Privacy Policy
Effective: 14 May 2026
This policy explains what personal data Qapital Quiz collects, why, how long it's kept, and what control you have over it. Qapital Quiz is operated by an individual developer in Norway, so this policy is written to comply with the EU General Data Protection Regulation (GDPR) — your rights apply regardless of where you live.
1. Who is the data controller
Daniel Tollefsen, an individual developer based in Norway, operating the service known as "Qapital Quiz" at qapitalquiz.trollefsen.com. For any privacy question or to exercise the rights listed below, write to support@trollefsen.com.
2. What we collect
Account information (from Google)
When you sign in with Google, we receive:
- Your Google account email address
- Your Google account display name
- Your Google account avatar URL
- A stable Google user identifier (used to recognise you on return visits)
We do not receive your Google password, contacts, Drive, Calendar, Gmail,
or any other Google data. We only request the standard openid, email,
and profile scopes.
Profile information you provide
During onboarding and in settings, you give us:
- A display name and a username (you can change either later)
- Geographic regions you want to learn (e.g. Europe, Asia)
- Self-rated skill level, daily practice goal, and a reminder time
- Your motivation for using the app (a single tag like "Travel", "School", etc.)
- The fact that you accepted the Terms of Service and when
Activity inside the app
- Quiz sessions you complete and per-question attempts (correct/incorrect, timestamps)
- Hit lists you create and the items inside them
- Aggregate statistics derived from the above (accuracy, streaks, XP)
What we deliberately do NOT collect
- Your date of birth or age
- Your physical address or precise location
- Marketing-email consent (no newsletter)
- Behavioural analytics, fingerprinting, or session recordings
- Advertising identifiers (AAID/IDFA)
Technical information
Our hosting and edge providers (Cloudflare, Supabase) write standard server access logs that include your IP address, the request URL, your User-Agent, and timestamps. These logs exist to operate, secure, and debug the service and are retained for at most 30 days. They are not used to build a profile of you.
3. Why we collect it (legal basis under GDPR)
- Performance of the contract (Art. 6(1)(b)) — to provide the quiz app, save your progress, deliver reminders you asked for, and let you log back in.
- Legitimate interests (Art. 6(1)(f)) — to keep the service secure (rate-limiting, abuse logs) and to debug crashes.
- Consent (Art. 6(1)(a)) — for optional features like push notifications you explicitly enable.
4. Who we share data with
The following processors and infrastructure providers receive your data strictly to deliver the service. None of them are permitted to use it for their own purposes.
- Supabase Inc. — provides our database and authentication. Hosted in the EU region.
- Cloudflare, Inc. — provides hosting (Pages) and the auth proxy (Workers).
- Google LLC — verifies your identity at sign-in (OAuth). Google receives only what's needed to issue the sign-in token.
We do not sell, rent, or share your personal data with advertisers. The app does not currently show advertisements and there are no third-party analytics or trackers loaded.
5. International transfers
Supabase and Cloudflare are US-headquartered companies that operate globally distributed infrastructure. When data is processed outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) signed with each provider as the legal transfer mechanism.
6. How long we keep your data
- Account & activity data: until you delete your account.
- Server access logs: 30 days, then automatic deletion.
- Backups: Supabase performs database backups with a 7-day retention. Deleted accounts are removed from backups when backups age out.
7. Your rights
Under GDPR you have the right to:
- Access a copy of your personal data (Art. 15)
- Rectification — fix anything that's wrong (Art. 16)
- Erasure / "right to be forgotten" (Art. 17)
- Restriction of processing (Art. 18)
- Data portability — a machine-readable copy of your data (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time (Art. 7(3))
- Lodge a complaint with your national data protection authority. In Norway, this is Datatilsynet.
8. How to exercise your rights
- Export your data: in the app, go to Settings → Account → "Download my data". You'll receive a JSON file containing every row tied to your account.
- Delete your account: in the app, go to Settings → Account → "Delete account". This removes your profile, quiz sessions, attempts, hit lists, and reminder settings immediately. Backups age out within 7 days.
- All other requests: email support@trollefsen.com. We respond within 30 days.
9. Children
Qapital Quiz is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, please email us and we will delete it.
10. Cookies and local storage
The app uses your browser's local storage to keep you signed in, remember your theme and
haptics preferences, and cache offline-friendly data such as your hit lists in guest mode.
We do not set any tracking or advertising cookies. Cloudflare may set a strictly necessary
cookie (__cf_bm) used to distinguish humans from bots; this expires after 30
minutes and contains no personal data.
11. Changes to this policy
If we make a material change — particularly anything that broadens what we collect or who we share it with — we'll notify you in the app before the change takes effect and update the "Effective" date at the top of this page.
12. Contact
Privacy queries: support@trollefsen.com
Postal: available on request to the email above.