Privacy Policy
Last updated: July 30, 2026
Short version: we collect what we need to teach you, keep the platform safe, and process your payments — nothing to sell to advertisers. Here is exactly what that means, and the rights you have over your data.
01Scope
This policy explains how ShellQuest (“we”, “us”) handles personal data when you use shellquest.dev. We are the data controller for that data. It applies to the marketing site, the learning platform, and the in-app mentor.
02What we collect
You give us
- Account data — your email address and a password (stored only as a salted hash), plus an optional display handle.
- Content you create — notes, answers, and messages you send to the in-app mentor.
Created as you use the platform
- Learning activity — missions attempted and solved, XP, ranks, streaks, timing, and hints used. This is the raw material for your progress and readiness scores.
- Sandbox activity — commands and output within your training container, used to run the mission, power the mentor, and keep the platform safe.
Collected automatically
- Technical data — IP address, browser and device type, and basic logs, used for security, abuse prevention, and reliability.
- Essential cookies — see Cookies.
We do not collect or store your payment-card details. Payments are handled by Paddle (see Who we share with).
03How we use your data
- To provide the platform: run sandboxes, track progress, issue certifications, and compute readiness scores.
- To operate the in-app mentor and improve your learning experience.
- To keep the service secure — detecting abuse, sandbox misuse, and fraud.
- To communicate with you about your account and important service changes.
- To understand aggregate usage so we can improve the curriculum. We never sell your data.
04Legal bases
Where the GDPR or similar laws apply, we rely on: contract (to deliver the service you signed up for), legitimate interests (security, abuse prevention, and improving the product), consent (where we ask for it, such as optional communications), and legal obligation (when the law requires us to retain or disclose data).
06AI processing
The in-app mentor sends the context it needs — your message and a snapshot of your current training session — to our model provider to produce a helpful answer. Do not paste real secrets, personal data of others, or confidential information into the mentor. We do not use your private mentor conversations to train third-party foundation models beyond what is needed to answer you.
08Data retention
We keep your account and learning data for as long as your account is active. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain some records to meet legal, security, or accounting obligations. Sandbox containers are ephemeral and are destroyed after your session ends.
09Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email support@shellquest.dev. You also have the right to complain to your local data-protection authority.
10Security
We protect your data with encryption in transit, hashed passwords, least-privilege access, isolated per-player sandboxes with no network access, and audit logging. No system is perfectly secure, but security is core to what we build and how we operate.
11Children
ShellQuest is not intended for children under 16 (or the age of digital consent where you live). We do not knowingly collect data from them. If you believe a child has given us data, contact us and we will remove it.
12International transfers
We and our processors may handle data in countries other than yours. Where we transfer personal data internationally, we rely on appropriate safeguards (such as standard contractual clauses) to protect it.
13Changes to this policy
We may update this policy as the platform evolves. We will change the date at the top and, for material changes, notify you where appropriate.
Questions about this document? Email support@shellquest.dev or reach us through the in-app community.