Goals Privacy Policy
Contact: Not configured
1. Scope and controller
This Policy explains how the operator identified above processes personal data when you use the global Goals Service. A separately operated or self-hosted server is controlled by its own operator. The person or organization that owns a local workspace also decides what local content to connect and share.
2. Data we process
| Category | Examples | Why |
|---|---|---|
| Account and device | Email address, username, user/device IDs, public device keys, device label, authentication records | Create and secure accounts, authenticate devices, recover access |
| Coordination metadata | Goals, session titles and published summaries/scope, memberships, permissions, event types, service/project/round status | Synchronize collaboration and enforce permissions |
| Encrypted shared content | Discussion frames, feedback, project conversations, selected deliverables | Relay content end to end or retain an encrypted copy when you enable hosting |
| Network and security | IP address and connection/rate-limit records, request time, service diagnostics | Operate, troubleshoot, prevent abuse, and protect the Service |
| Notifications | Push token, device/locale and expiry, minimal task routing metadata | Deliver notifications you enable |
| Support | Messages and diagnostics you deliberately send to us | Respond to requests and investigate problems |
Data that stays local
Full agent transcripts, source code and work trees, work-directory paths, credentials, third-party API keys, private execution history, and tool approvals stay on the executing owner's device. Mobile may keep an encrypted on-device reading cache for the signed-in account. Voice audio stays on the device and is not stored by Goals. An image you choose is sent end-to-end encrypted to the owner's device; it is not a central plaintext upload.
3. Sources and purposes
We receive data from you, your registered devices, people who collaborate with you, and infrastructure needed to deliver the Service. We use it to provide the contract, authenticate users, route collaboration, remember explicit sharing choices, send requested communications, maintain security, answer support requests, comply with law, and improve reliability using aggregated or de-identified service measurements. Goals does not use private content to train a generative AI model and does not sell personal data or use it for cross-context behavioural advertising.
4. Legal bases
Where applicable, processing is based on performance of our contract, legitimate interests in security and reliable operation, your consent for optional hosting/notifications or other optional processing, and legal obligations. You may withdraw consent for an optional feature in its settings without affecting prior lawful processing.
5. When data is disclosed
- People you choose. Content and metadata are shown according to your invitations, memberships, service permissions, and capability links.
- Processors. Hosting, backup, email, and push providers process the minimum information needed under contractual safeguards.
- Your chosen AI or agent provider. The owner device may send context to the third-party runtime the owner selected, under that provider's terms.
- Legal and safety. We may preserve or disclose data when lawfully required, or when necessary to protect rights, safety, and service integrity.
- Business changes. Data may transfer as part of a merger or reorganization subject to continued protection and required notice.
6. Retention
Account and coordination records are kept while the account or collaboration remains active and for the shortest additional period reasonably needed for security, disputes, and legal obligations. Email codes expire after 10 minutes. Push-token leases expire after 7 days unless renewed. Live encrypted frames are relayed without central content storage. When encrypted hosting or a service delivery explicitly applies, ciphertext expires within the displayed period, no longer than 30 days. Local data remains until the relevant device owner removes it.
7. Regions and international transfers
The global service and the mainland China service use separate origins, accounts, databases, secrets, and client profiles; data is not automatically copied between them. The global production service currently uses infrastructure in Hong Kong. Service providers may process limited data in other countries. Where required, we use recognized transfer safeguards and provide information needed to exercise your rights. A self-hosted operator determines its own storage region.
8. Your choices and rights
Depending on your location, you may request access, correction, deletion, portability, restriction, or objection; withdraw consent; appeal a refusal; or complain to a privacy authority. California residents may request the categories, sources, purposes, and recipients of covered personal information and exercise applicable correction/deletion rights. We do not sell or share personal information for cross-context behavioural advertising. Contact the operator from the email associated with your account; identity verification may be required.
9. Security
We use device public-key authentication, scoped permissions, end-to-end encryption for shared content channels, transport encryption, access controls, expiry limits, and encrypted backups where configured. No system is perfectly secure. Protect your device, email account, invitations, and capability links, and promptly report suspected compromise.
10. Children
Goals is not directed to children under 18, and we do not knowingly create accounts for them. Contact us if you believe a child has provided personal data.
11. Changes and contact
We will post revisions here and provide additional notice for material changes where required. The effective date above identifies this version. Contact the operator for privacy requests or an accessible copy.