Legal and privacy
Privacy Policy
Progress Realm stores the account and workspace information needed to provide the service. We do not sell personal information. Billing and generative-AI features are not currently offered.
Who this policy covers
This policy explains how Progress Realm collects, uses, stores, and deletes information when you visit the website, create an account, or use its productivity tools.
Information we collect
Account and authentication information
- Your name, email address, password hash, email-verification state, and account dates.
- If you choose Google sign-in, the Google account identifier and verified identity information Google returns for authentication.
- An optional profile avatar. Accepted avatars are normalized and stored under a server-generated filename.
Workspace content
- Tasks, task lists, completion state, dates, ordering, and focus-session timing.
- Journal entries, habits, habit-tracker entries, reports, and product preferences.
- Legacy workspace records that remain associated with your account while older features are migrated.
Security and technical information
- Session, CSRF, password-reset, email-verification, and access-token records needed to protect your account.
- Security-event metadata such as event type, time, and a keyed hash derived from an IP address. The application does not store the plain IP address in its security-event table.
- Ordinary server logs may include request time, route, status, device/browser information, and IP address. Production access, redaction, and retention depend on the hosting configuration.
How we use information
- Provide, synchronize, secure, troubleshoot, and improve the service.
- Authenticate users, verify email ownership, prevent abuse, and investigate security events.
- Send service messages such as verification, password, security, weekly-report, and deletion-confirmation emails when applicable.
- Comply with legal obligations and enforce service terms.
Cookies and browser storage
Progress Realm uses essential cookies for authenticated sessions, CSRF protection, and related security functions. The browser may also retain non-authoritative interface preferences and cached UI state. Clearing these values can sign you out or reset local preferences.
Google Analytics is disabled in the current product configuration. Before optional analytics is enabled, this policy and any required consent controls must be updated.
Third-party services
We do not sell personal information. The following services may receive limited information when you use the related feature:
- Google OAuth: provides optional Google sign-in and returns authentication identity information.
- Google Fonts: may receive network metadata such as IP address and browser information when font files are requested on current public and authenticated pages.
- Reddit: the Community feature requests public Reddit content directly from your browser, so Reddit receives ordinary request metadata.
- Email provider: processes destination address and message content to deliver account and service emails.
- Hosting and infrastructure providers: process stored data and technical logs as needed to operate the application.
CKEditor runs as part of the journal interface; Progress Realm does not intentionally send journal content to CKEditor. Stripe integration code exists, but paid plans and payment collection are disabled. This policy must be updated before billing is offered.
Data retention and deletion
Account and workspace data is kept while your account is active. Replacing or removing an avatar deletes the previous avatar from active private storage. Permanent account deletion removes your profile, workspace data, avatar, sessions, and access tokens from the active application database.
A pseudonymous deletion-completion record may remain for security and accountability. It does not contain your name or email address. Operational logs and encrypted backups may persist temporarily according to infrastructure retention schedules and are removed or overwritten through those schedules rather than restored into active service after a deletion.
Your choices and requests
- Review and correct profile information from Account.
- Change preferences and remove your avatar from Account.
- Permanently delete your account from Account → Data & privacy.
- Contact us to request privacy assistance, access, correction, or deletion that cannot be completed through Account.
Security
We use access controls, password hashing, private avatar storage, CSRF protection, rate limits on sensitive actions, and encrypted transport in production. No online service can guarantee absolute security.
Children
Progress Realm is not directed to children under 13, and we do not knowingly collect their personal information. Contact us if you believe a child has provided information so it can be reviewed and deleted.
Changes to this policy
Material changes will be posted here with a new effective date and version. When appropriate, we will provide additional notice inside the service or by email.
Contact
For privacy questions or requests, email privacy@productiverealm.com.