Skip to content

Privacy

How Goalward handles account and planning data

A plain-language description of the data the current Goalward MVP uses, why it is needed, and which controls are available today.

Last updated July 30, 2026

Launch status: this notice describes the current product accurately, but the legal entity details, privacy contact, and jurisdiction-specific rights process are still to be confirmed. It is not a substitute for legal review.

Data Goalward handles

When you create an account, Supabase Auth processes your email address and password credentials. Goalward does not receive or store your plaintext password.

When you use the planning flow, Goalward stores the information you enter, including planning context, goals, product inputs, themes, priority assessments, roadmap assignments, and the saved roadmap summary. Under the current product model, this information belongs to your account and is not published through a public roadmap link.

Goalward also records limited technical and product-usage data so the service can operate and the team can understand whether the workflow is useful. First-party product events can include an account identifier, a planning-session identifier, an event name, and a small set of non-content metadata.

Why the data is used

Account and planning data is used to authenticate you, keep your work available across navigation and refresh, produce your roadmap, and let you reopen or delete planning sessions.

Technical and usage data is used to maintain reliability, investigate failures, protect the service, and evaluate aggregate product behavior. Goalward does not need the text of your goals, inputs, themes, or roadmap to measure a workflow event.

Service providers and analytics

Goalward currently uses Supabase for authentication and database storage, and Vercel for application hosting and web analytics. Those providers process data as needed to deliver their services under their own terms and privacy practices.

Google Analytics is optional and is loaded only after you grant analytics consent in Goalward. The current Google Analytics events use declared product-event names and limited parameters; they are not intended to include your email address or roadmap content. You can reopen analytics preferences from the site footer.

Before Vercel Web Analytics events are sent, Goalward redacts planning-session identifiers from planning URLs and removes known sensitive authentication query values.

Disclosure and product sharing

Goalward does not currently sell account or roadmap data. Data is disclosed to the service providers described above only as needed to operate the product, or when disclosure is required to comply with applicable law.

The current Share step copies a roadmap brief to your clipboard or downloads a file. Goalward does not currently create a public collaboration workspace or public sharing link. After you copy or download content, you control where it is sent.

Retention and your controls

Planning sessions remain in the account until they are deleted or the service changes its retention approach. You can delete a planning session from the dashboard. Goalward does not yet offer self-service account deletion or a formal data-export request workflow.

Provider logs, backups, and security records may follow the retention settings of Supabase and Vercel. A specific support and privacy request address still needs to be confirmed before broader public launch.

  • Delete individual planning sessions from the dashboard.
  • Decline or change optional Google Analytics consent from the footer.
  • Avoid entering secrets, regulated data, or information you do not have permission to use.

Security and changes to this notice

Goalward uses authenticated sessions and database row-level access policies to separate account data. No internet service can promise absolute security, and this notice is not a certification.

This notice will be updated when the product, providers, data practices, or user controls materially change. The legal entity name, mailing address, jurisdiction-specific rights process, and privacy contact are launch placeholders that must be completed before a broader commercial release.