Privacy Policy
The app keeps your stuff on your phone — and, if you turn on iCloud sync, in your own private iCloud (which we can't read). There is no analytics SDK: we do not track what you do in the app. When the app crashes, it sends a crash report to Sentry so we can fix it — with your task titles, notes and tags stripped out before it leaves your phone. That's the whole story.
Short version
Goad stores your tasks, tags, streaks, and settings on your device — and, if you turn on iCloud sync, in your own private iCloud account (Apple-hosted, only you can read it). We don't run servers that hold your data, we don't have accounts, and we never see your tasks.
A few limited exceptions to "nothing leaves the device," each explicitly disclosed below:
- iCloud sync (optional, Goad Pro) — your tasks, tags, and settings sync through your own private iCloud account. Apple-hosted; only you and your devices can read it — we can't. Turn it off in Settings.
- Email feedback you choose to send via the Settings → Send feedback flow, which opens your Mail app with version + device info pre-filled.
- Crash reports — if the app crashes, a report goes to Sentry (our data processor) so we can fix the bug. It carries the crash itself: the stack trace, device model, OS version and app version. It does not carry your tasks. See “Crash reports” below for exactly what is stripped and how.
That's it. No cookies. No advertising. No third-party trackers. No remote storage of your tasks. No analytics on how you use the app.
What stays on your device
All of the following live exclusively in iOS's sandboxed storage for the app and never leave the device unless you explicitly choose to (export, share, backup):
- Tasks: title, notes, due times, priorities, tags, recurrence settings, notification ladders, completion history, snooze history.
- Tags: names + colours.
- Day plans: which tasks you committed to each day.
- Streak data: current streak, longest streak, grace days, past streaks.
- Achievements: which milestones you've unlocked.
- Pattern history: detected patterns + dismissal records (for the Patterns suggestions in the morning planner).
- Settings: appearance, notification preferences, quiet hours, timeline range, calendar overlay toggle, etc.
- Stoic quote rotation state: which quotes you've seen this cycle.
If you have iCloud Backup enabled, the on-device data above may be included in that backup — governed by Apple's privacy policy, not ours, and we never see it. Optional iCloud sync (Goad Pro) is described under "What we transmit" below; with sync on, this data also lives in your own private iCloud account.
What we transmit (and only if you let us)
1. Apple-side anonymized analytics
If you have "Share with App Developers" enabled in your iOS device's Settings → Privacy & Security → Analytics & Improvements, Apple shares anonymized crash and usage data with us through App Store Connect. Apple controls this and we receive only aggregated, anonymized data. To opt out, disable that toggle in iOS Settings. This is entirely Apple's channel — Goad itself sends us nothing.
2. Email feedback you send
When you tap Settings → Send feedback, the app opens your iOS Mail composer pre-filled with:
- The app version + build
- Your iOS version + device model
- A blank space for you to write
The email is sent through your Mail account to your support address. The contents of the email are governed by ordinary email-handling practices: we store incoming support emails for as long as needed to resolve the issue, then delete. The email address you write from is visible to us.
You're not required to use this feature; it's there if you want to reach us.
3. In-app purchases via Apple StoreKit
If you choose to upgrade to Goad Pro, the transaction is handled entirely by Apple's StoreKit. We receive only a receipt verification result (Pro or not). Apple controls the payment data and Apple Account information; we never see your name, billing address, or payment method.
4. iCloud sync (Goad Pro)
If you turn on iCloud sync, your tasks, tags, day plans, and settings are synced through Apple's CloudKit into the private database of your own iCloud account. This data is Apple-hosted and readable only by you and your own devices — we run no servers that store it and we cannot access it. Apple is the data processor; Apple's privacy policy governs the iCloud storage. Sync is optional and can be turned off in Settings at any time.
5. Crash reports (Sentry)
When Goad crashes, it sends a crash report to Sentry (Functional Software, Inc.), our data processor for diagnostics. This is how a bug that only happens on your device becomes something we can actually fix.
What the report contains: the stack trace of the crash, the device model, the iOS version, and the app version. No identifier we control is attached: the SDK’s install id is cleared from every report before it is sent, the app has no accounts, and session tracking — the one Sentry feature that would transmit a persistent per-install id on every launch — is switched off.
What it does not contain, and why you can hold us to it:
- No task titles, notes, tags, subtasks or day plans. Every piece of text in a report passes through an allowlist filter before it leaves the device: a word survives only if it is one of Goad's own vocabulary words (“task”, “ladder”, “failed”…), one of the words iOS uses to describe a crash (“fatal”, “range”…), or a short plain number such as a count or an error code. Everything else you typed is replaced with • — including phone numbers, dates, amounts and emoji. It is not matched against a blocklist of things we thought to exclude; it is removed unless we recognise it.
- No screenshots and no view hierarchy. Both are switched off explicitly.
- No breadcrumbs of what you tapped, and no network request bodies.
- No advertising identifier, no location, and no contact information.
Sentry processes this on our behalf under a data processing agreement and does not use it for its own purposes. Sentry deletes crash reports after the retention period that applies to our plan. Widgets and the Live Activity are not covered — the extension does not include the SDK at all.
What we do NOT do
- We do not embed Firebase, Google Analytics, Meta SDK, Mixpanel, Amplitude, PostHog, Adjust, AppsFlyer, or any other advertising or attribution SDK. The app embeds exactly one third-party SDK — Sentry, for crash reporting only. It is not an analytics SDK: it reports crashes, not what you do in the app.
- We do not use cookies. (This is an iOS app — cookies don't apply.)
- We do not show advertising and we do not embed advertising SDKs.
- We do not sell, lease, or otherwise transfer your data to any third party for marketing or any other purpose.
- We do not use AI / ML services that send your task content off-device.
- We do not collect location, contacts, photos, microphone audio, camera, or any other personal data category that requires iOS permission — except as noted below for the Calendar overlay (read-only, optional).
- We do not maintain user accounts or require sign-in.
Calendar permission (optional)
If you enable the calendar event overlay (Settings → Calendar → "Show calendar events on timeline"), the app requests calendar read permission so iOS lets us read your calendar events. We display them on the day timeline next to your tasks.
We never modify your calendar, never transmit calendar events anywhere, and never store them outside the in-memory view. Revoke access at any time in iOS Settings → Goad → Calendars.
Notification permission
The app requests notification permission so it can fire the escalating reminder ladder. Notifications are scheduled and delivered entirely by iOS; we don't have a server that sends pushes. Disable in iOS Settings → Goad → Notifications.
Your rights under GDPR (and similar laws)
You have the right to:
- Access the data we hold about you. (Answer: nothing on our servers — everything is on your device.)
- Rectify inaccurate data. (Edit anything in the app directly.)
- Erase ("right to be forgotten"). Delete the app and your data is gone.
- Restrict processing. There is nothing to restrict — we hold no data about you.
- Portability. Email us to request an export of your data.
- Object to processing. Same — there is no processing to object to.
- Lodge a complaint with your supervisory authority (e.g., ANSPDCP in Romania or your national equivalent).
To exercise these rights, email goadplan@xymex.app. We respond within 30 days as required by GDPR Article 12(3).
Data controllers + processors
For the purposes of the GDPR:
- Controller: Ioan-Cristian Vezure, Bucharest, Romania.
- Processor for purchases + iCloud sync: Apple Inc. — StoreKit for purchases, CloudKit for optional iCloud sync. Apple's privacy policy applies: https://apple.com/legal/privacy/
- Processor for crash reports: Sentry (Functional Software, Inc.), using its EU region: crash reports are ingested and stored in the European Union (
ingest.de.sentry.io), not transferred to the United States. Sentry is a US-incorporated company, so its DPA and the EU Standard Contractual Clauses still govern the relationship — but the crash data itself does not leave the EU. Sentry’s privacy policy applies: https://sentry.io/privacy/ - Email recipient: goadplan@xymex.app, handled via our email provider.
Children
Goad is rated 4+ on the App Store but contains no content directed at children under 13. We do not knowingly collect data from children, and there is no sign-up / account-creation flow that could collect data.
Changes to this policy
If we materially change the way data flows in or out of the app, we'll bump the "Last updated" date at the top and announce the change in the "What's new" notes of the next App Store release. For breaking changes (e.g., adding a new third-party processor), the in-app onboarding will prompt you to re-consent.
Back to home