Tämä asiakirja on saatavilla englanniksi.
Last updated: October 6, 2026
The short version
- We collect as little as we can while still making the app work.
- We do not sell your data, and we don't share it for advertising.
- What you write (goals, reflections, notes about people) stays out of analytics and is not used to train AI.
- We learn from how people use Goalito to improve it and to make useful suggestions; one switch in Settings turns that off.
- Health measurements you record are used only to run Goalito for you.
- Delete your account anytime. You have 30 days to change your mind, then we erase it. Copies in our encrypted backups are gone about 30 days after that.
The full policy follows. Jump to: what we collect · how we use it · data use and your opt-out · what we don't do · sharing and providers · cookies · retention · your rights · consumer health data · contact.
1. Introduction and scope
This policy applies to the applications and related services operated by Robertson Software LLC ("Robertson Software," "we," "us," "our"), including Goalito (web, iOS, and Android). Goalito helps you set goals, plan tasks, build habits, and reflect on your progress. Some of what you record is personal: health intentions, relationships, private reflections. We built our apps to collect as little as we can while still making them work.
Robertson Software operates one platform and one user identity across its apps, so your account may be usable across more than one of our apps over time; this policy governs all of them unless a specific app says otherwise. Robertson Software LLC is the controller (the "business" under California law).
Robertson Software Poster is an internal tool used only by Robertson Software staff to publish our own posts to our Facebook Page and Threads profile. No one else can sign in, and it collects no data about other people. To remove it, revoke it in your Facebook or Threads settings or email [email protected].
2. What data we collect and why
- Account data you give us: email, name or display name, timezone, language, country (asked at sign-up), and preferences. We use these to authenticate you, run the app correctly (your timezone drives "what day is it" for streaks and reflections), understand where our users are, communicate with you, and support you.
- Your content: goals, tasks, habits and streaks, reflections and journal entries, files and images you attach, and people you choose to track. It is yours. We store it to run the app for you, and use it beyond that only as section 4 describes, which leaves out your writing.
- First-party product analytics: lifecycle signals such as signed up, onboarded, activated, and feature usage. These events are deliberately minimal: account identifiers and event types from a fixed list we chose, not the titles or contents of your goals, tasks, habits, reflections, or people. If you arrive through one of our marketing links and sign up during that same visit, we also record the campaign parameters carried by that link (utm_source, utm_medium, utm_campaign) and which client platform your signup came from (web, iOS, or Android; a fixed three-value label, nothing more) so we know which of our marketing channels work. These are normalized short channel tokens we chose, not free text you typed, and are collected first-party only. We do not use third-party ad trackers or cross-site identifiers. Before you sign in, we also count aggregate, non-identifying visits to our public login and signup pages: no account, no cookies, and no identifier that we link to you if you later create an account. When a visit arrives through one of our marketing links, that count also records the link's channel and either the date of the post it came from or which of our own profiles the link was on, as a daily total only and never on the record of the visit itself. We also count, as a daily total, when a checkout is opened on our pricing page and for which plan (and, when you arrived from one of our emails, which email): no account, no cookies, and no identifier. If your browser sends Global Privacy Control or Do Not Track, we do not count it at all. When you open Goalito from a link in one of our emails, we record which email it was. If you install our mobile app from one of our links or ads, we record which link or campaign led to the install: on Android through Google Play's install referrer, and on iOS through Apple's ad attribution service: our server sends Apple the one-time token your iPhone creates and keeps only the Apple Ads campaign Apple returns. That campaign is stored on your account, is not shared with anyone else, and is not used to track you across other apps.
- Purchase records: what you bought, when, on which channel (our website, the App Store or Google Play), the price, currency and country, and whether it renews, was cancelled or was refunded. We get these from Paddle, Apple or Google. We use them to unlock your plan on every device, answer billing questions, keep tax records, and count revenue.
- Technical data needed to deliver and secure the service: IP address, device and app version, timestamps in server and security logs, and, if you turn notifications on, a device push token (see section 6). If you subscribe to your calendar feed, anyone holding that feed's web address can read the tasks and habits in it, so keep it private; you can replace it with a new address in Settings.
3. How we use your data
To provide and operate our apps; authenticate and secure your account; provide support; send service and account messages (and, only if you opt in or where permitted, occasional product updates); understand and improve the product via first-party analytics, including learning in aggregate which approaches and features actually help users reach their goals; and comply with law and protect rights and safety. We do not use your private content for advertising profiles or to train AI models.
4. Using data to improve Goalito and make suggestions
We do not sell your data. Nobody buys access to what you record, and we don't share it for advertising.
We want Goalito to get better at helping people reach their goals, and to give you useful suggestions. Three things happen, and one switch controls the last two.
From your own records. Goalito looks at your data to nudge you, for example when a habit has gone quiet. This is part of the app you asked for, and it runs only for you.
Learning from everyone. We study which features people use, the categories and schedules they pick, which optional fields they fill in (not what is in them), streaks, and whether tasks and habits get done, to learn what helps. We leave out what you write, notes about people, the numbers you record, and anything in health goals and habits. Before analysis we replace your name and email with a random code, and we report only on groups of at least five people.
Suggestions learned from others. To suggest an approach that worked for people who use Goalito the way you do, we match your own usage against those results. This part is linked to your account.
Your choice. One switch in Settings turns off the learning and the suggestions learned from others, straight away, with no reason needed. The app works the same. Afterwards we keep only an anonymous daily count of active users and request logs without your account attached. We rely on our legitimate interest in improving Goalito; the switch is how you object under the GDPR.
No decisions about you. Suggestions do not change your price, your access, or anything about your account, and no decision with legal or similarly significant effects is made by automated means.
AI. We do not use your data to train AI. If we add a feature that sends your content to an AI provider, we will tell you first, name the provider here, require that it does not train on your data and deletes it promptly, and you will turn the feature on yourself.
5. What we do not do
We do not sell your data, and we do not use the free text you write (goal names and descriptions, reflections, notes about people) to train AI or ML models of any kind; the learning described in section 4 uses usage patterns, not your writing. We do not run third-party ad networks, behavioral trackers, or analytics SDKs that profile you, and we do not use Apple ATT cross-app tracking. California law also asks whether we "share" personal information for cross-context behavioral advertising: we do not.
6. Sharing and providers
We do not sell your data.
These companies process data for us, under contracts that let them use it only on our instructions: DigitalOcean (our servers and database, New York, United States); Cloudflare (our domain names, delivery of our website and app updates, cookie-free counts of visits to our website, and storage of our nightly backups, which are encrypted before they leave our server); Postmark (our emails, including password resets, account notices, trial reminders and the optional weekly summary, which contains your own task and habit names); and Google Firebase Cloud Messaging and the Apple Push Notification service (push notifications, if you turn them on; they receive your device's push token and the text of each notification, which can include a habit or task name), or, in a web browser, your browser maker's push service.
These companies receive data as independent businesses under their own privacy policies. Paddle, Apple and Google take your payment when you subscribe: Paddle on our website as our merchant of record, Apple in the App Store and Google in Google Play. Each collects your payment details, which we do not see, and sends us the purchase record we need to unlock your plan. Paddle's payment script also runs on our pricing page, where it receives your IP address and browser type to show prices in your currency. Apple and Google also distribute our mobile apps. ProfitWell, part of Paddle: Paddle Retain's payment-recovery script. Paddle's payment script loads it on our pricing page, and on our home page only when you open the card-update link in a failed-payment email. It receives what any web request carries (your IP address and browser type) and uses it only to show a form to update your card if a subscription payment fails.
We update this list when a provider changes. We also disclose data when the law requires it, to enforce our Terms, or to protect someone's safety. If our business is sold or merged, your data moves with it and this policy keeps protecting it.
7. Cookies and local storage
We use no advertising or tracking cookies. To keep you signed in and remember your preferences, we store a sign-in token and your settings on your device (browser storage on the web; the secure Keychain or Keystore in the mobile apps). Everything the app stores on your device is strictly necessary to run the app; we store nothing on your device for analytics or marketing. That is why there is no cookie banner to click through. Our public web pages set no cookies of their own. On our pricing page, and on the card-update page a failed-payment email links to, Paddle's payment script receives a short-lived security cookie named __cf_bm (Cloudflare bot protection) on Paddle's own domain; it identifies no one and expires within 30 minutes. The card-update form also keeps its own settings in your browser's storage on Paddle's domain.
8. Staff access
A small number of authorized Robertson Software staff can access account data when that is needed to run, support or secure the service. Our support team can see your content in our support console only while you have support access turned on in Settings; it switches off after 3 days. Staff who operate the service can see account data without that switch when fixing a problem or restoring service, and our engineers can also reach the database directly for the same reasons; that access is limited to what the task requires. Every view of your content in our support console, by support or operations staff, is logged with who looked and when. Screenshots and files you attach to a support request are visible to our support team, and each view of them is logged too. Staff do not use your content for anything beyond operating and supporting the service.
9. International transfers
We are based in the United States and Goalito runs there; using Goalito from elsewhere sends your data to us there. For providers handling data from the EEA, UK or Switzerland, we rely on the EU-US Data Privacy Framework and its UK and Swiss extensions where the provider is certified, and on standard contractual clauses otherwise. Email us for a copy.
10. Data retention
Your content stays while your account is open. When you delete an item, it goes to the Recycle Bin, where you can restore it for 30 days; then we erase it. When you delete your account, you are signed out at once and nobody can use the account. For 30 days you can sign in again and restore it. After that we erase it permanently. Our account deletion page lists exactly what is erased and what is kept. Erased data can stay in our encrypted backups and our internal change history for about 30 more days until those copies age out, so the longest anything you delete can survive is about 60 days. If we ever restore a backup, deletions are applied again automatically, so deleted data does not come back. Analytics events lose their link to your account when it is erased and are kept only as counts. Purchase records keep the payment provider's transaction number, because they are part of our financial records, and we keep them as long as tax and accounting law requires. A record of which billing reminders we sent (the kind, the date, and the purchase reference, never your email address) is also kept, because the law requires those reminders and we may need to show they were sent. Our API and in-app activity logs are deleted after 30 days.
11. Your rights
We honor these globally as a baseline. GDPR (EEA and UK): access; data portability (export your content in a portable format from account settings, or email us); correction; deletion (available in-app); objection and restriction (including the analytics opt-out); withdrawal of consent; and the right to lodge a complaint with your data protection authority (in the UK, the ICO). Our legal bases are:
| What we do | Legal basis |
|---|---|
| Run the app, including nudges from your own records | Contract |
| Keep the service secure | Legitimate interest |
| Learning from everyone, and suggestions learned from others | Legitimate interest; the Settings switch is how you object |
| Purchases and tax records | Contract and legal obligation |
| Optional emails | Consent |
How we use what you record. We use your goals, tasks, habits, readings, reflections and notes to run Goalito for you: to show them back to you, work out streaks and reviews, and send the reminders, nudges and summaries you turn on. Some of that leaves our servers on its way to you: reminder text, such as a habit name, passes through Apple or Google to reach your device, and the weekly summary email, if you turn it on, contains your own task and habit names. We do not read your writing to learn about you. We do not use what you write, notes about people, the numbers you record (such as sleep hours or weight), or anything in health goals and habits for analytics, advertising or AI training, and we do not sell or share any of it. You can edit or delete any of it whenever you like, and you can export or delete your whole account from account settings.
California (CCPA/CPRA): know and access, delete, and correct; opt out of sale or sharing; limit use of sensitive personal information, which for us means health measurements you record and anything sensitive you write. We already use it only to provide Goalito to you; and non-discrimination. We do not sell or share personal information, so there is no sale or sharing to opt out of; browsers that send a Global Privacy Control signal get the same treatment as everyone else. The analytics opt-out in account settings is available to everyone.
Other regions: laws such as PIPEDA (Canada), the LGPD (Brazil), the Privacy Act (Australia), the APPI (Japan), and the privacy laws of other US states (for example Virginia, Colorado, Connecticut, and Texas) grant similar rights, and we extend the same baseline - access, correction, deletion, portability, and the analytics opt-out - to everyone, wherever you live.
Exercise these via in-app controls (account settings, account deletion) or by emailing [email protected]. We verify and respond within legally required timeframes; authorized agents are allowed where law permits.
12. Security
We encrypt data in transit and encrypt our offsite backups. Passwords are stored only as bcrypt hashes, so we cannot read yours. Access is limited and admin actions are logged. No system is perfectly secure. If a breach puts your data at risk, we tell you without undue delay and notify regulators as the law requires (within 72 hours under the GDPR).
13. A note on data about other people
Goalito lets you keep notes about the people in your life, so you can be a better friend, partner, parent, or colleague. Notes like these are personal data about people who are not users. You decide what's recorded; we store it only on your behalf; nothing you record about another person is ever shown to any other user; and deleting it removes it as described in section 10. Please be thoughtful: we ask you not to record other people's health or medical information, religious or political beliefs, or sexuality. These are "special category" data under privacy law and carry real risk for the people they describe.
14. Consumer health data
Some things you can record, such as sleep, weight, exercise or resting heart rate, count as consumer health data under laws like Washington's My Health My Data Act. We collect it only when you enter it and use it only to provide Goalito to you. We do not use it for analytics, advertising or AI training, and we do not sell it. Only the providers in section 6 handle it, to host, back up or deliver it for us. You can export or delete it anytime, and deleting your account erases it, including from backups, within about 60 days. To use these rights, or to ask which providers received it, email us; if we refuse, you can appeal by replying to our answer.
15. Children
Goalito is for people 13 and older. If the law where you live sets a higher age for using services like ours without a parent's permission (for example 14 in South Korea and Quebec, or 16 in some EU countries), you need a parent's or guardian's permission until then. If you think a child under 13 has an account, tell us and we will delete it.
16. Data category summary
| Category | Includes | Why | Retention |
|---|---|---|---|
| Account data | Email, name, timezone, language, country, preferences | Run and authenticate your account, support, understand where our users are | While active; deleted or anonymized after, except as legally required |
| Your content | Goals, tasks, habits, reflections, attached files, people | Provide the app to you; usage patterns (not your writing) feed the section 4 learning | While active; deleted on account deletion |
| Product analytics | Lifecycle and usage events (ids and enumerated types; no content or titles), signup campaign parameters (including install attribution from Google Play or Apple Ads), signup client platform, aggregate pre-signin page-view counts, checkout-opened counts | Understand and improve the product; measure our marketing channels | Anonymized on account deletion |
| Payment and billing | Purchase and subscription records from Paddle, Apple or Google (no card data) | Unlock your plan, billing support, tax and finance law | As legally required |
| Technical and security logs | IP, device and app version, timestamps, push tokens, admin audit logs | Security, debugging, abuse prevention, notification delivery | API and activity logs: 30 days. Admin audit logs: kept for security, unlinked from you when your account is erased. |
17. Changes
When a change matters, such as a new use of your data or a new company receiving it, we tell you in the app or by email before it takes effect and update the date above. If a change needs your consent, we will ask for it.
18. Contact
Robertson Software LLC, 13378 Sunshine Path, San Diego, CA 92129-4703, USA. Email [email protected]. Our privacy contact is Dave Robertson, Owner, who is also our data protection contact for Brazil and the person in charge of personal information under Quebec law.