Privacy Policy
This policy explains what personal data Messaging.Quest (Messaging Quest) collects, why, who we share it with, and the rights you have. We are the data controller for the data described here. Questions or requests: hello@messaging.quest.
1. Three kinds of people this covers
Messaging.Quest holds data about three groups, and it helps to keep them separate:
- Our customers — the people who sign up and run campaigns. That is data you give us to open and run your account.
- Business contacts in a campaign — the people our agents find from public sources so you can reach out to them. This is always business contact information at companies (a work email and role), never consumer profiles.
- People you answer in public communities — when you use the browser extension, we keep the public handle of whoever wrote the thread you replied to, so the opt-out and already-contacted promises can hold. Section 3 covers this in full.
2. What we collect and why
Account data — your email address and sign-in details, so we can create your account and authenticate you. Legal basis: performance of our contract with you.
Billing data — your plan and payment status. Card details are entered directly with Stripe and are never stored on our servers. Legal basis: contract and our legitimate interest in getting paid.
Campaign data you create — your company description, target criteria, contact lists, and the messages you approve. Legal basis: contract (to provide the service).
Contact data our agents find — a public work email, name/role, employer, website, and the public evidence for why the contact matches your product. We verify each address before it can be used. Legal basis: the legitimate interest of you and Messaging.Quest in relevant B2B outreach, balanced against the contact’s rights (see section 8 for how a contact can object or be removed).
Usage and analytics — how the app is used, so we can improve it. Analytics cookies (PostHog) are on by default and you can turn them off anytime; see our Cookie Policy. Legal basis: our legitimate interest in improving the product, which you can object to at any time.
Support and messages — anything you send us (for example feedback or bug reports). Legal basis: our legitimate interest in running and supporting the service.
3. How communities get read
Two things read public communities for you, and which one depends entirely on whether a place needs to know who you are.
Your browser reads anything that needs your session. The Messaging.Quest browser extension is optional and runs in your own Chrome. Reddit, and anywhere else that answers only a signed-in reader, is read there — with your session, from your own address. We never hold a cookie or a login for any platform.
Our server reads what any reader may read. Public feeds that a logged-out stranger can fetch — Discourse forums, Hacker News, RSS and Atom feeds — are read by us directly, on a schedule, so monitoring carries on when your laptop is shut and you can be told when something lands. Those requests carry no credentials and identify themselves as ours.
Nothing is ever posted for you, by either of them. Every reply is put in front of you and waits for your click — that has not changed and will not.
What the extension sends us. Public thread content from the places you approve (posts, comments, titles and links); the visible text, title and address of a page you explicitly ask about with “Draft a reply on this page”; the final reply text you confirm having posted; and, when your browser later revisits that thread, its public reception — votes, reply counts, whether the author answered you, and whether the reply was removed. Legal basis: performance of our contract with you.
Handles of people you answer. We store the public username and profile link of the person whose thread you replied to. That is what lets us keep two promises: never putting someone in front of you again after they asked to be left alone, and telling you when you have already written to this person. Legal basis: the legitimate interest, yours and theirs, in not being contacted twice or against their wishes.
Private messages. On-page drafting works on whatever page you choose, and that can include a private message thread. If you click Draft there, that page’s text is sent for drafting exactly like any other page. We never open or read a private conversation on our own — only the page you clicked on, at the moment you clicked it.
What the extension never collects. Your passwords, cookies or session tokens for any platform — those stay in Chrome and only in Chrome, and our servers could not read them if we wanted to. Nor your browsing history, your clicks, keystrokes or mouse movement, or your location. Inside the browser it stores only your pairing code, the server address, and which version of your writing style you have already been shown.
Where it goes and how long we keep it. Thread text is stored in our database and read by the drafting agent (Fly.io, OpenAI) so it can judge whether you are an honest answer and write the reply. The pre-selection buffer is deleted 7 days after a decision and its content is cleared after 14 days regardless; replies you confirmed posting remain in your activity history while your account is open.
Permissions. The extension installs with access to no site at all. Each place you watch is a single Chrome permission you grant in the moment, and you can revoke any of them at any time from Chrome’s extension settings.
4. Cookies
We use a small set of essential cookies to run the app, plus analytics cookies that are on by default and that you can turn off anytime. The full list is in the Cookie Policy, and you can change your choice anytime from “Cookie settings” in the footer.
5. Who we share data with
We do not sell your data or share it for advertising. We share it only with the service providers (sub-processors) that make Messaging.Quest work, each under a data processing agreement and only for the purpose shown:
| Provider | What they do for us |
|---|---|
| Supabase | Database, authentication, and file storage (EU region) |
| Cloudflare | The human check on the sign-in form (Turnstile) — it sees the browser, not the address you type |
| Vercel | Application hosting and content delivery |
| Fly.io | Compute for the research, judging and drafting agents |
| Stripe | Subscription billing and payment processing |
| SendGrid / Resend | Sending your campaign email and receiving replies |
| Spaceship | Registering your sending domains |
| MillionVerifier | Checking whether an email address is deliverable |
| OpenAI | The agents that research companies, judge forum threads, and draft replies |
| OpenRouter | AI models that draft message copy and domain-name ideas |
| PostHog | Product analytics (EU region) — on by default, can be turned off |
We may also disclose data where the law requires it, or to protect our rights, users, or the public.
6. International transfers
We host your core data (database, authentication, analytics) in the EU. Some providers may process data outside the EU/EEA; where they do, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. How long we keep it
We keep account and campaign data while your account is active and for as long as needed to provide the service, meet legal and accounting obligations, and resolve disputes. When you delete data or close your account, we delete or anonymise it within a reasonable period, except where we must retain some records (for example billing records). Suppression records (people who opted out) are kept so we can keep honouring the opt-out.
8. If you were contacted through Messaging.Quest
If you received a message sent through Messaging.Quest and want to be removed, use the one-click unsubscribe link in the email, or email hello@messaging.quest. We add you to a suppression list so you are not contacted again through our platform, and we can pass your request to the sender. You also have the rights in section 9, including the right to object to this processing.
9. Your rights
Under the GDPR you can ask to access, correct, delete, or export your personal data, and restrict or object to processing — including turning analytics off — at any time; this won’t affect processing done before you objected. To exercise any of these, email hello@messaging.quest. You also have the right to complain to your local data protection authority.
10. Children
Messaging.Quest is a business tool and is not intended for anyone under 18. We don’t knowingly collect data from children.
11. Changes
We’ll update this policy as the product and law change and will note the date above. If a change is material we’ll give reasonable notice.
12. Contact
For any privacy question or request, email hello@messaging.quest.