This page is maintained by Bmetrix Sweden AB ("we", "us") to explain what personal data Devlog Momentum Planner (the "Service") collects, why we collect it, and what you can do about it. We are the data controller under the EU General Data Protection Regulation (GDPR).
1. What we collect
Account data
When you sign in with email/password or Google we store your email address, a hashed password (if you use email sign-in), your display name, and your avatar URL if provided by Google. We never see or store your Google password.
Project data
Content you create in the app - your game project details, launch date, USP, calendar slots, drafts, checklist progress, Steam assets, wishlist snapshots, localization notes. You own this content; we store it so we can show it back to you.
AI drafting inputs
When you use "Draft with AI", "AI Suggest", or the USP generator, the prompt you send (including your notes, project title, and stage) is forwarded to our AI provider to generate a response. We do not use your prompts to train models.
Technical data
Standard server logs (IP address, user agent, timestamp) for security and abuse prevention. We do not run analytics scripts, tracking pixels, or advertising cookies.
2. Why we use it (legal basis)
- To provide the Service - contract performance (GDPR Art. 6(1)(b)).
- To keep it secure and prevent abuse - legitimate interest (Art. 6(1)(f)).
- To comply with legal obligations - Art. 6(1)(c).
3. Who processes it for us (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Lovable (lovable.dev) | Application hosting and platform | EU / global CDN edge |
| Supabase | Managed database and authentication (via Lovable Cloud) | EU |
| Google (Gemini via Lovable AI Gateway) | AI text generation for drafts and USP suggestions | EU / US |
| Google (OAuth) | Sign-in with Google (only if you use it) | EU / US |
We do not sell your data. We do not share it with anyone outside the subprocessors above except when required by law.
4. International transfers
Some subprocessors (Google) may process data outside the EEA. Such transfers are covered by the EU Standard Contractual Clauses and any additional safeguards those providers publish.
5. How long we keep it
- Account & project data: until you delete the account.
- Server/security logs: up to 90 days.
- AI request logs: up to 30 days for abuse prevention.
6. Your rights
You can access, correct, export, or delete your data at any time. See the GDPR / Data Rights page for how to exercise them. You can also lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) or your local EU supervisor.
7. Security
Data in transit is encrypted with TLS. Database access is scoped per user with row-level security. We use industry-standard managed infrastructure but we cannot promise absolute security - see the Terms for the limits of our liability.
8. Children
The Service is not directed at children under 16. If you believe a child has created an account, contact us and we will remove it.
9. Changes
We may update this policy. Material changes will be highlighted in the app and the "Last updated" date at the top will change.
10. Contact
Bmetrix Sweden AB, Sweden - andreas.waleij@bossmetric.com