Tup Quest privacy policy
Effective from 5 October 2026. Version 1.2.
Version 1.1, effective until 4 October 2026 — archive
What changes in version 1.2. Usage statistics — the ones you switch on yourself and that are off by default — now go to Amplitude, a product-analytics tool, in addition to our database in Ireland. Section 4.3 describes exactly what goes there, what does not, and how to have it deleted. We publish this version 14 days before it takes effect, as section 13 promises, and until that day nothing is forwarded to Amplitude. Version 1.1 applies until 4 October 2026.
This is a courtesy translation. In case of any discrepancy, the Polish version prevails.
In short
Tup Quest is a game about the city. It marks on the map the streets you have actually walked and the cultural places you find.
- No email or password is required. Leaderboards and groups use an automatically generated guest account that you can delete in Settings.
- Detailed walk history and GPS tracks are stored on your phone. Optional leaderboards and consent-based statistics retain the server data described below.
- GPS tracks are stored locally and are not sent to the leaderboard or usage statistics. In the launch release, the iOS SQLite database is excluded from system backups. Android Auto Backup and device-to-device app data transfer are disabled. Progress does not transfer automatically to a new phone. If you choose to share a walk card or diagnostic file, your chosen recipient receives the data in that material.
- There are no ads or cross-app tracking. Optional error reports go to Sentry (EU region) only with your consent.
- Usage statistics are off by default. With consent, events are stored without GPS tracks but with a technical player ID. These are pseudonymous data which can be linked to the leaderboard. They go to our database in Ireland and, in a narrowed form, to Amplitude — an analytics tool in the EU region. A single consent covers both recipients.
- The city leaderboard and friends' groups are voluntary. They send a nickname, a city name and three numbers — never coordinates or tracks. Until you enter a nickname, you're not on any leaderboard.
- Five network connections: map tiles, update checks, the leaderboard with groups, usage statistics, and crash reports. We describe each honestly below — because the map provider sees your device's IP address, and the update check sends an installation identifier. Your phone does not connect to Amplitude: the forwarding is done by our server, on the database side.
The rest of this document is detail. It's worth reading, but the points above are the whole truth about this app.
1. Who the data controller is
The controller of personal data is:
Cybird Consulting Dariusz Ptaszek ul. Chmielna 2/31, 00-020 Warsaw, Poland NIP (tax ID): 7343126589 REGON: 387337946 Poland
Contact for all privacy matters: d.ptaszek@gmail.com App website: https://tup.quest This policy: https://tup.quest/en/privacy (Polish: https://tup.quest/prywatnosc) Terms of service: https://tup.quest/en/terms Help & FAQ: https://tup.quest/en/help
We have not appointed a data protection officer — the activity does not meet the criteria of Article 37 GDPR. Messages are answered by the business owner.
2. What data are processed and where
2.1 Data that stay solely on your device
The app stores in a local SQLite database on the phone:
- the street segments you have walked in the chosen city,
- the cultural places you have found (music, film, literature, pop culture, art, history),
- walk history (date, duration, distance covered),
- the trace of the walked route as a series of coordinates, saved with each walk (coordinates are rounded to five decimal places, roughly one metre),
- experience points and earned badges (66); the level (1–10), daily-challenge progress and weekly-league position are computed from these records on the fly,
- a nickname, if you enter one,
- the guest account identifier assigned by Supabase and its session token (not an advertising identifier),
- app settings, including the chosen city and tracking mode.
The step count is not stored — the app reads it from the system live to show it on screen and never persists it.
GPS tracks, walked street details and detailed walk history remain local unless you choose to share a file containing them. Nickname, aggregate scores and the account identifier may be transmitted through the features described in sections 4 and 5. Uninstalling removes the local database, but does not delete the server account.
GPS matching and detailed track storage take place on your device. We do not hold a server copy of those tracks. Network features and user-initiated sharing are described separately below.
2.2 Data that actually reach us
When you contact support, we receive your message, email address and attachments. Separately, we process the network-feature data described below.
Beyond that: in the App Store Connect and Google Play Console dashboards we see aggregate, usage statistics (download counts, system versions, countries). We don't see who installed the app and cannot link these figures to a specific person.
Our database in Ireland receives technical identifiers, nickname, group names, city, scores and usage events described in sections 4.3 and 5. GPS tracks are not sent there. From that database, a narrowed version of the statistics events is forwarded onward to Amplitude — see section 4.3.
We describe separately the technical data that go to third-party service providers rather than to us — map tiles and update checks (section 4).
2.3 Data that are not collected at all
The app does not require email, password or phone number, access contacts or photos, or collect payment details. Support receives your email and attachments if you choose to contact us. Steps are read locally; after analytics consent, walk duration and distance are transmitted. We do not access HealthKit. The app is free, without ads or in-app purchases.
We do not use cross-app tracking or advertising identifiers. Privacy declarations also cover pseudonymous identifiers, city, game scores, interactions, group names, walk duration/distance and error reports, depending on enabled features and consent.
3. System permissions and what each is for
The app asks for four things. You can refuse each — the app keeps working, only some functions stop making sense.
3.1 Location while using the app ("While Using the App")
What for: to mark on the map the streets you walk and to recognise that you've approached a cultural place.
How the default "Only during a walk" mode works: position is read from pressing "Start a walk" until pressing "Finish". Outside a walk the app doesn't ask the system for location.
If you have granted "Always", a started walk continues with the screen locked and the app in the background — so it doesn't break off in your pocket. It ends when you press "Finish". Should you close the app mid-walk instead of finishing it, at the next launch the app in manual mode stops the background position-collecting task itself.
Where the coordinates go: solely to the local database on the phone, as matched street segments and a route trace. They do not leave the device.
3.2 Background location ("Always") — optional
What for: the "Automatically in the background" mode marks walked streets on its own while the app is in the background.
This mode is off by default. You turn it on yourself in the app's Settings — first the app explains plainly that in this mode it reads location also when closed or not in use, and only after your consent does the system ask for the "Always" permission. It uses more battery. You can turn it off at any time in the app's Settings or revoke the permission in the system settings. Coordinates from this mode likewise do not leave the device.
3.3 Motion & Fitness / activity recognition (pedometer)
What for: the app reads the step count from the system (Apple Motion on iOS, Activity Recognition on Android) to show it in Profile as a curiosity ("side effect").
The step count is read locally, not stored in the app's database, does not affect points and is not sent anywhere. The pedometer does not control location reading.
Tup Quest is not a sports or health app. It shows neither pace nor heart rate, has no step goal and stores no health data.
We store walk duration and distance locally, because the walk history is made of them. If you switch statistics on, those two numbers leave the phone — to our database and to Amplitude. We declare them in the store forms as physical-activity data, because that is what they are, joke framing notwithstanding.
In the walk summary we show one calorie figure, converted immediately into food — a joke at the expense of fitness metrics, not a measurement. We compute it on the phone as a fixed factor of distance, assuming a weight of 75 kg. We don't ask for your weight, height, age or sex, don't know them and don't want to. The figure is not an individual measurement, and it is neither stored nor sent anywhere.
3.4 Notifications — local only
What for: a single notification — when a walk closes itself after twenty minutes without movement (because it ended in your pocket, without a button), the app says so on the lock screen: how many new streets, how many kilometres, that the summary is waiting.
The app asks for notification permission once, at the first "Start a walk". The notification is created on the phone by the app itself — there is no push server, no device token, and nothing related to notifications leaves the phone. We send no promotions or "come back" nudges. The only additional notification — a weekly summary on Sunday at 6 pm (how many streets this week, which district is closest to done) — is off by default; you turn it on yourself in Settings, and its content and timing are also produced on the phone. You can revoke the permission in the system settings.
4. Map, updates and internet connections
The app connects to the network for five things: it downloads map tiles, checks whether an update is available, runs the city leaderboard with friends' groups (section 5), sends usage statistics and — when something in it breaks — a crash report (section 4.4). Beyond that it sends and downloads nothing.
4.1 Map tiles (OpenFreeMap)
The app downloads vector map tiles from the OpenFreeMap server (tiles.openfreemap.org).
As with any online map, the tile provider sees with such a request your device's IP address and which map fragments were requested. From the map fragments one can roughly infer which area you are in. We say this plainly because that is how it works and it can't be avoided without giving up the map.
We don't send the map provider your route, points, nickname or player identifier. We also have no access to the tile server's logs.
4.2 Update checks (Expo / EAS Update)
The app uses an over-the-air update mechanism (OTA, expo-updates). It lets fixes to the app layer reach you without waiting for a new store version. The mechanism is enabled in the versions published in the App Store and Google Play.
How it works: at launch the app asks the u.expo.dev server whether a newer package exists for its channel and version. If so, it downloads it in the background and runs it at the next app start. The downloaded package contains only the app's code and assets.
What such a request sends to the update service provider:
- the app installation identifier — a persistent, random identifier (UUID) assigned to this particular installation on your phone. It is not the advertising identifier (IDFA / Android Advertising ID) or a hardware identifier; it disappears when the app is uninstalled,
- the app's project identifier and update channel (in the store version:
production), - the app's runtime version and platform (iOS or Android),
- the device's IP address and standard HTTP headers, as with any network request.
What never goes there: coordinates, track traces, walk history, points, badges, nickname or step count.
The service provider is Expo Project Services, an entity based in the United States. This means a transfer of the above technical data outside the European Economic Area; see section 7.
We don't link the installation identifier with any other data and have no tool that would let us recognise anyone by it. We also have no access to the update server's raw logs.
4.3 Optional usage statistics (our database in Ireland and Amplitude)
Usage statistics help us improve the app. They are off by default. You can consent during onboarding or in Settings → Statistics and error reports. Declining does not limit the game. A previously default-enabled setting is not treated as consent.
Consent is single and indivisible. It covers storage in our database, forwarding a narrowed version of the event to Amplitude, and error reports in Sentry, all at once. You cannot accept one and refuse another — we say so plainly so that nobody hunts through Settings for a switch that isn't there.
Withdrawing consent immediately stops collecting events and clears the queue on your phone. It also orders the server-side queue — the one waiting to be forwarded to Amplitude — to be erased. If you have no internet at that moment, the order is remembered and we repeat it at every app start until the server confirms it. What it cannot undo: a request already sent over the network, or data forwarded earlier — those remain until you ask us to delete them or delete your account. Withdrawing consent does not switch off network features such as maps and the optional leaderboard.
What we send:
- an event name from a closed list: app opened and onboarding completed, screen opened, city chosen, walk started and finished, streets credited, place found, badge earned, district completed and city milestones, collection opened, catalogue viewed, route opened, route idea opened and stop checked, tour started and completed, group created, joined and invite shared, tracking mode changed, statistics switched on, and data erased,
- the slug of the chosen city (e.g.
warszawa) — one of a dozen or so values, the same for everyone in that city. This is the city you picked in the app, not one derived from your location, - the category of a found place (music, film, literature, pop culture, history, art) and the identifier of the collection, route or tour, plus whether the place was opened from a collection and whether it was found for the first time,
- a walk identifier — a number that lets us join “started” with “finished”; it carries neither a route nor a place,
- for routes and tours: how a stop was checked (manually or by GPS), the number of stops in total, checked by GPS and remaining, and the kind of tour. Counts — not which particular stop you checked,
- aggregate numbers: duration and distance of a finished walk, number of new streets, level, points, number of badges and finds, weekly league, district completion percentage,
- whether you granted location access, and the tracking mode you chose,
- the name of the screen the event came from, and for the catalogue, which view you opened,
- for a finished walk: whether it was long enough to count (at least two minutes and a hundred metres), and whether you ended it with the button or it closed itself after twenty minutes without movement,
- interface language (
ploren), app version and platform, - a session ID, an event ID (random, used to discard duplicates) and the event time read from your phone's clock. An event may have been created offline and sent days later.
Requests are authenticated: the server adds the player ID (auth.uid()) as player_id. Statistics can therefore be linked to that player's leaderboard entry. These data are pseudonymous, not anonymous.
What we never send: coordinates, track traces, street names, names of specific found places, which route stop you checked, nickname, group names, step count, calorie count, e-mail address, phone number, device model or advertising identifiers.
IP address. Events go to our own server, so — as with any HTTP request — the server gateway sees the device's IP address. We don't store it in any table: the stored event has no field for an IP address or for a network country or city. Addresses appear only in the hosting provider's technical logs, used for maintenance and abuse protection, and are deleted by the provider after a few days.
Where it lives. Statistics go to two places. The first is our own database — a Supabase project (PostgreSQL) in the eu-west-1 region, i.e. on servers in Ireland. It is the same database that serves the leaderboard and groups. The second is Amplitude, described below.
Amplitude — the tool we read statistics with
A database on its own does not answer the question "do people come back after a week". That is what Amplitude is for: a product-analytics tool that shows the same events as charts and funnels. We describe it separately because it is another entity processing your data, and we think that deserves a clear statement rather than a footnote.
How it works. The app does not connect to Amplitude. There is no Amplitude SDK on your phone, and the number of network connections from your device does not change because of this. The event reaches our database in Ireland, and only from there does our server forward a narrowed version onward.
Amplitude gets less than we do. We pass through only events from a closed list and only properties from an allowlist — the server strips the rest before anything leaves.
From the list above, what does not reach Amplitude is GPS recording diagnostics — those stay in our database and in Sentry. Everything else on the list does reach it.
Your player profile in Amplitude. Along with the events we forward seven numbers and labels describing your state in the game: chosen city, tracking mode, level, experience points, badge count, number of places found, and weekly league. In Amplitude these are not a property of a single event but a persistent profile attached to the player identifier, overwritten whenever it changes. They serve one purpose: making it possible to compare whether players who got further come back more often. None of them says where you have been — no coordinates, no street names, no names of places you found, no nickname.
Two things Amplitude gets that we don't store ourselves: interface language and an environment marker. We mention it so as not to leave the impression that Amplitude only ever sees a subset of our database.
The identifier. As the user identifier we use the same player ID as the leaderboard, with a prefix. It is therefore not a separate, weaker identifier — it is the same pseudonymous value. We say so plainly, because the opposite impression would simply be untrue.
IP address. In every forwarded event we hard-code the address 0.0.0.0, so that your address is not passed on and no location can be derived from it. The connection itself leaves our server in Ireland, not your phone, so Amplitude does not see your device's address. What we describe here is what we do — we do not make promises on the provider's behalf.
Where it lives and for how long. The project is set up in the European Union region, so the data stay in the Union. We set the project's retention to 12 months — the same period for which we keep events ourselves. The provider is Amplitude, Inc., based in the United States, acting as a processor; see section 7.
Deletion. When you delete your account in Settings, our server erases everything not yet forwarded and sends Amplitude a request to delete its copy. Honestly: this is a request addressed to the provider, not our own erasure of the data. Amplitude carries it out on its own schedule, and what we receive is confirmation that the request was accepted, not that the data were deleted.
Usage statistics use our HTTP interface to Supabase. Sentry handles optional error reports as described in section 4.4.
GPS recording diagnostics use the same consent. They include aggregate counts of accepted, rejected and late readings, accuracy bands, gap durations and delivery delays, trace splits, storage errors, foreground/background state, location mode and permissions, and OS, native build and update versions. A random report number helps us locate a support report. We do not send coordinates, street names or sequences of readings. Summaries go to Supabase including when no problem is found; anomalies and manual reports also go to Sentry. The shared report number can link these reports to the account’s pseudonymous statistics. GPS diagnostics are not forwarded to Amplitude — they stay in our database and in Sentry. Withdrawing consent clears pending summaries.
4.4 Error and GPS quality reports (Sentry)
With your consent to statistics and error reports, the app can send a JavaScript error report or an aggregate GPS recording quality report to Sentry. This is off by default. Automatic session tracking, performance tracing and native offline crash reporting are disabled.
Reports include the error, stack trace, app and update version, environment details, screen name and selected city. We remove user and request data and replace the IP address with a non-routable sentinel to prevent IP geolocation enrichment. We discard network breadcrumbs that could contain map tile URLs. GPS tracks, nicknames and player IDs are not attached. The server sees the connection IP; the project is configured not to store it in reports.
Withdraw consent in Settings → Statistics and error reports. No new report transmissions are started after withdrawal. Requests already sent cannot be recalled.
Where it lives. The service is provided by Functional Software, Inc. (Sentry) as a processor; our project is in the European Union region (servers in Frankfurt, Germany). Reports are kept for 90 days and then deleted automatically.
4.5 Where the city data come from
Street and place data come from OpenStreetMap, under the ODbL licence, © OpenStreetMap contributors. Cultural collections are edited by the Tup Quest editors. Each city's data are bundled with the app — they are not downloaded from the network during play.
5. City leaderboard and friends' groups
The leaderboard and groups are voluntary. Separately, usage statistics send the data in section 4.3 after explicit consent. The app works fully without them: the map, finds, badges and weekly league are computed on your phone.
Until you enter a nickname, you're not on any leaderboard. That is the moment you knowingly join the competition — and that is the consent referred to below.
5.1 Exactly what leaves the phone
- the guest account identifier assigned by Supabase and its session token (not an advertising identifier),
- the nickname you enter yourself,
- the name of the city the leaderboard concerns,
- the week key (year and week number),
- three numbers: the number of walked streets, the number of found places and the number of collection places, plus the point total computed from them.
The numbers concern that one city whose leaderboard you join, and the current week — they are not a sum across all the cities you walk in.
What is never sent: coordinates, track traces, walk history, street names, names of specific found places, step count, calorie count, e-mail address or any contact details.
5.2 Friends' groups
A group is a private leaderboard for people who know its code. When starting a group you give it a name; the app draws an eight-character invite code, which you send to whomever you like. To join, you enter that code.
On the server we store: the group's name, its code, who founded it, and the list of player identifiers that belong to it, with the date of joining. Group members see each other's nicknames and scores — and only that.
You choose the group name yourself and it is visible to all its members. If you put someone's real name in it, it becomes personal data — so better not to.
5.3 A guest account without email or password
No email or password is required. When an authenticated feature is first used, the app creates a guest account in Supabase and stores its identifier and session token on this phone. The account links scores, groups and statistics. A nickname can identify you if you choose a real name, so we recommend a pseudonym.
The session token is stored on this phone. After uninstalling or changing devices, access to the previous account cannot be recovered. Uninstalling does not itself delete server records: delete your account in Settings first.
5.4 Where it lives and for how long
Leaderboard and group data are kept in our own database — a Supabase project (PostgreSQL) in the eu-west-1 region, i.e. on servers in Ireland, in the European Union. Access to the tables is restricted by database-side rules: the app doesn't write to them directly, but calls a narrow set of functions that accept exactly the data listed above.
Weekly scores are kept for 12 months from the end of the week they concern. Nickname and group memberships — until you ask for their deletion or leave the group.
5.5 How to withdraw
You can withdraw consent at any time, with effect for the future:
- Delete account and progress. Choose Settings → Data → Delete account and all data. After confirmation we delete the guest account, scores, linked statistics, memberships and groups you created (also for their other members), followed by local game data. We also erase everything that was waiting to be forwarded to Amplitude and send it a request to delete its copy — Amplitude carries that out, so it does not happen in the same moment. This cannot be undone and requires internet access if a server account exists. Without server confirmation, local progress is retained for retry.
- Without access to the app. Email d.ptaszek@gmail.com with your player ID if you have it. We may request information needed to verify your authority to delete the data. An identifier alone is not proof of account ownership.
- Leaving a group. Just leave it in the app — your score disappears from its board.
6. Legal bases for processing
| What | What for | Legal basis |
|---|---|---|
| Access to device location | Marking walked streets and finding places | Your consent given through the system permission — Art. 6(1)(a) GDPR and Art. 399 of the Polish Electronic Communications Law of 12 July 2024 |
| Access to the pedometer | Showing the step count after a walk | Your consent given through the system permission — Art. 6(1)(a) GDPR |
| Saving progress in the phone's storage | Running the game (points, badges, league) | Necessity to perform the service you request by launching the app — Art. 6(1)(b) GDPR |
| Downloading map tiles (IP address visible to the provider) | Displaying the map | Necessity to provide the function you use — Art. 6(1)(b) GDPR |
| Update checks (installation identifier, version, platform, channel, IP address) | Delivering bug and security fixes without waiting for a new store version | Our legitimate interest in maintaining a correctly working and secure app — Art. 6(1)(f) GDPR |
| Usage statistics in our database (events, city, aggregate numbers, session and player identifiers) | Checking which features are used and developing the app on facts | Your consent — Art. 6(1)(a) GDPR. You can switch statistics off in Settings; collection stops at once and both queues are cleared |
| Forwarding narrowed statistics to Amplitude (events from a list, properties from a list, the prefixed player identifier, language) | Reading those same events as charts and funnels, i.e. seeing whether players come back | The same consent of yours — Art. 6(1)(a) GDPR. Consent is indivisible and covers both recipients |
| Error reports (error, stack trace, app version, screen and city) | Finding and fixing bugs | Your consent — Art. 6(1)(a) GDPR and, where applicable, Art. 399 of the Polish Electronic Communications Law. Withdraw it in Settings |
| Replying to your e-mail | Handling your report, support, exercising your rights | Our legitimate interest — Art. 6(1)(f) GDPR; for GDPR rights — Art. 6(1)(c) GDPR |
| City leaderboard (player identifier, nickname, city, week, numbers) | Comparing scores with other players | Your consent, given by entering a nickname — Art. 6(1)(a) GDPR |
| Friends' groups (group name, code, member list) | A private leaderboard among people you invite yourself | Your consent, given by starting a group or joining with a code — Art. 6(1)(a) GDPR |
7. Recipients of data
We don't sell data. We don't pass it to data brokers or ad networks. Below is the full list of entities that see any of your data — each with the reason we give beside it.
- OpenFreeMap — the map tile provider. Sees the device's IP address and the range of requested map fragments (section 4.1).
- Expo Project Services (USA) — provider of the app update service (EAS Update). On an update check it receives the app installation identifier, project identifier, channel, runtime version, platform and the device's IP address (section 4.2).
- Supabase, Inc. — hosting provider of our database, acting as a processor. Its infrastructure (
eu-west-1region, Ireland) holds the leaderboard, group and usage-statistics data described in sections 4.3 and 5. Supabase doesn't use these data for its own purposes. The company itself is based in the United States — see below. - Amplitude, Inc. — provider of the product-analytics tool, acting as a processor. It receives the narrowed version of the statistics events described in section 4.3: event names from a closed list, properties from an allowlist, the player identifier with a prefix, language, app version and platform, plus a persistent player profile (city, mode, level, points, badge and find counts, league). It does not receive coordinates, track traces, street or place names, your nickname, group names or GPS diagnostics. The project is in the European Union region. Amplitude doesn't use these data for its own purposes. The company is based in the United States — see below.
- Functional Software, Inc. (Sentry) — provider of the crash-reporting service, acting as a processor. The reports described in section 4.4 are stored in the European Union region (Frankfurt, Germany). Sentry doesn't use them for its own purposes. The company is based in the United States — see below.
- Apple Inc. and Google Ireland Limited / Google LLC — distributors of the App Store and Google Play. You install the app through their stores, under their own privacy rules, as separate controllers. We pass them no data from the app.
- E-mail provider — if you write to us, your message is stored on a mail server. Gmail, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. More: https://policies.google.com/privacy.
- Other players — your nickname and point count are visible on the city leaderboard to everyone who uses it, and in a group to its members. Only that; nothing else about you is there.
Data may also be disclosed to authorised authorities where the law so requires. We stress, however, that we simply do not hold data about your routes — we couldn't hand them to anyone, even if someone demanded them.
Transfers outside the European Economic Area
Three things are easy to confuse, so we separate them plainly. Your GPS track and detailed walk history never leave the phone at all — neither within the EEA nor outside it. Aggregate numbers about a walk and your progress (duration, distance, new streets, a badge, district percentage) do leave the phone if you switch statistics on, and are described in section 4.3. Technical data are described below.
Technical data are transferred:
- Update checks. Expo Project Services is based in the United States, so the data described in section 4.2 (installation identifier, runtime version, platform, channel, IP address) are processed outside the EEA. The basis for the transfer is standard contractual clauses (Art. 46(2)(c) GDPR) and, to the extent the provider participates in the Data Privacy Framework, the European Commission's adequacy decision (Art. 45 GDPR).
- Leaderboard, groups and usage statistics. Data are stored on servers in Ireland, i.e. in the European Union. The hosting provider, Supabase, Inc., is however based in the United States and may access them in the course of technical support. The basis for such access is standard contractual clauses (Art. 46(2)(c) GDPR) and, to the extent the provider participates in the Data Privacy Framework, the European Commission's adequacy decision (Art. 45 GDPR).
- Narrowed statistics in Amplitude. The project is set up in the European Union region, so the data are stored in the Union. The provider, Amplitude, Inc., is based in the United States and may access them in the course of technical support — on the same basis as above: standard contractual clauses (Art. 46(2)(c) GDPR) and, to the extent the provider participates in the Data Privacy Framework, the European Commission's adequacy decision (Art. 45 GDPR).
- Crash reports. Reports are stored on servers in Germany, i.e. in the European Union. The provider, Functional Software, Inc., is based in the United States and may access them in the course of technical support — on the basis of standard contractual clauses (Art. 46(2)(c) GDPR) and, to the extent it participates in the Data Privacy Framework, the European Commission's adequacy decision (Art. 45 GDPR).
- Map tiles and Apple and Google services. Technical data (e.g. IP address) may be processed outside the EEA under those entities' rules — most often on the basis of standard contractual clauses or European Commission adequacy decisions.
8. How long we keep data
- Game progress (locally on the phone) — until you delete it yourself or uninstall the app. It has no expiry, because it isn't with us.
- E-mail correspondence — for as long as needed to handle the matter, and then for 12 months after the matter is closed in case of follow-up questions or claims.
- Update requests — their records arise on the update service provider's side and are kept under its rules. We don't download or archive them and have no access to them.
- Usage-statistics events — kept in our database for no longer than 12 months from the event being recorded; a daily job deletes older ones. After switching statistics off in Settings, no new events arise, and those waiting in either queue — on the phone and on the server — are deleted immediately. You can ask for deletion of already-collected ones by e-mail, quoting your player identifier; we then delete them from our database and send Amplitude a request to delete its copy.
- The narrowed copy of statistics in Amplitude — the project's retention is set to 12 months, the same period for which we keep events ourselves. Deleting your account in the app sends a request there to delete them sooner.
- Your player profile in Amplitude — unlike the events, it does not expire on its own after twelve months: it is overwritten whenever it changes and lasts as long as the account does. It is removed by the request sent when you delete your account.
- The queue waiting to be forwarded to Amplitude — at most 6 days for an event not yet forwarded, and about a day after forwarding. The queue is built regardless of whether the Amplitude channel is switched on at the time; events that are not forwarded in time are simply deleted.
- Confirmations of deletion requests sent to Amplitude — 35 days from dispatch, so that it can be reconstructed that the request actually went out. They contain the player identifier and nothing else.
- Crash reports — 90 days at the service provider, then deleted automatically. After switching the toggle off in Settings, no new reports arise.
- Aggregate store statistics — under Apple's and Google's rules; not linked to a person.
- Leaderboard and group scores — weekly scores for 12 months from the end of the given week. Nickname and group memberships — until you ask for deletion or leave the group. A group with no members is deleted.
9. Your rights
You have the right to: access your data, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal).
How to exercise your rights:
- Access and portability. View local data on the map, profile and walk history. For a copy of server data, contact support and include the player ID from Settings to help locate the record.
- Erasure. Choose Settings → Data → Delete account and all data; section 5.5 describes the scope and consequences. Analytics, diagnostics and automatic tracking are switched off. Basic settings such as language and city remain. Uninstalling alone removes local data only. See Data deletion.
- Switching off usage statistics. Settings → Statistics and error reports. Immediately: the app stops collecting and sending events and clears the queue on your phone. The server-side queue waiting to be forwarded to Amplitude is erased at the next network connection — the order is remembered and repeated until it succeeds. With no retroactive effect: data forwarded earlier remain until you ask for their deletion or delete your account.
- Revoking location or pedometer consent. In the phone's system settings (iOS: Settings → Privacy & Security → Location Services / Motion & Fitness; Android: Settings → Apps → Tup Quest → Permissions). Background tracking mode can also be switched off in the app itself, in Settings.
- Objection, rectification, restriction and matters concerning correspondence. Write to d.ptaszek@gmail.com. We reply without undue delay, at the latest within a month of receiving the message.
Shortcuts to this policy, the Terms and Help are also in the app, in Settings → Documents.
We locate account records using the player identifier. We do not request additional identifying data unless needed to fulfil a request. If necessary, we may ask for confirmation of your authority to access or delete those records.
Complaint. If you believe we process data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
10. No ads, tracking or automated decisions
The app has none of the following and we don't plan them:
ads and ad networks,
cross-app or cross-site tracking, the IDFA or other advertising identifiers,
selling data or sharing it with data brokers,
automated decision-making producing legal or similarly significant effects concerning you (Art. 22 GDPR) — nothing in this app makes such decisions,
cookies — the mobile app doesn't use them.
What we will not claim, because it would be a stretch: that there is no analysis of behaviour here. If you switch statistics on, your events line up in Amplitude as a sequence attached to one identifier, beside which sits a persistent profile with your level, points, badge and find counts and league (section 4.3). Charts of return rates and funnels are built from it. That is analysis of user behaviour — done to develop the game, not to show you anything, sell you anything or decide anything about you. We don't build advertising profiles, we don't combine these data with any external source, and we pass them on to no one other than the Amplitude described in section 4.3.
The app uses the technical identifiers below and an analytics session identifier. They are not advertising identifiers:
- Player identifier — a random account ID assigned by Supabase. It links leaderboard, group and statistics records. In-app account deletion removes linked records; uninstalling alone only removes the token from the phone.
- App installation identifier — assigned by the update mechanism. It is sent to the update service provider when checking for a newer version (section 4.2). It serves solely to deliver the right update package, is not used for profiling or advertising, and disappears when the app is uninstalled.
11. Children
The app is not aimed at children under 13. Cultural descriptions may refer to alcohol, violence and historical events. The store displays the age rating applicable in your country after the content questionnaire is completed.
We do not verify dates of birth. Parents and guardians should consider the store age rating and discuss safe walking in the city.
12. Security
Game data are protected the way your phone's storage is protected: by the screen lock and the app-isolation mechanisms built into iOS and Android. It's worth setting a lock code and not handing an unlocked phone to strangers.
All the app's network connections — map tiles, update checks, the leaderboard with groups, and usage statistics — go over HTTPS. Update packages are downloaded over HTTPS, and the update mechanism verifies their integrity before running them.
13. Changes to this policy
We may change this policy when the app changes. The current version is always at https://tup.quest/prywatnosc (English: https://tup.quest/en/privacy), and a link to it is in the app under Settings → Documents.
We will announce material changes — especially ones involving sending anything off the device — by publishing the new version of the document at the above address at least 14 days before it takes effect. Every version has its effective date at the top, so you can always check what applies and from when. We won't change the rules quietly or retroactively.
We have no channel by which we could send you a notification — we don't know your e-mail address and the app sends no push notifications. So the only place where we publish changes is the document page.
14. Contact
d.ptaszek@gmail.com Cybird Consulting Dariusz Ptaszek, ul. Chmielna 2/31, 00-020 Warsaw, Poland
Privacy policy: https://tup.quest/en/privacy Terms of service: https://tup.quest/en/terms Help & FAQ: https://tup.quest/en/help
We reply in Polish or English.