What SideQuestle collects, why it is needed, and the choices you have. Photo memories and public photo sharing are unavailable in the first release.
1. Who is responsible
Sevvel Mahendranathan, based in Australia, operates SideQuestle and is responsible for the personal information described here. Where data-protection law uses the term, this is the data controller. Contact help@sidequestle.com for privacy requests or complaints.
This policy covers the app, website, Quest photo checking, accounts, social features, and support. It does not replace the privacy policies of a sign-in provider, app store, or other independent service you choose to use.
2. Information we handle
- Account information: an account or guest identifier, email and sign-in provider information when you register, username, display name, avatar selection, and age/safety confirmations. Apple may supply a private relay email. We do not receive your Apple or Google password.
- Game activity: Quests played, attempts, capture and completion times, verification outcomes, scores, rankings, streaks, and progress. Guest play can create server records as well as device-local data; guest does not mean anonymous to our systems.
- Photos: images you submit for checking, along with the associated Quest and capture time. Saved or shared copies from earlier testing may also have visibility and moderation records. An image may reveal people, surroundings, or information visible in the scene.
- Social activity: friend requests, connections, username searches, invitations you initiate, blocks, and reports. A username can also be supplied by another player searching for or reporting an account.
- Technical information: IP address, request timestamps, device/app/browser information and error or security records needed to deliver and protect the service. Your device also stores preferences, sessions, cached progress, and pending photos.
- Support: your contact details, message, and relevant account or issue information you provide, including complaints and privacy requests.
Information comes from you, your use of the service, chosen sign-in providers, and other players’ interactions with you. Providing an email is not required to explore the website. Account and photo features need the information used to provide them; if you withhold it, those features may not work.
3. Why we use it
We use this information to authenticate you, deliver daily games, check photos, record progress and fair results, manage content according to your choices, connect friends, resolve problems, investigate abuse, and comply with the law.
Where EU or UK data-protection law applies, the proposed bases for this launch are:
- Providing the service you request: essential account, gameplay, verification, and support processing needed to perform our agreement.
- Your consent: optional processing for which we ask for consent. Public photo sharing is unavailable in the first release. You can hide a photo shared during testing. Withdrawal does not change the lawfulness of earlier processing.
- Legitimate interests: proportionate security, abuse prevention, fair-play checks, service reliability, and resolving disputes, balanced against your rights and the interests of younger players.
- Legal obligations: responding to valid legal requests and keeping records where the law requires it.
We do not sell personal information or share it for cross-context behavioural advertising. The website does not include advertising trackers or an optional analytics SDK. New uses, paid features, or optional tracking will need updated disclosures and any required consent before they begin.
4. Photos and AI checking
During app setup, we ask for explicit permission before sending a Quest photo and the Quest criteria through our server to OpenAI to assess whether the image matches the clue. You may decline and still use parts of SideQuestle that do not require photo checking, but you cannot complete photo Quests. You can change your choice in Privacy & Safety. The response can be a pass, a mismatch, or an uncertain result. It affects whether the attempt is accepted and recorded. AI can make mistakes; you can contact support about a decision.
The verification request does not intentionally include your email, name, or account identifier. However, anything visible in the photo goes with the image. Do not include identity documents, screens with private messages, addresses, financial details, or other sensitive information.
We configure the check to assess the clue, not identify people or infer sensitive traits. SideQuestle does not use it for facial recognition or biometric identification. The app sends a newly rendered JPEG for checking rather than the original camera file. This does not remove information visible in the scene.
Our OpenAI request disables stored responses. This is not a promise of zero provider retention: OpenAI’s standard API abuse-monitoring logs may retain customer content for up to 30 days, with legal or safety exceptions. Its published API policy says API data is not used to train models by default. See OpenAI’s API data controls.
In contrast, the website demo processes camera or selected images in your browser. It does not upload them to SideQuestle or OpenAI, check them with AI, or save them to an account. Restarting or reloading clears the demo preview. Your device’s camera or photo picker may separately keep a copy.
5. What other players can see
Your username, avatar, eligible result, time, and rank may appear in account-based rankings. Your Quest photo is not shown on the leaderboard in the first release.
Saved photo memories and public photo sharing are unavailable in the first release. Older test photos, if any, remain subject to the controls and deletion process described below.
World rankings can show your username, avatar, time, and rank. Other players can find your account by username. Friends rankings show results within the relevant friends view; having a Friends view does not make a World result private. Your email and private display name are not leaderboard fields.
You can hide a shared photo and use report or block controls. Hiding stops new authorised access, but previously loaded or copied images can persist. Blocking is an interaction control, not a guarantee that someone cannot see information already made public.
6. Service providers and disclosures
- Supabase: account authentication, databases, photo storage, and server functions.
- OpenAI: photo-and-clue verification as explained above.
- Vercel: website hosting, delivery, and associated infrastructure/security logs.
- Apple or Google: authentication when you choose their sign-in option, and app distribution through their stores.
- Resend: delivery of authentication emails through the configured email service.
- Google email services: handling messages sent to our support mailbox.
Providers receive information needed for their role. Their own account, security, and legal obligations may also apply. We may disclose relevant information to authorised advisers or authorities when necessary for a legal obligation, to protect people or the service, or to resolve a claim. A business transfer would require appropriate protections and notice where required; it does not remove your privacy rights.
7. International processing
SideQuestle is operated from Australia and uses international providers. Information may be processed outside your country, including in Australia and the United States, and in locations used by those providers and their subprocessors. This is not a promise that all data stays in Australia.
Before this draft takes effect: the production hosting regions, complete recipient-country list, and applicable overseas-transfer safeguards must be confirmed. Where EU or UK law requires a transfer mechanism, the release must document the applicable adequacy decision or contractual safeguards and how to request a copy. Any required local representative’s contact details must also be added.
8. Retention and deletion
We retain personal information only for the purpose for which it is needed, taking account of whether your account remains active, unresolved support or safety issues, and legal requirements. We do not promise permanent photo storage.
- Account and results: kept to provide your account and progress until deletion, subject to specific legal, security, or dispute-related exceptions.
- Saved photos: new photo memories are not offered in the first release. Any older test copies require separate removal or account deletion.
- Verification: the image is sent for checking; the verdict and timing are recorded with the attempt. Temporary uploads and abandoned photo drafts have a separate cleanup lifecycle. Provider retention can still apply even if you do not save the photo.
- Support, moderation, and security records: retained for as long as reasonably needed to resolve the issue, protect the service, or comply with a specific legal obligation. Access should remain limited to those purposes.
- Backups and caches: deletion from active systems may precede expiry from backups and cached copies. Copies independently saved by other people or by your device are outside our control.
Release setting to confirm: temporary Quest photo uploads have a 24-hour cleanup deadline in the current backend. Production cleanup operation, backup expiry, log retention, and cloud-deletion completion time still need verification before publication.
See Delete your account to request deletion without reinstalling the app. If a specific record must be retained, we will explain its category, reason, and applicable period unless the law prevents that disclosure.
9. Device permissions and storage
The camera is requested for photo capture. You can decline or revoke permission in device or browser settings; photo capture will then be unavailable. The Quest camera does not require microphone, address-book, or precise GPS permission. An IP address and visible photo content may still reveal approximate location or surroundings.
The app stores sessions, settings, progress, and photo-related data on your device. The website’s demo uses temporary browser memory. Read Cookies & device storage for the distinction between website storage, app data, and hosting logs.
10. Your choices and rights
Depending on the law that applies, you may request access, correction, deletion, a portable copy, or restriction of use of your information. You can withdraw consent for an optional use, and you can complain to a privacy regulator. Exercising a right will not lead to unfair treatment.
Your right to object: where we rely on legitimate interests, you can object to that processing on grounds relating to your situation. Email help@sidequestle.com and describe the processing you object to.
Email us for a request covering your cloud account. The in-app export currently covers local data and does not include image files or necessarily every server record. We may need proportionate proof of account ownership before providing or deleting data. Do not send passwords, sign-in codes, or identity documents unless a secure, necessary verification process has been agreed.
We will respond within the period required by applicable law and explain any permitted extension or refusal. A privacy request does not require reinstalling the app or creating a new account. Where authorised agents are permitted, they can contact us with evidence of their authority.
You can raise a complaint with the Australian OAIC, the UK ICO, an EEA data-protection authority, or your local regulator, as applicable. You do not have to waive that right to contact us first.
11. Younger players
SideQuestle is intended for ages 13 and above, subject to higher local age or consent requirements. We do not knowingly offer accounts to children under 13. If you believe a child below the applicable age has supplied personal information, contact us so we can investigate and take appropriate action, including deletion.
Do not include children or other identifiable people in a submission without the necessary permissions. For younger players, privacy settings, notices, and safety protections need to be appropriate to their age. A general “13+” statement does not replace country-specific requirements.
12. Security and changes
We use access controls and provider security features to limit access to information. No online service or device can guarantee absolute security. If you suspect a vulnerability, email support with a description, without accessing another person’s data. If a breach requires notification, we will follow the applicable requirements.
We will update the date on this policy when it changes and provide additional notice of material changes where appropriate. We will seek new consent when required, rather than treating a policy update as permission for an unrelated use.
Questions about this page?
help@sidequestle.com