← Home

Privacy Policy

Last updated: June 27, 2026

1. Who we are

TuranForward (the "Service") is operated by Tahsin Azad Turan, a sole proprietor based in Bangladesh, trading as "TuranForward" (the "Seller", "we", "us"). For privacy matters, the Seller is the data controller of personal data processed through the Service. Contact us at the email address shown on the home page.

2. Data we collect

  • Account data — email, username, optional avatar URL, password hash, sign-in provider (e.g. Google).
  • Content data — goals, descriptions, generated tasks, journal/brain-dump entries, completion timestamps.
  • Proof images — photos you upload for AI task verification.
  • Usage and device data — pages visited, feature events, IP address, browser/device identifiers, error logs.
  • Communications — emails or messages you send us.
  • Payment data — collected and processed directly by Paddle (see §5). We only receive subscription status, plan, customer ID, and billing country.

3. Purposes and legal bases

  • Provide the Service (account, quests, XP, leaderboard, AI verification) — legal basis: performance of a contract.
  • Process payments and entitlements via Paddle — legal basis: performance of a contract and legal obligation (tax/invoicing).
  • Security, fraud prevention, abuse handling — legal basis: legitimate interests.
  • Product improvement and analytics (aggregate usage) — legal basis: legitimate interests.
  • Transactional and reminder emails — legal basis: performance of a contract.
  • Marketing emails (if any) — legal basis: consent, withdrawable any time.

4. AI processing

Proof images and goal text are sent to our AI provider (Google Gemini via the Lovable AI Gateway) solely to verify tasks and generate breakdowns. We do not use your content to train third-party models.

5. Who we share data with

We do not sell your data. We share the minimum needed with these categories of recipients:

  • Paddle.com Market Limited — our Merchant of Record. Paddle processes all payments, handles subscriptions, tax, invoicing, and refunds. See Paddle's privacy notice at paddle.com/legal/privacy.
  • Hosting and database — Lovable Cloud (Supabase) for application data storage.
  • AI provider — Google Gemini via the Lovable AI Gateway for verification and breakdowns.
  • Email delivery — our transactional email provider.
  • Professional advisers — legal and accounting, where needed.
  • Authorities — where required by law.

6. International transfers

Our providers may process data outside Bangladesh, including in the EEA, UK, and US. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions adopted by the relevant authority.

7. Retention

  • Account and content data — retained while your account is active, and deleted within 30 days of account deletion (backups purged within 90 days).
  • Proof images — retained for 12 months from upload, then deleted, unless tied to an open dispute.
  • Payment and tax records — retained by Paddle and by us for up to 7 years to meet legal obligations.
  • Usage logs — retained up to 13 months in aggregated form.

8. Your rights

Subject to applicable law (including GDPR for EEA/UK residents), you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") of your data.
  • Restriction of processing in certain cases.
  • Portability — receive your data in a machine-readable format.
  • Object to processing based on legitimate interests, including profiling.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email us via the contact address on the home page. We respond within 30 days.

9. Security

Data is encrypted in transit (TLS) and access is gated by row-level security so users only access their own data. No system is perfectly secure; please report suspected issues to us promptly.

10. Cookies

We use strictly necessary cookies for authentication and session management. Paddle may set cookies during checkout to process your payment. We do not currently use third-party advertising cookies.

11. Children

The Service is not directed to children under 13, and we do not knowingly collect their data.

12. Changes

We may update this Policy. Material changes will be announced in-app or by email.

13. Contact

Tahsin Azad Turan (sole proprietor), Bangladesh. Contact via the email address shown on the home page.