Privacy Policy
Last updated: May 20, 2026
1. What We Collect
When you create a GoalHash account, we collect:
- Your name and email address (required for account creation)
- Your goals and associated progress data that you enter
- Session data (login timestamps, browser type) for security
- Usage analytics (pages visited, features used) to improve the product
2. How We Use Your Data
We use your information to:
- Provide and operate the GoalHash service
- Send verification and account-related emails
- Let AI agents track and update your goal progress
- Improve and develop new features
- Prevent fraud and ensure security
3. Data Storage
Your data is stored in encrypted databases on AWS infrastructure in the US East region. Passwords are hashed using bcrypt and are never stored in plaintext. We retain your data as long as your account is active.
4. Data Sharing
We do not sell your personal data. We share data only with:
- AWS (cloud infrastructure)
- AI model providers (only goal content you explicitly submit for AI processing)
5. Your Rights
You can request export or deletion of your data at any time by emailing privacy@goalhash.com. Account deletion removes all associated goal data within 30 days.
6. Cookies
GoalHash uses localStorage (not cookies) to store your session token locally in your browser. No third-party tracking cookies are set.
7. Contact
Questions about this policy: privacy@goalhash.com