PROJECT NOTHING

Privacy Policy

A straightforward summary of what Project Nothing collects, why it is collected, and which systems handle the sensitive parts.

Context

This privacy policy works with the terms of use and the dedicated refund policy. It focuses on data handling, not product fulfillment, because the subscription still provides nothing.

01

What We Collect

We collect only the data needed to run the site and operate the experiment: basic analytics events, cookie preferences, subscription-related identifiers supplied by Stripe, and limited server-side logs needed for security and reliability.

02

Payments

Payments are processed by Stripe. Project Nothing does not store your full payment card details. Stripe may provide customer, subscription, and transaction metadata needed to confirm billing state and operate the customer portal.

03

Cookies and Analytics

The site uses cookies and similar storage for consent state, vote deduplication, session/auth flows, and analytics when allowed. Google Analytics is used for traffic and conversion measurement, and the cookie banner gives visitors an explicit choice on analytics storage.

04

How We Use Information

We use collected information to process subscriptions, operate the site, secure admin and public systems, measure experiment outcomes, and maintain transparent public reporting about the project.

05

Sharing

We share information only with service providers or infrastructure needed to operate the site, such as Stripe, hosting, analytics, and authentication vendors. We do not sell personal data as a standalone business activity.

06

Google Calendar Data (Spent)

One experiment, Spent, can read your Google Calendar with the read-only scope calendar.readonly. It is read inside your own browser and is never sent to, stored on, or logged by a Project Nothing server. Details, including how to revoke access, are in the dedicated section below.

07

Retention and Contact

We keep information for as long as reasonably needed for billing records, legal compliance, fraud prevention, and experiment operations. Questions about privacy can be sent to hello@projectnothing.ai. General platform rules still live in the main terms page.

GOOGLE USER DATA

Spent and your Google Calendar

Spent is an experiment that reads a calendar and reports where the time went. It can read your Google Calendar, and it can equally read a calendar file you export yourself — the result is identical, and connecting Google is never required to use it.

What is requested

One scope, https://www.googleapis.com/auth/calendar.readonly, which is read-only. Spent cannot create, change or delete anything in your calendar; the permission to do so is never requested and could not be used. Nothing else about your Google account is requested — not your contacts, not your email, not your profile.

What is accessed

Event titles, start and end times, time zones, attendee names and addresses, organiser, location, recurrence markers and event type, from the calendars you have selected in your own Google Calendar sidebar. Holiday, birthday and contact feeds are skipped. Descriptions, attachments and conferencing details are never requested. The free version reads the last thirty days; the rest of your history is read only if you buy the full statement.

Where it goes

Nowhere. Google issues the access token to the web page in your browser, not to us, and that page calls the Google Calendar API directly. Your events are read, counted and displayed entirely on your own device. No Project Nothing server receives, stores, logs or processes them, and we do not use an authorization-code flow, so we never hold a refresh token or any standing access to your calendar. When the reading is finished the access token is handed back to Google immediately.

What we do keep

Two things, neither of which is calendar data. First, anonymous counters: how many people opened the page, produced a statement, or paid. They are numbers, with no identity attached. Second, if you ask us to name commitments our own rules could not recognise, the titles of those few recurring entries are sent to a language model to be categorised — with no dates, no attendees, no durations and nothing identifying you — and the answer is cached against a one-way hash of the title, so the title itself is never stored. There is a switch on the page that turns even this off.

Sharing, and what we never do

Google user data obtained through Spent is never sold, never transferred to anyone, never used for advertising, never used to build a profile of you, and never used to train or improve any machine-learning model. It is not read by a human. Since it never reaches our servers, there is nothing for us to share even if we wanted to.

Retention and revoking access

Calendar data is retained for as long as the browser tab is open, and no longer. Closing or reloading the page discards it. Because nothing is stored, there is no deletion request to make and no account to close. You can revoke Spent’s access at any time from your Google account under Third-party apps & services, and Spent hands the permission back on its own as soon as it has finished reading.

Limited Use

Project Nothing’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Questions about any of the above can be sent to hello@projectnothing.ai.

PHOTOGRAPHS

On Me and the photo you upload

On Me is an experiment that shows the same garment on a model and on you, and counts which one you said you would wear. To do the second half it needs one photograph of you. It is the only part of Project Nothing that asks for one.

What happens to it

It is held in memory for the length of a single request, sent to the image provider that renders the pictures, and dropped when that request finishes. It is not written to disk, not placed in a bucket, and not recorded in a database. There is no field anywhere in this experiment’s storage that could hold a photograph, which is the only version of this promise worth printing.

What is kept, and for how long

The pictures generated from it, and your answers about them. They live under a random link for thirty days and then expire on their own. No account is created, no email is asked for, and nothing links that record to your name, your address or any other visit. Alongside them are anonymous counters — how many people arrived, submitted a photo, or paid — which are numbers with no identity attached.

The declaration

Before anything is generated you are asked to confirm that the photograph is of you and that you are over 18. Please do not upload a photograph of somebody else. We have no way to verify it, which is exactly why it is asked for plainly rather than buried.

What we never do

Your photograph is never sold, never shown to another visitor, never used for advertising, never used to build a profile of you, and never used to train or improve any machine-learning model by us. It is not looked at by a human. It is sent to the image provider solely to render your pictures and for no other purpose.

Deletion

The photograph is already gone, so there is nothing to delete. The pictures made from it expire within thirty days without you doing anything; if you would like them removed sooner, send the link to hello@projectnothing.ai and it will be dropped. On Me is an experiment and may be withdrawn at any time, at which point everything it holds goes with it.