01Overview
This Privacy Policy explains how Goal Planner (“we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you use the Goal Planner website, applications, and related services (the “Service”).
By using the Service, you acknowledge this Policy. If you do not agree, do not provide personal information through the Service.
02Information we collect
| Category | Examples |
|---|---|
| Account information | For temporary users, an anonymous user identifier and authentication record. If you sign in with Google, this also includes your name, email address, Google profile image, and account identifier. |
| Goal and plan content | Your goals, context answers, generated plans, steps, descriptions, time estimates, completion status, assumptions, and archived versions. |
| Activity information | Completion dates, streak activity, plan timestamps, timezone, AI generation status, usage count, token counts, and error information. |
| Technical information | Session cookies and information ordinarily recorded by hosting, security, and infrastructure providers, such as IP address, browser, device, request time, and diagnostic logs. |
| Communications | Information you include when you contact us about support, privacy, legal, or product feedback. |
Please avoid entering sensitive personal data that is not needed to make your plan. Goal content may reveal information about your health, finances, career, beliefs, relationships, or other personal circumstances depending on what you choose to submit.
03Where information comes from
We receive information directly from you when you enter goals, answer questions, update plans, complete steps, or contact us. You may begin with a temporary anonymous account. When you sign in with Google, Google provides the basic account details you authorize, such as your name, email address, profile image, and account identifier.
We also collect limited information automatically through session technology, product operations, and service logs. Temporary plan data is kept in your browser session until you sign in or return home. In developer demo mode, plan and activity data is stored only in your browser’s local storage.
04How we use information
We use personal information to:
- authenticate users and maintain accounts;
- create, store, display, update, archive, and delete plans;
- generate clarification questions, plans, step breakdowns, and estimates;
- calculate completion progress and streak activity;
- enforce usage limits and protect the Service from abuse;
- diagnose errors, maintain security, and improve reliability;
- respond to requests and communicate material service or policy changes; and
- comply with law and protect users, Goal Planner, and third parties.
Where applicable law requires a legal basis, we rely on performance of our agreement with you to provide the Service, our legitimate interests in securing and improving it, consent where specifically requested, and compliance with legal obligations.
05How AI processing works
When you request a plan, questions, or a step breakdown, relevant goal content is sent to OpenAI for processing. Depending on the feature, this may include your goal, plan summary, step title and description, ancestor steps, time estimate, and answers to context questions. We also send a privacy-preserving hashed safety identifier used for abuse prevention.
Goal Planner configures OpenAI Responses API requests with store: false, so it does not ask OpenAI to store response application state for later use. Under OpenAI’s standard API controls, prompts and responses are not used to train OpenAI models unless the API account owner explicitly opts in. OpenAI may retain abuse-monitoring logs containing customer content for up to 30 days unless different approved retention controls or a legal requirement apply.
AI output is returned to Goal Planner and becomes part of your saved plan when you choose to create or update it. Do not include sensitive information that is unnecessary for the planning request.
08How long we keep information
We generally keep registered account and plan information while your account is active or as needed to provide the Service. Temporary plan content is not stored in our plan database. We may delete abandoned anonymous authentication records and their usage counters after 30 days.
Archived plan versions remain associated with your saved plan so regeneration history can work. Deleting a plan removes its related steps, context answers, AI generation records, and completion events from the active database through linked deletion rules. If you request account deletion, we will delete or de-identify account-linked information unless we must retain limited records for security, fraud prevention, legal compliance, dispute resolution, or backup integrity. Provider logs and backups may persist for a limited period under provider retention schedules before being overwritten or deleted.
09International processing
Our providers may process information in countries other than where you live. Those countries may have different data-protection laws. Where required, we use contractual or other recognized safeguards for international transfers and take steps intended to ensure that providers protect information consistently with this Policy.
10Security
We use reasonable technical and organizational safeguards designed to protect personal information. Current measures include encrypted network connections, managed authentication, database row-level access controls, per-user authorization, server-side API credentials, and restricted AI usage quotas.
No internet service is completely secure. You should protect your Google account, use a trusted device, and avoid entering information that you would not want processed as described in this Policy.
11Your privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information; to object to certain processing; to withdraw consent; and to complain to a data-protection authority.
You can update or delete individual plans within the Service. For account-level requests, contact us using the address below. We may need to verify your identity and may retain information where an exception under applicable law applies. Authorized agents may submit requests where local law permits.
12Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Where a higher age threshold or parental consent applies, users must satisfy that requirement. If you believe a child has provided personal information contrary to this section, contact us so we can investigate and take appropriate action.
13Automated decision-making
Goal Planner uses AI to suggest planning content, but it does not make decisions that produce legal or similarly significant effects about you. You choose whether to use, edit, complete, or disregard every suggested step.
14Changes to this policy
We may update this Policy when the Service, our providers, or applicable requirements change. We will revise the effective date and provide additional notice when a change is material. Earlier versions may be retained for reference where appropriate.
15Contact us
For privacy questions, requests, or complaints, contact contact@goal-planner.com. You may also have the right to contact the data-protection authority where you live.
Use of the Service is also governed by our Terms & Conditions.