account and is necessary to provide the service.
Goal wizard and AI features
Questpad includes an AI-assisted goal wizard. Depending on how you use it:
- On questpad.app (no account): Text you enter in the wizard (your goal description, answers to questions, and conversation history for that session) is sent to our application servers to generate a structured plan. We apply rate limits using your IP address to prevent abuse.
- When you save a plan: Your generated plan may be stored temporarily (about one hour) as a signup draft so it can be imported when you create an account. After that period, the draft expires.
- AI processing: Wizard requests are processed using a third-party language-model provider (Groq). Content you submit in the wizard is transmitted to that provider to produce responses. Do not submit sensitive personal information (health diagnoses, financial account numbers, passwords, or information about others without their consent) into the wizard.
Authenticated users who use wizard features inside the app are subject to similar processing and separate usage limits based on plan tier.
Payment information
If you subscribe to Questpad Pro, checkout and subscription management are handled by Polar. We do not store your full payment card details on our servers. Polar processes payment information according to its own privacy policy. We receive subscription status and related billing metadata needed to enable Pro features.
Analytics and technical data
On questpad.app, we use Vercel Analytics to collect aggregated, privacy-oriented usage metrics (such as page views). This helps us understand how the marketing site is used. It is not intended to identify you personally.
When you use either site, standard technical information may be logged automatically — for example IP address, browser type, request timestamps, and error diagnostics. We use this for security, rate limiting, debugging, and service reliability.
Cookies and local storage
We and our providers use cookies and similar technologies where needed for:
- Authentication and session management (app.questpad.app)
- Security and abuse prevention
- Basic site functionality
Your browser may also store local preferences. You can control cookies through your browser settings; disabling essential cookies may prevent you from signing in or using core features.
How we use information
We use the information described above to:
- Provide, maintain, and improve Questpad
- Authenticate you and secure accounts
- Process subscriptions and enforce plan limits (Free vs Pro)
- Run the goal wizard and related AI features
- Communicate with you about your account (for example password reset)
- Detect abuse, enforce rate limits, and protect the service
- Comply with legal obligations
We do not sell your personal information. We do not use your goal and task content to train public AI models.
How we share information
We share information only with service providers that help us operate Questpad, including:
| Provider | Role |
|---|---|
| Supabase | Authentication and database hosting |
| Groq | AI processing for the goal wizard |
| Polar | Subscription billing and customer portal |
| Vercel | Hosting and analytics for our websites |
These providers process data on our behalf under their own terms and privacy policies. We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where appropriate).
Data retention
- Account and product data are kept while your account is active. You may delete your account or request deletion of your data by contacting us (see Contact).
- Signup drafts from the wizard expire automatically after approximately one hour if not used.
- Server logs are retained for a limited period for security and operations, then deleted or aggregated.
- Billing records may be retained as required for tax, accounting, or legal compliance.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. To make a request, email us at hello@questpad.app. We may need to verify your identity before responding.
You can update much of your product data directly inside the app. You can manage or cancel a Pro subscription through the Polar customer portal linked from your account settings.
Children
Questpad is not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
International users
Questpad is operated from the United States. If you access the service from other countries, your information may be processed in the United States and other locations where our providers operate. Those locations may have different data-protection laws than your home country.
Security
We use reasonable technical and organizational measures to protect information, including encryption in transit (HTTPS) and access controls on production systems. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be communicated through the app or by email where appropriate. Continued use after changes take effect constitutes acceptance of the updated policy.
Contact
Questions about this Privacy Policy or our data practices:
Email: hello@questpad.app
Website: questpad.app