Overview
1.1
Goose (“the App”) is a personal finance tracking application developed by Ivan Kolkovskiy. This policy explains what information the App handles, why it is used, and how you can request access or deletion.
Data We Collect
2.1
Account information. When you use Sign in with Apple, the App may receive your Apple user identifier and, if you choose to share it, your name and email address. Your email may be an Apple private relay address.
2.2
Expense data. Records you enter manually, such as amounts, categories, dates, notes, and related settings.
2.3
Subscription information. When you purchase a Goose Pro subscription, Apple processes the payment. The App receives confirmation of your subscription status (active or inactive) via RevenueCat. No payment card details are transmitted to or stored by the App.
2.4
Goose does not connect to bank accounts and does not request access to contacts, camera, microphone, location, or device sensor data for its core functionality.
How We Use Your Data
3.1
Your data is used to authenticate your account, save and sync the expense records you create, verify and manage your subscription status, and respond to support, privacy, or deletion requests.
3.2
Your data is not sold and is not used for advertising or third-party profiling.
Data Storage
4.1
Remote storage. Goose uses Supabase for backend infrastructure, authentication support, database storage, and data sync. Data is transmitted over HTTPS/TLS and stored on Supabase servers located in EU West (Ireland, AWS eu-west-1).
4.2
Local storage. The App also stores data locally on your device – including your session credentials, cached account data, and subscription state – to allow the App to function offline and start quickly. This data remains on your device and is not shared with third parties.
Third-Party Services
5.1
Sign in with Apple (Apple Inc.) – authentication only. Apple may retain your Apple ID and relay address per their own privacy policy.
5.2
Supabase – backend infrastructure, database storage, and data sync.
5.3
RevenueCat – subscription management and in-app purchase verification. RevenueCat receives your App user identifier and subscription status to verify purchases made through Apple.
5.4
PostHog – product analytics. When you are signed in, PostHog receives your account identifier and in-app usage events (such as screens viewed and features used) to help us understand how the App is used and improve it. PostHog processes this data on servers located in the European Union. Data is retained for up to 1 year.
5.5
Sentry – crash and error reporting. Sentry receives device information (such as OS version and device model), IP address, and diagnostic data when the App crashes or encounters an error, so we can identify and fix bugs. Sentry processes this data on servers located in the United States. Data is retained for up to 90 days.
5.6
No advertising SDKs are included in the App. PostHog and Sentry are used solely for analytics and crash reporting, not for advertising or third-party profiling, and are not used to sell your data.
5.7
Currency exchange rates.When you use accounts in different currencies, the App downloads a public exchange-rate table from a service operated by the developer on Cloudflare Workers. This request contains no account information and no transaction data – it carries only your device's IP address, as any network request does. All currency conversion is performed locally on your device, and the rate table is cached on your device for one hour.
Data Retention
6.1
Goose keeps your account and expense data while your account is active or as needed to provide the App.
6.2
If you request account deletion, associated personal data will be deleted within 30 days, except where retention is required to comply with a legal obligation, resolve a dispute, or enforce our agreements. In such cases, only the minimum data necessary is retained and solely for that purpose.
6.3
You can delete your account directly in the App: Settings → Erase Data → Delete user account.
Your Rights
7.1
Access. You may request a copy of your personal data held by the App.
7.2
Deletion. You may delete your account and associated data directly in the App (Settings → Erase Data → Delete user account) or by contacting us.
7.3
Correction. You may request correction of inaccurate account information where technically possible.
7.4
Portability. You may request export of your personal data in a portable format.
7.5
Revoke Apple access.You may revoke Sign in with Apple access via your Apple ID settings (Settings → [your name] → Password & Security → Apps Using Apple ID).
7.6
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
Children
8.1
Goose is not directed to children under 13. We do not knowingly collect personal data from anyone under 13. If we become aware that a user is under 13, we will promptly delete their account and associated data. If you believe a child has provided us with personal information, please contact us at the address below.
EU/EEA Users
9.1
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional terms apply.
9.2
Legal basis for processing. We process your personal data on the basis of performance of a contract – to provide the App and its features you signed up for – and legitimate interests such as maintaining security, preventing fraud, and improving the App, where these interests are not overridden by your rights.
9.3
Data transfers. Supabase (database storage and sync) and PostHog (product analytics) process data on servers located in the European Union. Sentry (crash and error reporting), RevenueCat (subscription management) and Cloudflare (exchange-rate delivery) process data in the United States, so some of your data may be transferred to and processed outside the EEA. These transfers are carried out under appropriate safeguards (Standard Contractual Clauses or equivalent mechanisms).
9.4
Additional rights. EEA/UK users may also object to processing based on legitimate interests, restrict processing in certain circumstances, and lodge a complaint with your local data protection supervisory authority.
Changes
10.1
This policy may be updated from time to time. Changes will be posted on this page with an updated effective date. For material changes, we will make reasonable efforts to notify you.
Contact
11.1
Questions or data requests: dev.kolkovskiy@gmail.com