Privacy Policy
Effective 7 March 2026
·
Last updated 2 May 2026
TL;DR — GoalAndLife collects only what it needs to operate your account
and deliver the service. We do not sell your personal data to third
parties, and we never will. Your personal planning data (goals, diary, decisions) is
stored securely and belongs to you.
1. Who We Are
GoalAndLife ("we", "us", or "our") is a personal
productivity application developed and operated as an independent software product.
The app is available on the web, Android, and iOS
(app ID com.goalandlife.app).
For privacy enquiries please use the contact details in Section 13.
2. Scope of This Policy
This Privacy Policy applies to all versions of GoalAndLife, including:
- The web application at goalandlife.com
- The Android application available on Google Play
- The iOS application available on the Apple App Store
3. Data We Collect
We collect the following categories of information:
3.1 Account & Identity Data (provided by you)
- Email address — provided via email/password signup, Google Sign-In, or Sign In with Apple
- Display name — your chosen profile name or identity-provider display name
- Profile photo URL — optional avatar URL from your identity provider profile
- Firebase UID — a unique identifier assigned by Firebase Authentication
3.2 Personal Planning Data (created by you)
All data below is explicitly entered by you and is stored on your behalf:
- Daily logs — mood ratings, energy levels, notes, daily scores
- Time blocks — scheduled tasks, activities, and time allocations
- Weekly plans — week-by-week planning and review notes
- Annual goals — goal titles, descriptions, progress, categories, due dates
- Decisions — decision statements, options, criteria, analysis, and reviews
- Life Balance assessments — self-reported scores across 10 life dimensions
- User settings & preferences — app configuration choices
3.3 Subscription & Payment Data
-
Subscription tier and status — whether you are on Free, Pro, or another tier
-
Stripe customer ID and subscription ID — references used to manage
billing (actual card/payment details are processed and stored solely by Stripe)
-
Subscription dates — start and expiry timestamps
We never store full credit card numbers or CVV codes on our servers.
3.4 Technical & Usage Data (collected automatically)
- Last login timestamp — to support session management
- Browser / OS information — passed by Google Analytics for aggregate reporting
- Page views and navigation events — collected via Google Analytics / Google Tag Manager
- Error logs — anonymised crash and error information for debugging
3.5 Data We Do NOT Collect
- Voice, microphone, or camera data
- Precise or background GPS location
- Contacts, SMS, or call logs
- Biometric data
- Financial account numbers or full payment card details
- Data from other apps on your device
4. How We Use Your Data
- Authenticate and manage your account
- Store and retrieve your planning data across devices
- Process subscription payments and manage billing via Stripe
- Send service-related emails (receipts, account notifications)
- Diagnose bugs and analyse anonymised aggregate usage patterns
5. How We Share Your Data
We do not sell, rent, or trade your personal data. We share limited
data only in the following circumstances:
- Service providers — infrastructure partners (see Section 6), bound by data-processor agreements.
- Legal obligations — if required by law or court order.
- Business transfers — in the event of a merger or acquisition.
- Aggregated data — anonymised statistics that cannot identify individuals.
7. Data Storage & Security
Where data is stored
-
Cloud database — when you are signed in, your data is stored in a
PostgreSQL database hosted by Neon, located in the United States.
-
Browser local storage — a copy may be cached in your browser's
localStorage for offline access. This data remains on your device and
is cleared when you sign out or clear browser data.
How we protect your data
- All data in transit is encrypted via HTTPS / TLS 1.2+
- Database connections use TLS encryption
- Database data is encrypted at rest
- Authentication tokens are managed by Firebase and never stored by us in plain text
- Access to production database is restricted to authorised personnel only
- HTTP security headers (HSTS, CSP, X-Frame-Options) are enforced on all pages
8. Data Retention
-
Active accounts — your data is retained for as long as your account is
active or as needed to provide the service.
-
Deleted accounts — upon account deletion your data is soft-deleted
immediately and permanently erased within 30 days.
-
Billing records — transaction records may be retained for up to 7 years
to comply with financial regulations.
-
Analytics data — aggregate, anonymised usage statistics have no
fixed retention limit as they cannot identify individuals.
9. Your Rights
- Access & Portability — request a copy of your personal data.
- Correction — ask us to correct inaccurate information.
- Deletion — request permanent deletion of your account and all data. Initiate in-app via Settings or contact us.
- Restriction — ask us to restrict processing in certain circumstances.
To exercise any right, use our Contact page. We respond within 30 days.
10. Children's Privacy (Under 13)
GoalAndLife is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe your child has provided us with data, contact us via our Contact page and we will delete it promptly.
11. International Users
GoalAndLife is operated from Australia; cloud infrastructure is hosted in the United States. By using the app, you consent to data being processed there. We comply with applicable data protection laws including GDPR and CCPA.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by updating the date above and displaying a notice in the app. Continued use constitutes acceptance.