Privacy Policy
Last updated: March 2026
Solo Project — No Formal Compliance
This policy is written in good faith by a single developer, not a legal team. The Creator collects minimal data and does not profit from it. If you need GDPR or CCPA-certified compliance, this Service is not the right fit.
1. Who We Are (And Are Not)
SpeciesQuest is operated by a single individual as a personal hobby project. There is no company, no organisation, no data protection officer, and no commercial entity behind this Service. References to "we," "us," or "our" in this policy refer solely to that individual. This is not a GDPR-compliant data processor in any formal sense. This privacy policy is provided in good faith as a best-effort disclosure, not as a legal compliance document prepared by lawyers.
2. What Data We Collect
We collect only what is strictly necessary to run the Service: • Email address — required for account creation and authentication • Username — chosen by you, displayed publicly in rankings • Gameplay data — your species genome, population stats, tile positions, and in-game actions • Technical data — IP address, browser type, and session metadata collected automatically by our authentication and hosting infrastructure (Supabase) We do not collect payment information (the Service is free). We do not collect real names, phone numbers, addresses, or any sensitive personal data.
3. How We Use Your Data
Your data is used solely to operate the game: • To authenticate your account and maintain your session • To run the simulation and track your species • To display rankings and leaderboards • To detect and prevent abuse We do not use your data for advertising, profiling, marketing, or any commercial purpose. We do not sell your data. We do not share your data with third parties except as described in section 4.
4. Third-Party Services
The Service is built on Supabase (database and authentication infrastructure). By using SpeciesQuest, your data is also subject to Supabase's own privacy policy and terms of service. We have no control over Supabase's data handling practices. The Creator has not negotiated data processing agreements with Supabase and cannot guarantee GDPR or CCPA compliance at the infrastructure level. Use of this Service constitutes acceptance of this limitation.
5. Data Retention
Your data is retained for as long as your account exists or as long as the Service is operational. If you request account deletion, the Creator will make a reasonable effort to delete your personal data within a reasonable timeframe — however, no specific timeline is guaranteed, and residual data may remain in backups or logs. If the Service is shut down, data may simply be deleted without any prior export opportunity.
6. Data Security
The Creator takes reasonable steps to protect your data, including use of TLS encryption (provided by Supabase and hosting infrastructure) and hashed password storage. However, no internet-based system is completely secure. The Creator cannot guarantee that your data will never be accessed by unauthorised parties. In the event of a breach, the Creator will make a reasonable effort to notify affected users but provides no guarantee of timely or complete notification.
7. Your Rights (Best-Effort Basis)
Depending on your location, you may have rights under applicable law to access, correct, or delete your personal data. The Creator will make a reasonable, good-faith effort to honour such requests when contacted. However, as this is a solo hobby project with no legal team or formal compliance programme, no specific response time is guaranteed and no formal appeals process exists. To request data access or deletion, contact: contact@speciesquest.io
8. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If the Creator becomes aware that a child under 13 has registered, the account will be deleted. If you believe a child under 13 has submitted data, contact: contact@speciesquest.io
9. Cookies
The Service uses cookies primarily for authentication session management. See the Cookie Policy for details. The Creator does not operate a consent management platform. Essential authentication cookies are set automatically upon login.
10. International Data Transfers
By using this Service, your data may be stored and processed in any country where Supabase or the hosting provider operates infrastructure. If you are located in the EU, EEA, or UK, be aware that your data may be transferred to countries that do not have data protection laws equivalent to those of your jurisdiction. No standard contractual clauses, adequacy decisions, or other transfer mechanisms have been formally implemented. Use of the Service constitutes informed consent to this.
11. Changes to This Policy
The Creator may update this Privacy Policy at any time without prior notice. The "Last updated" date will reflect when the most recent change was made. Continued use of the Service after changes constitutes acceptance of the revised policy. If you object to any change, your only recourse is to stop using the Service and delete your account.
12. Honest Disclaimer
This privacy policy was written by a solo developer, not a lawyer. It is intended to be honest and transparent, not legally exhaustive. If you require a service with formal GDPR compliance, a data protection officer, or certified security practices, this Service is not appropriate for you.