Privacy Policy

Last updated: 25 August 2026

This policy describes which data is processed when you visit rlquest.de and rlquest.app and when you use the RLQuest app. It is deliberately specific: RLQuest is an app that knows where people go, and that is exactly why what happens with that — and what does not — belongs here.

Controller

Nine to Zero UG (haftungsbeschränkt)
Malzer Chaussee 173, 16515 Oranienburg, Germany
Email: mail@ninetozero.de
Further details in the imprint.

This website

The site loads no external fonts, no analytics tools, no ad networks and no social embeds. No cookies are set.

On each request the web server writes a technical log entry: IP address, timestamp, requested address, amount of data transferred, browser identifier. This is necessary to operate the site and to defend against attacks (Art. 6(1)(f) GDPR, legitimate interest in a working and secure service). Entries are deleted after 14 days at the latest.

The app

Account

An account requires an email address and a password. The password is stored only as a hash and is not known to us. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).

Profile

Year of birth, time zone, language, chosen interests and the amount of time you set per day. The year of birth governs which tasks may be assigned; an exact date of birth is not collected.

Progress and quests

Experience points, streak, number of completed quests, total distance covered, assigned and completed quests, achievements, weekly goals, finds.

Location — and what of it is stored

No location is stored. Not your current one, not your last one, neither as a coordinate nor as a route.

The app converts positions on the device into cells of a global grid (H3, resolution 9, roughly 350 metres across) and transmits only the identifier of those cells. What is stored is therefore which cells someone has uncovered and when for the first time — not where within a cell they were or are.

For a quest with distance measurement the recorded track is sent to the server for checking and is not stored there. What is stored is the result: measured distance, duration, number of track points.

The legal basis is performance of the contract (Art. 6(1)(b) GDPR) — without this checking there is no service of the kind the app promises. The location permission is requested by the operating system and can be withdrawn at any time; quests that need it are then left out.

Photos

For a photo quest the picture you take is sent to our server and from there to OpenAI for checking. What comes back is an assessment of whether the subject is visible. The picture is deleted automatically 30 days after submission — which is why a data export contains no photos.

Location data in the image metadata (EXIF) is removed before upload.

What outlives the 30 days is a checksum of the image — a short string from which the image cannot be reconstructed, but which lets us tell whether the same image is submitted twice. It serves that purpose alone and is deleted with the account.

Weather

So that no snow quest is set in July, the server queries the weather from the Norwegian Meteorological Institute (api.met.no). A rounded position is transmitted, not an exact location.

Map

Map tiles come from our own server (api.ninetozero.de). There is no external map service that learns which area someone is looking at.

Usage events

The app reports a short, fixed list of event names (such as “premium screen opened”) with no content, no free text and no third-party identifiers. They exist to show which features are plainly going unused. The legal basis is the legitimate interest in a usable app (Art. 6(1)(f) GDPR).

Error reports

If something crashes, an error message without personal data is transmitted.

Premium

Purchases run through the App Store or Google Play. Payment details never reach us. We use RevenueCat to manage entitlements; an account identifier is processed there together with the subscription status.

Processors and recipients

Where data is processed in countries outside the EU, this takes place on the basis of the European Commission's standard contractual clauses or an adequacy decision.

Retention

Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR).

Access and erasure work directly in the app, under Settings — without having to write to anyone. Access arrives as a file; erasure removes the account and everything attached to it.

You also have the right to lodge a complaint with a supervisory authority, for example the Data Protection Commissioner of the State of Brandenburg.

Children and young people

Quests carry an age limit; the year of birth in the profile decides which ones may be assigned. Quests with elevated risk additionally carry a safety note.

Changes

If the processing changes, this policy changes. The date above says when it was last touched.