Privacy Policy

Last updated September 10, 2026

Conglomerate Media Group, LLC (“QEST,” “we,” “us”) operates the QEST family app at qest.kids and the QEST app for iOS (together, the “Service”). This policy explains what information we collect, how we use it, and the choices you have. It covers the website and the mobile app equally. By creating a QEST account, you agree to the practices described here.

The short version.We sell nothing and we advertise nothing. There are no advertising or analytics trackers in the website or the app. Your family's activity is private to your family unless a parent deliberately connects with another family, posts to the community, or shares a link. A parent controls every child profile and can delete the account, and everything in it, from inside the app.

Who this applies to

QEST is a family organization app used by parents and guardians and, under a parent's account, their children. A child never signs up for QEST independently. A parent or guardian creates every child profile, and a child only gets their own sign-in after a parent explicitly issues a claim code to a specific email address the parent controls or approves. We do not knowingly collect personal information directly from a child without a parent first setting up that child's profile.

Information we collect

Account information. When a parent creates an account, we collect an email address and, depending on how you sign up, either a password (stored hashed, we never see it in plain text) or your name and email as shared by Google, Apple, or Microsoft if you sign in with one of those providers.

Family and child information.Family name, household timezone, and for each child profile: a display name, a date of birth, and an optional avatar (either a preset illustration or a photo a parent uploads). We use the date of birth to show age-appropriate content, to award a birthday bonus, and to gate the Journey skill levels. If a parent turns on self-login for a child, that child's email address is stored solely to deliver and validate their claim code.

Language preference. Each family member has their own language setting, taken from the language of their device or browser the first time they sign in and changeable in Profile. We use it to show QEST, the emails we send, and any insight reports in that language.

Founding Families application. If you apply to the Founding Families program from our website, we collect the name and email address you give, your family name, how many kids you have, and the answer you write, in order to review the application and, if it is accepted, to attach founding status to your family.

Caregiver information.If a parent invites a co-parent or caregiver (grandparent, nanny, babysitter, and so on), we collect that person's email address to send the invitation and manage their access level.

Activity data.Completed tasks (“Qests”), streak, badge and Journey progress, points earned, deducted and redeemed, rewards, life-skill practice logs, calendar events you create in QEST, and the activity history shown to your family.

Photos, video, and files you upload. Avatars, and any photo or video attached to a comment or message. On mobile this may come from your camera, your photo library, or your microphone if you record video, each of which iOS asks your permission for the first time it is used, and each of which you can revoke in iOS Settings. We store these files in our own storage and do not scan them for advertising or any other purpose beyond delivering them to the people you sent them to and responding to reports.

Community, messages, and comments. If a parent opts into the community, we store a family profile (display name, optional bio, optional photo, and a profile link), the connections between your family and others, posts and comments, likes, tags and mentions, direct messages and their attachments, and parent-approved friendships between children. See what leaves your family below for how far each of these travels.

Calendar data (optional).If a parent chooses to connect a Google, Outlook, or Apple calendar, we store the credential needed to keep it in sync: an OAuth authorization token for Google and Outlook, or the Apple app-specific password you generate for QEST in the case of Apple Calendar. The credential is stored encrypted, with the key held outside the database. We use it to create and sync a dedicated “QEST” calendar on that account, and to read event titles and times (not full event details) from that account's other calendars so they can be displayed alongside QEST events. This only happens for a parent who explicitly connects their own calendar, and only that parent's connection is used to read or write to it. Disconnecting deletes the stored credential.

Billing information. If you subscribe to a paid plan, our payment processor, Stripe, collects your payment details directly. QEST never receives or stores your full card number. We store your subscription status and plan.

Notification and device information.If you allow push notifications, we store the push token issued by Expo's notification service for that device, plus the platform (iOS or Android), the device's language, and when it was last seen, so we can deliver notifications to the right device in the right language. Turning off notifications removes the device from delivery.

Crash and diagnostic data. The iOS app and the website report crashes and errors to Sentry so we can fix them. We have configured these reports to carry no account identity: the user field is removed before a report is sent, cookies and request headers are dropped, console output is not attached, and query strings are stripped from network URLs. What remains is technical, such as the error, the code path, the device model or browser, and the OS version. Nothing is sent from a device or browser while a child is signed in.

Usage and technical information. Standard technical information collected automatically by our hosting infrastructure, such as IP address, browser or app version, and requests made, used to keep the Service secure and working correctly. We do not run advertising or analytics trackers on the website or in the app.

How we use information

  • To provide and operate the Service, including kid profiles, Qests, streaks, rewards, the Journey, and the family calendar.
  • To send account-related email (confirmations, password resets, invitations, claim codes) and, if you have opted in, activity and product notifications by email or push.
  • To generate the optional insight reports and guided setup suggestions described below.
  • To operate the community features a parent has opted into, including connections, posts, and messages.
  • To process subscription billing through Stripe.
  • To review reports of objectionable content and enforce our Terms.
  • To provide customer support when you contact us.
  • To maintain the security, integrity, and reliability of the Service.

We do not sell your personal information, or your child's, to anyone. We do not use it for advertising, and we do not share it with advertising networks or data brokers.

Automated features and AI

Two optional features send a limited amount of information to Anthropic, the provider of the Claude AI model, to generate text:

  • Insight reports.A parent can enable these per child, and they are off unless a parent turns them on. When a report is generated we send that child's first name and a summary of the period's activity: how many Qests were completed, approved, or missed, which Qests came up most often, the reasons for any deductions, and the streak numbers. We do not send your email address, your child's date of birth or email, your family name, any photo, any message, or any comment.
  • Guided setup. If you use the setup questionnaire, your answers are used to pick a starter set of Qests and rewards from our own catalog.

Anthropic processes this as our service provider and does not use it to train its models. We do not use your family's content to train any AI model, our own or anyone else's. Insight reports are written by a model and are a prompt for your own judgment, not professional parenting, educational, or medical advice. You can turn them off for any child at any time.

What leaves your family, and when

By default, everything in your family's account is visible only to the members of your family. Information leaves that boundary only through a deliberate action by a parent:

  • A community profile.Creating one makes your family's chosen display name, bio, and photo visible to other QEST families. You choose whether your profile is discoverable in search; if it is not, other families can reach it only via a link or QR code you give them.
  • Connecting with another family.Once both sides accept, connected families can see each other's community posts and message each other.
  • Posts, comments, and tags. What you post to the community is visible to the families you are connected with. A separate setting controls who may tag your family in a photo or mention you in a post.
  • Children's friendships. A child cannot connect with a child in another family unless a parent on both sides approves it.
  • Share links.Sharing an achievement creates a link that anyone holding it can open, and social platforms such as Facebook, Instagram, and Threads will fetch a preview image from it. These pages deliberately show a child's first name only, never a full name, an email, or a birth date. The link is signed and short-lived, and the page asks search engines not to index it.

None of this happens automatically, and a parent can undo any of it: delete a post, disconnect from a family, block a family, remove a community profile, or revoke a child's friendship.

Who we share information with

We use a small set of service providers to run QEST, each only able to access the information they need to do their job:

  • Supabase for our database, authentication, file storage, and backend hosting.
  • Vercel for website and API hosting.
  • Resend for delivery of transactional and notification email.
  • Stripe for subscription billing and payment processing. Stripe is the merchant of record for paid subscriptions, so it also issues your receipt, handles applicable sales tax or VAT, and handles refunds and payment disputes.
  • Expo for delivering push notifications to your device.
  • Anthropic for the optional insight reports and guided setup described above.
  • Sentry for crash and error reports from the iOS app and the website, with account identity removed.
  • GIPHY if you search for a GIF to add to a comment or message. The search runs through our servers, so GIPHY receives the search term but not your identity or your device's address. Once a GIF is posted, it is loaded from GIPHY's servers to display it. Results are restricted to GIPHY's G rating.
  • Google, Apple, and Microsoft only if you choose to sign in with one of them, or connect a Google, Outlook, or Apple calendar.

We may also disclose information if required by law, or to protect the rights, safety, or property of QEST, our users, or the public.

Reports, safety, and moderation

Anyone can report a post, comment, message, or family profile from inside the app, and a parent can block another family outright, which immediately ends messaging and hides that family from your feed. When you send a report we record who reported it, what was reported, the reason you chose, anything you wrote, and a copy of the reported content as it appeared at that moment, so that we can still review it if the original is deleted. The person you reported is not told who reported them. We review reports and may remove content or suspend accounts under our Terms of Service, which do not tolerate objectionable content or abusive behaviour.

Some words are also blocked automatically at the moment a message, post, or comment is sent. A blocked attempt is simply refused; nothing about it is stored or reported.

Data retention and deletion

We keep your family's information for as long as your account is active. Read notifications are cleared automatically after 30 days. A parent can delete a child profile that has not yet been claimed at any time.

You can delete your account from inside the app.On the web and on iOS, open your profile and use “Delete account.” What this covers depends on your role: deleting a child or caregiver account removes that person and their data, and deleting the only parent account on a family removes the entire family, including every child profile, all activity history, uploaded files, messages, and any community profile.

Deletion takes effect immediately in the sense that matters: everyone affected is signed out and locked out at once, and any paid subscription is canceled straight away so you are not billed again. The data itself is then held for 30 days before a daily job destroys it permanently. That window exists so an accidental or disputed deletion can still be undone; if you need that, email us within the 30 days and we can restore the account. After the window closes it is gone and we cannot recover it. We may keep a record of a report or a billing transaction where the law requires it, and backups age out on their own schedule.

If you would rather we did the deletion for you, or you want a copy of your data first, email privacy@qest.kids.

Your rights and choices

  • Access, correct, or delete the information in your family's account at any time from Settings, or by contacting us.
  • Delete your account and your family's data from inside the app, as described above.
  • Turn insight reports on or off per child.
  • Choose whether your family profile is discoverable, and who can tag or mention you.
  • Disconnect a Google, Outlook, or Apple calendar at any time, which deletes the stored credential and stops all further sync immediately.
  • Opt out of non-essential notification email and push while still receiving essential account and security email.
  • Turn off camera, photo, microphone, or notification permissions for the app in iOS Settings.
  • Request a copy of your family's data by contacting us.

Depending on where you live, you may have additional rights over your personal information, such as the right to access, correct, delete, or object to certain processing. Email us and we will help, whatever your location.

Children's privacy

QEST is built for families to use together, and we take children's privacy seriously. Every child profile is created and controlled by a parent or guardian, who can view, edit, or delete that child's information at any time.

We collect only what the child needs to use the app: a display name, a date of birth, an optional avatar, their activity and progress, anything they write or attach in their own family, and, if a parent enables self-login, an email address for the claim code. We do not show children advertising, we do not profile them for advertising, and there are no advertising or analytics trackers in the app. We do not sell or rent children's information.

Children do not have unsupervised contact with people outside the family. A child cannot create a community profile, cannot connect with another family, and cannot become friends with a child in another family unless a parent on each side approves it. Everything a child posts stays inside boundaries a parent has set, and a parent can remove any of it or block another family at any time.

If you believe we have collected information from a child outside of this parent-managed flow, contact us at privacy@qest.kids and we will investigate and delete it.

Where your information is held

QEST is operated from the United States, and our providers store and process information there. If you use QEST from another country, you are sending your information to the United States, where privacy laws may differ from your own.

Security

We use industry-standard safeguards to protect your family's information, including encryption in transit, access-controlled infrastructure, and database rules that scope every record to the family it belongs to so one family cannot read another's data. Photos, videos, and files are held in private storage and are reached only through short-lived links issued to people allowed to see them. Calendar credentials are encrypted at rest with a key held outside the database. Crash reports carry no account identity, as described above. No method of transmission or storage is 100% secure, but we work to protect your data and will notify affected users if we become aware of a breach affecting their information, as required by law.

Changes to this policy

We may update this policy as QEST evolves. If we make a material change, we will update the date at the top of this page and, where appropriate, notify you directly.

Contact us

Questions about this policy or your family's data? Reach us at privacy@qest.kids. The company responsible for your information is Conglomerate Media Group, LLC, a Wyoming limited liability company, United States.

See also our Terms of Service.