Privacy Policy
DRAFT · LAST UPDATED Phase 0 draft
ReadMaxxer is a benchmark and training app that measures how fast and accurately you detect, notice, and track visual targets on screen. This page explains what data the product actually collects, why, where it lives, and what you can do about it, grounded in the real implementation (docs/14-security-privacy-a11y-compliance.md §7, §8; docs/05-data-model.md §7), not generic boilerplate.
What we collect
| Category | Why | Retention |
|---|---|---|
| Account identity (Firebase anonymous or signed-in user id; email/display name if you sign up) | Lets you use the app and return to your progress | Until account deletion |
| Age attestation (13+, a yes/no checkbox) | Legal/compliance gate. No birthdate is ever collected | Until account deletion |
| Device snapshot (coarse category: desktop/tablet/mobile, plus browser/OS family, refresh rate, viewport) | Interpreting your score in the context of the device you used it on | 90 days raw; coarse category kept longer as part of your result history |
| Trial-level timing and responses during an exercise | Computing your score server-side and detecting invalid sessions (e.g. tab backgrounded mid-trial) | 90 days raw, then only aggregated summaries remain |
| Session summaries, skill estimates, streaks, XP | The actual product: your progress over time | Until account deletion |
| Billing identity (if you subscribe) | Entitlement: knowing you have an active subscription | Until account deletion; card details are never held by us at all (see Sub-processors) |
| Product-usage events (which pages/exercises you use, funnel drop-off) | Understanding whether the product works, at all. Not sold, not shared for advertising | Governed by PostHog’s/GA4’s own retention; only collected after you accept the cookie banner |
What we never collect
Medical history or diagnoses, exact physical location, biometric data, webcam video, or eye-tracking data. No field in our data model can hold any of these. This is a structural absence, not just a policy statement. The only age-related data point anywhere is the 13+ yes/no attestation; no birthdate is ever stored.
Sub-processors
Companies that process data on our behalf, and what they see:
| Sub-processor | Role |
|---|---|
| Google / Firebase | Sign-in, our primary database (Cloud Firestore) |
| Vercel | Hosts the application |
| Google BigQuery | Aggregate analytics warehouse (never queried in a way that affects your live experience) |
| Paddle | Merchant of record for billing. Paddle handles your card details directly; we never see or store them |
| PostHog | Product analytics (funnels, feature usage), only after you accept the cookie/consent banner |
| Google Analytics (GA4) | Marketing/acquisition analytics, only after you accept the cookie/consent banner |
Not yet built (Phase 0): A formal Data Processing Agreement (DPA) with each sub-processor above is a business/legal action tracked separately, not yet executed as of this draft.
Cookies and analytics consent
Neither PostHog nor Google Analytics loads on your device until you explicitly accept the consent banner shown on your first visit, not “loaded but not tracking.” The script itself does not exist in the page until you accept. Declining is exactly as easy as accepting: one click, equal-sized buttons, nothing pre-selected. See our Cookie Policy for the full detail.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or export a copy of your personal data.
You can export a copy of your data or request account deletion yourself from Settings → Your account once you have an account. For any other request, or to exercise a right before creating an account, contact us and we will handle it manually, with a target of completing it within 30 days.
Contact
For any privacy question or to exercise a data-subject right, contact us at readmaxxer@gmail.com.