MyQuests

Privacy Policy

Effective date: July 14, 2026  ·  Notice version: 2026-07-13 (the version recorded against your consent in the app)

The short version: a parent creates the only account (email + PIN). Kids never get an email, a password, or an account of their own — they're set up by the parent with just a first name and a chosen character, and join a device with a short pairing code. We don't show ads, we don't use third-party analytics or ad trackers, and we don't sell data. Apple only ever sees what it needs to bill the subscription.

Who we are

MyQuests is an app made by Winn.solutions ("we", "us"). This policy explains what information MyQuests collects, why, and the choices and rights you have — especially around your children's information, since MyQuests is a family app.

What we collect

About the parent (the account holder)

About children

For each child profile, we collect only:

That's the entire child data model. We do not collect a child's email address, we do not create a login, password, or account for a child, and we do not collect photos, precise location, or any other personal information from or about a child.

Game and account activity

To run the app we store quest completions, parent approvals, and a gold ledger tied to your family's account, plus your subscription/trial status. This activity is associated with your family account and a child's first name — not with any additional identifying information, because we don't collect any.

What we do not collect

We do not collect payment card details (Apple handles all billing — see "How we share information" below), precise location, contacts, photos/camera access, or advertising identifiers.

Why we collect it

Children's privacy (COPPA)

MyQuests is designed around the Children's Online Privacy Protection Act (COPPA, 16 CFR Part 312) from the ground up, not bolted on after the fact:

This is a data-minimization posture: because we only ever collect a first name and a character choice for a child, we've scoped this policy — and our systems — to match, rather than collecting more and asking for broader verified parental consent under 16 CFR §312.5.

How we share information

We share the minimum necessary with one processor:

We do not share, rent, or sell family or child data to advertisers, data brokers, or any other third party. If we ever turn on optional account-verification email (a capability that exists in our systems but is currently disabled), it would be sent through a transactional email provider solely to deliver a one-time verification code to the parent's email address — never for marketing, and never involving a child's information.

Data retention

We keep your family's data for as long as your account exists. Canceling a subscription stops billing but does not delete your data automatically — your account and history stay intact in case you come back. If you want your data removed, use Delete account (below), which is immediate and permanent.

Your rights and choices

As the parent account holder, you can at any time, from inside the app:

Because children never have their own account or email, these rights are exercised entirely by the parent on behalf of the whole family — there's no separate child login to manage.

Security

PINs are never stored in plain text (salted PBKDF2-SHA256 hashing). Sessions and device-pairing tokens are randomly generated, short-lived, and scoped to your family's account only — no request can read or change another family's data.

Changes to this policy

If we materially change what we collect or how we use it, we'll update this page and the notice version number above, and — for changes affecting children's data — ask parents to re-consent in the app.

Contact us

We're finalizing a dedicated support/privacy contact address. In the meantime, please reach us through the Support page.