1. Who we are
Proga is a customer-journey intelligence service operated by Jeremy Wold, DBA Proga, in Utah, United States. This policy covers the Proga website at proga.ai, the Proga customer portal, and the Proga reporting service (together, the "Service"). Questions, requests, or deletion demands: jeremy@proga.ai.
2. Information we collect
Information you give us
- Account information — your name, work email address, company name, and role, used to create and secure your portal account.
- Intake and profile information — what you tell us about your business, customers, goals, and current marketing activity, so the analysis is about your actual situation.
- Metrics you enter — the monthly numbers you choose to record in the portal so Proga can show you movement over time.
- Billing information — handled by our payment processor, Stripe. Proga never receives or stores your full card details.
Information we collect automatically
- Site analytics — we use Google Analytics on proga.ai to understand which pages are useful. This is standard web analytics about visits to our site, and is separate from the Google data described in section 3.
- Portal logs — sign-ins, report runs, and errors, retained so we can secure the account and fix problems.
Information from connected data sources
If — and only if — you choose to connect a data source, Proga reads data from it on a schedule. This is covered in detail below.
3. Google user data — what we access and why
Proga can connect to Google Analytics 4 and Google Search Console. Both connections are optional, both are read-only, and both are initiated by you.
| Scope we request | What it lets us read | Why we need it |
|---|---|---|
.../auth/analytics.readonly |
Read-only access to your Google Analytics 4 reporting data and the list of properties you can access. | To measure how visitors move through your customer journey — which channels bring them, which pages they engage with, and where they drop off — and to compare this period against the previous one. |
.../auth/webmasters.readonly |
Read-only access to your Search Console performance data (queries, pages, clicks, impressions, position) and the list of properties you have verified. | To separate branded search demand from unbranded search demand and map search intent to journey stages — the read that tells you whether you are creating new demand or only harvesting demand you already had. |
We request read-only scopes in both cases. Proga cannot modify, create, or delete anything in your Google Analytics or Search Console account, and cannot see your Gmail, Drive, Calendar, Contacts, or any other Google service.
How Google user data is used
- To generate the customer-journey reports, evidence files, and recommended next steps you asked Proga to produce.
- To show period-over-period movement in your portal so you can see whether things are improving.
- Nothing else. We do not use Google user data for advertising, for building profiles of individuals, or for any purpose unrelated to producing your reports.
How Google user data is stored
We store aggregated results — for example, "unbranded queries produced N clicks this month" — as evidence files inside your own company's isolated storage area in Proga's AWS account (US region). Data is encrypted in transit and at rest. Access is limited to Proga's automated processing and, where support requires it, to Jeremy Wold. We retain connected-source data for as long as your account is active, so that month-over-month comparison is possible, and delete it on request or when your account closes.
Where a connection uses per-user Google sign-in, the resulting refresh token is encrypted with a dedicated AWS KMS key and is never stored in plain text. Where a connection instead uses Proga's shared reader service account — an address you grant read access to inside your own Google tools — no credential of yours is stored by Proga at all, and revoking our access in your Google settings immediately and completely cuts off our access.
How Google user data is shared
We do not sell, rent, or trade Google user data, and we do not transfer it to third parties for their own purposes. It is disclosed only: (a) to infrastructure providers that host or process it strictly on our instructions under confidentiality obligations — currently Amazon Web Services; (b) to a private, business-tier AI provider used to analyze it, contractually configured not to train models on it (we do not use free or consumer AI tools); (c) to you and the people you invite to your own account; or (d) where required by law, in which case we will give you notice to the extent legally permitted.
Limited Use disclosure. Proga's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How to revoke our access
You can disconnect a source at any time from Connections in the Proga portal, which stops all further reads, revokes the stored credential where one exists, and deletes the connection record. You can also revoke access directly in Google — at myaccount.google.com/permissions for a Google sign-in connection, or by removing Proga's reader address from Search Console's Users and permissions or GA4's Property Access Management for a granted-access connection. To have the data we already read deleted as well, email jeremy@proga.ai and we will delete it promptly.
4. Other connected sources
Proga can also connect to HubSpot, using read-only CRM scopes, to understand how contacts and deals progress. The same rules apply: read-only, used only to produce your reports, never sold, disconnectable in one click.
5. Legal bases and your rights
Where the GDPR or UK GDPR applies, we process your information to perform our contract with you (delivering the Service), on the basis of your consent (for optional connected data sources), and for our legitimate interest in securing and improving the Service. You have the right to access, correct, export, restrict, or delete your information, and to withdraw consent for any connected source at any time.
Where the California Consumer Privacy Act applies: in the past twelve months we have not sold or shared personal information as those terms are defined by the CCPA, and we do not sell the personal information of minors. You have the right to know, delete, correct, and to be free from discrimination for exercising these rights.
To exercise any of these rights, email jeremy@proga.ai. We respond within 30 days.
6. Retention and deletion
We keep account and report data for as long as your account is active, and for a limited period afterward so that a returning customer's history is intact. You may request return or deletion at any time and we will comply promptly; routine backup copies remain protected under this policy until they age out of the backup cycle.
7. Security
Your data is stored in Proga's own AWS account rather than a consumer app, kept separate per company, encrypted in transit and at rest, and access-controlled. Credentials for connected sources are encrypted with a dedicated key, or — in the granted-access model — not stored at all. More detail is on our Security & data handling page.
8. Children
The Service is a business product, is not directed to children, and we do not knowingly collect personal information from anyone under 16.
9. International transfers
Proga operates in the United States and stores data in AWS US regions. If you access the Service from outside the United States, you understand that your information will be processed in the United States.
10. Changes to this policy
If we change this policy materially — particularly if we ever request an additional Google scope — we will update the effective date above and notify account holders by email before the change takes effect.
11. Contact
Proga · Jeremy Wold, DBA Proga · Utah, United States · jeremy@proga.ai. See also our Terms of Use.