AviaQuest
Privacy Policy
This policy explains what AviaQuest collects, how the data is used, how community safety is handled, how long data is kept, and how users can contact us about privacy or deletion requests.
Last updated: June 7, 2026
1. Who Operates AviaQuest
AviaQuest is a bird-learning application developed by Gong Qiao for research and learning activities connected with Tampere University and the Research Centre of Gameful Realities.
For privacy, deletion, support, or moderation questions, contact gong.qiao@tuni.fi.
AviaQuest is currently a testing and research app. Features, content, and study procedures may change while the app is being evaluated and improved.
2. Scope Of This Policy
This policy applies to the AviaQuest Android and iOS app, the AviaQuest server APIs, the AviaQuest support pages, account deletion requests, support tickets, notifications, learning features, quiz features, badges, and community features.
External websites opened from AviaQuest, such as university pages, research centre pages, app-store pages, or third-party browser links, are governed by their own privacy policies.
3. Data We Collect
- Account information: full name, username, email address, password hash, selected country, account role, account status, account creation time, last known timezone, and account deletion status where applicable.
- Registration and login records: registration attempts, invitation code use, login success or failure records, session records, refresh-token hashes, current session identifier, IP address, user agent, device identifier, app version, operating system type, timezone, and UTC offset.
- Learning and quiz data: daily learning package state, birds assigned for learning or review, completed learning items, quiz questions, quiz answers, correctness, redo rounds, review schedules, completion timestamps, learning streaks, and related progress records.
- Gamification data: XP transactions, XP totals, levels, titles, badge progress, earned badges, badge timestamps, login streaks, daily task completion, and knowledge-base activity used for badges or progress.
- Knowledge-base activity: bird detail opens, random bird opens, source or reason for the open where available, target bird identifiers, and timestamps.
- Community content: posts, comments, post images, board/category choices, likes, author identifiers, moderation status, timestamps, and deleted or hidden states.
- Community safety data: reports about posts, comments, or users; report reasons; optional report details; report status; reviewed/actioned/dismissed timestamps; block and unblock relationships; and Community Guidelines acceptance records.
- Support data: support tickets, ticket messages, ticket categories, ticket statuses, ticket images, admin replies, and related timestamps.
- Profile data: avatar image path, public username, public level/title, earned badges shown on community profile sheets, and selected non-sensitive profile details needed to show the app experience.
- Notification data: push notification preferences, reminder settings, Firebase Cloud Messaging token, notification delivery records, and notification read/unread status.
- Technical and diagnostic data: server logs, request metadata, error records, timestamps, app version, platform, IP address, user agent, and security or abuse-prevention records.
4. How We Use Data
- To create accounts, authenticate users, protect sessions, prevent unauthorized access, and revoke sessions when needed.
- To provide daily bird learning, quizzes, review scheduling, knowledge-base browsing, progress tracking, XP, levels, titles, and badges.
- To show dashboards, profiles, badge collections, notification counts, learning history, and community activity inside the app.
- To operate community features, including posts, comments, likes, user profile sheets, board filters, reports, blocks, and Community Guidelines acceptance.
- To provide support tickets, admin replies, account deletion handling, user safety handling, and moderation review.
- To send optional push notifications, daily reminders, or app-related messages when notification permissions and app settings allow it.
- To debug app errors, investigate failed submissions, protect the service from abuse, monitor server health, and improve reliability.
- To support academic research analysis of learning and app-use patterns. Research reporting is intended to use aggregated, pseudonymised, or de-identified results where practical.
5. Community, Reports, And Blocks
AviaQuest includes user-generated community features. Community posts, comments, profile information, reports, and block relationships are processed to operate these features and keep the community usable and safe.
Users can report posts, comments, or profiles for review. Reports include the reporter, target type, target content or user, selected reason, optional details, status, and review timestamps. Administrators may review reports and mark them as reviewed, dismissed, or actioned.
Users can block another user. Blocks are applied as a two-way safety rule: both users are hidden from each other in community feeds and profiles, and blocked users cannot like, comment, reply, or open each other's community profiles through the app.
Community content may be rejected, hidden, removed, or reviewed when it violates the Community Guidelines, app safety, research integrity, or legal requirements.
6. Public Information Inside The App
Some information may be visible to other AviaQuest users when you use community features. This may include your username, avatar, level, title, earned badges, posts, comments, likes, and timestamps. Your email address, password hash, access tokens, refresh tokens, support ticket contents, and private deletion request details are not intentionally shown to other users.
If an account is anonymized after a deletion request, public author information is replaced where practical with a generic deleted-user presentation.
7. Security And Local Storage
AviaQuest uses HTTPS for app-server communication. Access tokens, refresh tokens, and session identifiers are stored on the device using iOS Keychain or Android encrypted storage where supported. Non-sensitive profile cache, such as username, display information, country, or avatar path, may be stored in normal app preferences so the app can load quickly.
Passwords are not stored in plain text by AviaQuest. The server stores password hashes. Refresh tokens are stored on the server as hashes. Active sessions and push tokens can be revoked during logout, session expiry, security handling, or account deletion.
No internet-based system can be guaranteed to be completely secure, but AviaQuest uses reasonable technical and organizational measures to reduce privacy and security risks.
8. Third-Party Services And Processors
AviaQuest uses Firebase Cloud Messaging to deliver push notifications. Firebase may process the push token and technical delivery information needed to route notifications to the device. Notification content is intended to be limited to app reminders or app-related messages and should not contain passwords or highly sensitive personal information.
AviaQuest also uses hosting, database, networking, and infrastructure services needed to run the app and public support pages. These services may process data such as server logs, IP addresses, request metadata, and database records as needed for operation, security, backups, and troubleshooting.
App distribution through Apple App Store, TestFlight, Google Play, or operating-system services may involve platform processing by Apple or Google according to their own terms and privacy settings. AviaQuest does not use third-party advertising SDKs and does not sell personal data.
9. Sharing
We do not sell personal data. We do not use AviaQuest data for third-party advertising tracking.
Data may be processed by hosting, infrastructure, notification, security, support, and research systems needed to operate AviaQuest. Access is limited to people or systems that need it for app operation, support, moderation, security, deletion handling, or approved research work.
Data may be disclosed if required by law, necessary to protect users or the service, necessary to investigate abuse or security incidents, or necessary to protect research integrity.
10. Retention
Account, learning, badge, community, support, moderation, and technical records are kept while needed to operate AviaQuest, support users, maintain security, debug issues, and conduct the related research. Different data types may have different retention periods depending on the purpose and technical system.
- Account and session data are kept while the account is active and for a limited period where needed for security, support, deletion handling, or audit records.
- Learning, quiz, XP, badge, and usage records may be retained for app functionality and research analysis, especially after they have been aggregated, pseudonymised, or de-identified.
- Community posts, comments, reports, blocks, support tickets, and moderation records may be retained while needed for community operation, safety review, abuse prevention, or support history.
- Technical logs and backups may be retained for security, debugging, disaster recovery, and compliance purposes, then deleted or overwritten according to operational needs.
After an account deletion request is accepted, the account is disabled immediately and cannot be used to log in. Active sessions and push tokens are revoked or deleted where applicable. Manual anonymization is usually completed within 30 days. Some records may remain in aggregated, de-identified, backup, log, moderation, security, or compliance form when deletion is not technically or legally practical.
11. Account Deletion And Anonymization
Users can request account deletion inside the app from Profile > Settings > Delete account, or without the app through the account deletion page. The reason field is optional.
When a deletion request is accepted, AviaQuest disables the account, removes or invalidates active sessions and push tokens, and records the deletion request. Manual anonymization is usually completed within 30 days. During anonymization, direct identity fields such as email, name, username, password hash, avatar path, and current session are cleared or replaced where applicable. After anonymization is completed, personal identity fields cannot be restored from the admin panel.
12. User Choices And Controls
- You can choose not to create an account or stop using the app.
- You can disable push notifications in the app profile settings or through device settings.
- You can report community posts, comments, or profiles from the community interface.
- You can block or unblock users from community profile controls.
- You can avoid optional community posting, commenting, avatar upload, or support-ticket image upload if you do not want to provide that content.
- You can request account deletion in the app or through the public deletion page.
13. Research Use
AviaQuest is connected to learning and research activities. Learning progress, quiz performance, app-use patterns, XP, badges, and engagement data may be analyzed to understand learning, motivation, gameful experience, and app usability. Research outputs are intended to use aggregated, pseudonymised, or de-identified results where practical and should not intentionally publish direct identifiers such as email addresses, passwords, tokens, or raw private support messages.
14. International Processing
AviaQuest may be accessed from different countries. App data may be processed on servers, infrastructure, or platform services used to operate the app, deliver notifications, or distribute the app. Where external processors are used, the project aims to use services and configurations appropriate for app operation, security, and research needs.
15. Children
AviaQuest is not intended for children under 13. If you believe a child has provided personal data, contact us so we can review and delete the information where appropriate.
16. Privacy Rights And Contact
Depending on where you live and the legal basis for processing, you may have rights to request access, correction, deletion, restriction, objection, or information about how your personal data is processed. Some rights may be limited where data has already been anonymized, where deletion would affect research integrity, where data must be retained for security or legal reasons, or where records are technically stored in backups or logs for a limited period.
To make a privacy request, contact gong.qiao@tuni.fi. Please include enough information to identify your AviaQuest account, such as your username and the email address used for the app.
17. Changes
We may update this policy when AviaQuest changes, when research procedures are clarified, or when legal, platform, or security requirements change. The latest version will be available at this URL. Significant changes may also be communicated inside the app or through other appropriate channels where required.