Privacy Policy

1. Three kinds of people this covers

Messaging.Quest holds data about three groups, and it helps to keep them separate:

2. What we collect and why

Account data — your email address and sign-in details, so we can create your account and authenticate you. Legal basis: performance of our contract with you.

Billing data — your plan and payment status. Card details are entered directly with Stripe and are never stored on our servers. Legal basis: contract and our legitimate interest in getting paid.

Campaign data you create — your company description, target criteria, contact lists, and the messages you approve. Legal basis: contract (to provide the service).

Contact data our agents find — a public work email, name/role, employer, website, and the public evidence for why the contact matches your product. We verify each address before it can be used. Legal basis: the legitimate interest of you and Messaging.Quest in relevant B2B outreach, balanced against the contact’s rights (see section 8 for how a contact can object or be removed).

Usage and analytics — how the app is used, so we can improve it. Analytics cookies (PostHog) are on by default and you can turn them off anytime; see our Cookie Policy. Legal basis: our legitimate interest in improving the product, which you can object to at any time.

Support and messages — anything you send us (for example feedback or bug reports). Legal basis: our legitimate interest in running and supporting the service.

3. How communities get read

Two things read public communities for you, and which one depends entirely on whether a place needs to know who you are.

Your browser reads anything that needs your session. The Messaging.Quest browser extension is optional and runs in your own Chrome. Reddit, and anywhere else that answers only a signed-in reader, is read there — with your session, from your own address. We never hold a cookie or a login for any platform.

Our server reads what any reader may read. Public feeds that a logged-out stranger can fetch — Discourse forums, Hacker News, RSS and Atom feeds — are read by us directly, on a schedule, so monitoring carries on when your laptop is shut and you can be told when something lands. Those requests carry no credentials and identify themselves as ours.

Nothing is ever posted for you, by either of them. Every reply is put in front of you and waits for your click — that has not changed and will not.

What the extension sends us. Public thread content from the places you approve (posts, comments, titles and links); the visible text, title and address of a page you explicitly ask about with “Draft a reply on this page”; the final reply text you confirm having posted; and, when your browser later revisits that thread, its public reception — votes, reply counts, whether the author answered you, and whether the reply was removed. Legal basis: performance of our contract with you.

Handles of people you answer. We store the public username and profile link of the person whose thread you replied to. That is what lets us keep two promises: never putting someone in front of you again after they asked to be left alone, and telling you when you have already written to this person. Legal basis: the legitimate interest, yours and theirs, in not being contacted twice or against their wishes.

Private messages. On-page drafting works on whatever page you choose, and that can include a private message thread. If you click Draft there, that page’s text is sent for drafting exactly like any other page. We never open or read a private conversation on our own — only the page you clicked on, at the moment you clicked it.

What the extension never collects. Your passwords, cookies or session tokens for any platform — those stay in Chrome and only in Chrome, and our servers could not read them if we wanted to. Nor your browsing history, your clicks, keystrokes or mouse movement, or your location. Inside the browser it stores only your pairing code, the server address, and which version of your writing style you have already been shown.

Where it goes and how long we keep it. Thread text is stored in our database and read by the drafting agent (Fly.io, OpenAI) so it can judge whether you are an honest answer and write the reply. The pre-selection buffer is deleted 7 days after a decision and its content is cleared after 14 days regardless; replies you confirmed posting remain in your activity history while your account is open.

Permissions. The extension installs with access to no site at all. Each place you watch is a single Chrome permission you grant in the moment, and you can revoke any of them at any time from Chrome’s extension settings.

4. Cookies

We use a small set of essential cookies to run the app, plus analytics cookies that are on by default and that you can turn off anytime. The full list is in the Cookie Policy, and you can change your choice anytime from “Cookie settings” in the footer.

5. Who we share data with

We do not sell your data or share it for advertising. We share it only with the service providers (sub-processors) that make Messaging.Quest work, each under a data processing agreement and only for the purpose shown:

ProviderWhat they do for us
SupabaseDatabase, authentication, and file storage (EU region)
CloudflareThe human check on the sign-in form (Turnstile) — it sees the browser, not the address you type
VercelApplication hosting and content delivery
Fly.ioCompute for the research, judging and drafting agents
StripeSubscription billing and payment processing
SendGrid / ResendSending your campaign email and receiving replies
SpaceshipRegistering your sending domains
MillionVerifierChecking whether an email address is deliverable
OpenAIThe agents that research companies, judge forum threads, and draft replies
OpenRouterAI models that draft message copy and domain-name ideas
PostHogProduct analytics (EU region) — on by default, can be turned off

We may also disclose data where the law requires it, or to protect our rights, users, or the public.

6. International transfers

We host your core data (database, authentication, analytics) in the EU. Some providers may process data outside the EU/EEA; where they do, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. How long we keep it

We keep account and campaign data while your account is active and for as long as needed to provide the service, meet legal and accounting obligations, and resolve disputes. When you delete data or close your account, we delete or anonymise it within a reasonable period, except where we must retain some records (for example billing records). Suppression records (people who opted out) are kept so we can keep honouring the opt-out.

8. If you were contacted through Messaging.Quest

If you received a message sent through Messaging.Quest and want to be removed, use the one-click unsubscribe link in the email, or email hello@messaging.quest. We add you to a suppression list so you are not contacted again through our platform, and we can pass your request to the sender. You also have the rights in section 9, including the right to object to this processing.

9. Your rights

Under the GDPR you can ask to access, correct, delete, or export your personal data, and restrict or object to processing — including turning analytics off — at any time; this won’t affect processing done before you objected. To exercise any of these, email hello@messaging.quest. You also have the right to complain to your local data protection authority.

10. Children

Messaging.Quest is a business tool and is not intended for anyone under 18. We don’t knowingly collect data from children.

11. Changes

We’ll update this policy as the product and law change and will note the date above. If a change is material we’ll give reasonable notice.

12. Contact

For any privacy question or request, email hello@messaging.quest.