QuestLife: Privacy Policy
The short version. QuestLife collects nothing. There are no accounts, no analytics, no advertising, and no third-party SDKs. Everything you enter stays in the storage of the device you entered it on. Nothing is transmitted anywhere unless an administrator at your organization explicitly configures a CoreTrack Nexus sync endpoint, which is off by default.
What the app stores, and where
- On your device only. Resident initials, avatar choices, ISP goal titles, session records (date, support level, XP, staff initials, optional note), staff initials and points, and route neighbor entries.
- Uploaded avatar photos are held in a separate device-local storage area. They are excluded from every export, from the Save File feature, and from sync. They cannot leave the device through the app.
- Access PINs are stored as a salted hash, never as the PIN itself, in a device-local settings area that is never exported or transmitted.
- A CoreTrack API key, if an administrator enters one, stays in that same settings area and is never exported or included in any file the app produces.
What we never collect
- No names. Residents and staff are identified by 2–3 letter initials, enforced at every entry point including data import.
- No accounts, email addresses, phone numbers, or device identifiers sent anywhere.
- No analytics, crash reporting, telemetry, advertising identifiers, or tracking of any kind.
- No location data. The route map is a stylized illustration, not a real map, and uses no location services.
Optional sync (off by default)
An administrator may configure a CoreTrack Nexus endpoint belonging to their own organization. When enabled, the app sends session records (initials, goal titles, support levels, dates, XP, and any note) to that endpoint over HTTPS with an organization-supplied API key. Route neighbor names and addresses, avatar photos, PINs, and the API key itself are never included. Turning sync on is a deliberate administrator action; it never happens automatically.
Compliance framing, stated plainly. QuestLife is designed to support HIPAA compliance: device-local, de-identified-leaning data, sync off by default. Software cannot be HIPAA compliant on its own; organizations comply. Initials are not Safe Harbor de-identification: in a small group home, initials plus goal data can identify a person to anyone with context. Treat all QuestLife data as PHI-adjacent and apply your usual safeguards. Many adult residential facility operators are not HIPAA covered entities, but California CMIA and Title 22 confidentiality still apply, which is why these safeguards are unconditional rather than gated on coverage.
Device security is your safeguard
Because data is stored on the device, the device is the perimeter. On first run QuestLife asks an administrator to acknowledge four conditions: the device requires a passcode, PIN, or biometric to unlock; full-device encryption is enabled; auto-lock is set to five minutes or less; and the device stays in the facility control, with loss reported within one business day. That acknowledgment is date-stamped and stored on the device only. In-app PINs deter casual access on a shared tablet; they are not encryption.
Children
QuestLife is a staff documentation tool used by adult direct-support professionals. It is not directed at children and is not distributed to consumers. Records may concern children receiving services, which is exactly why the initials-only design exists.
Your data, your control
- Export everything at any time as JSON or CSV from inside the app.
- Reset wipes all app data, including avatar photos, from the device.
- Uninstalling the app removes its storage.
- Because we hold nothing, there is no server-side copy to request or delete.
Changes
If this policy changes, the updated version is published at this URL and shipped with the app release it applies to.
Contact
QualiCore Consulting LLC. Questions about this policy or about deploying QuestLife in a licensed facility can be directed to your QualiCore account contact.