Privacy Policy
Last updated: 23 June 2026
This policy explains what personal data Questline (“we”, “us”, the “service”), operated by Mirko Baffa at questline.baffa.ch, collects from you, why, how we protect it, and the rights you have over it. Questline is a personal study-tracking app; we collect only what we need to run it.
Because Questline is operated from Switzerland and may be used from the EU/EEA, this policy is written to meet both the Swiss Federal Act on Data Protection (revFADP) and the EU General Data Protection Regulation (GDPR).
- Who is responsible
- What data we collect
- How and why we use it
- Cookies & local storage
- Sharing & third parties
- Advertising (Google Ads)
- How long we keep it
- Your rights
- Security
- Children
- Changes to this policy
- Contact
1. Who is responsible
The data controller for your personal data is:
- Mirko Baffa
- Switzerland
- Contact: mirko@baffa.ch
2. What data we collect
Account data
When you create an account we store your email address, a display name you choose, and a hashed version of your password. We never store your password in plain text. We also keep email-verification timestamps and a temporary verification token until your email is confirmed.
Your study data
Content you create while using the tracker: per-week progress and status (done / to-do), notes you write, and completion dates.
Settings & reminders
Your reminder preferences (whether reminders are on, your chosen reminder time, and your timezone). If you enable push notifications, we store the push subscription issued by your browser (an endpoint URL and the keys needed to deliver a notification to your device).
Technical data
To keep the service secure and working, we process a session identifier (stored in a cookie, see below) and we record rate-limit events tied to actions such as sign-in and registration (e.g. the email or identifier used and a timestamp) to defend against abuse and brute-force attempts. Our web server may also keep standard access logs.
3. How and why we use it
- To create and manage your account and sign you in (revFADP / GDPR Art. 6(1)(b) — performance of a contract).
- To store and display your study progress, the core function of the app (contract).
- To send the verification email and, if you opt in, reminder push notifications (contract / your consent — GDPR Art. 6(1)(a)).
- To keep the service secure, prevent abuse, and fix bugs (our legitimate interests — GDPR Art. 6(1)(f)).
We do not sell your personal data, and we do not use your study data or account data for advertising.
4. Cookies & local storage
Questline uses a single essential cookie, questline_sid, to keep you signed in. It is strictly necessary for the service to work and is set with HttpOnly, SameSite=Lax, and the Secure flag over HTTPS. We also keep a CSRF token in your session to protect form submissions.
As an installable app (PWA), Questline may store data locally on your device (e.g. a service-worker cache and offline copies of your data) so it works offline and loads fast. This data stays on your device.
We currently set no advertising or analytics cookies. If that changes (see Advertising), we will ask for your consent first where required.
5. Sharing & third parties
We share personal data only with the providers needed to run the service:
- Hosting — our web host stores the database and serves the app.
- Email delivery — verification and reminder emails are sent via our mail provider.
- Push notifications — if you enable them, notifications are delivered through your browser vendor’s push service (for example Google, Mozilla, Microsoft, or Apple). The endpoint is created by your own browser.
These providers process data on our behalf and only as needed to provide their service. Some may process data outside Switzerland/the EEA; where that happens we rely on appropriate safeguards (such as EU Standard Contractual Clauses).
6. Advertising (Google Ads)
At present Questline shows no ads and runs no advertising trackers.
We may introduce advertising in the future, likely through Google AdSense / Google Ads. When and if we do, this section will be updated before ads go live, and:
- Google and its partners may use cookies and similar technologies to serve and measure ads, and may collect data such as your IP address and ad interactions.
- Where required (e.g. for EU/EEA and Swiss users), we will request your consent for advertising and measurement cookies through a consent banner before any such cookie is set, and you will be able to withdraw it.
- Ads may be personalised or non-personalised depending on your choice and applicable law.
- You can review how Google uses data from sites that use its services at policies.google.com/technologies/partner-sites, and manage ad personalisation at adssettings.google.com.
Your study data and account details will never be shared with advertisers.
7. How long we keep it
- Account & study data — kept while your account exists. If you delete your account, the associated progress, notes, settings, and push subscriptions are deleted along with it.
- Rate-limit records — short-lived; old entries are purged automatically.
- Server logs — kept only as long as needed for security and troubleshooting.
8. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete your data (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time (e.g. turn off push reminders), without affecting prior processing.
To exercise any of these, email mirko@baffa.ch. You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, your local data protection authority.
9. Security
We protect your data with measures including hashed passwords, HTTPS, hardened session cookies (HttpOnly, SameSite, Secure), CSRF protection, rate limiting, and standard security headers. No method of transmission or storage is ever 100% secure, but we work to keep your data safe.
10. Children
Questline is not directed at young children. If you are under the age of digital consent in your country, please use the service only with the involvement of a parent or guardian. If you believe a child has given us personal data without consent, contact us and we will remove it.
11. Changes to this policy
We may update this policy as the service evolves (for example, when introducing advertising). We will revise the “Last updated” date above, and for significant changes we will provide a more prominent notice.
12. Contact
Questions about this policy or your data? Email mirko@baffa.ch.