Privacy Notice
Last updated: 2 August 2026
This notice explains how Quest for Life ("we", "us"), the provider of Bible Quest, collects and uses personal data. Quest for Life is the data controller for the personal data described here and decides why and how it is processed. This page is maintained by Quest for Life to answer common privacy questions about Bible Quest.
What we collect and why
- Account data — email address and login credentials (or a Google sign-in identifier). Used to create your account and let a child's progress follow them across devices. Legal basis: performance of our contract with you.
- Learning progress — chapters completed, stars earned, quiz results, hero cards collected and streaks. Used to run the adventure map, unlock chapters and power the parent dashboard. Legal basis: contract performance.
- Purchase and entitlement data — which pass you hold, its status and renewal date, and identifiers received from our payment provider. Used to give you the access you paid for. Legal basis: contract performance and legal obligation. Card and billing details are collected by Paddle, not by us.
- Support messages — what you send us when you ask for help. Legal basis: legitimate interests in supporting our customers.
- Technical and usage data — device type, browser, approximate region, IP address and error/diagnostic logs. Used for security, fraud prevention, and fixing and improving the app. Legal basis: legitimate interests.
Accounts are intended to be created by a parent or guardian. We do not ask children for personal details, and we do not use children's data for advertising or profiling.
Children and parents (US — COPPA)
Bible Quest is designed for children aged 7–14 to use under parental supervision. We do not knowingly collect personal information directly from a child. The only personal information tied to an account — an email address, login credentials and an optional public nickname — is provided by the parent or guardian who sets up and controls the account. Children play on the adventure map without being asked for their name, email, photo, location, contact details or any other identifier.
Accounts must be created by a parent or guardian. A child cannot create an account on their own. This is enforced in the account creation flow: the app can be played with no account at all, sign-up asks for a grown-up's email address and requires an explicit confirmation that the person signing up is the parent or guardian of the child who will play, the account must be verified through a link sent to that adult's email inbox (or an adult's Google account), and any public nickname is set by the parent from the Parental Control dashboard rather than by the child. Payment, plan changes, content filters and the PIN-protected Parental Control area are all reachable only from that adult account.
Parent rights under COPPA. As the parent or guardian of a child who uses Bible Quest, you may at any time:
- Review the personal information we hold that relates to your child, including the account details and the learning progress recorded under the account;
- Request deletion of that information and closure of the account; and
- Refuse further collection or use of your child's information — you can stop any further collection by deleting the account, and you may ask us to stop collecting or using it while keeping your purchase records only for tax and accounting purposes.
Exercising these rights will not cost you anything. Because deleting the account also deletes saved stars, hero cards and streaks, we may ask you to confirm the request from the email address on the account before we act on it.
If we ever learn that we have collected personal information from a child without a parent or guardian being involved, we delete it promptly.
COPPA contact
For COPPA requests — reviewing, deleting or refusing further collection of your child's information — contact Quest for Life through the support option in the Parental Control dashboard and mark your message "COPPA request", sending it from the email address on the account. We aim to respond within 30 days. This is in addition to the general contact method described below, which you can use for any other privacy question.
Who we share data with
- Service providers / subprocessors — cloud hosting, database and authentication providers that store your account and progress data, and error monitoring tools.
- Merchant of Record — Paddle.com, which handles the sale of our passes, subscription management, payments, tax compliance, invoicing and refunds. When the purchase page is opened, Paddle also receives the device's IP address and uses it to estimate the country, so it can show the correct currency and calculate the right sales tax or VAT. Paddle does not use this for advertising.
- Google Sign-In (optional) — if an adult chooses to sign in with Google instead of an email and password, Google shares the account's email address and Google account identifier with us so we can create or recognise the account. If you sign up with email and password instead, nothing is sent to Google.
- Google Fonts — our pages load two typefaces from Google's font service. As with any file requested from another website, the browser sends its IP address and browser/device type (user agent) to Google as part of that request. No account details, progress or reading activity are shared, and no cookies are set by this request.
- Professional advisers — legal and accounting advisers where necessary.
- Authorities — where we are required to disclose by law.
We do not sell personal data.
International transfers
Our providers may process data outside your country, including outside the UK/EEA. Where that happens we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.
Retention
We keep account and progress data for as long as your account is active, and delete or anonymise it within a reasonable period after you close your account or after a long period of inactivity. Purchase records are kept as long as required for tax and accounting purposes. Diagnostic logs are kept for a short period only.
Your rights (UK/EEA — GDPR and other regions)
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our use of your personal data, to receive a portable copy, and to withdraw consent where we rely on it. If you are in the UK or EEA you may also complain to your local supervisory authority. Contact us through the parent dashboard and we will respond within one month.
Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and row-level database policies so a signed-in account can only read its own progress and purchase records.
Cookies and local storage
Bible Quest uses no advertising, analytics or tracking cookies, and no third-party tracking scripts. We do not profile you or your child, and nothing here is shared with advertisers. Because every item below is strictly necessary or a setting you chose yourself, no cookie consent banner is required — this disclosure is the notification the law asks for.
The app itself does not set any first-party cookies. Instead it stores the following in your browser's own storage, on your device:
- Sign-in session (local storage) — the login token that keeps you signed in between visits. Strictly necessary.
- Learning progress (local storage) — chapters completed, stars, quiz results, hero cards, daily quests and streaks, plus a small queue of results waiting to sync when you are back online. Strictly necessary for the app to work offline.
- Your settings (local storage) — light/dark theme, sound and music mute, narration preferences, whether you dismissed the "install app" prompt, and the chapter/game content filters chosen by a parent.
- Parental Control PIN (local storage) — stored only as a hashed value, never as the digits you typed.
- Parental Control unlock (session storage) — a short-lived timestamp so you do not have to re-enter the PIN on every screen. Cleared when you close the tab.
- Offline chapter packs (local storage and the browser cache) — story text, images and audio you chose to download for offline play.
- Payment pages — when you open the pass/pricing page or a checkout, our payment provider Paddle loads its own script and may set cookies that are necessary to show prices in your local currency, run the checkout securely and prevent fraud. These are used only for the purchase and are governed by Paddle's own privacy notice.
You can clear this data at any time in your browser settings, though doing so will sign you out and remove downloaded offline packs and saved settings. Progress saved to your account will return when you sign in again.