GOALS · GLOBAL SERVICE

Goals Privacy Policy

Effective · 2026-09-14
Pre-launch configuration required: the operator's legal name and a monitored contact address have not been configured. This page is a review draft and must not be treated as the published agreement.
Operator: Not configured
Contact: Not configured
Privacy by architecture. Full transcripts, source trees, work directories, credentials, and tool approvals stay on the executing owner's device. Goals centrally processes account and coordination data, routes end-to-end encrypted traffic, and stores encrypted shared copies only when a feature expressly says so.

1. Scope and controller

This Policy explains how the operator identified above processes personal data when you use the global Goals Service. A separately operated or self-hosted server is controlled by its own operator. The person or organization that owns a local workspace also decides what local content to connect and share.

2. Data we process

CategoryExamplesWhy
Account and deviceEmail address, username, user/device IDs, public device keys, device label, authentication recordsCreate and secure accounts, authenticate devices, recover access
Coordination metadataGoals, session titles and published summaries/scope, memberships, permissions, event types, service/project/round statusSynchronize collaboration and enforce permissions
Encrypted shared contentDiscussion frames, feedback, project conversations, selected deliverablesRelay content end to end or retain an encrypted copy when you enable hosting
Network and securityIP address and connection/rate-limit records, request time, service diagnosticsOperate, troubleshoot, prevent abuse, and protect the Service
NotificationsPush token, device/locale and expiry, minimal task routing metadataDeliver notifications you enable
SupportMessages and diagnostics you deliberately send to usRespond to requests and investigate problems

Data that stays local

Full agent transcripts, source code and work trees, work-directory paths, credentials, third-party API keys, private execution history, and tool approvals stay on the executing owner's device. Mobile may keep an encrypted on-device reading cache for the signed-in account. Voice audio stays on the device and is not stored by Goals. An image you choose is sent end-to-end encrypted to the owner's device; it is not a central plaintext upload.

3. Sources and purposes

We receive data from you, your registered devices, people who collaborate with you, and infrastructure needed to deliver the Service. We use it to provide the contract, authenticate users, route collaboration, remember explicit sharing choices, send requested communications, maintain security, answer support requests, comply with law, and improve reliability using aggregated or de-identified service measurements. Goals does not use private content to train a generative AI model and does not sell personal data or use it for cross-context behavioural advertising.

4. Legal bases

Where applicable, processing is based on performance of our contract, legitimate interests in security and reliable operation, your consent for optional hosting/notifications or other optional processing, and legal obligations. You may withdraw consent for an optional feature in its settings without affecting prior lawful processing.

5. When data is disclosed

6. Retention

Account and coordination records are kept while the account or collaboration remains active and for the shortest additional period reasonably needed for security, disputes, and legal obligations. Email codes expire after 10 minutes. Push-token leases expire after 7 days unless renewed. Live encrypted frames are relayed without central content storage. When encrypted hosting or a service delivery explicitly applies, ciphertext expires within the displayed period, no longer than 30 days. Local data remains until the relevant device owner removes it.

7. Regions and international transfers

The global service and the mainland China service use separate origins, accounts, databases, secrets, and client profiles; data is not automatically copied between them. The global production service currently uses infrastructure in Hong Kong. Service providers may process limited data in other countries. Where required, we use recognized transfer safeguards and provide information needed to exercise your rights. A self-hosted operator determines its own storage region.

8. Your choices and rights

Depending on your location, you may request access, correction, deletion, portability, restriction, or objection; withdraw consent; appeal a refusal; or complain to a privacy authority. California residents may request the categories, sources, purposes, and recipients of covered personal information and exercise applicable correction/deletion rights. We do not sell or share personal information for cross-context behavioural advertising. Contact the operator from the email associated with your account; identity verification may be required.

9. Security

We use device public-key authentication, scoped permissions, end-to-end encryption for shared content channels, transport encryption, access controls, expiry limits, and encrypted backups where configured. No system is perfectly secure. Protect your device, email account, invitations, and capability links, and promptly report suspected compromise.

10. Children

Goals is not directed to children under 18, and we do not knowingly create accounts for them. Contact us if you believe a child has provided personal data.

11. Changes and contact

We will post revisions here and provide additional notice for material changes where required. The effective date above identifies this version. Contact the operator for privacy requests or an accessible copy.