Project X Privacy Policy
Last updated: 15 October 2025
Table of Contents
Table of Contents
Introduction
This Privacy Policy explains—in plain language—what personal information we collect, why we collect it, and how you stay in control. Reading it will help you understand and confidently use all Project X products and services.
Our Values
A. Your personal information belongs to you.
B. We protect it. We never disclose it to anyone without your clear permission.
Why We Process Your Information
We use your information only to:
- improve and personalize the service we provide to you;
- enhance our products;
- generate internal reports and analytics.
Google User Data Accessed
When you sign in with Google, Project X requests access to basic profile information to authenticate you and create your account. Specifically, we access:
- Your Google account email address
- Your basic profile information (name and profile image)
- Your OpenID identifier
We do not request or access your Google Drive files, Gmail content, Calendar events, contacts, or any other Google data beyond the scopes required for authentication (openid, email, profile). If our scope needs change, we will update this Policy and prompt you for consent.
How We Use Google Data
We use Google user data only for the following purposes in accordance with the Google API Services User Data Policy (including the Limited Use requirements):
- Authenticate you and keep you signed in
- Create and manage your account profile (e.g., name and avatar)
- Associate your orders, preferences, and roles with your account
- Send essential service communications to your email (e.g., receipts, account notices)
We do not sell Google user data or use it for advertising. We do not allow humans to read your Google user data except when required for security, compliance, or to diagnose an issue at your request.
Data Sharing
We do not sell your personal information. We share limited data with service providers solely to operate our services:
- Authentication and hosting: We may store your Google account email, name, profile image URL, and identifiers in our database to manage your account.
- Payments: Stripe (payment processing). Your Google data is not used by Stripe; payment details are handled directly by Stripe.
- Email delivery: our email service provider (for receipts and essential notifications) may receive your name and email address to send messages.
- Push notifications: our push service provider may store a device token linked to your account; no Google content is shared.
We disclose data if required by law or to protect our rights, users, or the public. We do not transfer Google user data to data brokers or use it for ads.
Data Storage & Protection
- Data is stored in managed Postgres with encryption at rest and TLS in transit.
- Access is restricted using role-based access controls and least-privilege principles.
- We never store your Google password. OAuth tokens are handled by Supabase; we store only what is necessary to maintain your session.
- We use industry-standard security practices and regularly review access logs and configurations.
Data Retention & Deletion
We keep your account data while your account is active. If you delete your account, we will retain necessary records for up to two (2) years to comply with legal, tax, or fraud-prevention obligations, after which they are deleted or anonymized.
- You can request deletion of your account and associated data by contacting us at admin@getprojectx.store.
- You can revoke our access to your Google account at any time at Google Account Permissions. Revoking access may sign you out.
- Backups may persist for a limited period and are purged on a rolling schedule.
User Choices & Controls
- Access, update, or correct your profile information in-app.
- Revoke Google access at Google Account Permissions.
- Request data export or deletion by emailing admin@getprojectx.store.
Changes to This Policy
We may update this Privacy Policy to reflect changes to our practices or for legal, regulatory, or operational reasons. If changes are material, we will provide prominent notice (e.g., in-app notice or email). Your continued use of Project X after an update constitutes acceptance of the revised Policy.
How You Can Reach Out
Questions, concerns, or requests about this Privacy Policy or your personal information can be sent to:
admin@getprojectx.store
