Privacy Policy
Last updated July 25, 2026
This policy describes what Goalday Inc. ("Goalday", "we") collects when you use goalday.com, and how we use it.
What we collect
- LinkedIn sign-in. When you choose Continue with LinkedIn, we receive the basic profile you authorize: your name, email, profile photo, LinkedIn ID, and (where available) your headline. We use these to create and operate your account.
- Roles you post. The role description you paste and the opportunity profile you approve and publish.
- Applications. The repositories and work you nominate, your written answers, and the evidence-based analysis generated from them. Applications are private — visible only to you and the poster of the role you applied to. They are never public.
- Your code — read, not kept. To write the analysis we read the repositories you nominate, including the contents of a sample of source files. We keep the analysis and the list of what you nominated. We do not store your source code: it is held only for the length of the reading and then discarded. We keep no copy, no cache, and no archive of it.
- Repository names. We record which repositories you nominated so you can be shown your own application later. The poster never sees those names — in the analysis your work appears as Product 1, Product 2, described by what the code does.
- GitHub access tokens. If you grant a scoped token so your private work can be read, it is used once for that reading and is never stored or logged.
- Notification email. An optional address you set for where we contact you, separate from your sign-in email.
- Messages you send us. What you submit through the contact form.
- Basic usage data. A session cookie that keeps you signed in (the only cookie we set), and standard server logs needed to run and secure the service. When you view a role through a share link while signed in, the poster of that role can see that you viewed it.
How we use it
- To operate your account and publish the roles you approve.
- To generate an application's evidence-based analysis — this uses automated processing of the work you nominate — and deliver it to the role's poster.
- To notify you about activity that concerns you (for example, applications to your roles).
- To respond when you contact us.
- To operate, secure, and improve the service.
Automated analysis, and who else sees the material
The analysis in an application is written by a large language model, not by a person. To produce it we send the material being assessed — the sampled contents of the repositories you nominated, your written answers, and the role's requirements — to our model provider, Anthropic, which processes it on our behalf and returns the analysis. Repository names are replaced with neutral labels before anything is sent. Your GitHub token is never sent. Under our agreement with Anthropic, material we send is not used to train their models.
Anthropic is the only third party that receives the contents of your work. Our other providers handle the service around it, not the code: hosting and databases (Railway, Vercel), transactional email (Mailgun), and payments for posters who subscribe (Stripe, which receives the poster's billing details, never an engineer's).
What we don't do
We don't sell your personal data. We don't run ads or use advertising trackers. We don't post to your LinkedIn or take actions on your behalf. We never store GitHub tokens. We never store your source code. We never show a poster your repository names. We never make an application public.
Retention
- Your source code: not retained at all. It is read once to produce the analysis and discarded when that finishes — there is no copy to delete later.
- GitHub tokens: not retained at all. Used once for the reading, never written to storage or to our logs.
- Applications — the analysis, your written answers, and the list of repositories you nominated: kept until you ask us to delete them, so that both you and the poster keep access to a record you each relied on.
- Account data and content you've published: kept until you ask us to delete it.
- Contact-form messages: kept up to 24 months.
- Server logs: kept up to 90 days. They record that a reading happened, never its contents.
Your rights
You can request access to, correction of, export of, or deletion of your data at any time via the contact form. Deleting your account removes your profile and unpublishes your roles; applications you sent are removed from the posters' views.
Where data is processed
Goalday is operated from the United States, and your data is processed there.
Children
Goalday is not directed at anyone under 16, and we don't knowingly collect their data.
Changes
If we change this policy in a way that matters, we'll note it here with a new date. Your continued use after a change means the updated policy applies.
Contact
Questions or requests: the contact form.