Impossible Goals
Privacy Policy
Effective date: [TBD]
This is a working DRAFT pending review by legal counsel. It accurately describes how Impossible Goals handles your data today, but the wording is not yet final and should not be relied upon as a binding policy until it has been reviewed and dated.
Impossible Goals is a place to declare a big goal, see it every day, record small proof of progress, and let people you choose witness and support your journey. This notice explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights you have over it.
1. Who we are
Impossible Goals (“we”, “us”, the “service”) is operated by [TBD: legal entity name], the data controller for the personal data described here.
Registered office: [TBD: registered office address]
Privacy contact: angusbuttar@gmail.com
2. What this notice covers
This notice covers the Impossible Goals mobile app and the backend service that supports it. It does not cover third-party sites or services we link out to, which have their own privacy notices.
3. The data we collect, and who collects it
Account and identity (via Clerk)
We use Clerk as our authentication provider. When you create an account, Clerk collects and stores the email address and/or phone number you sign in with, your name, and an avatar image or avatar URL (where your sign-in method provides one). Our servers store an internal user identifier issued by Clerk that lets us recognise you across sessions and devices.
Your profile
Once signed in, you can set a public handle, a short bio, and a profile avatar. Your handle and profile are visible to other people on the service; your bio and avatar are shown on your profile as you choose.
Goals and proof-of-progress entries
The core of the product is the goals you declare and the entries you add to them. We store the goal’s title and details, its status, and each entry’s content — including the photos you upload as proof of progress, which are held in private object storage and referenced by your entries. Every goal has a visibility setting you control — private (only you and any collaborators on the goal), supporters (people who support that goal, plus collaborators), or public — and we render your goals and entries only to the audience that setting allows.
Push notification device tokens
If you enable notifications, we store the push token your device is issued so we can deliver the notifications you have opted into (for example, when someone you share a goal with adds an entry). We also store your notification preferences.
Product analytics (via PostHog)
We use PostHog to understand how the app is used and to detect and fix errors. PostHog receives product-usage events (which screens you view, which controls you interact with, timing between actions) and error/diagnostic data (error type and message, app version, device and OS). Once you sign in, your user identifier is used as the analytics distinct ID so events from the same person can be linked. See PostHog’s privacy notice for how they process this data.
What we do not do
We do not sell your personal data, and we do not share it with advertisers or advertising trackers.
4. How and why we use your data
- To operate the social graph — letting you Follow a person, Support a goal, and Adopt a goal to start your own version of it.
- To render your goals and entries to the people you have chosen to share them with, according to each goal’s visibility setting.
- To deliver the notifications you have opted into.
- To understand aggregate feature usage and to find and fix bugs and crashes.
- To keep the service secure — including rate limiting and other anti-abuse measures that protect against spam and automated attacks.
5. Our legal bases (GDPR)
Where the UK/EU GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) for the core service: your account, your goals and entries, and sharing them with the audiences you choose.
- Consent (Art. 6(1)(a)) for push notifications. You can withdraw consent at any time in Settings or your device settings.
- Legitimate interests (Art. 6(1)(f)) for security, anti-abuse, and understanding aggregate product usage to improve the service.
6. Who we share your data with
We share personal data only with the service providers (sub-processors) we use to run Impossible Goals, each bound by contract to use it only as we instruct. By category, these are:
- Authentication — receives your email/phone, name, and profile data (Clerk).
- Product analytics and error reporting — receives usage events and diagnostic data (PostHog).
- Hosting and object storage — stores the server-side data in this notice, including your uploaded photos.
- Push notification delivery — receives your push token and the notification content, and (through the platform push services) delivers it to your device.
The specific vendors in each category, their locations, and the data processing agreements with them are [TBD: name each sub-processor and its DPA].
7. International transfers
Some of our providers may process data outside your country. Where personal data is transferred internationally, we rely on an appropriate safeguard (such as Standard Contractual Clauses or an equivalent mechanism): [TBD: confirm transfer mechanism].
8. How long we keep your data
- Active accounts: we keep your account, goals, and entries for as long as your account is active.
- Deleted accounts: when you delete your account (see your rights below), we erase your stored photos and other blobs and then your database rows, and we delete your identity at our authentication provider.
- Push tokens: removed when you sign out of a device or when the push provider reports the token as expired.
- Analytics: retained by our analytics provider for their configured retention window; [TBD: confirm retention period].
9. Your rights
Depending on where you live, you have rights to access, correct, export, restrict, object to, and delete the personal data we hold about you (including the access, deletion, and “do not sell” rights under the GDPR and the CCPA/CPRA). We do not sell your personal data.
You can delete your account and all of its data yourself from the app: go to Settings → Delete account. This runs a full erasure — your uploaded photos and other stored files are deleted, then your database rows, then your identity at our authentication provider.
For any other request — access, correction, or a portable export — email us at angusbuttar@gmail.com and we will respond within the time the law requires. If you are in the UK/EU and believe we have mishandled your data, you may also complain to your local data protection authority.
10. Children
Impossible Goals is not intended for children below our minimum age of [TBD: minimum age, e.g. 13 or 16]. We do not knowingly collect personal data from anyone under that age. If you believe a child has created an account, contact us at angusbuttar@gmail.com and we will delete it.
11. How we protect your data
Connections to the service are encrypted in transit (TLS). Uploaded photos are kept in private object storage rather than a public bucket. Authentication tokens are short-lived and rotated.
12. Changes to this notice
If we make a material change to how we handle your personal data, we will update the effective date above and, where appropriate, notify you in the app before the change takes effect.
13. Contact
Questions about this notice or your data? Email angusbuttar@gmail.com.
Draft · effective date [TBD] · pending legal review. © Impossible Goals.