// legal document
Privacy Policy
Version 1.0 · last updated: July 13, 2026 · applies to prodquest.app (closed beta phase)
This document is currently published in English only. Localized legal versions (matching the interface languages available on the main site) are planned for a future release, once reviewed by qualified counsel in each relevant jurisdiction.
Fields marked [ ] are details about the entity operating the service (legal name, form, address, registration numbers) that can't be filled in without binding registration data — complete these before publishing this policy. The rest of the content is ready to publish and reflects the actual scope of data processing described in the product specification.
1. Data controller and contact
The data controller for personal data processed in connection with the ProdQuest service (prodquest.app) is:
[Entity name / legal form]
[Registered address]
[Company registration number, if applicable]
email: hello@prodquest.app
For anything related to the protection of your personal data, you can reach us at the email address above.
2. What data we process and why
| Category of data | Purpose of processing |
| Registration data (email, username, hashed password) | Creating and managing your account, logging in, service-related communication |
| Closed-beta signup form data (self-reported experience level, interests, learning goal) | Placing you in a cohort and an initial match to a learning path |
| Gameplay data (task history, grades, test results, skill matrix, XP/HP points, rank) | Delivering the service — difficulty selection, progress evaluation, ranking features |
| Content of conversations with the AI agent (mentor) | Running learning sessions, generating personalized tasks and explanations, remembering context between sessions |
| Code snapshots (workspace, git history) | Letting you work on tasks and projects, evaluating your solutions |
| Technical data and logs (hashed IP address, device/session identifier, timestamps) | Account security, abuse detection, session continuity |
| Cookies | Keeping you logged in (essential) and — with consent — analytics and preferences |
| Newsletter email address (optional) | Updates on project progress and new features — only with separate consent |
3. Legal basis for processing
- GDPR Art. 6(1)(b) — processing necessary to enter into and perform the service contract (including participation in the closed beta).
- GDPR Art. 6(1)(a) — consent, in particular for the newsletter and for non-essential cookies.
- GDPR Art. 6(1)(f) — legitimate interest of the controller: service security, preventing ranking abuse and fraud, product analytics, establishing or defending legal claims.
- GDPR Art. 6(1)(c) — legal obligation, e.g. regarding billing data (applies to future paid plans).
4. Who we share data with
Data may be shared with the following categories of recipients, strictly to the extent necessary to provide the service:
- Cloud infrastructure providers — hosting the application, databases, and execution environments.
- AI language model providers — task content, code, and messages to the agent may be processed by third-party AI model providers used to generate tasks, grade solutions, and power mentor conversations. The technical layer of the service is deliberately designed to support multiple providers (including self-hosted models), with the specific provider for a given operation determined by administrative configuration.
- Supporting service providers — e.g. transactional email delivery, analytics tools, where enabled.
- Public authorities — only in response to a lawful request.
Where a recipient processes data outside the European Economic Area, the transfer relies on safeguards provided for under the GDPR, in particular Standard Contractual Clauses.
5. How long we keep data
- Account and gameplay data — for as long as you hold an active account.
- Raw agent-conversation history and detailed work-process logs — by default for 12 months, after which only consolidated progress summaries remain (without losing continuity of your learning path).
- The administrative audit log and sanction history — retained for longer, due to accountability obligations.
- After account deletion — a 14-day grace period, during which you can reverse the decision. After that, personal data is cascade-deleted (including the agent's memory and its vector representations); entries required for accounting or billing purposes are anonymized, and tasks you previously contributed to the shared task bank remain — they contain no personal data.
6. Your rights
Under the GDPR you have the right to:
- access your data — your account settings show you everything the system knows about you (profile, skills, agent memory),
- rectify inaccurate data,
- erase your data ("the right to be forgotten") — self-service, from your account settings,
- restrict processing and object to processing based on legitimate interest,
- data portability — a self-service export of all your data (profile, task and grade history, conversations, workspace) as JSON + ZIP,
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal,
- lodge a complaint with your national data protection authority (in Poland: the President of the Personal Data Protection Office, UODO) if you believe processing violates the GDPR.
In addition, your account settings give you visibility into individual agent-memory entries, and you can dispute or request deletion of a specific entry independently of a full account deletion.
7. The AI agent and automated decisions
The AI agent assesses your skills and uses that to select the difficulty and order of tasks (educational profiling). This does not produce legal effects or similarly significantly affect you — it's a gameplay mechanism, not an administrative decision. You can contest any task grade and get an independent second review carried out through a separate evaluation pass.
8. Data security
- Passwords are stored hashed (Argon2id), never in plain text.
- Two-factor authentication (2FA) is available optionally for players, and mandatory for moderator and admin roles.
- Hard isolation of data between accounts at the database query level.
- Especially sensitive data (e.g. health, financial) is not intentionally collected or persisted in the agent's memory — it is filtered out at write time.
- Access keys for external services are stored encrypted and are never sent to the user's browser.
9. Cookies
| Type | Purpose | Consent required? |
| Essential | Keeping you logged in, security | No — necessary for the service to function |
| Analytics | Usage statistics, product improvement | Yes |
| Preference | Remembering interface settings (e.g. language) | Yes |
You can withdraw consent at any time via the cookie banner or your browser settings. Declining analytics and preference cookies does not limit access to the core functionality of the service.
10. Minimum age
The service is not directed at individuals under the age of 16. Anyone under 16 may only use the service with the consent of a parent or legal guardian, in accordance with GDPR Art. 8.
11. Changes to this policy
We will notify you of any material changes to this policy with reasonable advance notice, by email and via an in-service notice. The date of the last update appears at the top of this document.
For anything related to the protection of personal data, write to hello@prodquest.app.