Privacy Policy

How ProGantt Flow handles your personal data — what we collect, why, who processes it on our behalf, and the rights you have over it.

Last updated: 22 September 2026

1. Who we are

ProGantt Flow (“ProGantt”, “we”, “us”) is a Gantt chart and project planning service, available at progantt.com and app.progantt.com, together with a Model Context Protocol (MCP) server that lets AI assistants read and update your plans on your behalf.

The service is operated by ALT17, mobile and web development SL, a company registered in Spain under tax identification number (CIF) B66200767, with its registered office at C/ Sant Sebastià 10, 08182 Sant Feliu de Codines, Barcelona, Spain. ALT17 is the data controller for the personal data described in this policy.

You can reach us about anything on this page — including any request to exercise your rights — at support@progantt.com.

2. The short version

3. What we collect and why

3.1 Account and identity data

When you sign in with Google, we receive and store your user identifier, email address, display name and profile photo URL, along with the dates your account was created and last used. We need this to give you an account, to attribute your projects to you, and to let collaborators identify you.

3.2 Project content

Everything you create in the app: projects, tasks, milestones, resources, tags, notes, dates, progress and colours. Where you share a project, we also store the email addresses of the people you share it with and the role you gave each one (editor or viewer). This is the service itself — we process it to provide it to you.

3.3 Billing data

Paid plans are handled by Stripe. Card details never reach our servers — they are entered on Stripe's own checkout and stored by Stripe. On our side we keep your Stripe customer and subscription identifiers, your subscription status and the date your current period ends, so we know which plan to give you.

3.4 MCP access tokens

To connect an AI client you create an access token. We store a label, the creation date, the date it was last used, and — if you revoke it — the revocation date. The token itself is stored only as a SHA-256 hash; the raw value is shown to you once and never again, and we cannot recover it. You can revoke any token at any time from your profile.

3.5 MCP usage telemetry

Each time an AI assistant calls one of our MCP tools we record metadata about the call: the tool name, whether it succeeded or failed, how long it took, and whether the client authenticated with an API key or OAuth. These are aggregated into one document per user per day.

We do not record the arguments, task titles, project names or any other content that passed through the call. We use this to understand which capabilities are used and to find broken ones. It is kept for 400 days and then deleted automatically.

3.6 Product analytics

We use Google Analytics for Firebase to understand how the app is used in aggregate. It only runs if you accept it in the cookie banner; your choice is stored locally in your browser and you can change it by clearing your browser storage for the site. Declining does not restrict any feature.

3.7 Support conversations

If you use the in-app support chat, your messages and our replies are stored against your account so the conversation has context, and are processed by Google Vertex AI (Gemini) to generate the assistant's answers. If you email us instead, we keep that correspondence to handle your request. Please do not put information in support messages that you would not want us to read.

3.8 Technical logs

Our infrastructure providers record standard server logs — IP address, timestamp, requested endpoint, response status and user agent — which we use to keep the service secure and to diagnose faults.

3.9 Guest mode

You can use ProGantt without signing in. In guest mode, projects are written to your browser's local storage and never transmitted to us. Clearing your browser data deletes them permanently — we hold no copy and cannot restore them.

Data Legal basis
Account data, project content, MCP tokens Performance of a contract (Art. 6(1)(b)) — without it there is no service
Billing data Performance of a contract, and legal obligation (Art. 6(1)(b), (c)) for tax and accounting records
MCP usage telemetry, technical logs Legitimate interests (Art. 6(1)(f)) — keeping the service working, secure and improving. The data is metadata only, which keeps the impact on you minimal
Product analytics cookies Consent (Art. 6(1)(a)) — collected through the cookie banner, withdrawable at any time
Support conversations Performance of a contract and legitimate interests (Art. 6(1)(b), (f)) — answering you and improving our documentation

5. AI assistants you connect

ProGantt is built to be driven by AI assistants. When you connect a client — Claude, Cursor, VS Code or any other MCP-capable tool — using an access token or the OAuth connector, you are authorising that client to read and modify your project data on your behalf. Project content the assistant reads is sent to whoever operates that assistant, and is then governed by their privacy policy, not ours.

This is deliberate and is the point of the integration, but it is your decision: we only transmit data to a client you have connected yourself, and only while a valid token exists. Revoking the token, or disconnecting the connector, stops it immediately.

6. Who processes data on our behalf

We do not sell personal data and we do not share it with third parties for their own purposes. We do rely on a small number of processors to run the service:

Provider What they handle
Google Cloud / Firebase Authentication, database (Firestore), hosting, serverless functions, analytics
Google Cloud Vertex AI Generating support-chat replies
Stripe Payment processing and subscription management

We may also disclose data where we are legally required to, or to establish or defend legal claims. If the service is ever transferred to another owner, your data would move with it and you would be told beforehand.

7. International transfers

Our providers may process data outside the UK and the European Economic Area, including in the United States. Where that happens, transfers are covered by the safeguards those providers offer — principally the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

8. How long we keep it

If you ask us to delete your account, we remove your account data and project content. Anything we are legally required to keep, such as invoices, is retained for the period the law sets and nothing more.

9. Your rights

If you are in the UK or the EEA, you have the right to:

Email support@progantt.com to exercise any of these. We will respond within one month. If you are unhappy with how we have handled your data, you can complain to a supervisory authority. We are established in Spain, so our lead authority is the Agencia Española de Protección de Datos; you may also complain to the authority where you live or work, such as the Information Commissioner's Office in the UK.

10. Security

Access to your projects is enforced server-side by database security rules, not just in the interface. MCP tokens are stored as hashes and are individually revocable. Traffic is encrypted in transit, and data is encrypted at rest by our infrastructure provider. Administrative access to production data is limited to those who need it to operate the service.

No system is perfectly secure. If a breach affects your personal data and is likely to put your rights at risk, we will notify you and the relevant supervisory authority as the law requires.

11. Children

ProGantt is a tool for professional work and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the service changes. The date at the top always reflects the current version, and where a change materially affects how we use your data we will tell account holders directly rather than relying on you to re-read this page.

13. Contact

Questions, requests or complaints about privacy: support@progantt.com.