Case Studies

Compare QuestWorks

How it works

FAQ

Try It Free

QUESTWORKS PRIVACY POLICY

Last Updated: March 3, 2026
Effective Date: March 3, 2026

QuestWorks Games, LLC ("QuestWorks," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered team dynamics platform (the "Platform").

Important Notice: This Privacy Policy should be read in conjunction with our Terms of Service.

1. INFORMATION WE COLLECT

1.1. Information from Slack Authentication

When you access the Platform through Slack:

  • Profile Information: Name, email address, username, profile picture
  • Workspace Information: Workspace name and affiliation
  • Authentication Tokens: Necessary for platform access and security

1.2. Voice Recordings and Transcripts

During AI interactions within QuestRooms:

  • Voice Recordings: Audio captured when you engage with AI features (only during "🎤 Listening..." moments, not continuous)
  • Transcriptions: Text conversions of your speech using speech-to-text technology
  • Interaction Timing: When and how long you interacted with AI features

IMPORTANT CLARIFICATION:

  • We record and transcribe your words during AI interactions
  • We do NOT analyze voice characteristics to create voice signatures or "voiceprints"
  • We do NOT use voice analysis to identify or verify your identity
  • Your identity is already known via Slack authentication
  • We simply transcribe what you say, not analyze how you sound

1.3. Session Content

  • AI-generated highlight videos using cartoon avatars (when avatar feature is enabled)
  • Text communications within sessions
  • Participant engagement metrics
  • Session metadata (date, time, duration, participants)

1.4. Platform Usage Data

  • Activity Logs: Features accessed, time spent, interaction patterns
  • XP and Achievements: Gamification metrics, skill development tracking
  • Performance Analytics: Completion rates, progression metrics
  • Technical Data: Device information, IP address, browser type, operating system

1.5. Avatar Data (Optional)

If you opt into avatar creation:

  • Profile Picture: Your Slack profile picture used as input for AI art generation
  • Generated Avatar: AI-created cartoon representation (using ChatGPT /images endpoint)
  • Avatar Customizations: Any modifications you make
  • Video Usage Data: Tracking of which videos include your avatar, for opt-out management

Important Note on Public Use: Videos featuring your avatar may be posted publicly on QuestWorks' social media channels for promotional purposes unless you opt out.

1.6. Communications

  • Support Requests: Content of your inquiries and our responses
  • Feedback: Surveys, testimonials, or other feedback you provide
  • Notifications: Communication preferences and delivery records

1.7. Project Management Integration Data

When your workspace admin connects a project management tool (Linear, GitHub, Jira, Asana, or Monday.com) to QuestWorks, we collect read-only aggregate metrics from those platforms:

  • Issue/Ticket Metadata: Status, creation date, completion date, and status transition timestamps (used to compute cycle time and throughput)
  • Sprint/Cycle Data: Sprint names, start/end dates, completed story points, and scope (used to compute velocity and completion rate)
  • Pull Request Metadata (GitHub only): PR creation date, merge date, and first review timestamp (used to compute PR review time)
  • Task Lifecycle Events (Asana, Monday.com): Section/status transitions, completion and reopen events, due date changes, and blocking periods (used to compute on-time rate, reopen rate, due date drift, and blocker metrics)
  • Comment Counts (Asana, Monday.com): The number of comments per task (used to compute comment density). We do not read or store comment content.

We DO NOT collect from project management tools:

  • Issue/ticket descriptions or attachments
  • Comment or discussion content (we only count comments, not read them)
  • Individual contributor names or assignments
  • Source code, commits, or file contents
  • Private messages or internal discussions

This data is used solely to calculate aggregate team metrics such as cycle time, throughput, sprint velocity, and completion rates.

1.8. Culture & Engagement Survey Integration Data

When your workspace admin connects a culture or engagement survey platform (Culture Amp, Lattice, or 15Five) to QuestWorks, we collect read-only, aggregated survey data from those platforms:

  • Aggregate Engagement Scores: Overall and category-level engagement scores, eNPS scores, and participation rates
  • Survey Themes and Questions: Survey question text, factor/theme groupings, and rating scales
  • Aggregated Response Summaries: Team-level and department-level score breakdowns, trend data across survey cycles, and areas of strength/improvement
  • Survey Metadata: Survey names, launch and close dates, survey status, and survey type (pulse, engagement, onboarding, exit)

We DO NOT collect from culture and engagement survey platforms:

  • Individual employee survey responses or how any specific person answered
  • Open-ended comment text attributable to individuals
  • Individual respondent identifiers or demographic breakdowns that could identify a specific person's answers
  • Raw response data at the individual level

This data is used solely to inform QuestWorks' Culture Thesis analysis, quest generation insights, and simulation guidelines — helping tailor team development experiences to your organization's actual culture and engagement landscape. It replaces the manual CSV survey upload process and enables automatic updates when new survey results become available.

2. HOW WE USE YOUR INFORMATION

2.1. Service Delivery

  • Authenticate and authorize your access to the Platform
  • Facilitate QuestRooms sessions and AI interactions
  • Generate personalized learning experiences and feedback
  • Calculate and display XP, achievements, and leaderboards
  • Create and animate optional character avatars
  • Enable team collaboration and communication
  • Inform Culture Thesis analysis, quest generation insights, and simulation guidelines using aggregated engagement survey data from connected platforms (Culture Amp, Lattice, 15Five)

2.1.1. AI Processing of Integration Data

When your workspace connects project management or culture/engagement tools, certain data from those integrations is sent to our AI providers (currently Google Gemini, OpenAI, and Anthropic) for analysis. Specifically:

  • Project Management Tools (Linear, GitHub, Jira, Asana, Monday.com): Aggregate metrics (cycle times, throughput, completion rates, blocker rates, sprint velocity) and sprint names are sent to AI providers for cultural analysis and quest generation. No individual issue titles, task descriptions, or employee names from these tools are sent to AI providers.
  • Culture & Engagement Survey Platforms (Culture Amp, Lattice, 15Five): Aggregate survey scores, participation rates, and goal theme summaries (aggregated word frequencies from goal titles, not individual titles) are sent to AI providers for cultural analysis. No individual survey responses are sent to AI providers.

AI providers process this data under Data Processing Agreements and are prohibited from using it to train their general-purpose models. See Section 4.1 for the full list of AI providers and Section 1.7–1.8 for details on what integration data we collect.

2.2. Platform Improvement

  • Analyze usage patterns to enhance features and functionality
  • Train and improve AI models using anonymized, aggregated data
  • Identify and fix technical issues
  • Develop new features and capabilities

2.3. Marketing and Promotional Use

  • Create highlight videos featuring gameplay moments for social media
  • Post promotional content on platforms including LinkedIn, Twitter, Instagram, TikTok, and YouTube
  • Share user success stories and achievements (with consent)
  • Promote the Platform through case studies and testimonials

Your cartoon avatar may appear in promotional videos unless you opt out. We will never use your real photo, voice recordings, or personally identifiable information in marketing without separate explicit consent.

2.4. Communications

  • Send transactional notifications about your account or sessions
  • Provide customer support and respond to your inquiries
  • Deliver platform updates and feature announcements
  • Send optional marketing communications (with your consent)

2.5. Legal Compliance

  • Respond to legal requests and regulatory requirements
  • Conduct security investigations and incident response
  • Enforce our Terms of Service and other policies
  • Protect our rights, property, and safety, and that of our users

2.6. AI Training and Model Improvement

We, and/or our third-party service providers, may use anonymized and aggregated session data, interaction patterns, and transcripts to train, improve, and develop AI models and platform functionality. Such use occurs only after removal of all personally identifiable information. Individual users cannot be re-identified from such anonymized data.

3. LEGAL BASIS FOR PROCESSING (GDPR)

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

Processing ActivityLegal BasisPlatform access and authenticationPerformance of contractVoice recording during AI interactionsConsentSpeech-to-text transcriptionPerformance of contractAvatar creationExplicit consent (optional)Promotional videos with avatarsConsent (can opt out)Service improvement and analyticsLegitimate interestMarketing communicationsConsent (optional)Legal complianceLegal obligationSecurity and fraud preventionLegitimate interest

4. HOW WE SHARE YOUR INFORMATION

4.1. Service Providers

We share personal data with trusted third-party processors who maintain industry-standard data protection practices. Data Processing Agreements are available upon request.

Authentication & Communication:

  • Slack Technologies, Inc.

AI & Language Processing:

  • OpenAI, L.P. (transcription, language generation, and image generation)
  • Google LLC (language generation via Gemini)
  • Anthropic, PBC (language generation via Claude)

Real-Time Media Infrastructure:

  • LiveKit, Inc.

Speech Recognition & Transcription:

  • Deepgram, Inc. (speech-to-text only, not voice identification)

Project Management Integrations (read-only):

  • Atlassian Corporation (Jira — issue and sprint metadata)
  • GitHub, Inc. (issue, pull request, and review metadata)
  • Linear Inc. (issue, cycle, and velocity metadata)
  • Asana, Inc. (read-only access to workspaces, projects, tasks, and task stories for productivity metrics)
  • Monday.com Ltd. (read-only access to boards, items, activity logs, and updates for productivity metrics)

Each service has its own privacy policy governing their use of your data. Project management integrations (Linear, GitHub, Jira, Asana, Monday.com) are optional and require explicit admin authorization via OAuth.

AI Processing of Integration Data: Aggregate metrics and sprint names from connected project management tools are processed by our AI providers (listed under "AI & Language Processing" above) to generate cultural insights, quest content, and simulation guidelines. No individual issue titles, task descriptions, or employee names from these tools are sent to AI providers. See Section 2.1.1 for full details.

Culture & Engagement Survey Integrations (read-only):

  • Culture Amp Pty Ltd (read-only access to aggregated engagement survey results, scores, and themes via OAuth 2.0)
  • Lattice, Inc. (read-only access to aggregated engagement survey results, eNPS scores, and performance review summaries via API key)
  • 15Five, Inc. (read-only access to aggregated engagement survey results, pulse data, and check-in summaries via API key)

Culture and engagement survey integrations are optional and require explicit admin authorization. These integrations provide read-only, aggregated data only — individual survey responses are never accessed or stored.

AI Processing of Survey Data: Aggregate survey scores, participation rates, and goal theme summaries from connected culture/engagement platforms are processed by our AI providers (listed under "AI & Language Processing" above) to inform Culture Thesis analysis and quest generation. No individual survey responses are sent to AI providers. See Section 2.1.1 for full details.

Cloud Infrastructure:

  • Render Services, Inc.

IMPORTANT DATA TRANSFER SAFEGUARDS: For transfers of personal data outside the European Economic Area (EEA), we implement appropriate safeguards including EU Standard Contractual Clauses (SCCs) where required, to ensure adequate protection for international data transfers. Enterprise customers may request copies of applicable transfer mechanisms.
‍

4.2. Employer/Organization (Enterprise Users Only)

For users accessing the Platform through an Enterprise subscription, we provide your employer/organization with:

Team-Level Metrics:

  • Team-level XP totals and trends
  • Participation rates and session attendance
  • Collective achievement progress

Individual Performance Display (Leaderboards):

  • Individual names and avatars
  • Individual XP scores and rankings
  • Specific achievements earned
  • Comparative performance metrics

AI-Generated Behavioral Insights (Admin Reports):

Our platform uses AI to analyze participation patterns during gameplay sessions and may surface the following to your employer's designated administrator:

  • Soft Skill Spotlight: Individual names paired with positive behavioral traits observed during sessions (e.g., leadership, communication, conflict resolution). These are AI-generated observations based on gameplay interactions, not formal assessments.
  • Rising Leaders: Individuals who demonstrate consistent growth in collaborative behaviors over multi-week periods. This feature tracks positive trends only and does not flag negative performance.

Important limitations on behavioral insights:

  • These features surface positive signals only — the system does not generate negative assessments, warnings, or criticism of any individual
  • Insights are derived from in-game behavior (communication patterns, collaboration, participation), not from external data
  • These are AI-generated observations intended as professional development conversation starters, not validated assessments or evaluations

Data NOT Shared with Employers:

  • Voice recordings or audio files
  • Session transcripts or detailed conversation content
  • Negative individual assessments or criticism
  • Raw AI model outputs or prompts

Important: All analytics — including behavioral insights — are intended solely for professional development and team-building purposes. QuestWorks expressly prohibits customers from using platform data for employment decisions, performance evaluations, or disciplinary actions. See our Terms of Service (Section 4.1) and Master Subscription Agreement (Section 3.4(a)) for binding restrictions.

4.3. Legal Requirements

We may disclose your information when required by law or in response to legal process, government requests, or to protect our legal rights.

4.4. Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity.

4.5. With Your Consent

We may share your information for purposes not described in this policy with your explicit consent.

4.6. Aggregated and Anonymized Data

We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you.

4.7. Public Promotional Use

Social Media and Marketing:If you have created an avatar and have not opted out, we may publicly share:

  • Videos featuring your cartoon avatar in gameplay highlights
  • Your first name or username in connection with achievements
  • Screenshots of gameplay featuring your avatar

What We DO NOT Share Publicly:

  • Your real photograph or likeness
  • Voice recordings or audio
  • Personal contact information
  • Session transcripts or detailed conversations

Platforms Where Content May Appear:

  • QuestWorks social media accounts (LinkedIn, Twitter, Instagram, TikTok, YouTube)
  • QuestWorks website and marketing materials
  • Industry presentations and case studies
  • Press releases and media coverage

How to Opt Out:Email asa@questworks.games with subject "Opt Out of Promotional Videos" to prevent future inclusion. We will remove existing videos featuring your avatar within 30 business days where technically feasible.

5. DATA SECURITY

5.1. Security Measures

We implement industry-standard technical and organizational measures:

Technical Safeguards:

  • Encryption in Transit: TLS 1.3 or higher
  • Encryption at Rest: AES-256 or equivalent
  • Access Controls: Role-based permissions and authentication
  • Network Security: Firewalls, intrusion detection, and monitoring

Organizational Safeguards:

  • Limited Access: Personal data access restricted to authorized personnel only
  • Confidentiality Agreements: All employees and contractors sign NDAs
  • Security Training: Regular training on data protection best practices
  • Vendor Management: Contractual security requirements for all processors
  • Incident Response: Documented procedures for breach detection and response

5.2. Limitations

While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security of your data.

6. DATA RETENTION

6.1. Retention Principles

We retain personal data only as long as necessary for the purposes described in this Privacy Policy or as required by law.

6.2. Retention Periods by Data Category

Data CategoryRetention PeriodDeletion MethodAccount InformationUntil account deletion or 90 days after last login (Trial Users)Permanent deletion with 30-day backup retentionVoice Recordings & Transcripts90 days (Trial); Per MSA terms (Enterprise)Permanent deletionGame Highlight Videos90 days (Trial); Per MSA terms (Enterprise); Deleted upon requestPermanent deletionXP and Achievements7 years from last account activity or until deletion requestedPermanent deletionAvatar DataUntil consent withdrawn or account deletionPermanent deletion within 30 daysSecurity Logs90 daysAutomatic deletionSupport Communications2 yearsAutomatic deletionProject Management Integration DataRetained while integration is connected; deleted immediately on disconnection; expired tokens auto-purged after 30 days; deleted within 30 days of account deletionPermanent deletionCulture & Engagement Survey Integration DataRetained while integration is connected; deleted immediately on disconnection; expired credentials auto-purged after 30 days; deleted within 30 days of account deletionPermanent deletionAnonymized AnalyticsIndefinitely (cannot be re-identified)Not applicable

6.3. Disconnecting Project Management Integrations

Workspace administrators can disconnect any project management integration at any time via the /admin productivity command in Slack. Upon disconnection:

  • All associated metric snapshots, baselines, workspace records, and sync logs are permanently deleted immediately
  • The OAuth access token is revoked where the provider supports programmatic revocation (currently Linear and Asana)
  • For providers that do not support programmatic token revocation (GitHub, Jira, Monday.com), administrators should also revoke access from the provider's own settings page
  • The connection record is removed

Connections whose OAuth tokens remain expired for more than thirty (30) days are automatically purged, including all associated data.

6.4. Disconnecting Culture & Engagement Survey Integrations

Workspace administrators can disconnect any culture or engagement survey integration at any time via the admin settings in Slack. Upon disconnection:

  • All associated aggregated survey data, Culture Thesis inputs derived from that integration, and sync logs are permanently deleted immediately
  • The OAuth token or API key is revoked where the provider supports programmatic revocation
  • The connection record is removed

Connections whose access credentials remain expired for more than thirty (30) days are automatically purged, including all associated data.

7. YOUR PRIVACY RIGHTS

7.1. Rights Under GDPR (EEA, UK, Switzerland)

If you are located in the European Economic Area, United Kingdom, or Switzerland:

  • Right of Access: Obtain confirmation and a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure: Request deletion under certain circumstances
  • Right to Restriction: Limit how we process your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File complaint with your Data Protection Authority

7.2. Rights Under CCPA (California Residents)

  • Right to Know: Request disclosure of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: We do not sell personal information
  • Right to Non-Discrimination: Not be discriminated against for exercising rights

7.3. Other State Privacy Rights

Residents of other states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah) may have similar rights.

8. HOW TO EXERCISE YOUR RIGHTS

8.1. Making a Request

Email: asa@questworks.games
Mail: QuestWorks Games, LLC, Attn: Privacy Officer, 3745 Canfield St, Unit 304, Boulder, CO 80301

8.2. Request Process

  • Acknowledgment: Within 5 business days
  • Verification: We may request additional information to verify your identity
  • Response Time: Within 45 days for GDPR/CCPA requests
  • No Fee: We do not charge for your first request

8.3. Marketing Opt-Out

To opt out of marketing communications:

  • Click "unsubscribe" in any marketing email
  • Update preferences in Account Settings
  • Email asa@questworks.games

To opt out of promotional video features:

  • Email asa@questworks.games with subject "Opt Out of Promotional Videos"
  • We will prevent future inclusion in new promotional content
  • Existing videos may be removed within 30 business days where technically feasible

9. INTERNATIONAL DATA TRANSFERS

9.1. Data Processing Location

Your personal data may be processed in the United States and other countries where our service providers operate.

9.2. Safeguards for International Transfers

We implement appropriate safeguards including:

  • EU Standard Contractual Clauses (SCCs): For transfers from the EEA
  • Additional Security Measures: Encryption, access controls, and contractual protections

9.3. Your Consent

By using the Platform, you consent to the transfer of your information to countries outside your country of residence.

10. DATA BREACH NOTIFICATION

10.1. Our Commitment

We have implemented comprehensive measures to prevent unauthorized access, use, or disclosure of personal data.

10.2. Notification Procedures

In the event of a personal data breach that poses a risk to your rights:

  • Notify Supervisory Authorities: Within 72 hours where required by law (GDPR)
  • Notify Affected Individuals: Without undue delay when required
  • Provide Details: Nature of breach, likely consequences, remedial measures

10.3. Limitation of Liability

QuestWorks' liability for any data breach shall be limited to direct damages actually incurred, not to exceed $100,000 per incident or total fees paid in the preceding 12 months, whichever is less, except where prohibited by law.

11. CHILDREN'S PRIVACY

11.1. Age Restriction

The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.

11.2. Parental Notice

If you believe we have inadvertently collected information from someone under 18, please contact us immediately at asa@questworks.games.

12. THIRD-PARTY LINKS AND SERVICES

The Platform may contain links to third-party websites or services not operated by QuestWorks. We are not responsible for the privacy practices of these third parties. We encourage you to review their policies.

13. DO NOT TRACK SIGNALS

The Platform does not currently respond to Do Not Track signals due to lack of industry standards.

14. CHANGES TO THIS PRIVACY POLICY

14.1. Right to Modify

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.

14.2. Notice of Changes

We will notify you of material changes by:

  • Posting the updated Privacy Policy with a new "Last Updated" date
  • Sending email notification
  • Displaying a prominent notice on the Platform

14.3. Continued Use

Your continued use after changes constitutes acceptance of the updated Privacy Policy.

15. DATA PROTECTION OFFICER

Our founder currently serves as interim Privacy Officer until a formal Data Protection Officer (DPO) is appointed.

Contact: Asa Reilkoff, Interim Privacy Officer
Email: asa@questworks.games
Mail: QuestWorks Games, LLC, Attn: Privacy Officer, 3745 Canfield St, Unit 304, Boulder, CO 80301

16. CONTACT INFORMATION

QuestWorks Games, LLC
3745 Canfield St, Unit 304
Boulder, CO 80301

Email: asa@questworks.games

Response Time: We aim to respond to all inquiries within 5 business days.

17. SUPERVISORY AUTHORITY CONTACT

If you are located in the EEA, UK, or Switzerland and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local Data Protection Authority.

BY USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO ITS TERMS.

‍