Legal
Privacy Policy
Last updated: 19 July 2026
This Privacy Policy explains how QuestDrop AB ("Side", "we", "us") collects, uses, and shares information when you use the Side mobile application (the "App"). Side is operated from Sweden, and we act as the data controller for the personal data described below under the EU General Data Protection Regulation (GDPR).
If you have any questions, contact us at hello@side-social.com.
Note on naming: The App is published as "Side". The legal entity, certain internal identifiers, and the questdrop:// link scheme retain the "QuestDrop" name.1. Who can use Side
Side is not directed to children under 13 (or the minimum digital-consent age in your country, which is 16 in some EU member states). You must meet this minimum age to create an account. If we learn we have collected personal data from a child below the applicable age without verifiable parental consent, we will delete it. To report such an account, email hello@side-social.com.
2. Information we collect
Information you provide:
- Account information — email address, name, and username (via email, Google Sign-In, or Apple Sign-In).
- Profile content — profile photo and any biographical details you add.
- User-generated content — challenge photos and videos, captions, posts, comments, replies, and direct (chat) messages.
- Social connections — friends, friend requests, and quest invitations.
Information collected automatically:
- Location data — when you use map quests, we process your device location to show nearby quests and to attach a location to quests you create. Location access is only requested with your permission and can be revoked in iOS Settings.
- Device & push data — a Firebase Cloud Messaging (FCM) push token and device identifiers, used to deliver notifications.
- Usage & product-interaction data — in-app events (screens viewed, features used) via PostHog analytics (hosted in the EU) and Google Analytics for Firebase, used to understand and improve the App. We do not use this data for cross-app tracking or advertising, and you can turn analytics off at any time in Settings → Privacy → Share Usage Analytics (this disables both PostHog and Google Analytics).
- Crash & diagnostic data — if the App crashes, a crash report (device model, OS version, and the App's state at the time of the crash) is collected via Firebase Crashlytics so we can find and fix bugs.
Permissions we request: camera, microphone, photo library, and location. Each is requested in context and is optional — declining limits the related feature only.
3. How we use your information
- To provide and operate the App (authentication, feed, challenges, social features, chat).
- To deliver notifications you've enabled.
- To show map quests near you.
- To maintain safety — reviewing reported content and enforcing our Terms and Community Guidelines.
- To analyse and improve the App.
- To comply with legal obligations.
Legal bases (GDPR): performance of our contract with you (core app functionality); your consent (location, camera, microphone, photos, push notifications); and our legitimate interests (security, abuse prevention, crash reporting, product improvement).
4. How we share information
We do not sell your personal data. We share it only with:
- Other users — content you post (profile, posts, comments, messages) is visible to the users you share it with.
- Service providers (processors) acting on our behalf:
- Google Firebase — our database (Firestore), file storage, and server functions are hosted in the EU. Firebase Authentication, Cloud Messaging (push notifications), Crashlytics crash reporting, and Google Analytics for Firebase are global Google services that may process data in the United States.
- Google Sign-In and Apple Sign-In — authentication.
- PostHog (product analytics) — hosted in the EU.
- Legal / safety — where required by law or to protect users' rights and safety.
Where data is transferred outside the EU/EEA (e.g. Firebase Authentication or Crashlytics processing in the US), we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
5. Data retention
We keep your personal data for as long as your account is active. When you delete your account (see Section 7), we delete your profile, posts, comments, replies, chat conversations and messages, quest invitations, friend connections, uploaded images and videos (profile pictures and challenge evidence), and your analytics profile and its associated events in PostHog. Crash reports in Firebase Crashlytics are retained for 90 days and then deleted automatically. Moderation records (e.g. reports filed by or about you) may be retained for a limited period for safety and legal purposes, and backups are purged on a rolling cycle.
6. Your rights
Subject to applicable law (GDPR and others), you may:
- access the personal data we hold about you;
- correct inaccurate data (much of which you can edit in-app);
- delete your account and associated data;
- object to or restrict certain processing;
- request portability of data you provided;
- withdraw consent (e.g. revoke camera/location/notification permissions in iOS Settings).
To exercise these rights, use the in-app controls or email hello@side-social.com. You also have the right to lodge a complaint with your local supervisory authority; in Sweden this is the Integritetsskyddsmyndigheten (IMY).
7. Deleting your account
You can permanently delete your account from Settings → Delete Account in the App. This runs a server-side process that removes your data as described in Section 5. Deletion is irreversible.
8. Security
We use Firebase Authentication and access-controlled Firestore/Storage rules to protect your data. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard measures.
9. Changes to this policy
We may update this Policy. When we make material changes, we'll update the "Last updated" date and, where appropriate, ask you to re-accept within the App.
10. Contact
QuestDrop AB
Email: hello@side-social.com