Privacy Policy for System Quest: Habit RPG

Effective date: August 5, 2026

This Privacy Policy explains how MarOst ("MarOst", "we", "us", or "the Service Provider") handles information when you use the mobile application System Quest: Habit RPG (the "Application").

Summary: System Quest is primarily a local-first application. Goals, quests, private notes, reflections, challenge history, and locally derived Health Connect step totals are stored on your device. The optional Online Party feature uses Google Firebase to create an anonymous server identity and synchronize limited party information with other members of the same party. The Application uses Google AdMob for native and rewarded advertisements.

1. Data Controller

MarOst is the data controller for personal data processed for System Quest. Google may act as a processor or service provider for Firebase-hosted data and may process certain information independently for advertising and security purposes under Google's terms.

2. Information stored locally on your device

The Application may store the following information in private application storage on your device:

These local records are used to provide the Application's core functionality. They are not uploaded to Firebase merely because you use Online Party. In particular, your goals, private notes, and reflections are not uploaded through Online Party.

3. Health Connect and step permission

System Quest may offer optional step-based quests. To support this feature, the Application may request android.permission.health.READ_STEPS through Android Health Connect.

Step data is used only to display step progress, verify progress toward optional walking or step quests, and apply related in-app progress or XP. Health Connect step data is not used for advertising, ad personalization, credit decisions, insurance decisions, or unrelated profiling.

Access is optional and begins only after you grant permission. If you decline or revoke access, the rest of System Quest remains usable, but automatic step tracking will not work. You may revoke access at any time through Health Connect or Android settings.

The Application requests only step data needed for the enabled feature. It does not request exercise sessions, exercise routes, or precise GPS location through Health Connect.

Step records are read and processed on your device. System Quest may store daily totals, quest progress, or completion results in private local storage. Health Connect step data is not uploaded to Online Party, Firebase, AdMob, or other advertising partners.

Revoking Health Connect permission stops future access but may not automatically remove step totals or quest results already saved locally. You can remove locally stored System Quest data by clearing the Application's storage or uninstalling it. Revoking System Quest's permission does not delete the original records held in Health Connect or by the app or device that created them.

4. Optional Online Party and Firebase

Online Party is optional. You can use the rest of System Quest without opening, joining, or creating an Online Party.

When you open or use Online Party, System Quest may use Firebase Authentication to create an anonymous Firebase user identifier. This identifier is a server-side identity used to authenticate the Application and control access to party data; it is not a traditional account requiring your email address or password.

To provide multiplayer party synchronization, System Quest may transmit the following information to Google Firebase:

Goals, private notes, and reflections are not uploaded to Firebase through Online Party. Health Connect step records and locally stored step totals are also not uploaded through Online Party.

Party information is visible to other members of the same party. Do not put sensitive, confidential, medical, financial, or identifying information in a party display name, party name, pact, or check-in message.

Firebase Authentication may automatically process the Firebase user ID, IP address, Firebase Android App ID, SDK and app information, and device or user-agent information. Google uses this technical information to provide authentication, maintain the service, improve compatibility, secure requests, and prevent abuse.

Google Firebase acts as a service provider or processor for the hosting, authentication, synchronization, security, and deletion capabilities used by Online Party. Firebase may use subprocessors as described in Google's documentation and contractual terms.

5. Advertising

The Application uses Google AdMob for native and rewarded advertisements. Rewarded advertisements are optional and may provide an in-app benefit after the advertisement is successfully completed.

The Application does not use banner or interstitial advertisements in this version.

Depending on your device, region, consent choices, and Google settings, the Google Mobile Ads SDK may automatically process or share:

Where required, the Application uses Google's User Messaging Platform to request or record advertising consent. You may be able to review or change advertising privacy choices through the Application's privacy choices control, Android settings, or Google account settings.

6. Purposes and legal bases

Where the General Data Protection Regulation applies, information is processed on the following legal bases:

7. Data sharing and visibility

MarOst does not sell your goals, notes, reflections, Health Connect data, or party data. Information may be disclosed or processed:

8. International transfers

Google and its subprocessors may process information outside Austria or the European Economic Area. Where the GDPR applies, transfers must rely on an applicable legal mechanism, such as an adequacy decision, Standard Contractual Clauses, or another permitted safeguard.

9. Data retention and deletion

Local Application data

Local goals, quests, notes, reflections, step totals, and progress remain on your device until you delete them in the Application, clear the Application's storage, uninstall the Application, or replace the device. Android backup or restoration features may retain or restore copies according to your device and Google settings.

Firebase Online Party data

Party data is retained while needed to operate the party and until it is removed through an in-app deletion function, the party is deleted, or MarOst completes a verified deletion request. Unless one of those events occurs, active party records may not have a fixed automatic expiry.

After a verified deletion request, MarOst aims to remove the requesting user's Firebase party profile, membership, check-in content, progress snapshot, and associated anonymous Firebase Authentication user within 30 days, unless retention is required by law, needed to investigate abuse or security incidents, or technically impossible to separate without affecting other party members. Deletion from Firebase live and backup systems may require additional time under Google's retention processes.

Firebase Authentication may retain logged IP addresses for a few weeks. After the associated Firebase user is deleted, Google states that authentication information is removed from live and backup systems within up to 180 days.

Advertising and technical data

Google retains advertising, consent, security, and diagnostic information according to its own retention policies and legal obligations. MarOst does not independently control those retention periods.

10. How to delete Online Party data

Use the DELETE ONLINE PARTY DATA control in the Application when available. If deletion cannot be completed automatically, the control opens a deletion-request email to imad.m.zahi@gmail.com.

Use the subject System Quest Online Party Data Deletion and provide:

Do not send passwords, authentication tokens, Health Connect data, private notes, or reflections. MarOst may request an additional in-app verification step before deleting data to prevent unauthorized deletion requests.

Deleting Online Party data may remove you from the party and permanently erase your synchronized party history. It does not automatically delete local goals, notes, reflections, or the original step records stored in Health Connect.

11. Your privacy choices

12. GDPR and EEA rights

If the GDPR applies to you, you may have rights of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent, subject to applicable legal conditions. Because Online Party uses an anonymous identifier, MarOst may need the Firebase user ID and party details listed above to locate your information.

You may lodge a complaint with a competent supervisory authority. In Austria, the supervisory authority is the Austrian Data Protection Authority (Datenschutzbehörde).

13. California and other U.S. state privacy rights

Residents of California and certain other U.S. states may have rights to know, access, correct, delete, or opt out of certain processing of personal information, and to receive equal service when exercising those rights. MarOst does not sell your local quest content or Firebase party data. Advertising partners may process identifiers for advertising purposes as described above.

14. Children's privacy

The Application is not directed to children under 13. In the EEA, the Application is not intended for children below the applicable age at which they may independently consent to online data processing. MarOst does not knowingly collect party information from children in violation of applicable law.

If you believe a child has provided information through Online Party, contact imad.m.zahi@gmail.com.

15. Security

Local data is stored using Android application storage. Firebase communications and Google Mobile Ads communications use encrypted network connections provided by their SDKs. Access to party data should be restricted by Firebase Authentication and Firebase Security Rules. No device, storage system, or transmission method can be guaranteed to be completely secure.

16. Third-party privacy information

17. Changes to this Privacy Policy

We may update this Privacy Policy when the Application, Online Party, third-party services, or legal requirements change. The revised policy will be posted on this page with a new effective date. Material changes may also be communicated in the Application where appropriate or legally required.

18. Contact

For questions, complaints, access requests, or deletion requests, contact:

MarOst
Graz, Styria, Austria
imad.m.zahi@gmail.com