Skip to main content
← Back to home

Privacy Policy

Last updated : Jul 26, 2026 · v2026-07-26

GrowQuest is a family app used by adults and by children. That makes privacy a design constraint, not a formality. This page explains — in plain language — what we collect, why, who can see it, and how to get it back or erased.

If anything here is unclear, write to contact@growquest.ai and we will answer.

1. Who is responsible for your data

The data controller for GrowQuest is:

  • Altaïr Engineer SRL
  • Boulevard Sainctelette 80, 7000 Mons, Belgique
  • BE0745990376
  • Contact for anything privacy-related: contact@growquest.ai

We have not appointed a Data Protection Officer — we are not required to. The address above reaches the person who actually handles these requests.

2. Who has an account, and who creates it

  • A parent or legal guardian creates the family account with an email address and a password. You must be 18 or older.
  • Children never sign up on their own. The parent creates each child account with a username and a password. A child account has no email address, and we never ask a child for one.

This is deliberate: under Article 8 GDPR, consent for a child under 16 (or the lower age set by your country, down to 13) must be given or authorised by the holder of parental responsibility. Making the parent the sole entry point is how we satisfy that, rather than asking a child to self-declare an age.

3. What we collect

From the parent

DataWhy
Name, email addressIdentify the account, send service emails, password recovery
Password (hashed with bcrypt — we never see it)Sign-in
Language preferenceInterface, emails and notifications in the right language
Notification preferencesDeciding whether to email you
Stripe customer and subscription identifiers, plan statusManaging a Premium subscription
IP address, at sign-up / sign-in / contact form onlyRate limiting and abuse prevention
Date of last sign-inAccount activity, inactivity clean-up

From each child account (entered by the parent, or generated in-app)

DataWhy
First name or nickname, username, password (hashed)Sign-in and display
Age, and a boy/girl marker used for the pixel-art characterAge-appropriate content and avatar
Chosen character, cosmetics, Growy companionsThe game itself
Level, XP, coins, badges, streaksProgression
Tasks assigned, completed and reviewed, with timestampsThe core of the service
Purchases from the family reward storeParent approval workflow
Messages exchanged inside the familyFamily messaging feature
Behaviour notes and daily state recorded by the parentDaily-state and multiplier features
Accessibility settings (reduced motion, reading font), Focus ModeAdapting the interface
Web push subscription, if enabledTransition reminders

Emotion check-ins — a special category, treated as such

If — and only if — the parent switches it on for a specific child, GrowQuest records a daily emotional check-in: an emotion picked from a wheel, an intensity from 1 to 3, and a timestamp. There is no free-text field.

Data about a person's emotional state, used in the context of wellbeing support, can qualify as special-category data under Article 9 GDPR. We therefore:

  • keep the feature off by default;
  • require the parent to pass an explicit consent screen before it can be enabled, per child;
  • restrict it to a fixed vocabulary — no free text, so nothing unexpected can be written down;
  • never reward it with XP, coins or streaks, so the child has no incentive to answer anything other than truthfully;
  • show the child plainly that their parent can see these check-ins;
  • automatically delete check-ins older than 12 months, every day, by a scheduled job;
  • let the parent delete the entire history with one button, at any time.

Consent can be withdrawn at any moment by turning the feature off. Withdrawal does not affect the lawfulness of what happened before it.

Collected automatically

  • A session cookie so you stay signed in. It is strictly necessary for the service to work.
  • Aggregated page analytics through Vercel Analytics. It sets no cookie, does not build a profile, and does not identify a visitor. We use it to know which pages are visited, nothing more.
  • Server logs (request, status code, timestamp) kept briefly for security and debugging.

We do not use advertising trackers, we do not do behavioural advertising, and we never sell or rent data to anyone. There are no third-party trackers of any kind in the children's area of the app.

4. Why we are allowed to process it (legal bases)

PurposeLegal basis (GDPR Art. 6)
Creating and running your account and the servicePerformance of a contract — Art. 6(1)(b)
Billing and managing a Premium subscriptionPerformance of a contract — Art. 6(1)(b)
Service emails (verification, password reset, weekly report)Performance of a contract — Art. 6(1)(b)
Security, rate limiting, abuse preventionLegitimate interests — Art. 6(1)(f)
Aggregated, cookieless audience measurementLegitimate interests — Art. 6(1)(f)
Emotion check-insExplicit consent of the holder of parental responsibility — Art. 6(1)(a) and Art. 9(2)(a)
Web push notificationsConsent, given through the browser permission prompt
Keeping accounting records for paymentsLegal obligation — Art. 6(1)(c)

5. Who else sees the data

We use a small number of service providers. Each acts as a processor on our instructions, under a data-processing agreement.

ProviderRoleWhere
VercelHosting and application deliveryApplication deployed in the Paris region (cdg1)
SupabasePostgreSQL databaseEU region
StripePayment processing for PremiumEU / global, under its own controller responsibility for payment data
ResendSending transactional emailEU / US, under Standard Contractual Clauses

Where a provider processes data outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses.

Beyond that, nobody. We do not share data with advertisers, data brokers, schools or insurers. We would disclose data to a public authority only where a valid legal order compels us to.

Inside your own family, visibility is exactly what you would expect: a parent sees their children's data; a child sees their own, plus the shared family surfaces (boss quest, family messages, siblings' progress where enabled).

6. How long we keep it

DataRetention
Account and game dataAs long as the account exists
Account after a deletion requestDeactivated immediately, permanently erased after 30 days
Emotion check-ins12 months, rolling, deleted automatically
Printed-board access tokensExpire with the board (14 to 28 days)
Notifications90 days
Server logsA few days
Invoices and payment recordsAs required by accounting law (held by Stripe)

The 30-day window on deletion exists so an account deleted by mistake — or by a child who got hold of a parent's session — can be recovered. Say the word before it elapses and we restore it; after that, it is gone for good.

7. Your rights

Under the GDPR you can, at any time:

  • Access your data and get a copy;
  • Rectify anything inaccurate;
  • Erase your data ("right to be forgotten");
  • Restrict or object to processing based on legitimate interests;
  • Port your data — receive it in a structured, machine-readable format;
  • Withdraw consent for anything based on consent (emotion check-ins, push notifications), without affecting what came before.

Two of these are built into the app, under Settings → Privacy and your data:

  • Download my data produces a complete JSON export of your account and your children's accounts, immediately.
  • Delete my account removes the family account and every child account attached to it, following the 30-day process above.

For anything else, write to contact@growquest.ai. We answer within one month, as the GDPR requires — in practice, much faster.

Children's rights are exercised by the parent who holds parental responsibility, since they created and control the account.

If you think we have mishandled your data, you can complain to your national supervisory authority — for example the CNIL in France (cnil.fr) or the Data Protection Authority in Belgium (autoriteprotectiondonnees.be). We would rather you told us first, but it is your right either way.

8. Security

  • Passwords are hashed with bcrypt (cost factor 12). Nobody, including us, can read them.
  • All traffic runs over HTTPS.
  • The database enforces row-level security, so the public API surface exposes nothing.
  • Sign-up, sign-in, password reset and the contact form are rate-limited.
  • Emotion check-ins are hard-restricted to a fixed vocabulary at the server level — the API rejects free text even if a client sends it.

No system is perfect. If a breach ever puts your rights at risk, we will notify the supervisory authority within 72 hours and tell you directly, as Articles 33 and 34 require.

9. Changes to this policy

If we add a feature that changes what we collect, we update this page and its version date first. For anything material we will also email account holders. The current version is 2026-07-26, published on 2026-07-26.

10. Contact

Questions, requests, complaints: contact@growquest.ai, or the contact form.

See also : Terms of Service