Tup Quest privacy policy

Effective from 5 October 2026. Version 1.2.

Version 1.1, effective until 4 October 2026 — archive

What changes in version 1.2. Usage statistics — the ones you switch on yourself and that are off by default — now go to Amplitude, a product-analytics tool, in addition to our database in Ireland. Section 4.3 describes exactly what goes there, what does not, and how to have it deleted. We publish this version 14 days before it takes effect, as section 13 promises, and until that day nothing is forwarded to Amplitude. Version 1.1 applies until 4 October 2026.

This is a courtesy translation. In case of any discrepancy, the Polish version prevails.

In short

Tup Quest is a game about the city. It marks on the map the streets you have actually walked and the cultural places you find.

The rest of this document is detail. It's worth reading, but the points above are the whole truth about this app.

1. Who the data controller is

The controller of personal data is:

Cybird Consulting Dariusz Ptaszek ul. Chmielna 2/31, 00-020 Warsaw, Poland NIP (tax ID): 7343126589 REGON: 387337946 Poland

Contact for all privacy matters: d.ptaszek@gmail.com App website: https://tup.quest This policy: https://tup.quest/en/privacy (Polish: https://tup.quest/prywatnosc) Terms of service: https://tup.quest/en/terms Help & FAQ: https://tup.quest/en/help

We have not appointed a data protection officer — the activity does not meet the criteria of Article 37 GDPR. Messages are answered by the business owner.

2. What data are processed and where

2.1 Data that stay solely on your device

The app stores in a local SQLite database on the phone:

The step count is not stored — the app reads it from the system live to show it on screen and never persists it.

GPS tracks, walked street details and detailed walk history remain local unless you choose to share a file containing them. Nickname, aggregate scores and the account identifier may be transmitted through the features described in sections 4 and 5. Uninstalling removes the local database, but does not delete the server account.

GPS matching and detailed track storage take place on your device. We do not hold a server copy of those tracks. Network features and user-initiated sharing are described separately below.

2.2 Data that actually reach us

When you contact support, we receive your message, email address and attachments. Separately, we process the network-feature data described below.

Beyond that: in the App Store Connect and Google Play Console dashboards we see aggregate, usage statistics (download counts, system versions, countries). We don't see who installed the app and cannot link these figures to a specific person.

Our database in Ireland receives technical identifiers, nickname, group names, city, scores and usage events described in sections 4.3 and 5. GPS tracks are not sent there. From that database, a narrowed version of the statistics events is forwarded onward to Amplitude — see section 4.3.

We describe separately the technical data that go to third-party service providers rather than to us — map tiles and update checks (section 4).

2.3 Data that are not collected at all

The app does not require email, password or phone number, access contacts or photos, or collect payment details. Support receives your email and attachments if you choose to contact us. Steps are read locally; after analytics consent, walk duration and distance are transmitted. We do not access HealthKit. The app is free, without ads or in-app purchases.

We do not use cross-app tracking or advertising identifiers. Privacy declarations also cover pseudonymous identifiers, city, game scores, interactions, group names, walk duration/distance and error reports, depending on enabled features and consent.

3. System permissions and what each is for

The app asks for four things. You can refuse each — the app keeps working, only some functions stop making sense.

3.1 Location while using the app ("While Using the App")

What for: to mark on the map the streets you walk and to recognise that you've approached a cultural place.

How the default "Only during a walk" mode works: position is read from pressing "Start a walk" until pressing "Finish". Outside a walk the app doesn't ask the system for location.

If you have granted "Always", a started walk continues with the screen locked and the app in the background — so it doesn't break off in your pocket. It ends when you press "Finish". Should you close the app mid-walk instead of finishing it, at the next launch the app in manual mode stops the background position-collecting task itself.

Where the coordinates go: solely to the local database on the phone, as matched street segments and a route trace. They do not leave the device.

3.2 Background location ("Always") — optional

What for: the "Automatically in the background" mode marks walked streets on its own while the app is in the background.

This mode is off by default. You turn it on yourself in the app's Settings — first the app explains plainly that in this mode it reads location also when closed or not in use, and only after your consent does the system ask for the "Always" permission. It uses more battery. You can turn it off at any time in the app's Settings or revoke the permission in the system settings. Coordinates from this mode likewise do not leave the device.

3.3 Motion & Fitness / activity recognition (pedometer)

What for: the app reads the step count from the system (Apple Motion on iOS, Activity Recognition on Android) to show it in Profile as a curiosity ("side effect").

The step count is read locally, not stored in the app's database, does not affect points and is not sent anywhere. The pedometer does not control location reading.

Tup Quest is not a sports or health app. It shows neither pace nor heart rate, has no step goal and stores no health data.

We store walk duration and distance locally, because the walk history is made of them. If you switch statistics on, those two numbers leave the phone — to our database and to Amplitude. We declare them in the store forms as physical-activity data, because that is what they are, joke framing notwithstanding.

In the walk summary we show one calorie figure, converted immediately into food — a joke at the expense of fitness metrics, not a measurement. We compute it on the phone as a fixed factor of distance, assuming a weight of 75 kg. We don't ask for your weight, height, age or sex, don't know them and don't want to. The figure is not an individual measurement, and it is neither stored nor sent anywhere.

3.4 Notifications — local only

What for: a single notification — when a walk closes itself after twenty minutes without movement (because it ended in your pocket, without a button), the app says so on the lock screen: how many new streets, how many kilometres, that the summary is waiting.

The app asks for notification permission once, at the first "Start a walk". The notification is created on the phone by the app itself — there is no push server, no device token, and nothing related to notifications leaves the phone. We send no promotions or "come back" nudges. The only additional notification — a weekly summary on Sunday at 6 pm (how many streets this week, which district is closest to done) — is off by default; you turn it on yourself in Settings, and its content and timing are also produced on the phone. You can revoke the permission in the system settings.

4. Map, updates and internet connections

The app connects to the network for five things: it downloads map tiles, checks whether an update is available, runs the city leaderboard with friends' groups (section 5), sends usage statistics and — when something in it breaks — a crash report (section 4.4). Beyond that it sends and downloads nothing.

4.1 Map tiles (OpenFreeMap)

The app downloads vector map tiles from the OpenFreeMap server (tiles.openfreemap.org).

As with any online map, the tile provider sees with such a request your device's IP address and which map fragments were requested. From the map fragments one can roughly infer which area you are in. We say this plainly because that is how it works and it can't be avoided without giving up the map.

We don't send the map provider your route, points, nickname or player identifier. We also have no access to the tile server's logs.

4.2 Update checks (Expo / EAS Update)

The app uses an over-the-air update mechanism (OTA, expo-updates). It lets fixes to the app layer reach you without waiting for a new store version. The mechanism is enabled in the versions published in the App Store and Google Play.

How it works: at launch the app asks the u.expo.dev server whether a newer package exists for its channel and version. If so, it downloads it in the background and runs it at the next app start. The downloaded package contains only the app's code and assets.

What such a request sends to the update service provider:

What never goes there: coordinates, track traces, walk history, points, badges, nickname or step count.

The service provider is Expo Project Services, an entity based in the United States. This means a transfer of the above technical data outside the European Economic Area; see section 7.

We don't link the installation identifier with any other data and have no tool that would let us recognise anyone by it. We also have no access to the update server's raw logs.

4.3 Optional usage statistics (our database in Ireland and Amplitude)

Usage statistics help us improve the app. They are off by default. You can consent during onboarding or in Settings → Statistics and error reports. Declining does not limit the game. A previously default-enabled setting is not treated as consent.

Consent is single and indivisible. It covers storage in our database, forwarding a narrowed version of the event to Amplitude, and error reports in Sentry, all at once. You cannot accept one and refuse another — we say so plainly so that nobody hunts through Settings for a switch that isn't there.

Withdrawing consent immediately stops collecting events and clears the queue on your phone. It also orders the server-side queue — the one waiting to be forwarded to Amplitude — to be erased. If you have no internet at that moment, the order is remembered and we repeat it at every app start until the server confirms it. What it cannot undo: a request already sent over the network, or data forwarded earlier — those remain until you ask us to delete them or delete your account. Withdrawing consent does not switch off network features such as maps and the optional leaderboard.

What we send:

Requests are authenticated: the server adds the player ID (auth.uid()) as player_id. Statistics can therefore be linked to that player's leaderboard entry. These data are pseudonymous, not anonymous.

What we never send: coordinates, track traces, street names, names of specific found places, which route stop you checked, nickname, group names, step count, calorie count, e-mail address, phone number, device model or advertising identifiers.

IP address. Events go to our own server, so — as with any HTTP request — the server gateway sees the device's IP address. We don't store it in any table: the stored event has no field for an IP address or for a network country or city. Addresses appear only in the hosting provider's technical logs, used for maintenance and abuse protection, and are deleted by the provider after a few days.

Where it lives. Statistics go to two places. The first is our own database — a Supabase project (PostgreSQL) in the eu-west-1 region, i.e. on servers in Ireland. It is the same database that serves the leaderboard and groups. The second is Amplitude, described below.

Amplitude — the tool we read statistics with

A database on its own does not answer the question "do people come back after a week". That is what Amplitude is for: a product-analytics tool that shows the same events as charts and funnels. We describe it separately because it is another entity processing your data, and we think that deserves a clear statement rather than a footnote.

How it works. The app does not connect to Amplitude. There is no Amplitude SDK on your phone, and the number of network connections from your device does not change because of this. The event reaches our database in Ireland, and only from there does our server forward a narrowed version onward.

Amplitude gets less than we do. We pass through only events from a closed list and only properties from an allowlist — the server strips the rest before anything leaves.

From the list above, what does not reach Amplitude is GPS recording diagnostics — those stay in our database and in Sentry. Everything else on the list does reach it.

Your player profile in Amplitude. Along with the events we forward seven numbers and labels describing your state in the game: chosen city, tracking mode, level, experience points, badge count, number of places found, and weekly league. In Amplitude these are not a property of a single event but a persistent profile attached to the player identifier, overwritten whenever it changes. They serve one purpose: making it possible to compare whether players who got further come back more often. None of them says where you have been — no coordinates, no street names, no names of places you found, no nickname.

Two things Amplitude gets that we don't store ourselves: interface language and an environment marker. We mention it so as not to leave the impression that Amplitude only ever sees a subset of our database.

The identifier. As the user identifier we use the same player ID as the leaderboard, with a prefix. It is therefore not a separate, weaker identifier — it is the same pseudonymous value. We say so plainly, because the opposite impression would simply be untrue.

IP address. In every forwarded event we hard-code the address 0.0.0.0, so that your address is not passed on and no location can be derived from it. The connection itself leaves our server in Ireland, not your phone, so Amplitude does not see your device's address. What we describe here is what we do — we do not make promises on the provider's behalf.

Where it lives and for how long. The project is set up in the European Union region, so the data stay in the Union. We set the project's retention to 12 months — the same period for which we keep events ourselves. The provider is Amplitude, Inc., based in the United States, acting as a processor; see section 7.

Deletion. When you delete your account in Settings, our server erases everything not yet forwarded and sends Amplitude a request to delete its copy. Honestly: this is a request addressed to the provider, not our own erasure of the data. Amplitude carries it out on its own schedule, and what we receive is confirmation that the request was accepted, not that the data were deleted.

Usage statistics use our HTTP interface to Supabase. Sentry handles optional error reports as described in section 4.4.

GPS recording diagnostics use the same consent. They include aggregate counts of accepted, rejected and late readings, accuracy bands, gap durations and delivery delays, trace splits, storage errors, foreground/background state, location mode and permissions, and OS, native build and update versions. A random report number helps us locate a support report. We do not send coordinates, street names or sequences of readings. Summaries go to Supabase including when no problem is found; anomalies and manual reports also go to Sentry. The shared report number can link these reports to the account’s pseudonymous statistics. GPS diagnostics are not forwarded to Amplitude — they stay in our database and in Sentry. Withdrawing consent clears pending summaries.

4.4 Error and GPS quality reports (Sentry)

With your consent to statistics and error reports, the app can send a JavaScript error report or an aggregate GPS recording quality report to Sentry. This is off by default. Automatic session tracking, performance tracing and native offline crash reporting are disabled.

Reports include the error, stack trace, app and update version, environment details, screen name and selected city. We remove user and request data and replace the IP address with a non-routable sentinel to prevent IP geolocation enrichment. We discard network breadcrumbs that could contain map tile URLs. GPS tracks, nicknames and player IDs are not attached. The server sees the connection IP; the project is configured not to store it in reports.

Withdraw consent in Settings → Statistics and error reports. No new report transmissions are started after withdrawal. Requests already sent cannot be recalled.

Where it lives. The service is provided by Functional Software, Inc. (Sentry) as a processor; our project is in the European Union region (servers in Frankfurt, Germany). Reports are kept for 90 days and then deleted automatically.

4.5 Where the city data come from

Street and place data come from OpenStreetMap, under the ODbL licence, © OpenStreetMap contributors. Cultural collections are edited by the Tup Quest editors. Each city's data are bundled with the app — they are not downloaded from the network during play.

5. City leaderboard and friends' groups

The leaderboard and groups are voluntary. Separately, usage statistics send the data in section 4.3 after explicit consent. The app works fully without them: the map, finds, badges and weekly league are computed on your phone.

Until you enter a nickname, you're not on any leaderboard. That is the moment you knowingly join the competition — and that is the consent referred to below.

5.1 Exactly what leaves the phone

The numbers concern that one city whose leaderboard you join, and the current week — they are not a sum across all the cities you walk in.

What is never sent: coordinates, track traces, walk history, street names, names of specific found places, step count, calorie count, e-mail address or any contact details.

5.2 Friends' groups

A group is a private leaderboard for people who know its code. When starting a group you give it a name; the app draws an eight-character invite code, which you send to whomever you like. To join, you enter that code.

On the server we store: the group's name, its code, who founded it, and the list of player identifiers that belong to it, with the date of joining. Group members see each other's nicknames and scores — and only that.

You choose the group name yourself and it is visible to all its members. If you put someone's real name in it, it becomes personal data — so better not to.

5.3 A guest account without email or password

No email or password is required. When an authenticated feature is first used, the app creates a guest account in Supabase and stores its identifier and session token on this phone. The account links scores, groups and statistics. A nickname can identify you if you choose a real name, so we recommend a pseudonym.

The session token is stored on this phone. After uninstalling or changing devices, access to the previous account cannot be recovered. Uninstalling does not itself delete server records: delete your account in Settings first.

5.4 Where it lives and for how long

Leaderboard and group data are kept in our own database — a Supabase project (PostgreSQL) in the eu-west-1 region, i.e. on servers in Ireland, in the European Union. Access to the tables is restricted by database-side rules: the app doesn't write to them directly, but calls a narrow set of functions that accept exactly the data listed above.

Weekly scores are kept for 12 months from the end of the week they concern. Nickname and group memberships — until you ask for their deletion or leave the group.

5.5 How to withdraw

You can withdraw consent at any time, with effect for the future:

6. Legal bases for processing

What What for Legal basis
Access to device location Marking walked streets and finding places Your consent given through the system permission — Art. 6(1)(a) GDPR and Art. 399 of the Polish Electronic Communications Law of 12 July 2024
Access to the pedometer Showing the step count after a walk Your consent given through the system permission — Art. 6(1)(a) GDPR
Saving progress in the phone's storage Running the game (points, badges, league) Necessity to perform the service you request by launching the app — Art. 6(1)(b) GDPR
Downloading map tiles (IP address visible to the provider) Displaying the map Necessity to provide the function you use — Art. 6(1)(b) GDPR
Update checks (installation identifier, version, platform, channel, IP address) Delivering bug and security fixes without waiting for a new store version Our legitimate interest in maintaining a correctly working and secure app — Art. 6(1)(f) GDPR
Usage statistics in our database (events, city, aggregate numbers, session and player identifiers) Checking which features are used and developing the app on facts Your consent — Art. 6(1)(a) GDPR. You can switch statistics off in Settings; collection stops at once and both queues are cleared
Forwarding narrowed statistics to Amplitude (events from a list, properties from a list, the prefixed player identifier, language) Reading those same events as charts and funnels, i.e. seeing whether players come back The same consent of yours — Art. 6(1)(a) GDPR. Consent is indivisible and covers both recipients
Error reports (error, stack trace, app version, screen and city) Finding and fixing bugs Your consent — Art. 6(1)(a) GDPR and, where applicable, Art. 399 of the Polish Electronic Communications Law. Withdraw it in Settings
Replying to your e-mail Handling your report, support, exercising your rights Our legitimate interest — Art. 6(1)(f) GDPR; for GDPR rights — Art. 6(1)(c) GDPR
City leaderboard (player identifier, nickname, city, week, numbers) Comparing scores with other players Your consent, given by entering a nickname — Art. 6(1)(a) GDPR
Friends' groups (group name, code, member list) A private leaderboard among people you invite yourself Your consent, given by starting a group or joining with a code — Art. 6(1)(a) GDPR

7. Recipients of data

We don't sell data. We don't pass it to data brokers or ad networks. Below is the full list of entities that see any of your data — each with the reason we give beside it.

Data may also be disclosed to authorised authorities where the law so requires. We stress, however, that we simply do not hold data about your routes — we couldn't hand them to anyone, even if someone demanded them.

Transfers outside the European Economic Area

Three things are easy to confuse, so we separate them plainly. Your GPS track and detailed walk history never leave the phone at all — neither within the EEA nor outside it. Aggregate numbers about a walk and your progress (duration, distance, new streets, a badge, district percentage) do leave the phone if you switch statistics on, and are described in section 4.3. Technical data are described below.

Technical data are transferred:

8. How long we keep data

9. Your rights

You have the right to: access your data, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal).

How to exercise your rights:

Shortcuts to this policy, the Terms and Help are also in the app, in Settings → Documents.

We locate account records using the player identifier. We do not request additional identifying data unless needed to fulfil a request. If necessary, we may ask for confirmation of your authority to access or delete those records.

Complaint. If you believe we process data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.

10. No ads, tracking or automated decisions

The app has none of the following and we don't plan them:

What we will not claim, because it would be a stretch: that there is no analysis of behaviour here. If you switch statistics on, your events line up in Amplitude as a sequence attached to one identifier, beside which sits a persistent profile with your level, points, badge and find counts and league (section 4.3). Charts of return rates and funnels are built from it. That is analysis of user behaviour — done to develop the game, not to show you anything, sell you anything or decide anything about you. We don't build advertising profiles, we don't combine these data with any external source, and we pass them on to no one other than the Amplitude described in section 4.3.

The app uses the technical identifiers below and an analytics session identifier. They are not advertising identifiers:

11. Children

The app is not aimed at children under 13. Cultural descriptions may refer to alcohol, violence and historical events. The store displays the age rating applicable in your country after the content questionnaire is completed.

We do not verify dates of birth. Parents and guardians should consider the store age rating and discuss safe walking in the city.

12. Security

Game data are protected the way your phone's storage is protected: by the screen lock and the app-isolation mechanisms built into iOS and Android. It's worth setting a lock code and not handing an unlocked phone to strangers.

All the app's network connections — map tiles, update checks, the leaderboard with groups, and usage statistics — go over HTTPS. Update packages are downloaded over HTTPS, and the update mechanism verifies their integrity before running them.

13. Changes to this policy

We may change this policy when the app changes. The current version is always at https://tup.quest/prywatnosc (English: https://tup.quest/en/privacy), and a link to it is in the app under Settings → Documents.

We will announce material changes — especially ones involving sending anything off the device — by publishing the new version of the document at the above address at least 14 days before it takes effect. Every version has its effective date at the top, so you can always check what applies and from when. We won't change the rules quietly or retroactively.

We have no channel by which we could send you a notification — we don't know your e-mail address and the app sends no push notifications. So the only place where we publish changes is the document page.

14. Contact

d.ptaszek@gmail.com Cybird Consulting Dariusz Ptaszek, ul. Chmielna 2/31, 00-020 Warsaw, Poland

Privacy policy: https://tup.quest/en/privacy Terms of service: https://tup.quest/en/terms Help & FAQ: https://tup.quest/en/help

We reply in Polish or English.