Privacy policy

A plain-language privacy policy.

Everything we collect, why we collect it, who can see it, and how to delete it. If something here is unclear, that's our fault — write to privacy@questiy.com and we'll fix it.

Last updated May 2026

Questiy (“we”) is built for parents of school-age children. The product’s entire purpose is to record sensitive information about minors. We treat that as the highest-stakes responsibility on the team. This policy explains, without legalese, what we do.

1. What we collect

We collect only what we need to build a longitudinal portfolio for a child:

  • Account info — your name, email, and password (handled by our auth provider; we never see the plaintext password).
  • Child profile data — display name, date of birth, class, board, and school name. Date of birth is encrypted at rest.
  • Achievements — marksheets, certificates, photos of trophies, and the structured fields you enter (domain, level, date).
  • Verification evidence — if your jurisdiction requires verifiable parental consent, we store the verification artefact (a signed form, or hashed OTP attempt records).
  • Operational telemetry — the minimum needed to run a reliable service: request logs, error traces, and audit events. IP addresses and user-agent strings are hashed before persistence.

2. What we don’t do

  • We do not run ads. We do not have an advertising business.
  • We do not profile, segment, or target your child for any third party. There is no “data licensing” tier.
  • We do not show percentiles, rankings, or comparisons to a child by default. Those views are parent-only and require an explicit consent action to enable.
  • We do not assign career labels (“your child will be an engineer”). Our trajectory projections are directional only and always show the data points behind them.

3. The privacy regime that applies to your family

At signup we ask for your country of residence and the age of your youngest child. From that we resolve a privacy regime — DPDP (India), COPPA (US, under 13), GDPR-K (EU/UK, ages 13–16 depending on country), or our standard high-privacy defaults for everywhere else. Where multiple rules could apply, the strictest one always wins. The resolved regime is shown plainly on your account.

4. Verifiable parental consent

Some regulated actions — like collecting your child’s data, including them in anonymised peer cohorts, or generating a portfolio to share outside the app — require us to verify that you, the parent or legal guardian, have consented. We do that with:

  • Email + phone OTP for DPDP and GDPR-K families.
  • A signed consent form (PDF) for COPPA families. We store the artefact’s cryptographic hash so the regulator can verify it later.

You can revoke any consent at any time from your account. A revoke takes effect on the next request — we never “cache” a granted state past its revoke.

5. Where data is stored and who can see it

Data is stored in encrypted Postgres on managed infrastructure in the region closest to your residence (India for IN accounts; EU for EEA accounts; US for US accounts). Inside Questiy, access to production data is limited to a small named on-call rotation and audited.

6. Sharing with others

We do not sell your data, ever. We do not share it with a third party unless one of the following is true:

  • You explicitly chose to share it — for example, by generating a portfolio share link for a counsellor.
  • A subprocessor needs it to run the service — e.g. our authentication, hosting, or OCR providers. These are listed in our DPA and bound by data-processing terms.
  • A law obliges us — in which case we’ll fight any overbroad request and tell you whenever we’re legally permitted to.

7. Your rights

You can:

  • Access everything we hold about your family (one click).
  • Export a machine-readable copy.
  • Correct or delete any field.
  • Delete your account entirely (the “right to be forgotten”); we destroy your records within 30 days, except where a specific legal hold applies.
  • Withdraw any specific consent without losing access to the app.

8. Children’s rights

Children who are bound to a profile via the kid-link flow can:

  • See what their parent has and has not enabled, in plain language.
  • Add their own “wins” (if the parent has enabled that scope).
  • Choose their own avatar.

Children cannot change their parent’s consent settings, see other children’s data, or see comparative percentile framing. The kid surface is deliberately quieter than the parent surface.

9. Retention

We keep your data for as long as your account is active. If you close your account, we delete it within 30 days, except for a minimal audit-trail row (regime + timestamp, no PII) that we’re required to retain under DPDP / COPPA / GDPR.

10. Contact

For privacy questions write to privacy@questiy.com. We acknowledge requests within 72 hours and respond substantively within 30 days — faster in most cases. For general feedback or partnership questions, see our contact page.