QuestDraft.

What we do with your data

The short version: we collect what the service needs, we send your briefs to the model providers that write with them, we do not sell anything to anybody, and where the honest answer is awkward it is written down here rather than left out.

What this covers

This policy is about personal data: what QuestDraft collects about you, why, who else sees it, and how long it stays. It is written to match what the software actually does rather than what a template would say, so where the honest answer is awkward it is written out instead of left vague.

The terms of service, which cover the scripts themselves, are a separate page.

What we collect, and why

When you sign in with Google we receive and store your verified email address and the display name on that Google account. The email is how the account is identified and how we reach you. We never receive or store your Google password, and we do not ask Google for anything beyond your email and basic profile.

If you sign in with a key instead, we store only a SHA-256 hash of that key. The key itself is shown once when it is created and is never written down by us.

When you send a campaign we store what you submit: the game, the deal description, the publisher's brief, and any notes or writing instructions you add. That is the material the script is made from, so it is kept with the campaign.

Buying coins creates a ledger row recording the amount, the coins, and the Stripe checkout session id. Card and bank details go to Stripe directly and never reach us.

Asking to be paid referral earnings in cash stores the PayPal address you type, the amount, and later the transaction reference of the payment we send. That address is kept and shown back to you so a second request does not have to be typed again. It is the only way of paying somebody that we store, and we store it only for accounts that have asked to be paid.

We do not record visitor IP addresses. The application never sees one.

YouTube, and the other platforms

QuestDraft uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service at https://www.youtube.com/t/terms, and Google's own privacy policy at https://policies.google.com/privacy explains how Google handles your data on their side.

When you connect a YouTube channel, the access token Google issues is used for a single request, in the moment, and is never stored. We do not ask Google for a refresh token at all, so we hold nothing that could read your account later. What we keep from that request is your channel id, your handle, your channel title, and when it was verified. That is what proves the channel is yours, and the paragraph below says what we then do with it.

Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We use the channel id, handle and title to confirm which channel is yours, and then to name your account. Your channel title becomes the name on your profile and on the creator rankings, with your @handle under it, until you switch the rankings off in settings. We also use the handle to look up your channel's public figures for your own Insights page. We do not sell or transfer them, we do not use them for advertising, and we never send the channel details we receive from Google to an AI model provider. A studio administrator can read your profile, including these details, and can also link your account to a channel on your behalf. That is the same access they have to the rest of your profile.

Everything else we show about a channel comes from YouTube's public data using our own API key, not from your grant. Recent video titles, links and their public view, like and comment counts are cached for about a day. Channel art is copied and kept for about a week before it is fetched again.

None of that channel data is sent to any AI model provider, and none of it is used to train or improve any model.

TikTok and Instagram cannot be connected at the moment. They work differently and you should know the difference, because a connection made earlier still holds. Those platforms only give up their numbers to a stored token, so a connection to them stores their access token, and TikTok's refresh token, in our database. They are not encrypted at rest. They are never sent to your browser and never shared. Disconnecting deletes them from our database, though it does not withdraw the grant on the platform's own side, which you can do in that platform's settings.

You can withdraw Google's permission at any time at https://security.google.com/settings/security/permissions, which opens your Google account permissions page. Doing that stops any future access immediately.

One precise note, because the simple version would be untrue. Disconnecting a YouTube channel in QuestDraft clears the verified channel details and deletes the cached channel art, but the channel link on your profile and a nickname taken from the channel title remain until you change them. If you want those gone as well, ask us and we will remove them.

What we send to other companies

Writing a script means sending text to a model provider. The brief, your notes and your writing instructions go to DeepSeek, and to Moonshot if the alternative drafting engine is switched on, as part of the prompt. Research queries built partly from your text go to Tavily. Your name, your email, your channel identity and your balance are not included in any of those requests, but anything personal you type into a brief travels with the brief, so it is worth not putting personal details in one.

Those providers handle that text under their own terms. We do not train anything on your briefs, and we ask you to read that sentence precisely: it is a statement about us, not a guarantee about them.

Stripe receives your username and the amount when you buy coins. Cloudflare carries the traffic to the site.

PayPal receives the address you gave us and the amount when we pay out referral earnings in cash. The payment is made by hand, so nothing is fed to PayPal automatically: the address and the amount go across at the moment we pay you, and nothing else does.

There is no analytics, no advertising network, no tracking pixel and no third party script anywhere on this site. Every page it serves is self-contained. We do not sell personal data and never have.

Who can see your work

Other creators cannot see your campaigns, your briefs, your scripts, your email or your balance. What they can see, if you leave the rankings on, is your display name and handle, your channel avatar, a title and any medals, and your scores. One toggle in settings takes you off every board.

If somebody's code brought you here, they can see how many of the creators they invited are spending and what they have earned from it. With one invite that is enough to work out roughly what you spend. They never see your campaigns, your briefs, your scripts, your email or your balance, and this page never names your games to them.

Studio administrators can read every campaign and can open a read-only view of any account, including its settings and coin history. That access exists to run the service and support it. We would rather say so than let you discover it.

How long we keep things

Account details, campaigns, briefs, research and drafts are kept for as long as the account exists, because that is what makes your dashboard work. None of it is deleted on a timer today. A referral share running out is a rule about money and not about data: the ledger row saying it ran out is kept like every other one.

The coin ledger is append-only by design, so a correction is a new row rather than an edit. Money history cannot be erased, and that carve-out applies to any deletion request. Cash-out records are kept under the same carve-out, including the PayPal address on them, because they are payment records we have to be able to account for. Those records are not append-only: answering a request updates the row in place with the outcome, the date and the transaction reference.

Operational logs record errors, sign-in failures and payment events, and some of those lines name an account. A local record of what each provider call cost keeps the account name and a short fragment of the research query, never the script text.

Backups are taken every few days to an offline drive and currently have no expiry, so material removed from the live service can persist in an archive. We are telling you because a deletion promise that ignores backups is not a real promise.

Getting your data, or getting rid of it

There is no self-service delete button in the product yet. To see what we hold, to correct it, to get a copy, or to have it removed, email us and say what you want. We may ask you to confirm the request from the address on the account, so that nobody can delete your work by asking nicely.

If you withdraw permission through QuestDraft or ask us to delete data we obtained from Google, we will remove it within 7 days. If you withdraw it through Google's own permissions page, we will remove it within 30 days. Removing data here does not touch anything held by YouTube or Google, which you manage in your Google account.

Two things survive any request, and both are legal obligations rather than preferences: the coin ledger, and records we have to keep for tax and payment purposes.

Depending on where you live you may have rights to access, correct, delete, restrict or object to how your data is used, to receive it in a portable form, and to complain to your local data protection authority. Exercising any of them starts with the same email, and using them will never cost you the service or the price.

We do not sell or share personal information for advertising, so there is nothing to opt out of on that front.

Where your data goes, and on what basis

QuestDraft runs from one location and its providers operate internationally, so your data will be processed in countries other than your own, including the United States and China, under the terms those providers publish.

We process your account details to provide the service you asked for, your payment records because the law requires us to keep them, and operational logs because we have a legitimate interest in a service that stays up and is not abused. Connecting a platform is always your choice, and withdrawing it is always available to you.

How it is protected

Traffic to the site is encrypted in transit. Sign-in cookies are first-party, HttpOnly, functional only, and carry no advertising or third-party trackers. Access to the server is restricted to the operator.

Being straight about the limits: the database is not encrypted at rest, and the stored TikTok and Instagram tokens sit inside it. Sessions last 90 days and signing out clears the cookie in that browser rather than everywhere at once. If you think an account is compromised, email us and we will invalidate every session on it.

Children

QuestDraft is a business tool for creators taking paid sponsorships and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child has an account here, tell us and we will remove it.

Changes

If we change what data we collect or what we do with it, we will update this page and, where the change is significant, ask for your agreement again rather than treating silence as consent.

Who is asking

Service: QuestDraft

Operated by: Abdulrahman Hashim

Privacy contact: questdraft@yahoo.com