Privacy Policy

Last updated: June 2026

Quosque asks you one anonymous yes/no question per day and shows you how the rest of the world answered. This policy explains, in plain language, the very small amount of data the app processes and why.

The short version: there are no accounts, no sign-up, no tracking, no ads, and no analytics SDKs. The app stores a random token on your phone so it can count your vote only once per day. That token lives on our server for at most 48 hours and is then deleted automatically. Everything else we keep is just anonymous totals — how many people tapped yes and how many tapped no.

1. Who is responsible for your data

The data controller for Quosque is Gian Luca Matteucci, an individual developer established in Italy, operating under Italian and European Union law.

You can contact the controller about anything in this policy at: privacy@quosque.app

2. What data we process

Quosque is built to process as little data as possible. The complete list is below.

DataWhat it isHow it is used
Device token A random identifier (a UUID) generated on your device the first time you open the app. It is not your phone number, your advertising ID, or any account. Sent with each vote so that we can make sure one device votes only once per day. Nothing else.
Your vote A single yes or no for the question of the day. Added to the public running totals. We never store a row that links your token to your specific answer.
Language preference The Accept-Language header your device sends with web requests. Used only to produce aggregated statistics about the languages of our audience. It is never linked to your token.
Device type The User-Agent header your device sends with web requests. Used only to produce aggregated statistics about device types. It is never linked to your token.

We do not collect or process: your name, email, phone number, contacts, location, photos, advertising identifiers, payment data, or any precise device fingerprint. We do not use cookies for tracking.

3. About the device token

The aggregated totals and statistics are genuinely anonymous. The device token, while it exists, is a pseudonymous identifier — it is an online identifier within the meaning of Article 4(1) of the GDPR, and we treat it as personal data even though it is not tied to your real-world identity.

4. Why we are allowed to process this (lawful basis)

For the short-lived device token used for deduplication, our lawful basis is legitimate interest under Article 6(1)(f) of the GDPR. The legitimate interest is keeping the per-question results honest by ensuring one vote per device per day. The token is random, short-lived, used for nothing else, and never combined with other data to profile you.

The aggregated language and device-type statistics, and the public yes/no totals, do not identify anyone and are not personal data.

5. Sensitive questions

Some daily questions may touch on topics that could be considered sensitive under Article 9 of the GDPR. Because of how Quosque is built, your answer to such a question is only ever added to an anonymous counter. No record is written that links a sensitive answer to your device token or to you.

6. How long we keep data

7. Who we share data with

No one. Quosque contains no third-party SDKs, no analytics services, no advertising networks, and no social-media trackers. We do not sell, rent, or share your data.

8. Where your data is stored

All processing happens on servers hosted by Hetzner inside the European Union (Germany and/or Finland). Your data is not transferred outside the European Economic Area.

9. Automated decision-making

Quosque does not carry out profiling or automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 of the GDPR. The app simply counts votes.

10. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to data portability. You also have the right to lodge a complaint with the Italian supervisory authority: garante.it.

To make a request or ask a question: privacy@quosque.app

11. Children

Quosque is not directed at children and does not knowingly process data that identifies anyone, including children. Because there are no accounts and no personal profiles, the app does not collect information that would identify a child.

12. Security

We keep the amount of data at risk as low as possible by design: no accounts, no personal profiles, and a token deleted within 48 hours. The server is hosted in the EU and access is restricted to the controller.

13. Changes to this policy

If we change this policy, we will update the "Last updated" date at the top of this page and, where the change is significant, note it within the app.

14. Contact

privacy@quosque.app