Robertson Software LLC

מדיניות הפרטיות

Last updated: July 29, 2026

The short version

  • We collect as little as we can while still making the app work.
  • We do not sell your data, and we don't share it for advertising.
  • What you write (goals, reflections, notes about people) stays out of analytics and is not used to train AI.
  • We improve the product using aggregate, de-identified usage patterns; one switch in account settings opts you out.
  • Delete your account anytime and your data goes with it; backup copies age out within about 30 days.

The full policy follows. Jump to: what we collect · how we use it · analytics and your opt-out · what we don't do · sharing and sub-processors · cookies · retention · your rights · contact.

1. Introduction and scope

This policy applies to the applications and related services operated by Robertson Software LLC ("Robertson Software," "we," "us," "our"), including Goalito (web, iOS, and Android). Goalito helps you set goals, plan tasks, build habits, and reflect on your progress. Some of what you record is personal: health intentions, relationships, private reflections. We built our apps to collect as little as we can while still making them work.

Robertson Software operates one platform and one user identity across its apps, so your account may be usable across more than one of our apps over time; this policy governs all of them unless a specific app says otherwise. Robertson Software LLC is the controller (the "business" under California law).

2. What data we collect and why

  • Account data you give us: email, name or display name, timezone, language, country (asked at sign-up), and preferences. We use these to authenticate you, run the app correctly (your timezone drives "what day is it" for streaks and reflections), understand where our users are, communicate with you, and support you.
  • Your content: goals, tasks, habits and streaks, reflections and journal entries, files and images you attach, and people you choose to track. It is yours. We store it to run the app for you, and use it beyond that only as section 4 describes: de-identified, and not your writing.
  • First-party product analytics: lifecycle signals such as signed up, onboarded, activated, and feature usage. These events are deliberately minimal: account identifiers and event types from a fixed list we chose, not the titles or contents of your goals, tasks, habits, reflections, or people. If you arrive through one of our marketing links, we also record the campaign parameters carried by that link (utm_source, utm_medium, utm_campaign) and which client platform your signup came from (web, iOS, or Android; a fixed three-value label, nothing more) so we know which of our marketing channels work. These are normalized short channel tokens we chose, not free text you typed, and are collected first-party only. We do not use third-party ad trackers or cross-site identifiers. Before you sign in, we also count aggregate, non-identifying visits to our public login and signup pages: no account, no cookies, and no identifier that we link to you if you later create an account.
  • Technical data needed to deliver and secure the service: IP address, device and app version, timestamps in server and security logs, and, if you turn notifications on, a device push token (see section 6).

3. How we use your data

To provide and operate our apps; authenticate and secure your account; provide support; send service and account messages (and, only if you opt in or where permitted, occasional product updates); understand and improve the product via first-party analytics, including learning in aggregate which approaches and features actually help users reach their goals; and comply with law and protect rights and safety. We do not use your private content for advertising profiles or to train AI models.

4. Analytics, product improvement, and your opt-out

We do not sell your data. Nobody buys access to what you record, and we don't share it for advertising.

We do study how people use the product, in aggregate and with identities removed, to make it better: for example, learning which approaches help people actually reach their goals. That analysis does not include anything you write. No goal names, no reflections, no notes about people. It looks at structure and patterns, not words, and it is not linked back to you.

You can opt out in account settings. The app works exactly the same if you do.

The details, for those who want them:

  • Our product-analytics events (section 2) are first-party and minimal: account identifiers and event types from a fixed list we chose, not your content.
  • Product improvement can include fitting statistical models (for example regressions or cohort groupings) on de-identified signals about how you use and structure the product: goal categories, target cadences, whether you lean on habits or on tasks, which optional fields you use, streaks, completion patterns, and, if you provided it, your country. Whether an optional field is filled in can be one of those signals; the text inside it is not.
  • We may use what we learn to tailor in-app suggestions to you (for example, suggesting an approach that has worked well for users whose usage looks like yours). Suggestions are only suggestions: you can ignore them, and they have no legal or similarly significant effects.
  • A small-group rule applies: when analysis groups users by an attribute such as country, any group of fewer than five users is suppressed - we neither report on it nor base suggestions on it - so no pattern can point back to an individual.
  • One opt-out in your account settings covers all of the above, including personalized suggestions, and using it does not reduce any core functionality. Where law requires consent rather than legitimate interest, we ask for consent and honor your choice.

5. What we do not do

We do not sell your data, and we do not use the free text you write - goal names and descriptions, reflections, notes about people - to train AI or ML models of any kind; the statistical models described in section 4 learn only from de-identified structural and usage signals, not from your writing. We do not run third-party ad networks, behavioral trackers, or analytics SDKs that profile you, and we do not use Apple ATT cross-app tracking. California law also asks whether we "share" personal information for cross-context behavioral advertising: we do not.

6. Sharing and sub-processors

We don't sell your data. We share it only with service providers under contracts requiring them to protect it and use it only for us. Today those are: Hetzner (cloud hosting and database, United States); Cloudflare (DNS and website delivery); Paddle (merchant of record and payments for web purchases; billing and transaction data - Paddle handles card data and we receive no raw card numbers); the Apple App Store and Google Play (merchant of record and payments for purchases made through them); Apple and Google also deliver push notifications if you turn them on (your device's push token is shared with them for that purpose); and Postmark (account and support email). We update this list here when providers change. We may also disclose data to comply with law, enforce our Terms, protect rights or safety, or in a business transfer (with notice; this policy continues to protect your data).

7. Cookies and local storage

We use no advertising or third-party cookies. To keep you signed in and remember your preferences, we store a sign-in token and your settings on your device (browser storage on the web; the secure Keychain or Keystore in the mobile apps). These are strictly necessary to run the app, so there is no cookie banner to click through. Our public web pages set no cookies at all.

8. Staff access

Authorized Robertson Software staff can access account data to operate the service, provide support, debug, and keep it secure. Access through our internal admin console is restricted, logged, and audited. As a small company, our engineers can also access the underlying database directly when troubleshooting or restoring service; that access is limited to authorized staff and to what the task requires. Staff do not use your personal content beyond operating and supporting the service. We do not claim "no one can ever see your data"; we claim access is limited, controlled, and accountable.

9. International transfers

We serve users worldwide, including in the EU, UK, and California. Data is processed and stored in the United States. For transfers from the EEA and UK we rely on appropriate safeguards, including standard contractual clauses where applicable. You can request details via the contact below.

10. Data retention

Your content is retained while your account is active and deleted when you delete your account. Deletion is immediate in the app; for safety we keep database backups and an internal change history, and deleted data remains in those copies until they age out on a roughly 30-day cycle. Items you delete within the app first go to a recoverable recycle area and are permanently removed after a 30-day recycle window; copies may remain in our secure backups for up to 30 days after that permanent deletion. Analytics events are anonymized on account deletion (the link to you is severed; only aggregate, non-identifying signals are kept). Account data is retained while active, then deleted or anonymized, except records we must keep by law. Financial and tax records are retained as long as legally required, then deleted. Operational and security logs are retained for a limited window, then deleted.

11. Your rights

We honor these globally as a baseline. GDPR (EEA and UK): access; data portability (export your content in a portable format from account settings, or email us); correction; deletion (available in-app); objection and restriction (including the analytics opt-out); withdrawal of consent; and the right to lodge a complaint with your data protection authority (in the UK, the ICO). Our legal bases are contract (to provide the app), legitimate interest (first-party analytics, security, improvement), consent (where required), and legal obligation (financial records).

California (CCPA/CPRA): know and access, delete, and correct; opt out of sale or sharing; limit use of sensitive personal information (already limited); and non-discrimination. We do not sell or share personal information, so there is no sale or sharing to opt out of; browsers that send a Global Privacy Control signal get the same treatment as everyone else. The analytics opt-out in account settings is available to everyone.

Other regions: laws such as PIPEDA (Canada), the LGPD (Brazil), the Privacy Act (Australia), the APPI (Japan), and the privacy laws of other US states (for example Virginia, Colorado, Connecticut, and Texas) grant similar rights, and we extend the same baseline - access, correction, deletion, portability, and the analytics opt-out - to everyone, wherever you live. We are not required to appoint a Data Protection Officer and have not; the contact below reaches the people responsible for privacy.

Exercise these via in-app controls (account settings, account deletion) or by emailing [email protected]. We verify and respond within legally required timeframes; authorized agents are allowed where law permits.

12. Security

Encryption in transit (TLS); hashed passwords (we store no plaintext passwords and cannot read yours); access controls and least privilege; and audit logging of administrative actions taken through our admin tools. No system is perfectly secure; we notify affected users and regulators of a qualifying breach as required, including the GDPR 72-hour authority-notification timeline where applicable.

13. A note on data about other people

Goalito lets you keep notes about the people in your life, so you can be a better friend, partner, parent, or colleague. Notes like these are personal data about people who are not users. You decide what's recorded; we store it only on your behalf; nothing you record about another person is ever shown to any other user; and deleting it removes it as described in section 10. Please be thoughtful: we ask you not to record other people's health or medical information, religious or political beliefs, or sexuality. These are "special category" data under privacy law and carry real risk for the people they describe.

14. Children

Our apps are intended for users 13 and older (or a higher local minimum). They are not directed to children under 13 and we do not knowingly collect their data. Contact us to report an underage account and we will delete it.

15. Data category summary

CategoryIncludesWhyRetention
Account data Email, name, timezone, language, country, preferences Run and authenticate your account, support, understand where our users are While active; deleted or anonymized after, except as legally required
Your content Goals, tasks, habits, reflections, attached files, people Provide the app to you; de-identified structural signals (not your writing) feed the section 4 models While active; deleted on account deletion
Product analytics Lifecycle and usage events (ids and enumerated types; no content or titles), signup campaign parameters, signup client platform, aggregate pre-signin page-view counts Understand and improve the product; measure our marketing channels Anonymized on account deletion
Payment and billing Transaction and subscription records (no raw card data) Process purchases; tax and finance law As legally required
Technical and security logs IP, device and app version, timestamps, push tokens, admin audit logs Security, debugging, abuse prevention, notification delivery Limited window, then deleted

16. Changes

We may update this policy. For material changes we notify you (in-app and/or by email) and update the "Last updated" date. Continued use after changes take effect means acceptance.

17. Contact

Robertson Software LLC · [email protected]