We don’t do anything weird with your data.
Plain-language explanation of what we collect, how long we keep it, and what we don’t do.
We do not sell your data. We do not use it for advertising. We do not share it with third parties. That’s the short version.
What we collect
- Your email address, collected by Stripe when you pay, or when you join the newsletter. We never see your card details; Stripe handles those directly.
- Quest inputs: the closed-ended picks you make when building a quest (mode, theme, vibe, constraints). There is no free-text field anywhere in the builder.
- Generated quest content: the sub-quests, companion-voice lines, and resolved places for your specific outing.
- Payment identifiers: Stripe session and receipt IDs, stored for support and tax purposes.
- Anonymous analytics events: page views and funnel steps (e.g. “quest generated”). No PII in any event payload.
How long we keep it
- Paid quests: quest content and inputs are kept for as long as your quest link is active, and deleted after a short grace period once it expires.
- Unpaid / abandoned reservations: deleted after approximately 7 days. These are tiny database rows with no generated content attached.
- Payment records: retained for as long as legally required for tax and support (Stripe holds payment data per their own terms).
Security
- All data is transmitted over HTTPS.
- API keys and secrets are server-only, never exposed to the browser.
- Quest URLs use unguessable random slugs, cryptographically random.
- We use Neon Postgres and Vercel, both of which have their own security practices.
Requesting deletion
If you want your data deleted before it would otherwise expire, email us at hello@touchgrass.quest and we’ll take care of it promptly.
Changes to this policy
If we make any material changes, we’ll update this page and note the date below. We won’t bury changes in a changelog no one reads.
Last updated: August 2026
Questions? Contact us →