Privacy Policy
What stays on your device, what touches our servers for billing or optional analytics, and how you control it.
Local-first by design. Most of your data never leaves your device. You can use GoodShape without creating an account, keeping personal data collection limited by default.
Data Stored Locally
Task lists, appliance profiles, maintenance cost entries, photos, and documents are stored in your browser's local storage and IndexedDB. This data remains on your device unless you export it. If you clear browser storage, this local data will be removed.
AI-Powered Features
GoodShape offers optional AI-powered photo recognition and text extraction (OCR) for Premium users. When you use these features, your photo is sent to Google Cloud Vision API for processing. Google may process the image on its servers to return labels, detected text, and product identifiers.
Photos are sent only when you explicitly tap the scan button, never automatically. Google's use of this data is governed by the Google Cloud Privacy Notice. GoodShape does not store your photos on any server; results are returned to your browser and stored locally.
GoodShape also offers optional AI-powered document extraction and a home maintenance copilot for Premium users, both powered by Anthropic (Claude). When you use these features, uploaded photos, document text, and the messages you send to the copilot are sent to Anthropic for processing. This data is not retained by GoodShape, and per Anthropic's policy is not used to train their models. See Anthropic's entry in the Third-Party Services section below for details.
Payments and Billing
Premium checkout is handled by Stripe. GoodShape does not collect or store full payment card numbers. Stripe may share limited order metadata (such as customer email) needed to confirm a successful Premium purchase.
To support Premium restoration across devices, we store a minimal purchase indicator keyed to a hash of your checkout email. The original email address is not stored.
Analytics and Tracking
GoodShape uses optional analytics on your device to understand how the product is used. These scripts only load in the browser after you accept (cookie banner or in-app controls). We do not send analytics events from our servers tied to your email when you use optional email reminders. That flow does not use product analytics. When you enable email or calendar-feed reminders, GoodShape may store a minimal schedule digest (email or private feed token, timezone, task titles and due dates) in Redis so a daily job can notify you while the app is closed. Digests expire after about 30 days unless refreshed when you reopen the app, and are removed if you delete your account data or turn reminders off.
- Vercel Analytics - Page views and performance metrics
- Vercel Speed Insights - Core Web Vitals monitoring
- PostHog (if enabled) - Product analytics for feature usage
You can decline analytics and still use all product features. You can change your choice anytime in the app (dashboard) or using the controls below.
Your analytics preference
The same preference applies on the marketing site and in the app (stored in your browser).
Analytics
Optional product analytics (Vercel Analytics, Speed Insights, PostHog) help us improve GoodShape. Your maintenance data stays on your device. You can change this anytime.
Status: Not set (see cookie banner on the marketing site)
Cookies and similar storage
GoodShape does not require login cookies to use the product. Your analytics choice is stored in browser local storage (key: analytics consent). When you accept analytics, third-party tools may set their own cookies or use local storage per their policies.
Typical technologies after consent (exact names may vary by vendor release):
- PostHog - session/feature analytics (see PostHog privacy policy for duration)
- Vercel - web analytics / vitals (see Vercel privacy policy)
- Stripe - during checkout only; fraud/prevention cookies as described by Stripe
Third-Party Services
Data Retention
- Local data - Retained until you clear browser storage or delete items
- Premium status hash - Retained indefinitely to support device restoration
- Analytics data- Per each service's policy (typically 12-24 months)
- Error logs - 90 days in Sentry
- Rate limit records - Automatically expire after 1 hour
Your Rights
Under GDPR, CCPA, and similar privacy laws:
Account Deletion
To delete your data:
- Clear your browser's local storage and IndexedDB for this site (removes tasks, photos, documents)
- Use the account deletion API or contact support@goodshape.app to remove your premium status indicator from our servers (Redis). This does not delete your payment history inside Stripe; Stripe retains records per its policies and legal requirements. You may also request erasure through Stripe or your card issuer as applicable.
Server-side backups may retain deleted data for a short period until rotated; we do not use deleted premium flags for new processing after erasure is confirmed.
We process deletion requests within 30 days and confirm completion via email if you provide one.
California Residents
Under the California Consumer Privacy Act (CCPA):
- Right to Know - Request what personal information we collect
- Right to Delete - Request deletion of your personal information
- Right to Opt-Out - We do not sell personal information
- Right to Non-Discrimination - We will not discriminate against you for exercising your rights
Data Security
We protect your data through HTTPS encryption in transit, secure API endpoints with rate limiting and origin validation, hashed storage of email identifiers, and restrictive Content Security Policy headers. Sentry receives error reports and performance metadata in production; we do notuse Sentry Session Replay (no session video/behavioral replay). Provider infrastructure (e.g. Upstash Redis) is encrypted in transit; at-rest encryption depends on the provider's architecture.
In the unlikely event of a data breach, we will notify affected users within 72 hours via email or in-app notification.
Questions? Contact support@goodshape.app