Progredi Legal
GDPR ยท CCPA ยท COPPA Data controller: Charos S.r.l. Last updated: 25 March 2026

Privacy Policy

This Privacy Policy explains how Charos S.r.l. ("Charos", "we", "us") collects, uses, and protects your personal data when you use Progredi. We act as the data controller under the EU General Data Protection Regulation (GDPR โ€” Regulation (EU) 2016/679).


1. Who We Are

Charos S.r.l., Italy โ€” charossrl@gmail.com

2. Data We Collect

2.1 Account Data

When you register, we collect:

Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

2.2 Wellness and Gaming Session Data

When you complete check-ins, we collect mood, sleep quality, stress, focus, and energy ratings, KSS scores, games played, session duration, time of day, habit streaks, and reward points.

This data is health-adjacent personal data under Art. 9 GDPR. By voluntarily entering it, you explicitly consent to its processing (Art. 9(2)(a) GDPR). You may withdraw consent at any time by deleting your account.

2.3 Technical Data

Device OS and version, authentication tokens (short-lived JWTs stored in encrypted device storage), and app error logs if crash reporting is enabled.

Legal basis: legitimate interest in maintaining service security (Art. 6(1)(f) GDPR).

2.4 Subscription Data

Your subscription status (active/inactive) is received from RevenueCat. We do not process or store payment card information โ€” all payments are handled by Apple App Store or Google Play.

3. How We Use Your Data

PurposeLegal basis
Creating and managing your accountContract (Art. 6(1)(b))
Delivering session check-ins and historyContract (Art. 6(1)(b))
Generating AI Coach insightsContract + Consent (Art. 6(1)(b), Art. 9(2)(a))
Managing your Premium subscriptionContract (Art. 6(1)(b))
Security monitoring and fraud preventionLegitimate interest (Art. 6(1)(f))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))

We do not sell your data. We do not use your data for advertising.

4. AI Coach and OpenAI

The AI Coach transmits a summary of your session data to OpenAI, L.L.C. (USA) to generate personalised insights. OpenAI acts as a data processor under a Data Processing Agreement. Under our agreement, your data is not used by OpenAI to train its models.

5. Third-Party Processors

ProcessorPurposeLocation
Google FirebaseAuthentication and token storageEU / USA
OpenAIAI Coach insight generationUSA
RevenueCatSubscription managementUSA
AWS (via Supabase)Database hostingUSA
RailwayApplication server hostingUSA
Apple App Store / Google PlayPayment processingUSA

International transfers to US-based processors are governed by Standard Contractual Clauses (Art. 46(2)(c) GDPR) or the EUโ€“US Data Privacy Framework.

6. Data Retention

7. Your Rights

Art. 15 GDPR
Access
Request a copy of all data we hold about you
Art. 16 GDPR
Rectification
Correct inaccurate or incomplete data
Art. 17 GDPR
Erasure
Delete your account and all associated data
Art. 18 GDPR
Restriction
Restrict processing in certain circumstances
Art. 20 GDPR
Portability
Receive your data in a machine-readable format
Art. 21 GDPR
Objection
Object to processing based on legitimate interest

To exercise any right, email charossrl@gmail.com. We will respond within 30 days.

You may also lodge a complaint with the Italian supervisory authority: Garante per la Protezione dei Dati Personali โ€” garanteprivacy.it

8. California Residents (CCPA)

If you are a California resident, you have the right to know what data we collect, to delete it, and to opt out of its sale. We do not sell personal information. Contact us at charossrl@gmail.com to exercise these rights.

9. Children's Privacy

The App is not directed to children under 13. We do not knowingly collect data from anyone under 13. If we become aware of such data, we will delete it promptly. Users aged 13โ€“15 in the EU must have parental consent. Parents may contact us at charossrl@gmail.com.

10. Security

We implement HTTPS/TLS encryption, cryptographically hashed passwords, short-lived JWT tokens stored in encrypted device storage, and server-side access controls. No internet transmission is 100% secure; you use the App at your own risk.

11. Changes to This Policy

Material changes will be communicated in-app at least 14 days before taking effect. Continued use after the effective date constitutes acceptance.

Contact & Data Requests

Charos S.r.l. โ€” Italy
charossrl@gmail.com

To request data access, correction, or deletion, email us with the subject line "GDPR Request".