← Back to Goal-to-Action
Privacy
Last updated August 2026
Goal-to-Action stores your goals, tasks, and history only on your own device — never on a server we control, whether you're on the free plan or a paid one. Here's exactly what that means, and how multi-device use works without breaking that promise.
Your goals and tasks never leave your device
Your goals, sharpening answers, scores, tasks, and history are stored only in your browser's local storage, on your own device. This is true whether or not you sign in, and whether or not you subscribe. We don't have a database table for it — there's nowhere for it to go.
Clearing your browser's site data, switching browsers, or switching computers will remove this data locally. Use Export data in the sidebar to back it up as a file, and Import data to bring it back — see below for how to also use this for multi-device sync.
Using multiple devices: sync it yourself, through your own cloud
Since we never hold a copy of your data, moving it between your devices is something you control directly, in one of two ways:
- Manual export/import. Use Export data to save a backup file, then Import data on another device to load it.
- Linked sync file (supported browsers). In Settings, you can link a file inside a folder that your own cloud provider already syncs — iCloud Drive, Dropbox, Google Drive, OneDrive, etc. Goal-to-Action then saves to that file directly each time your data changes, and your cloud provider carries it to your other devices, where you link the same file to pick it up. The app talks only to that local file — never to us.
Paid plans: what's stored is account and billing state, not your data
If you sign in and subscribe, we store an account record so we know your plan and can enforce your monthly AI quota. This never includes the content of your goals or tasks.
- What we store: your account (via Supabase Auth), your subscription tier and status (for billing), and a log of AI call timestamps by type — e.g. "decompose, 2026-08-14" — used only to count usage against your quota. No goal or task text is in that log.
- Account authentication (email/password) is handled by Supabase Auth. We don't store your password ourselves.
- Subscription billing is handled by Stripe. We don't store your card details — Stripe does, under their own privacy policy.
- You can request deletion of your account at any time by contacting us (see below). Since your goal/task data was never on our servers, there's nothing further to delete on that front.
Bring your own AI key (works on any plan)
In Settings, you can connect your own API key for an OpenAI-compatible AI provider to get richer scoring rationale and assisted task breakdown. This is entirely optional and free — the app is fully functional without it.
- Requests go directly from your browser to the AI provider you configured. We never see them.
- Your API key is stored in your browser's local storage only if you turn on "Remember on this device." Otherwise it's held in memory for the current tab and cleared when you reload.
- A key stored this way is readable by anyone with access to that browser profile, or by a malicious script if this page were ever compromised. Use a key with billing limits you're comfortable exposing client-side, and use "Clear key" if you're on a shared device.
Hosted AI (paid plans, no key needed)
If you'd rather not manage your own key, a paid plan lets you use our pooled AI access instead. When you do, the goal/task title and description involved in that specific request pass through our server to the AI provider and back, in order to get you a response — this is not additionally stored anywhere on our side. We only log that the call happened (type + timestamp) to count it against your quota.
Optional feedback prompts
At a few natural points — after your first task breakdown, a few days in, and after a week or more of use — the app may show a small, dismissable card asking a quick question (a thumbs up/down, or a short rating). Answering is entirely optional and anonymous: it's not tied to your account, and it never includes your goal or task text — just your rating and whatever you optionally type in the comment box.
What we don't do
- We don't store your goals, tasks, or their content on any server we control — not for free users, not for paid users. The only exception, moment-to-moment, is a hosted-AI request in transit to your chosen provider, which isn't retained afterward.
- We don't run servers that see your API keys unless you turn on hosted AI — the BYOK path sends your key only to the AI provider you configured, never to us.
- We don't use analytics that track you individually beyond standard, aggregate page-view tools (like Vercel Analytics) common to most websites.
- We don't sell your data. Sharing is limited to the processors above (Supabase for accounts, Stripe for billing, your chosen AI provider) strictly to provide the plan you signed up for.
Questions
Goal-to-Action is a Morrow AI product. If anything here is unclear, or you'd like your account deleted, reach out at morrowaiteam@gmail.com.