Privacy Policy
Last updated: July 8, 2026 · Interim version; we may update this policy as practices change.
This Privacy Policy describes how Synquesta ("we", "us") collects, uses, stores, and shares information when you use the Synquesta quest platform and related interfaces (collectively, the "Service"). It complements our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms where applicable.
1. Who operates the Service
The controller responsible for processing personal data collected through the Service is the Synquesta team or the legal entity identified in deployment or commercial materials for your environment ("Synquesta"). For questions, first see the primary contact paths linked from our website footer (for example, Synquesta on X).
2. Information we collect
2.1 Account data (via Clerk)
Authentication is delegated to Clerk. Subject to how you configured your Clerk account, Synquesta may synchronize and retain your platform user identifier, primary email address, name fields, display name, avatar URL, approximate last login timestamps, account status, and linkage between our internal user profile and Clerk user id. Clerk processes sign-in telemetry and fraud signals under their own policy.
2.2 Wallet and blockchain-related data
When you link a wallet via SIWE-compatible flows we store one Ethereum-compatible address tied to your user row, linkage timestamps, and short-lived cryptographic nonces strictly as needed to complete verification. Addresses you use on-chain are public by design; subscribing to quests may also record the wallet snapshot used at subscription time alongside your user identity.
2.3 Quest activity and organization workspaces
We process quest metadata you create as an organizer (titles, descriptions, media references, eligibility parameters, escrow and contract addresses on supported networks), your participation subscriptions, and moderation outcomes (reviews, rejects, approvals) attributed to admins. Organization applications store application text, proposed branding assets in object storage, and reviewer audit details. Published quest pages may show deployed contract addresses and links to public block explorers.
2.4 Payment intents and mediator gas bank
When you pay per-play gas through the QuestPaymentMediator or when an organizer funds a subsidized quest gas bank on an EVM rail, we process payment-intent records (quest and step binding, wallet address, token, quoted amounts, status, transaction hashes, and GenLayer submission references), verified deposit transactions, credited GEN-equivalent snapshots where applicable, refund-request metadata, and the deposit wallet address used for mediator refunds. This data is used to verify on-chain payments, operate subsidized participation, and execute organizer refund workflows.
2.5 Monetary referral program
When monetary referral bonuses are enabled for a quest, we process referral relationships, voucher issuance metadata, and registration status needed to support on-chain ReferralRegistry flows. Voucher payloads and resulting on-chain registrations are designed so escrow contracts can verify bonuses without a live API call at claim time; registry state on supported networks is public by design.
2.6 Product telemetry and diagnostics
The Service may ingest allow-listed browser analytics events routed to our APIs. Such events can include coarse page or quest context, a session identifier stored locally in your browser, your user agent string, timestamps, and hashed client IP (SHA-256) for abuse control rather than verbatim IP retention. Optionally, instrumentation through providers such as Sentry may receive error reports configured in deployments.
2.7 Security audit trail
Sensitive administrative actions append-only audit logs that may include actor identifiers (user id where applicable), collaborator email snapshots captured at execution time, moderation targets (resource types and opaque ids), and JSON metadata describing the operational change.
2.8 Email deliveries
Transactional notifications (welcome messages, subscription acknowledgements, quest lifecycle notices, moderation decisions, etc.) create delivery records referencing template kind, hashed idempotency keys, recipient snapshots, timestamps, anonymized provider message ids, retry counts, and error strings for debugging failed sends. Rendering uses our email vendors (currently Resend-compatible providers when configured).
2.9 Uploaded media and files
Quest media or organization logos you upload reside in Synquesta managed cloud object storage keyed by deterministic object paths; we store opaque keys alongside database metadata and may serve public URLs from our edge or CDN as designed.
2.10 Platform reputation and play moderation
For users participating as quest players, we process reputation and moderation data including: cached reputation scores and breakdowns; append-only ledger lines (titles, point deltas, timestamps, appeal status, and whether a line was included in an on-chain commit); per-day activity records used for tenure eligibility; play suspension records (reason metadata for operators, optional public messages shown to you, expiry timestamps); on-chain commit metadata (transaction references, networks, claimed scores, and ban-related parameters where applicable); and, when you use those features, connected social account identifiers, referral relationships (including reputation-only referrals distinct from monetary escrow bonuses), results of on-demand asset checks you initiate, and (when enabled) external attestation identifiers from supported attestation services. Reputation applies to the player role, not to organization agent activity on the same account.
Your detailed reputation history in the product is visible to you and authorized platform staff, not to other players. Numeric reputation committed for your bound wallet on supported blockchains is public on those networks by design.
3. Purposes for processing
- Provide authentication, personalization, wallet binding.
- List, approve, moderate, settle, refund, and notify around quests, including payment-mediator verification and gas-bank accounting.
- Communicate transactional messages about your participation and organizations.
- Maintain security across accounts, moderation, hashed IP-rate limits, and anomaly detection hooks.
- Observe escrow and consensus outcomes associated with quests that rely on compatible smart contracts—including signals related to GenLayer and EVM bridging infrastructure—with no implication that we operate the underlying decentralized networks.
- Operate analytics and improve reliability of the Service.
- Operate platform reputation (scoring, quest eligibility gates, on-chain claims, appeals, play suspensions, and anti-abuse controls tied to participation).
- Issue and track monetary referral vouchers and related on-chain registration support where that feature is enabled.
- Comply with law, contractual obligations, and enforce Terms.
4. Legal bases (EEA / UK users)
Where GDPR-style rules apply, we rely on one or more of: (a) performance of a contract with you; (b) legitimate interests in operating, securing, and improving the Service (balanced against your rights); (c) compliance with legal obligations; (d) consent where we explicitly request it (for example certain optional communications or cookies not strictly necessary). You may withdraw consent where processing is consent-based without affecting prior lawful processing.
5. Sharing and subprocessors
We share data with infrastructure and integration partners who process it on our instructions, including but not limited to authentication (Clerk), hosting and database providers, Redis queues, email delivery (e.g. Resend), object storage (e.g. S3-compatible services), analytics / error reporting (e.g. Sentry), wallet/RPC vendors surfaced in the web client, and GenLayer or related blockchain networks you interact with (public by design). We require appropriate contractual protections where standard in the industry; public chain data cannot be recalled from the chain by Synquesta alone.
6. Retention
We keep personal data only as long as needed for the purposes above, including legal, tax, and dispute resolution needs. Append-only audit logs and certain notification delivery records may be retained longer where required for security or compliance. Analytics events are designed for operational metrics and may be rotated or truncated over time in line with engineering policy. Reputation ledger entries and play-moderation records may be retained for the life of the account and longer where needed for disputes, security, or legal obligations; on-chain reputation commits persist on public networks independently of account deletion requests. Blockchain history persists independently on public networks.
7. International transfers
We and our subprocessors may process data in the United States, European Economic Area, United Kingdom, and other regions where our providers operate. Where required we implement appropriate safeguards (for example Standard Contractual Clauses) in agreements with vendors.
8. Your rights
Depending on your location you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability for information you supplied. You may also lodge a complaint with a supervisory authority. To exercise rights, contact us through the channels noted in the footer; we may verify your identity before fulfilling requests. Some requests may be limited where we must retain data for legal reasons or where chain-level immutability prevents erasure of public transaction history.
9. Cookies and similar technologies
The Service uses cookies and local storage as needed for session establishment (including Clerk session cookies), wallet UI state, analytics session identifiers, and anti-abuse measures. Consult your browser settings to limit cookies; disabling strictly necessary cookies may break sign-in.
10. Children
The Service is not directed to children under 16 (or the digital age of consent in your jurisdiction). We do not knowingly collect personal data from children; if you believe we have, contact us to request deletion.
11. Changes to this policy
We will post updates here and adjust the "Last updated" date. Material changes may also be highlighted in-product or by email where appropriate.
12. Contact
Use the official Synquesta contact options linked from the website footer (for example the Synquesta account on X/Twitter). For account-specific settings you can also open your account area in the product.
See also Terms of Service.