App privacy
About this page
This page documents the data flows specific to the companion app at /lifegoalsapp/. It sits alongside the main goalsandprogress.com Privacy Statement, which is the canonical document for the controller identity, your data subject rights, retention periods, international transfers, security measures, and complaint authorities. Where this page is silent, the main Privacy Statement applies.
1. What stays only on your device
Everything you type into the App (values, life-area scores, vision text, goals, milestones, KPI targets, journal entries, habit logs, reflections) is stored in your browser's localStorage. It is not transmitted to any server the Operator controls. The Operator has no technical means to read it.
2. Downloading a save file
If you click Save in the App, a .save JSON file downloads to your computer. You keep it. The Operator never sees it. The file is plain JSON; you can open it in any text editor.
3. The licence check (Gumroad)
The App is unlocked with a licence code from your purchase receipt. When you enter the code, the App sends three values to https://api.gumroad.com/v2/licenses/verify. They are the product id of the Life Goals App, the code you entered, and whether this browser counts as a new one. It sends them again when the App starts and the last answer from Gumroad is 7 days old or older. Until an answer comes, and while the App is in the view-only state, it sends them at every start. Nothing else is sent. Your plan never goes with it.
Gumroad answers with the purchase record for that code, which includes the buyer email address. The answer is read in your browser and is not forwarded anywhere. The App stores four things from it in your browser's localStorage: the code, the sale id, the date of the check, and the result. The email address is never stored.
Gumroad is Gumroad, Inc. (San Francisco, United States), the company you bought from, so it already holds the purchase. The request also gives Gumroad your IP address and basic browser information, as any request does.
If a check cannot reach Gumroad, the App keeps working for 14 days from the first check that failed, and then opens in a view-only state until a check succeeds. A code that could not be checked when it was first entered works for three opens, and then the App opens in that view-only state until a check succeeds. A refunded code entered in the code box opens the App in the view-only state at once. If the weekly check finds a refund, the App opens in that view-only state 14 days after the refund is found. After a chargeback, or when the code is disabled or used on too many browsers, the App opens in the view-only state at once. After 5 November 2026, a browser that was opened with the old beta password opens in the view-only state until a licence code is entered. Your plan is never deleted in any of these cases: it stays in your browser, and the download button keeps working.
4. Optional Dropbox sync
If you click Settings → Connect Dropbox, the App stores an OAuth access token and a refresh token in your browser's localStorage and uses them to sync your plan as a JSON file into a private Apps/Goals & Progress Life Goals App/ folder in your personal Dropbox. Before the App replaces the plan there, it keeps the earlier plan in the same folder as a dated copy, and Settings lists these copies. The token grants the App access only to its own app folder, never to the rest of your Dropbox. Dropbox sees the file content (it has to, in order to store it). The Operator does not.
You can revoke the connection at any time from Dropbox's account settings (Connected apps) or by clicking Disconnect Dropbox inside the App. Disconnect Dropbox also tells Dropbox to drop both tokens, so the App leaves your connected apps list.
Both tokens sit in the browser storage of this app, so any script running on the page could read them. The App has no server, so there is nowhere safer to keep them. The app folder limits what a stolen token can reach to that one folder, and to nothing else in your Dropbox.
The App also asks Dropbox which account is connected, so the Settings card can name it. That email address is shown on your screen and is never stored or sent anywhere.
5. Cookieless analytics (Plausible)
Anonymous traffic data is collected by Plausible Insights OÜ (Tallinn, Estonia, in the EU). Per page-view, Plausible sees the IP address (truncated before storage so no individual record exists), the user-agent class, the URL, the referrer, and any UTM parameters. No cookies are set. No persistent identifier is created. The data is aggregated only.
Custom events. The App also fires anonymous custom events to Plausible when you interact with specific surfaces (e.g. when the app finishes its first paint, when you open the demo, complete a cascade step, change the colour palette, export a save file, connect Dropbox, open feedback, or click out to one of the doc pages). The event sends only the event name plus a small, fixed set of structural props — for example { step: "T1A" } for a step-completion, { palette: "neon-meadow", theme: "dark" } for a theme change, or { ms: 1234 } for first-paint latency. No goal content, value rankings, vision text, or any other planning data ever leaves your browser via these events. The full event list is published at the Plausible Goals dashboard for this domain.
6. Feedback widget (Senja)
The Send feedback button in the topbar and the More menu opens a form hosted by Senja Pty Ltd (Australia). The form is only loaded when you click the button. When you submit, Senja sees your IP, the user-agent, and any content you wrote (rating, written feedback, video if you recorded one, name and email if you chose to provide them, consent to publish if you ticked the box). Senja forwards the submission to the Operator. You keep ownership of the underlying ideas. Testimonials are published only if you explicitly consent on the Senja form itself.
7. Third-party fonts, icons, and CDNs
To keep the App fast, a few resources load from public CDNs the first time you visit. Each request gives the CDN your IP address and basic browser info. None of them see your goal-planning data.
- Google Fonts (
fonts.googleapis.com,fonts.gstatic.com): the DM Sans typeface. Google may log the IP for traffic analysis. No cookies. Google's privacy notice. - Adobe Fonts / Typekit (
use.typekit.net,p.typekit.net): the Loretta italic accents. Adobe may log the IP and set a font-serving cookie on its own domain. Adobe's privacy notice. - Cloudflare CDN (
unpkg.com,cdnjs.cloudflare.com): Phosphor icons (every page load) plus on-demand screenshot helpers (only if you click "Save as image"). Cloudflare may log the IP. No cookies. Cloudflare's privacy policy.
If you want to load the App with fewer external CDN calls, install it as a PWA (Add to Home Screen). After the first visit, the Service Worker caches the App shell on your device and most repeat traffic stays local.
8. Cookies set by the App itself
None. The App sets zero first-party cookies. Plausible is cookieless. Senja, Adobe Typekit, Gumroad, and Dropbox may set cookies on their own domains when their scripts or fonts load, as described above.
9. Your rights
For data subject rights under Swiss FADP and EU GDPR (access, rectification, deletion, restriction, portability, objection, withdrawal of consent), see Section 6 of the main goalsandprogress.com Privacy Statement. For App planning data, you exercise these rights directly: edit the data in the App, or clear your browser's localStorage for goalsandprogress.com. The Operator does not hold a copy.
For data held by third parties (Plausible aggregates, Senja submissions, Gumroad purchases, Dropbox sync), email support@goalsandprogress.com and the Operator will respond within one month.
10. Children
The App is not designed for users under 16 in the EU, EEA, Switzerland, or the United Kingdom, or under 13 in the United States.
11. Changes
The Operator updates this page when anything changes about what the App sends or stores. The "Last updated" date at the top reflects the latest version. Material changes are surfaced inside the App.