TicQuest Privacy Policy
Effective date: 2026-09-02 Version: 2.1
TicQuest is operated by Velynq, Inc., a Delaware corporation ("Velynq", "we", "us", "our"). This Privacy Policy explains what personal data we collect through the TicQuest mobile and web application ("TicQuest" or the "App"), how we use it, with whom we share it, how long we keep it, and the rights you and your child have.
TicQuest is a children's routine and chore-reward tool for families. Only a parent or legal guardian creates and manages an account; children use the App under their parent's or guardian's supervision and never create an account or sign in. If you are a parent or guardian, please read Section 5 (Children's Privacy) carefully — it explains how we obtain your consent and how you can review, export, or delete your child's information at any time.
1. Summary
- We collect the minimum data needed to run the App. From your child we collect only a name or nickname (that you choose), their in-app activity (stars, streaks, completed tasks, certificates), and a device-pairing token if you link a second device.
- We collect a parent email address (or an OAuth sign-in identity) to create and secure your account.
- We show no advertising, use no third-party analytics, advertising, or tracking SDKs, and never sell or share personal information.
- A few features are off by default: optional first-party product & attribution analytics (Section 2.5) and optional on-device reminder notifications. Before analytics opt-in, the App may stage a minimised install-source envelope only on your device for up to 30 days; it is uploaded, already keyed to your family account, only if you opt in. No anonymous install is stored on our servers. The analytics carries no direct child identifier, stays first-party (the data reaches no third-party analytics service), and builds no profile. Turning it off stops collection and deletes the family-linked analytics from our live systems.
- We obtain verifiable parental consent before collecting a child's personal information (Section 5).
- You can export or delete all of your family's data at any time from within the App.
2. Data We Collect
2.1 Parent / Account-Holder Data
- Email address — collected at sign-up (email-and-password flow), used for account creation, verification, security, password reset, and the emails described in Section 2.6. Stored by our authentication provider (Supabase); every email we send you is delivered by our email provider (Resend).
- OAuth identity — if you sign in with Apple, Google, or Facebook, we receive a verified identity token and basic profile (e.g., a display name) from that provider. We never receive your password.
- Parental-consent record — the consent tier and the timestamp when you gave consent, stored on your family record as our COPPA consent record (Section 5).
- Subscription / billing metadata — if you subscribe, we store subscription status, plan interval, period dates, and an external subscription identifier from the App Store, Google Play, or our subscription-management provider. We do not receive or store your payment-card number or any other financial-instrument details (Section 3).
- App settings — notification preferences, audio/haptic settings, and display options you configure.
- Device-pairing data — if you pair a child's device, a time-limited 6-character pairing code, a device token (UUID), and the times the device was linked / last seen. The device token links the second device to your family and authenticates and rate-limits that device's requests to our servers — including the de-identified reliability diagnostic in Section 2.7. To prevent abuse of these endpoints we keep short-lived security counters (Section 8): the token- and IP-based counters are keyed on a salted, one-way hash (never the raw token or IP address), and a per-child upload counter references the child only to cap request volume; all are retained no more than a few days.
2.2 Child Data (deliberately minimal)
- Name or nickname — a name or nickname you type when adding a child; no real name is needed and no surname is requested.
- Behavioral / gameplay data — routine and task completion logs (per-task on-time status, stars earned, timestamps), star counts, streaks and active-day counters, certificates earned, optional alarm settings, monthly/yearly progress summaries, quest-completion and rest-day records, and reward unlocks.
- Avatar — a preset illustration key (e.g.,
avatar-boy1) you choose from our built-in library. Never a photograph or uploaded image. - Time zone — your device's time zone (e.g., "America/New_York"), used only to calculate streak and activity dates in your child's local time. This is a coarse regional setting, not precise location, and we request no location permission.
2.3 Parent-Authored Free Text
You may create routine titles, task names, and reward labels. These are stored as-is; we neither require nor parse them for personal information. Please avoid entering sensitive data in these fields (see Section 6 of the Terms of Service).
2.4 Parent Feedback (optional)
If you choose to send us feedback from inside the App (Settings → "Send feedback" — available only in the parent area), we collect the message you write, together with the app version, platform (Android/iOS/web), and the App's display language, so we can respond to problems and improve the App. A copy of that message — and only that message plus those three technical fields, with no account, family, or child identifier attached — is relayed to our support mailbox by our network provider (Cloudflare; Section 6). Feedback is written by parents, never requested from children. Please don't include sensitive personal data in a feedback message.
2.5 Anonymous Usage Counters
We keep aggregate, non-identifying usage counters — screen-view counts recorded by day and hour bucket and by platform — to see which screens are used and where new families drop off during setup, so we can improve the App. These counters are never linked to any account, device, or child, carry no identifier of any kind and no free text, and cannot be traced back to an individual. They are our own first-party counts (no third-party analytics or advertising SDK — see Section 3).
Optional product & attribution analytics (off by default). Separately from the anonymous counters above, TicQuest includes a first-party analytics feature that is off by default: unless you opt in, nothing about your family is uploaded to or stored on our servers. At first open the App reads the Google Play install referrer once and stages one minimised envelope only on your device: the coarse install source and medium (never a campaign name, and with click-identifiers stripped so no per-click token is kept), your device's language, a 2-letter country code, and the time of first open. The pending envelope is discarded after 30 days if you do not opt in, and there is no server call or anonymous server-side install record at capture time. Only after you, the authenticated parent, opt in does the App upload that envelope, already keyed to your family account, and record family-account-keyed setup / activation / subscription milestones (an allowlisted event name + a timestamp; for example onboarding finished, a routine added, the paywall viewed, or a trial started, renewed, or cancelled). We use this only to understand how consenting families discover and start using the App so we can improve it. When you opt in, the analysis also looks at your family's existing setup and activity from before you opted in — for example, it derives, from data already on your account, when your family created its first routine and completed its first task — so the picture reflects your whole start-up journey rather than only what happens after you opt in. This retrospective analysis runs shortly after you opt in (during our scheduled processing) and reads the setup and activity already on your account; the analytics it then stores is limited to your family account, an allowlisted milestone name, and its timestamp — it stores no direct child identifier, no routine or task content, and no free text. Milestone events carry no custom event properties or free text, and the analytics carries no direct child identifier. Because some milestones reflect your child's activity, we apply the same child-privacy safeguards as elsewhere in the App (minimised, off by default, never used for ads or profiling, and covered by your review, export, withdrawal, and delete rights). It is first-party — stored only in our own systems and sent to no third-party analytics or attribution service (Section 3); the open-source on-device bridge calls Google Play's own Install Referrer API. It builds no advertising or behavioural profile. Turning the feature off stops further collection and deletes your family-linked install, event, and activation-analytics rows from our live systems.
Optional reminder notifications (off by default). You can turn on gentle on-device reminders for your child's routines. These are scheduled locally on your child's device — they send us no data — and the reminder shown on the lock screen is generic and carries no child name (just a prompt to start the next quest). You turn them on, and off, from the App.
App-rating prompt. From time to time the App may show the operating system's own rating prompt. To limit how often it appears, we store only an on-device last-prompt timestamp — it never leaves your device. If you choose to rate the App, your rating goes to the app store under its policy; the App does not receive your individual rating, and we collect no new data to decide when to show the prompt beyond in-app activity we already hold.
2.6 Emails We Send You About Your Child
Besides account emails (verification and password reset), we send you two kinds of message about your child. Both go to your address, never to a child.
- A confirmation when you add a child — sent once, automatically. It tells you the profile was created, repeats what we collect, and carries a one-tap link that removes that child and all of their data. It contains the name or nickname you chose for that child and that removal link.
- Optional activity emails — off unless you turn them on. A daily summary when your child earns a reward, and a Saturday recap of the week. They contain the name or nickname you chose and a short summary of that child's in-app activity — the reward earned, or their stars, days completed and tasks completed for the week. Both are off by default; you switch them on during setup or in the App, and every one of these emails links to a page where you can switch them off again.
We also send you one kind of message about your subscription (not about your child):
- A trial-ending reminder. If you are on a free trial, we send a short heads-up to your address as the trial nears its end so a renewal is never a surprise. It is a subscription message: it contains no child data — only how many days remain and a link to manage your plan.
These emails are delivered by our email provider, Resend (Section 6), which therefore receives your email address, the name or nickname in the child-related messages, the activity summary in the optional activity emails, and — for the trial reminder — the days-remaining count and manage link (no child data).
2.7 Crash & Error Diagnostics
To keep the App stable, if the App crashes or hits an unexpected error — or if a paired child's device detects that it cannot reliably read or save progress — it automatically sends us a structured, technical diagnostic report. A crash / error report contains the error type and category (for example, a display, runtime, or unhandled-promise error), whether it was fatal, an anonymized code-location fingerprint (which part of our own code failed — never your content), the app version, the platform, the display language, the approximate hour it happened, and a short internal de-duplication code (a one-way value, not reversible to your content). A storage-reliability report is narrower still: it contains only closed read / write status and fault-cause fields, the app version, the platform, and the approximate hour — no code-location fingerprint and no display language. Neither report includes the raw error text, your child's name, or any other content you or your child entered, and the stored diagnostic record contains no account, family, child, or device identifier (a paired device's token is transmitted to authenticate and rate-limit the reliability report, as described in Section 2.1, and is never written to the record). These reports are stored in our own systems (Supabase) — we use no third-party crash-reporting service (Section 3, Section 6) — and are deleted within 90 days. Separately, from Settings → About you may choose to send us a fuller diagnostic when you contact support; that one stays on your device until you decide to share it.
3. What We Deliberately Do NOT Collect
These are design decisions, not omissions:
| Category | Status |
|---|---|
| Child age or date of birth | Not collected. |
| Child photographs or uploaded images | Not collected. Avatars are preset illustration keys only. |
| Precise location or GPS | Not collected. No location permission is requested. |
| Third-party analytics / advertising / tracking SDKs | Not present. No Sentry, PostHog, Firebase Analytics, Mixpanel, Amplitude, AppsFlyer/Adjust-style attribution SDKs, ad networks, or equivalent. (The optional, off-by-default product & attribution analytics in Section 2.5 are first-party — they run in our own backend and the data reaches no third-party analytics or attribution service. We read the install source with an open-source on-device bridge that calls Google Play's own Install Referrer API; that bridge is not a third-party analytics or attribution service, and no such service receives the data.) |
| Payment-card or bank-account data | Not collected. All payments are handled by the App Store / Google Play. |
| Child email, phone, or postal address | Not collected. Children never authenticate. |
| Behavioral advertising profiles | Never created. We have no advertising partners. |
4. How We Use Data and Our Legal Bases
4.1 Purposes
| Purpose | Data used |
|---|---|
| Running and personalizing the App (routines, progress, stars, certificates) | Child name or nickname, behavioral/gameplay data |
| Account creation, authentication, security | Parent email, OAuth identity |
| Account-verification and password-reset emails | Parent email |
| Confirming a child profile was created, and giving you a link to remove it (Section 2.6) | Parent email, child name or nickname |
| Optional reward and weekly-recap emails, if you turn them on (Section 2.6) | Parent email, child name or nickname, that child's in-app activity |
| Trial-ending reminder email, if you are on a free trial (Section 2.6) | Parent email; days remaining and a manage-plan link (no child data) |
| Understanding how families discover and start using the App — optional, off by default (Section 2.5) | Family-account-keyed setup / activation / subscription milestones, a coarse install source, and device language / country; no child identifier |
| Optional on-device reminder notifications, if you turn them on (Section 2.5) | Scheduled locally on the child's device; sends us no data |
| Recording and honoring parental consent | Consent record |
| Managing your subscription | Subscription / billing metadata |
| Pairing a child's device | Device-pairing data |
| Responding to your feedback (Section 2.4) | Feedback message, app version, platform, display language |
| Keeping the App stable, debugging failures, and preventing abuse | De-identified crash / error / storage-reliability diagnostics (Section 2.7) and short-lived security counters (Section 2.1) |
| Responding to support and legal requests | Relevant account data |
We do not use any data for advertising, behavioural, or cross-app profiling, we use no third-party analytics SDK, and we build no advertising or behavioural profile, nor make automated decisions that produce legal or similarly significant effects about your child. The optional first-party product & attribution analytics in Section 2.5 are off by default, keyed to your family account (with no direct child identifier) and build no profile. The App does compute ordinary progress figures to run its features — for example how many tasks were completed, on-time rates, streak/active-day counts, and reward progress — which is core service functionality needed to run the App for your family (see the legal bases below), not marketing or behavioural profiling.
4.2 Legal Bases (GDPR Article 6 / Article 8)
For users in the European Economic Area (EEA), UK, or Switzerland: TicQuest is set up and run by a parent or guardian, who creates the account, agrees to our terms, and manages everything in it. We process your child's data because it is necessary to run the family service you asked us to provide — not because a child gives consent.
- Legitimate interests (Art. 6(1)(f)) — the legal basis for your child's core in-app data: the name or nickname you choose, their character/avatar, the activity we record to run the App (stars, streaks, completed-task counts, certificates), a device time zone (for local-time dates), and a device-pairing token if you link a second device. Our legitimate interest is providing the chore-and-reward service you have set up for your child. We rely on this rather than a child's consent because the processing is necessary to deliver the service, and we have weighed it under a child-weighted balancing test: we collect no age or date of birth, no free text from a child, and no contact details; we do not profile your child, show ads, or sell or share their data; high-privacy settings are the default; and you can see, export, and delete your child's data at any time. You can object to this processing at any time — in practice, by removing the child's profile or closing your account.
- Contract (Art. 6(1)(b)) — for your own parent-account data: creating and securing your account and providing your subscription. Your child is not a party to that contract, so we do not use this basis for your child's data.
- Legitimate interests (Art. 6(1)(f)), ancillary technical — narrow processing that builds no profile of your child: de-identified crash / error / storage-reliability diagnostics for App stability (Section 2.7), which carry no account, family, child, or device identifier; and short-lived abuse-prevention counters (Section 2.1) — most keyed on a salted one-way hash of a token or IP, and one (a per-child upload cap) that references the child only to limit request volume and is deleted within a few days. Each is minimised to what is strictly necessary and child-weighted where it touches your child.
- Verifiable parental permission is a safeguard, not the basis — before your child's data is created, we obtain your verifiable parental permission and send you a confirmation email (Section 5), and keep a record of it. This is a child-protection control (required by U.S. COPPA; reflecting the UK Children's Code) that keeps you in charge and lets you withdraw at any time — it is not the Article 6 basis for processing your child's data.
- Consent (Art. 6(1)(a)) — the basis for the genuinely optional features that are off by default: the optional product & attribution analytics (Section 2.5) and optional on-device reminder notifications (Section 2.5). Before analytics opt-in, the minimised install envelope is processed locally on the device only and expires after 30 days; upload and all family analytics require your parental opt-in. We keep the feature off by default, let you turn it off at any time, and delete the family-linked analytics from our live systems on withdrawal. The analytics is keyed to your family account, with no direct child identifier. Nothing in the core App relies on a child's own consent.
- Accountability (Art. 5(2) / 7(1)) — we keep records (including your parental-permission confirmation) so that we can demonstrate a valid legal basis, as GDPR / UK-GDPR accountability requires. (U.S. COPPA separately requires these records; that is a U.S.-law obligation.)
Under GDPR Art. 8 the age below which a child's own consent to an online service must be authorised by the holder of parental responsibility is 16 by default; EU member states may lower it by law to no less than 13 — for example Ireland 16, Spain 14, France 15, Germany 16, while the UK sets it at 13, and France additionally requires the consent of a parent and the child where the child is under 15. TicQuest is a parent-managed service: a parent or guardian creates the account and manages their child's data, the child never registers or gives their own consent, and we collect no age or date of birth. Because the core service does not rely on a child's own consent — we process your child's data under our legitimate interest in running the service you set up (§4.2) — these parental-consent-age thresholds, including France's under-15 rule (which governs consent-based processing), are not the operative basis for that processing. We treat the strictest thresholds as our baseline and assess this in our child Data Protection Impact Assessment.
5. Children's Privacy (COPPA + GDPR-K)
TicQuest is designed around children's privacy and the U.S. Children's Online Privacy Protection Act (COPPA, 16 C.F.R. Part 312, including the FTC's 2025 amendments), GDPR Article 8, and equivalent laws.
Parent-controlled accounts. Only a parent or legal guardian creates and manages a TicQuest account. Children never register, never sign in with credentials, and are identified to us by the name or nickname you enter and the in-app activity described above. A paired child's device is also linked to your family by a device token (Section 2.1); any crash, error, or reliability diagnostics we collect from that device are de-identified and do not identify your child (Sections 2.7 and 2.1).
Verifiable parental consent (how we obtain it). Children's data is collected only after a parent or guardian consents. We:
- give you a direct notice of what we collect from your child — a name or nickname you choose, in-app activity, a device time zone (for local-time dates), and a device-pairing token, plus de-identified crash / error / reliability diagnostics and short-lived abuse-prevention counters (Sections 2.7 and 2.1) — that this data is used only to operate, stabilize, and secure the App for your family and is never disclosed to third parties for their own purposes, and that you can revoke consent at any time;
- require you to create a parent account and send a confirmation link to your email address (or, if you sign in through Apple, Google, or Facebook, rely on the verified email that provider gives us) — so the person consenting holds a real, contactable account they control and attests they are the child's parent or legal guardian; and
- capture your explicit parental consent: you confirm you are the child's parent or legal guardian and consent to TicQuest collecting the name or nickname you choose and their activity — both when you accept this Policy at sign-up and again when you add a child; and
- email you a confirmation at your verified address once the profile exists (Section 2.6), repeating the direct notice and carrying a one-tap link that removes that child and all of their data.
Because the personal data TicQuest collects to identify your child is limited to a name or nickname you choose plus in-app activity, used solely to run the App — with only limited technical device-pairing, diagnostic, and security data (Sections 2.1 and 2.7) kept to operate, stabilize, and secure the App — with no advertising, and never disclosed to third parties for their own purposes, this method is reasonably designed to confirm that the person consenting is the child's parent or guardian, consistent with COPPA's verifiable-parental-consent standard (16 C.F.R. § 312.5). You can withdraw consent at any time by deleting the child's profile or your account (Section 9), or by emailing privacy@velynq.co.
We make no other use of your child's data. We use it only to operate the App's features for your family — showing routines, awarding stars, and tracking progress. We do not analyze it for any other purpose, build advertising or behavioral profiles, train AI models, advertise, sell, or share it — ever. Our cloud service providers (Section 6) process child data only to run the App on our behalf, under written data-processing agreements, and may not use it for their own purposes. The optional product & attribution analytics (Section 2.5) operate at the family-account level — your family's setup milestones and the coarse source that brought you to the App — with no direct child identifier. Because some of those milestones can reflect your child's activity, we treat this data with the same child-privacy safeguards as the rest of the App (minimised, off by default, never used for ads or profiling, and covered by your review, export, and delete rights); it is off by default and never uses a direct child identifier.
No advertising or profiling of children. TicQuest shows no ads, builds no advertising or behavioral profiles, and shares no child data with ad networks or data brokers.
Your parental rights. At any time you may review, export, or delete your child's data, and revoke consent — directly in the App (Settings → "Export my family data" / "Delete account") or by contacting privacy@velynq.co. We respond to verifiable parental requests within 30 days.
6. Sharing and Sub-Processors
We do not sell personal information, do not "share" it for cross-context behavioral advertising, and do not disclose it to advertising networks, data brokers, or any third party for their own purposes.
Our processors. Each provider below acts only on our instructions and only to support the App's internal operations, under written data-protection terms in force between it and Velynq, Inc. — a separately signed data-processing agreement in Supabase's case, and for the others a published data-processing addendum (or, for Expo, equivalent processing terms) that the provider's own terms of service make binding on us.
| Processor | Role | Data it processes |
|---|---|---|
| Supabase | Backend: database, authentication, edge functions, hosting | Account, family, and child data in Section 2; de-identified crash / error / storage-reliability diagnostics (Section 2.7); short-lived abuse-prevention counters (Section 2.1); the optional, off-by-default first-party product & attribution analytics (Section 2.5) if a parent enables them, keyed to the family account with no child identifier; platform request logs (including IP at the infrastructure layer, which we do not store in App data tables) |
| PowerSync | Offline sync: mirrors a subset of family/child data to the device for offline use | The synced tables incl. child behavioral data (routine history, stars, streaks, completions, certificates, alarms, device links) |
| Resend | Delivery of every email we send you: account verification, password reset, the confirmation when you add a child, the optional activity emails, and the trial-ending reminder (Section 2.6) | Your email address; the contents of those messages — which include the name or nickname you chose for a child, the removal link in the confirmation email, that child's reward or weekly star / day / task counts in the optional emails, and, in the trial reminder, only the days-remaining count and a manage-plan link (no child data); delivery logs retained by Resend for approximately 30 days |
| RevenueCat | Subscription-state management (live) | A random family identifier we generate (never your name, your email, or a child's name), the store's subscription and transaction identifiers, subscription status, and the app and device information its SDK sends to operate the purchase flow. It receives no child data. |
| Cloudflare | Hosting for our public web pages (velynq.co) and email routing for our published addresses |
Web-request logs (including IP at the infrastructure layer); the contents of email you send to our published addresses, and of in-app feedback, which is relayed with no account, family, or child identifier (Section 2.4); de-identified operational alert counts we send to ourselves (aggregate fault / health totals, with no user, family, or child data) |
| Expo / EAS | App build and over-the-air update delivery | App binaries and updates — no App data; its infrastructure sees the update request itself (including IP) when your device checks for an update |
Not our processors. Apple and Google act on their own behalf, not on ours, when they sell and process a subscription: they are the seller, they take the payment, and they handle your payment data under their privacy policies. We never receive your card number (Section 3); we receive only the subscription receipt data described above. Google also distributes the App through Google Play under its own terms.
We do not use any third-party advertising, product-analytics, attribution, or crash-reporting processor. The optional analytics in Section 2.5 run in our own backend (Supabase); the install source is read from Google Play's own install referrer — not from a third-party attribution service — and reminder notifications are scheduled on the device with no server or push provider. We will update this section before adding any new processor (for example, a push-notification provider).
7. International Transfers
Our primary backend (Supabase) hosts data in the European Union (Ireland). Our offline-sync provider (PowerSync) is configured to process data in the European Union. Our email provider (Resend) sends from its EU (Ireland) region but is a U.S. company. RevenueCat, Cloudflare, Expo, Apple, and Google are U.S. companies and may process the data described in Section 6 in the United States.
If you are in the EEA, UK, or Switzerland and your data is transferred to a country outside those regions, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses, which are part of each of those providers' data-processing terms.
8. Data Retention Policy
This section is our written data-retention policy (COPPA, 16 C.F.R. § 312.10, as amended in 2025; GDPR Art. 5(1)(e)). We keep children's personal information only as long as is reasonably necessary to fulfill the purpose for which it was collected, and we do not retain it indefinitely. For each category we state the purpose, the business need, and when it is deleted:
| Data | Purpose / business need | Retention |
|---|---|---|
Routine completion logs (routine_history) |
Show recent day-by-day history to the parent | 7-day rolling — automatically deleted daily by a scheduled job |
| Monthly progress summaries | Parent progress dashboard (current-period view) | Kept while the account is active; deleted when the child or account is deleted |
| Yearly progress summaries (aggregate counts only) | Show your child's progress over time | Kept while the account is active to display long-term progress; deleted when the child or account is deleted |
| Child profile, routines, tasks, rewards, streaks, certificates | Operate the App for your family | Kept while the account is active; deleted when the child or account is deleted |
| Parental-consent record | Demonstrate COPPA/GDPR-K compliance | Kept while the account is active; deleted on account deletion — we keep no separate copy |
| Device-pairing records | Link a child's device | Pairing codes expire automatically; link records persist until you unpair or delete the account |
| Subscription / billing metadata | Manage your subscription and resolve disputes | Kept while the account is active; deleted on account deletion (see the de-identified financial records noted below) |
| Parent feedback messages (Section 2.4) | Respond to problems and improve the App | 24 months, deleted automatically by a scheduled job; also deleted earlier when the account is deleted |
| Inactive accounts | None — the data is no longer needed | If an account has no activity for 24 months, we email you a 30-day notice and then delete the account and all of its data |
| Diagnostic and server logs (requests, sync, authentication) | Security, debugging, abuse prevention | 90 days, then purged |
| Security / rate-limit counters (Section 2.1) — salted, one-way token/IP hashes and a per-child upload counter | Abuse prevention on our endpoints | A few days (a daily scheduled job purges them; typically within ~3 days) |
| Crash, error & storage-reliability diagnostics (Section 2.7) | Keep the App stable and debug failures — structured and de-identified: for a crash / error, the error type and category, whether fatal, anonymized code-location fingerprint, app version, platform, display language, approximate hour, and a non-reversible de-duplication code; for a storage-reliability report, only closed read / write status and fault-cause fields with app version, platform and approximate hour; no raw content and no account, family, child, or device identifier | 90 days, then deleted by a scheduled job |
| Anonymous usage counters (Section 2.5) | Improve the App; they identify nobody | 14 months, then deleted by a scheduled job |
| Optional product & attribution analytics (Section 2.5), if enabled and you opt in — a family-linked install record (coarse source + medium, device language / country, first-open time) and family-account-keyed setup / activation / subscription milestones (allowlisted event name + timestamp), with no direct child identifier. Before opt-in, the minimised install envelope stays only on the device | Understand how consenting families discover and start using the App; the ~12-month event window supports cohort / seasonality analysis | Pending on-device install envelope → up to 30 days, then discarded if still pending; general analytics events → 12 months (365 days), then purged by a scheduled job; family-linked install + activation events → retained with your family, deleted immediately when you turn analytics off, and also deleted when you delete your account. No anonymous install is stored server-side |
Account and data deletion. You can delete your account at any time in the App (Settings → "Delete account"). This immediately deletes your account and all associated data — family record, every child profile, all activity data, routines, tasks, rewards, and subscription records — by a cascading database deletion. Deletion is immediate and cannot be undone from within the App. We may retain limited billing and transaction records in de-identified form (with your family identifier removed, so they no longer identify you) where required for financial record-keeping, fraud prevention, or legal compliance. Separately, copies cached offline on your device(s) are cleared when you sign out or delete the account, and routine infrastructure backups held by our hosting provider are overwritten on that provider's rolling backup cycle — currently 7 days — and are never used to restore a deleted account.
We review this schedule at least annually, and whenever we start collecting a new category of data.
9. Your Rights
9.1 All Users
- Access / portability — request a machine-readable copy of your family's and children's data (the information in Section 2) directly in the App (Settings → "Export my family data"). Your account login email is the address you sign in with; for a copy of any other account-identity data held by our authentication provider, contact privacy@velynq.co.
- Erasure — delete your account and all associated data (Settings → "Delete account"), or contact privacy@velynq.co.
- Rectification — update your account details; child names or nicknames and content are editable directly in the App.
- Withdraw consent — withdraw consent for your child's data by deleting the child's profile or your account, or by contacting privacy@velynq.co.
9.2 EEA / UK Users (GDPR)
You also have the right to restrict or object to processing, and to lodge a complaint with a data-protection supervisory authority: in the UK, the Information Commissioner's Office (ICO); in the EEA, your local supervisory authority in the member state where you live or work. You may also raise any data-protection concern with our EU / UK representative (Section 12). We ask that you contact us first so we can help.
9.3 California Users (CCPA / CPRA)
We do not sell personal information and do not "share" it for cross-context behavioral advertising. You have the right to know what we collect (Section 2), access a copy (in-app export), delete it (in-app "Delete account"), and not be discriminated against for exercising these rights. To exercise them, use the in-app tools or contact privacy@velynq.co.
10. Security
We maintain reasonable administrative, technical, and organizational measures to protect personal data, including:
- TLS/HTTPS encryption for all data in transit between the App and our servers;
- short-lived authentication tokens managed by our authentication provider;
- time-limited pairing codes and signed tokens for device pairing;
- database Row-Level Security that scopes every query to the authenticated parent's own family; and
- a database-level rule that a child profile cannot be created unless a parental-consent timestamp is recorded.
No method of transmission or storage is perfectly secure. To report a security concern, contact privacy@velynq.co.
11. Changes to This Policy
We may update this Policy when the App changes (for example, if we add a push-notification provider). We will revise the effective date above and, for material changes, provide an in-app notice or email. Continued use after the effective date constitutes acceptance.
Governing language. This Policy was drafted in English. Any translation we provide is for your convenience; the English-language version is authoritative and controlling — except to the extent applicable mandatory consumer-protection or data-protection law requires that the local-language version govern.
12. Contact
Velynq, Inc. (data controller)
221 W 9th Street, PMB 858, Wilmington, DE 19801, United States
Phone: +34 919 933 168
Privacy / data requests: privacy@velynq.co
General support: support@velynq.co
A Data Protection Officer is not required for our processing (we do not carry out large-scale monitoring of individuals or process special categories of data); for any data-protection question, contact privacy@velynq.co.
EU / UK Representative (GDPR Article 27)
Velynq, Inc. is established in the United States. Under Article 27 of the EU GDPR and Article 27 of the UK GDPR we have appointed Prighter as our representative in the European Union and the United Kingdom, with a separate representative entity for each region. Individuals in the EEA and the UK, and supervisory authorities, may contact the relevant representative about how we process personal data:
- EU / EEA representative: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria
- UK representative: Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom
- Contact the representative or lodge a request: app.prighter.com/portal/12906258038
Our representative forwards your request to us. Appointing a representative does not change that Velynq, Inc. remains the data controller.
This Privacy Policy is maintained by Velynq, Inc. and applies to the TicQuest app and the services that power it.