QUESTWORKS PRIVACY POLICY
Last Updated: October 11, 2025
Effective Date: October 11, 2025
QuestWorks Games, LLC ("QuestWorks," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered gamified professional development platform (the "Platform").
Important Notice: This Privacy Policy should be read in conjunction with our Terms of Service.
1. INFORMATION WE COLLECT
1.1. Information from Slack Authentication
When you access the Platform through Slack:
- Profile Information: Name, email address, username, profile picture
- Workspace Information: Workspace name and affiliation
- Authentication Tokens: Necessary for platform access and security
1.2. Voice Recordings and Transcripts
During AI interactions within QuestRooms:
- Voice Recordings: Audio captured when you engage with AI features (only during "🎤 Listening..." moments, not continuous)
- Transcriptions: Text conversions of your speech using speech-to-text technology
- Interaction Timing: When and how long you interacted with AI features
IMPORTANT CLARIFICATION:
- We record and transcribe your words during AI interactions
- We do NOT analyze voice characteristics to create voice signatures or "voiceprints"
- We do NOT use voice analysis to identify or verify your identity
- Your identity is already known via Slack authentication
- We simply transcribe what you say, not analyze how you sound
1.3. Session Content
- AI-generated highlight videos using cartoon avatars (when avatar feature is enabled)
- Text communications within sessions
- Participant engagement metrics
- Session metadata (date, time, duration, participants)
1.4. Platform Usage Data
- Activity Logs: Features accessed, time spent, interaction patterns
- XP and Achievements: Gamification metrics, skill development tracking
- Performance Analytics: Completion rates, progression metrics
- Technical Data: Device information, IP address, browser type, operating system
1.5. Avatar Data (Optional)
If you opt into avatar creation:
- Profile Picture: Your Slack profile picture used as input for AI art generation
- Generated Avatar: AI-created cartoon representation (using ChatGPT /images endpoint)
- Avatar Customizations: Any modifications you make
- Video Usage Data: Tracking of which videos include your avatar, for opt-out management
Important Note on Public Use: Videos featuring your avatar may be posted publicly on QuestWorks' social media channels for promotional purposes unless you opt out.
1.6. Communications
- Support Requests: Content of your inquiries and our responses
- Feedback: Surveys, testimonials, or other feedback you provide
- Notifications: Communication preferences and delivery records
2. HOW WE USE YOUR INFORMATION
2.1. Service Delivery
- Authenticate and authorize your access to the Platform
- Facilitate QuestRooms sessions and AI interactions
- Generate personalized learning experiences and feedback
- Calculate and display XP, achievements, and leaderboards
- Create and animate optional character avatars
- Enable team collaboration and communication
2.2. Platform Improvement
- Analyze usage patterns to enhance features and functionality
- Train and improve AI models using anonymized, aggregated data
- Identify and fix technical issues
- Develop new features and capabilities
2.3. Marketing and Promotional Use
- Create highlight videos featuring gameplay moments for social media
- Post promotional content on platforms including LinkedIn, Twitter, Instagram, TikTok, and YouTube
- Share user success stories and achievements (with consent)
- Promote the Platform through case studies and testimonials
Your cartoon avatar may appear in promotional videos unless you opt out. We will never use your real photo, voice recordings, or personally identifiable information in marketing without separate explicit consent.
2.4. Communications
- Send transactional notifications about your account or sessions
- Provide customer support and respond to your inquiries
- Deliver platform updates and feature announcements
- Send optional marketing communications (with your consent)
2.5. Legal Compliance
- Respond to legal requests and regulatory requirements
- Conduct security investigations and incident response
- Enforce our Terms of Service and other policies
- Protect our rights, property, and safety, and that of our users
2.6. AI Training and Model Improvement
We, and/or our third-party service providers, may use anonymized and aggregated session data, interaction patterns, and transcripts to train, improve, and develop AI models and platform functionality. Such use occurs only after removal of all personally identifiable information. Individual users cannot be re-identified from such anonymized data.
3. LEGAL BASIS FOR PROCESSING (GDPR)
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
Processing ActivityLegal BasisPlatform access and authenticationPerformance of contractVoice recording during AI interactionsConsentSpeech-to-text transcriptionPerformance of contractAvatar creationExplicit consent (optional)Promotional videos with avatarsConsent (can opt out)Service improvement and analyticsLegitimate interestMarketing communicationsConsent (optional)Legal complianceLegal obligationSecurity and fraud preventionLegitimate interest
4. HOW WE SHARE YOUR INFORMATION
4.1. Service Providers
We share personal data with trusted third-party processors who maintain industry-standard data protection practices. Data Processing Agreements are available upon request.
Authentication & Communication:
AI & Language Processing:
- OpenAI, L.P. (transcription and AI generation)
Real-Time Media Infrastructure:
Speech Recognition & Transcription:
- Deepgram, Inc. (speech-to-text only, not voice identification)
Database Infrastructure:
Cloud Infrastructure:
For customers subject to GDPR, QuestWorks will execute appropriate data transfer mechanisms including Standard Contractual Clauses as required.
4.2. Employer/Organization (Enterprise Users Only)
For users accessing the Platform through an Enterprise subscription, we provide your employer/organization with:
Team-Level Metrics:
- Team-level XP totals and trends
- Participation rates and session attendance
- Collective achievement progress
Individual Performance Display (Leaderboards):
- Individual names and avatars
- Individual XP scores and rankings
- Specific achievements earned
- Comparative performance metrics
Data NOT Shared with Employers:
- Voice recordings or audio files
- Session transcripts or detailed conversation content
- Individual AI feedback or recommendations
Important: These analytics are intended solely for professional development and team-building purposes. QuestWorks expressly prohibits customers from using platform data for employment decisions, performance evaluations, or disciplinary actions.
4.3. Legal Requirements
We may disclose your information when required by law or in response to legal process, government requests, or to protect our legal rights.
4.4. Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity.
4.5. With Your Consent
We may share your information for purposes not described in this policy with your explicit consent.
4.6. Aggregated and Anonymized Data
We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you.
4.7. Public Promotional Use
Social Media and Marketing:If you have created an avatar and have not opted out, we may publicly share:
- Videos featuring your cartoon avatar in gameplay highlights
- Your first name or username in connection with achievements
- Screenshots of gameplay featuring your avatar
What We DO NOT Share Publicly:
- Your real photograph or likeness
- Voice recordings or audio
- Personal contact information
- Session transcripts or detailed conversations
Platforms Where Content May Appear:
- QuestWorks social media accounts (LinkedIn, Twitter, Instagram, TikTok, YouTube)
- QuestWorks website and marketing materials
- Industry presentations and case studies
- Press releases and media coverage
How to Opt Out:Email marketing@questworks.games with subject "Opt Out of Promotional Videos" to prevent future inclusion. We will remove existing videos featuring your avatar within 30 business days where technically feasible.
5. DATA SECURITY
5.1. Security Measures
We implement industry-standard technical and organizational measures:
Technical Safeguards:
- Encryption in Transit: TLS 1.3 or higher
- Encryption at Rest: AES-256 or equivalent
- Access Controls: Role-based permissions and authentication
- Network Security: Firewalls, intrusion detection, and monitoring
Organizational Safeguards:
- Limited Access: Personal data access restricted to authorized personnel only
- Confidentiality Agreements: All employees and contractors sign NDAs
- Security Training: Regular training on data protection best practices
- Vendor Management: Contractual security requirements for all processors
- Incident Response: Documented procedures for breach detection and response
5.2. Limitations
While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security of your data.
6. DATA RETENTION
6.1. Retention Principles
We retain personal data only as long as necessary for the purposes described in this Privacy Policy or as required by law.
6.2. Retention Periods by Data Category
Data CategoryRetention PeriodDeletion MethodAccount InformationUntil account deletion or 90 days after last login (Trial Users)Permanent deletion with 30-day backup retentionVoice Recordings & Transcripts90 days (Trial); Per MSA terms (Enterprise)Permanent deletionGame Highlight Videos90 days (Trial); Per MSA terms (Enterprise); Deleted upon requestPermanent deletionXP and Achievements7 years from last account activity or until deletion requestedPermanent deletionAvatar DataUntil consent withdrawn or account deletionPermanent deletion within 30 daysSecurity Logs90 daysAutomatic deletionSupport Communications2 yearsAutomatic deletionAnonymized AnalyticsIndefinitely (cannot be re-identified)Not applicable
7. YOUR PRIVACY RIGHTS
7.1. Rights Under GDPR (EEA, UK, Switzerland)
If you are located in the European Economic Area, United Kingdom, or Switzerland:
- Right of Access: Obtain confirmation and a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure: Request deletion under certain circumstances
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: File complaint with your Data Protection Authority
7.2. Rights Under CCPA (California Residents)
- Right to Know: Request disclosure of personal information collected
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: We do not sell personal information
- Right to Non-Discrimination: Not be discriminated against for exercising rights
7.3. Other State Privacy Rights
Residents of other states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah) may have similar rights.
8. HOW TO EXERCISE YOUR RIGHTS
8.1. Making a Request
Email: privacy@questworks.games
Mail: QuestWorks Games, LLC, Attn: Privacy Officer, 3745 Canfield St, Unit 304, Boulder, CO 80301
8.2. Request Process
- Acknowledgment: Within 5 business days
- Verification: We may request additional information to verify your identity
- Response Time: Within 45 days for GDPR/CCPA requests
- No Fee: We do not charge for your first request
8.3. Marketing Opt-Out
To opt out of marketing communications:
- Click "unsubscribe" in any marketing email
- Update preferences in Account Settings
- Email privacy@questworks.games
To opt out of promotional video features:
- Email marketing@questworks.games with subject "Opt Out of Promotional Videos"
- We will prevent future inclusion in new promotional content
- Existing videos may be removed within 30 business days where technically feasible
9. INTERNATIONAL DATA TRANSFERS
9.1. Data Processing Location
Your personal data may be processed in the United States and other countries where our service providers operate.
9.2. Safeguards for International Transfers
We implement appropriate safeguards including:
- EU Standard Contractual Clauses (SCCs): For transfers from the EEA
- Additional Security Measures: Encryption, access controls, and contractual protections
9.3. Your Consent
By using the Platform, you consent to the transfer of your information to countries outside your country of residence.
10. DATA BREACH NOTIFICATION
10.1. Our Commitment
We have implemented comprehensive measures to prevent unauthorized access, use, or disclosure of personal data.
10.2. Notification Procedures
In the event of a personal data breach that poses a risk to your rights:
- Notify Supervisory Authorities: Within 72 hours where required by law (GDPR)
- Notify Affected Individuals: Without undue delay when required
- Provide Details: Nature of breach, likely consequences, remedial measures
10.3. Limitation of Liability
QuestWorks' liability for any data breach shall be limited to direct damages actually incurred, not to exceed $100,000 per incident or total fees paid in the preceding 12 months, whichever is less, except where prohibited by law.
11. CHILDREN'S PRIVACY
11.1. Age Restriction
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.
11.2. Parental Notice
If you believe we have inadvertently collected information from someone under 18, please contact us immediately at privacy@questworks.games.
12. THIRD-PARTY LINKS AND SERVICES
The Platform may contain links to third-party websites or services not operated by QuestWorks. We are not responsible for the privacy practices of these third parties. We encourage you to review their policies.
13. DO NOT TRACK SIGNALS
The Platform does not currently respond to Do Not Track signals due to lack of industry standards.
14. CHANGES TO THIS PRIVACY POLICY
14.1. Right to Modify
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.
14.2. Notice of Changes
We will notify you of material changes by:
- Posting the updated Privacy Policy with a new "Last Updated" date
- Sending email notification
- Displaying a prominent notice on the Platform
14.3. Continued Use
Your continued use after changes constitutes acceptance of the updated Privacy Policy.
15. DATA PROTECTION OFFICER
Our founder currently serves as interim Privacy Officer until a formal Data Protection Officer (DPO) is appointed.
Contact: Asa Reilkoff, Interim Privacy Officer
Email: privacy@questworks.games
Mail: QuestWorks Games, LLC, Attn: Privacy Officer, 3745 Canfield St, Unit 304, Boulder, CO 80301
16. CONTACT INFORMATION
QuestWorks Games, LLC
3745 Canfield St, Unit 304
Boulder, CO 80301
Email Contacts:
- Privacy inquiries: privacy@questworks.games
- Opt out of promotional videos: marketing@questworks.games
- Support: support@questworks.games
- Legal: legal@questworks.games
- Accessibility: accessibility@questworks.games
Response Time: We aim to respond to all inquiries within 5 business days.
17. SUPERVISORY AUTHORITY CONTACT
If you are located in the EEA, UK, or Switzerland and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local Data Protection Authority.
BY USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO ITS TERMS.