TicQuest Privacy Policy

Effective date: 2026-09-02 Version: 2.1

TicQuest is operated by Velynq, Inc., a Delaware corporation ("Velynq", "we", "us", "our"). This Privacy Policy explains what personal data we collect through the TicQuest mobile and web application ("TicQuest" or the "App"), how we use it, with whom we share it, how long we keep it, and the rights you and your child have.

TicQuest is a children's routine and chore-reward tool for families. Only a parent or legal guardian creates and manages an account; children use the App under their parent's or guardian's supervision and never create an account or sign in. If you are a parent or guardian, please read Section 5 (Children's Privacy) carefully — it explains how we obtain your consent and how you can review, export, or delete your child's information at any time.


1. Summary


2. Data We Collect

2.1 Parent / Account-Holder Data

2.2 Child Data (deliberately minimal)

2.3 Parent-Authored Free Text

You may create routine titles, task names, and reward labels. These are stored as-is; we neither require nor parse them for personal information. Please avoid entering sensitive data in these fields (see Section 6 of the Terms of Service).

2.4 Parent Feedback (optional)

If you choose to send us feedback from inside the App (Settings → "Send feedback" — available only in the parent area), we collect the message you write, together with the app version, platform (Android/iOS/web), and the App's display language, so we can respond to problems and improve the App. A copy of that message — and only that message plus those three technical fields, with no account, family, or child identifier attached — is relayed to our support mailbox by our network provider (Cloudflare; Section 6). Feedback is written by parents, never requested from children. Please don't include sensitive personal data in a feedback message.

2.5 Anonymous Usage Counters

We keep aggregate, non-identifying usage counters — screen-view counts recorded by day and hour bucket and by platform — to see which screens are used and where new families drop off during setup, so we can improve the App. These counters are never linked to any account, device, or child, carry no identifier of any kind and no free text, and cannot be traced back to an individual. They are our own first-party counts (no third-party analytics or advertising SDK — see Section 3).

Optional product & attribution analytics (off by default). Separately from the anonymous counters above, TicQuest includes a first-party analytics feature that is off by default: unless you opt in, nothing about your family is uploaded to or stored on our servers. At first open the App reads the Google Play install referrer once and stages one minimised envelope only on your device: the coarse install source and medium (never a campaign name, and with click-identifiers stripped so no per-click token is kept), your device's language, a 2-letter country code, and the time of first open. The pending envelope is discarded after 30 days if you do not opt in, and there is no server call or anonymous server-side install record at capture time. Only after you, the authenticated parent, opt in does the App upload that envelope, already keyed to your family account, and record family-account-keyed setup / activation / subscription milestones (an allowlisted event name + a timestamp; for example onboarding finished, a routine added, the paywall viewed, or a trial started, renewed, or cancelled). We use this only to understand how consenting families discover and start using the App so we can improve it. When you opt in, the analysis also looks at your family's existing setup and activity from before you opted in — for example, it derives, from data already on your account, when your family created its first routine and completed its first task — so the picture reflects your whole start-up journey rather than only what happens after you opt in. This retrospective analysis runs shortly after you opt in (during our scheduled processing) and reads the setup and activity already on your account; the analytics it then stores is limited to your family account, an allowlisted milestone name, and its timestamp — it stores no direct child identifier, no routine or task content, and no free text. Milestone events carry no custom event properties or free text, and the analytics carries no direct child identifier. Because some milestones reflect your child's activity, we apply the same child-privacy safeguards as elsewhere in the App (minimised, off by default, never used for ads or profiling, and covered by your review, export, withdrawal, and delete rights). It is first-party — stored only in our own systems and sent to no third-party analytics or attribution service (Section 3); the open-source on-device bridge calls Google Play's own Install Referrer API. It builds no advertising or behavioural profile. Turning the feature off stops further collection and deletes your family-linked install, event, and activation-analytics rows from our live systems.

Optional reminder notifications (off by default). You can turn on gentle on-device reminders for your child's routines. These are scheduled locally on your child's device — they send us no data — and the reminder shown on the lock screen is generic and carries no child name (just a prompt to start the next quest). You turn them on, and off, from the App.

App-rating prompt. From time to time the App may show the operating system's own rating prompt. To limit how often it appears, we store only an on-device last-prompt timestamp — it never leaves your device. If you choose to rate the App, your rating goes to the app store under its policy; the App does not receive your individual rating, and we collect no new data to decide when to show the prompt beyond in-app activity we already hold.

2.6 Emails We Send You About Your Child

Besides account emails (verification and password reset), we send you two kinds of message about your child. Both go to your address, never to a child.

We also send you one kind of message about your subscription (not about your child):

These emails are delivered by our email provider, Resend (Section 6), which therefore receives your email address, the name or nickname in the child-related messages, the activity summary in the optional activity emails, and — for the trial reminder — the days-remaining count and manage link (no child data).

2.7 Crash & Error Diagnostics

To keep the App stable, if the App crashes or hits an unexpected error — or if a paired child's device detects that it cannot reliably read or save progress — it automatically sends us a structured, technical diagnostic report. A crash / error report contains the error type and category (for example, a display, runtime, or unhandled-promise error), whether it was fatal, an anonymized code-location fingerprint (which part of our own code failed — never your content), the app version, the platform, the display language, the approximate hour it happened, and a short internal de-duplication code (a one-way value, not reversible to your content). A storage-reliability report is narrower still: it contains only closed read / write status and fault-cause fields, the app version, the platform, and the approximate hour — no code-location fingerprint and no display language. Neither report includes the raw error text, your child's name, or any other content you or your child entered, and the stored diagnostic record contains no account, family, child, or device identifier (a paired device's token is transmitted to authenticate and rate-limit the reliability report, as described in Section 2.1, and is never written to the record). These reports are stored in our own systems (Supabase) — we use no third-party crash-reporting service (Section 3, Section 6) — and are deleted within 90 days. Separately, from Settings → About you may choose to send us a fuller diagnostic when you contact support; that one stays on your device until you decide to share it.


3. What We Deliberately Do NOT Collect

These are design decisions, not omissions:

Category Status
Child age or date of birth Not collected.
Child photographs or uploaded images Not collected. Avatars are preset illustration keys only.
Precise location or GPS Not collected. No location permission is requested.
Third-party analytics / advertising / tracking SDKs Not present. No Sentry, PostHog, Firebase Analytics, Mixpanel, Amplitude, AppsFlyer/Adjust-style attribution SDKs, ad networks, or equivalent. (The optional, off-by-default product & attribution analytics in Section 2.5 are first-party — they run in our own backend and the data reaches no third-party analytics or attribution service. We read the install source with an open-source on-device bridge that calls Google Play's own Install Referrer API; that bridge is not a third-party analytics or attribution service, and no such service receives the data.)
Payment-card or bank-account data Not collected. All payments are handled by the App Store / Google Play.
Child email, phone, or postal address Not collected. Children never authenticate.
Behavioral advertising profiles Never created. We have no advertising partners.

4.1 Purposes

Purpose Data used
Running and personalizing the App (routines, progress, stars, certificates) Child name or nickname, behavioral/gameplay data
Account creation, authentication, security Parent email, OAuth identity
Account-verification and password-reset emails Parent email
Confirming a child profile was created, and giving you a link to remove it (Section 2.6) Parent email, child name or nickname
Optional reward and weekly-recap emails, if you turn them on (Section 2.6) Parent email, child name or nickname, that child's in-app activity
Trial-ending reminder email, if you are on a free trial (Section 2.6) Parent email; days remaining and a manage-plan link (no child data)
Understanding how families discover and start using the App — optional, off by default (Section 2.5) Family-account-keyed setup / activation / subscription milestones, a coarse install source, and device language / country; no child identifier
Optional on-device reminder notifications, if you turn them on (Section 2.5) Scheduled locally on the child's device; sends us no data
Recording and honoring parental consent Consent record
Managing your subscription Subscription / billing metadata
Pairing a child's device Device-pairing data
Responding to your feedback (Section 2.4) Feedback message, app version, platform, display language
Keeping the App stable, debugging failures, and preventing abuse De-identified crash / error / storage-reliability diagnostics (Section 2.7) and short-lived security counters (Section 2.1)
Responding to support and legal requests Relevant account data

We do not use any data for advertising, behavioural, or cross-app profiling, we use no third-party analytics SDK, and we build no advertising or behavioural profile, nor make automated decisions that produce legal or similarly significant effects about your child. The optional first-party product & attribution analytics in Section 2.5 are off by default, keyed to your family account (with no direct child identifier) and build no profile. The App does compute ordinary progress figures to run its features — for example how many tasks were completed, on-time rates, streak/active-day counts, and reward progress — which is core service functionality needed to run the App for your family (see the legal bases below), not marketing or behavioural profiling.

4.2 Legal Bases (GDPR Article 6 / Article 8)

For users in the European Economic Area (EEA), UK, or Switzerland: TicQuest is set up and run by a parent or guardian, who creates the account, agrees to our terms, and manages everything in it. We process your child's data because it is necessary to run the family service you asked us to provide — not because a child gives consent.

Under GDPR Art. 8 the age below which a child's own consent to an online service must be authorised by the holder of parental responsibility is 16 by default; EU member states may lower it by law to no less than 13 — for example Ireland 16, Spain 14, France 15, Germany 16, while the UK sets it at 13, and France additionally requires the consent of a parent and the child where the child is under 15. TicQuest is a parent-managed service: a parent or guardian creates the account and manages their child's data, the child never registers or gives their own consent, and we collect no age or date of birth. Because the core service does not rely on a child's own consent — we process your child's data under our legitimate interest in running the service you set up (§4.2) — these parental-consent-age thresholds, including France's under-15 rule (which governs consent-based processing), are not the operative basis for that processing. We treat the strictest thresholds as our baseline and assess this in our child Data Protection Impact Assessment.


5. Children's Privacy (COPPA + GDPR-K)

TicQuest is designed around children's privacy and the U.S. Children's Online Privacy Protection Act (COPPA, 16 C.F.R. Part 312, including the FTC's 2025 amendments), GDPR Article 8, and equivalent laws.

Parent-controlled accounts. Only a parent or legal guardian creates and manages a TicQuest account. Children never register, never sign in with credentials, and are identified to us by the name or nickname you enter and the in-app activity described above. A paired child's device is also linked to your family by a device token (Section 2.1); any crash, error, or reliability diagnostics we collect from that device are de-identified and do not identify your child (Sections 2.7 and 2.1).

Verifiable parental consent (how we obtain it). Children's data is collected only after a parent or guardian consents. We:

  1. give you a direct notice of what we collect from your child — a name or nickname you choose, in-app activity, a device time zone (for local-time dates), and a device-pairing token, plus de-identified crash / error / reliability diagnostics and short-lived abuse-prevention counters (Sections 2.7 and 2.1) — that this data is used only to operate, stabilize, and secure the App for your family and is never disclosed to third parties for their own purposes, and that you can revoke consent at any time;
  2. require you to create a parent account and send a confirmation link to your email address (or, if you sign in through Apple, Google, or Facebook, rely on the verified email that provider gives us) — so the person consenting holds a real, contactable account they control and attests they are the child's parent or legal guardian; and
  3. capture your explicit parental consent: you confirm you are the child's parent or legal guardian and consent to TicQuest collecting the name or nickname you choose and their activity — both when you accept this Policy at sign-up and again when you add a child; and
  4. email you a confirmation at your verified address once the profile exists (Section 2.6), repeating the direct notice and carrying a one-tap link that removes that child and all of their data.

Because the personal data TicQuest collects to identify your child is limited to a name or nickname you choose plus in-app activity, used solely to run the App — with only limited technical device-pairing, diagnostic, and security data (Sections 2.1 and 2.7) kept to operate, stabilize, and secure the App — with no advertising, and never disclosed to third parties for their own purposes, this method is reasonably designed to confirm that the person consenting is the child's parent or guardian, consistent with COPPA's verifiable-parental-consent standard (16 C.F.R. § 312.5). You can withdraw consent at any time by deleting the child's profile or your account (Section 9), or by emailing privacy@velynq.co.

We make no other use of your child's data. We use it only to operate the App's features for your family — showing routines, awarding stars, and tracking progress. We do not analyze it for any other purpose, build advertising or behavioral profiles, train AI models, advertise, sell, or share it — ever. Our cloud service providers (Section 6) process child data only to run the App on our behalf, under written data-processing agreements, and may not use it for their own purposes. The optional product & attribution analytics (Section 2.5) operate at the family-account level — your family's setup milestones and the coarse source that brought you to the App — with no direct child identifier. Because some of those milestones can reflect your child's activity, we treat this data with the same child-privacy safeguards as the rest of the App (minimised, off by default, never used for ads or profiling, and covered by your review, export, and delete rights); it is off by default and never uses a direct child identifier.

No advertising or profiling of children. TicQuest shows no ads, builds no advertising or behavioral profiles, and shares no child data with ad networks or data brokers.

Your parental rights. At any time you may review, export, or delete your child's data, and revoke consent — directly in the App (Settings → "Export my family data" / "Delete account") or by contacting privacy@velynq.co. We respond to verifiable parental requests within 30 days.


6. Sharing and Sub-Processors

We do not sell personal information, do not "share" it for cross-context behavioral advertising, and do not disclose it to advertising networks, data brokers, or any third party for their own purposes.

Our processors. Each provider below acts only on our instructions and only to support the App's internal operations, under written data-protection terms in force between it and Velynq, Inc. — a separately signed data-processing agreement in Supabase's case, and for the others a published data-processing addendum (or, for Expo, equivalent processing terms) that the provider's own terms of service make binding on us.

Processor Role Data it processes
Supabase Backend: database, authentication, edge functions, hosting Account, family, and child data in Section 2; de-identified crash / error / storage-reliability diagnostics (Section 2.7); short-lived abuse-prevention counters (Section 2.1); the optional, off-by-default first-party product & attribution analytics (Section 2.5) if a parent enables them, keyed to the family account with no child identifier; platform request logs (including IP at the infrastructure layer, which we do not store in App data tables)
PowerSync Offline sync: mirrors a subset of family/child data to the device for offline use The synced tables incl. child behavioral data (routine history, stars, streaks, completions, certificates, alarms, device links)
Resend Delivery of every email we send you: account verification, password reset, the confirmation when you add a child, the optional activity emails, and the trial-ending reminder (Section 2.6) Your email address; the contents of those messages — which include the name or nickname you chose for a child, the removal link in the confirmation email, that child's reward or weekly star / day / task counts in the optional emails, and, in the trial reminder, only the days-remaining count and a manage-plan link (no child data); delivery logs retained by Resend for approximately 30 days
RevenueCat Subscription-state management (live) A random family identifier we generate (never your name, your email, or a child's name), the store's subscription and transaction identifiers, subscription status, and the app and device information its SDK sends to operate the purchase flow. It receives no child data.
Cloudflare Hosting for our public web pages (velynq.co) and email routing for our published addresses Web-request logs (including IP at the infrastructure layer); the contents of email you send to our published addresses, and of in-app feedback, which is relayed with no account, family, or child identifier (Section 2.4); de-identified operational alert counts we send to ourselves (aggregate fault / health totals, with no user, family, or child data)
Expo / EAS App build and over-the-air update delivery App binaries and updates — no App data; its infrastructure sees the update request itself (including IP) when your device checks for an update

Not our processors. Apple and Google act on their own behalf, not on ours, when they sell and process a subscription: they are the seller, they take the payment, and they handle your payment data under their privacy policies. We never receive your card number (Section 3); we receive only the subscription receipt data described above. Google also distributes the App through Google Play under its own terms.

We do not use any third-party advertising, product-analytics, attribution, or crash-reporting processor. The optional analytics in Section 2.5 run in our own backend (Supabase); the install source is read from Google Play's own install referrer — not from a third-party attribution service — and reminder notifications are scheduled on the device with no server or push provider. We will update this section before adding any new processor (for example, a push-notification provider).


7. International Transfers

Our primary backend (Supabase) hosts data in the European Union (Ireland). Our offline-sync provider (PowerSync) is configured to process data in the European Union. Our email provider (Resend) sends from its EU (Ireland) region but is a U.S. company. RevenueCat, Cloudflare, Expo, Apple, and Google are U.S. companies and may process the data described in Section 6 in the United States.

If you are in the EEA, UK, or Switzerland and your data is transferred to a country outside those regions, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses, which are part of each of those providers' data-processing terms.


8. Data Retention Policy

This section is our written data-retention policy (COPPA, 16 C.F.R. § 312.10, as amended in 2025; GDPR Art. 5(1)(e)). We keep children's personal information only as long as is reasonably necessary to fulfill the purpose for which it was collected, and we do not retain it indefinitely. For each category we state the purpose, the business need, and when it is deleted:

Data Purpose / business need Retention
Routine completion logs (routine_history) Show recent day-by-day history to the parent 7-day rolling — automatically deleted daily by a scheduled job
Monthly progress summaries Parent progress dashboard (current-period view) Kept while the account is active; deleted when the child or account is deleted
Yearly progress summaries (aggregate counts only) Show your child's progress over time Kept while the account is active to display long-term progress; deleted when the child or account is deleted
Child profile, routines, tasks, rewards, streaks, certificates Operate the App for your family Kept while the account is active; deleted when the child or account is deleted
Parental-consent record Demonstrate COPPA/GDPR-K compliance Kept while the account is active; deleted on account deletion — we keep no separate copy
Device-pairing records Link a child's device Pairing codes expire automatically; link records persist until you unpair or delete the account
Subscription / billing metadata Manage your subscription and resolve disputes Kept while the account is active; deleted on account deletion (see the de-identified financial records noted below)
Parent feedback messages (Section 2.4) Respond to problems and improve the App 24 months, deleted automatically by a scheduled job; also deleted earlier when the account is deleted
Inactive accounts None — the data is no longer needed If an account has no activity for 24 months, we email you a 30-day notice and then delete the account and all of its data
Diagnostic and server logs (requests, sync, authentication) Security, debugging, abuse prevention 90 days, then purged
Security / rate-limit counters (Section 2.1) — salted, one-way token/IP hashes and a per-child upload counter Abuse prevention on our endpoints A few days (a daily scheduled job purges them; typically within ~3 days)
Crash, error & storage-reliability diagnostics (Section 2.7) Keep the App stable and debug failures — structured and de-identified: for a crash / error, the error type and category, whether fatal, anonymized code-location fingerprint, app version, platform, display language, approximate hour, and a non-reversible de-duplication code; for a storage-reliability report, only closed read / write status and fault-cause fields with app version, platform and approximate hour; no raw content and no account, family, child, or device identifier 90 days, then deleted by a scheduled job
Anonymous usage counters (Section 2.5) Improve the App; they identify nobody 14 months, then deleted by a scheduled job
Optional product & attribution analytics (Section 2.5), if enabled and you opt in — a family-linked install record (coarse source + medium, device language / country, first-open time) and family-account-keyed setup / activation / subscription milestones (allowlisted event name + timestamp), with no direct child identifier. Before opt-in, the minimised install envelope stays only on the device Understand how consenting families discover and start using the App; the ~12-month event window supports cohort / seasonality analysis Pending on-device install envelope → up to 30 days, then discarded if still pending; general analytics events → 12 months (365 days), then purged by a scheduled job; family-linked install + activation events → retained with your family, deleted immediately when you turn analytics off, and also deleted when you delete your account. No anonymous install is stored server-side

Account and data deletion. You can delete your account at any time in the App (Settings → "Delete account"). This immediately deletes your account and all associated data — family record, every child profile, all activity data, routines, tasks, rewards, and subscription records — by a cascading database deletion. Deletion is immediate and cannot be undone from within the App. We may retain limited billing and transaction records in de-identified form (with your family identifier removed, so they no longer identify you) where required for financial record-keeping, fraud prevention, or legal compliance. Separately, copies cached offline on your device(s) are cleared when you sign out or delete the account, and routine infrastructure backups held by our hosting provider are overwritten on that provider's rolling backup cycle — currently 7 days — and are never used to restore a deleted account.

We review this schedule at least annually, and whenever we start collecting a new category of data.


9. Your Rights

9.1 All Users

9.2 EEA / UK Users (GDPR)

You also have the right to restrict or object to processing, and to lodge a complaint with a data-protection supervisory authority: in the UK, the Information Commissioner's Office (ICO); in the EEA, your local supervisory authority in the member state where you live or work. You may also raise any data-protection concern with our EU / UK representative (Section 12). We ask that you contact us first so we can help.

9.3 California Users (CCPA / CPRA)

We do not sell personal information and do not "share" it for cross-context behavioral advertising. You have the right to know what we collect (Section 2), access a copy (in-app export), delete it (in-app "Delete account"), and not be discriminated against for exercising these rights. To exercise them, use the in-app tools or contact privacy@velynq.co.


10. Security

We maintain reasonable administrative, technical, and organizational measures to protect personal data, including:

No method of transmission or storage is perfectly secure. To report a security concern, contact privacy@velynq.co.


11. Changes to This Policy

We may update this Policy when the App changes (for example, if we add a push-notification provider). We will revise the effective date above and, for material changes, provide an in-app notice or email. Continued use after the effective date constitutes acceptance.

Governing language. This Policy was drafted in English. Any translation we provide is for your convenience; the English-language version is authoritative and controlling — except to the extent applicable mandatory consumer-protection or data-protection law requires that the local-language version govern.


12. Contact

Velynq, Inc. (data controller)
221 W 9th Street, PMB 858, Wilmington, DE 19801, United States
Phone: +34 919 933 168
Privacy / data requests: privacy@velynq.co
General support: support@velynq.co

A Data Protection Officer is not required for our processing (we do not carry out large-scale monitoring of individuals or process special categories of data); for any data-protection question, contact privacy@velynq.co.

EU / UK Representative (GDPR Article 27)

Velynq, Inc. is established in the United States. Under Article 27 of the EU GDPR and Article 27 of the UK GDPR we have appointed Prighter as our representative in the European Union and the United Kingdom, with a separate representative entity for each region. Individuals in the EEA and the UK, and supervisory authorities, may contact the relevant representative about how we process personal data:

Our representative forwards your request to us. Appointing a representative does not change that Velynq, Inc. remains the data controller.


This Privacy Policy is maintained by Velynq, Inc. and applies to the TicQuest app and the services that power it.