QuestLoom Privacy Notice
Version 1.1.2 · Antimatter Zone LLC
What we keep
We keep your immutable AZAS subject, current handle and display name, campaign data you choose to store, security audit records, and redacted operational metrics. We do not use email for authorization, advertising identifiers, or product analytics. Crash reports are opt-in.
AZAS and friends
QuestLoom requests explicit consent for the AZAS friends:read, friends:write, and admin:read scopes. AZAS access tokens, authorization codes, client secrets, and raw callback URLs are not stored or logged. AZAS administrator status is checked only for current, fail-closed diagnostic and community-curation eligibility; QuestLoom permissions remain separate.
Uploads and notifications
Uploaded images, approved audio, PDFs, and plain or Markdown text are stored with their campaign or library record, scanned, type-checked, and quota-limited. Rejected partial uploads are removed. Push endpoints are encrypted at rest and notification bodies remain encrypted through the relay. The self-hosted push relay retains encrypted payloads for no more than 24 hours; notification preferences are controlled per campaign.
Retention
Delivered events are kept seven days; soft-deleted game data and operational logs 30 days; security audits 90 days. Encrypted backups may retain deleted data until their ordinary expiry.
Exports and deletion
You may stream an account export or request deletion. Ownership safeguards must be resolved first. Local-only encrypted backups are best effort and total node loss may destroy data.