Privacy Policy

Last updated 2026-05-17.

What we collect.

Your email, a hashed password (or your SSO identity), the handle and display name you choose, the posts and replies you create, who you follow, which villages you join, and basic device/log data (IP, user-agent, timestamps). Optional fields like avatar, bio, website, and location are visible on your profile if you fill them in.

How we use it.

To run Goodkin: show you a timeline, deliver notifications, run the community kindness rule, prevent abuse, debug crashes, and bill ad accounts you create. We do not sell your personal information.

Who sees what.

Posts and replies are visible to anyone using Goodkin (or, in restricted/private villages, to that village). Follows, likes, and village memberships are public. Bookmarks, mutes, blocks, and flag actions are private and never shown to the other person.

Ads & targeting.

Goodkin's ad system uses non-identifying signals (the topic of the village you're viewing, your country) to choose which ad to show. We do not share viewer identity with advertisers. Advertisers see aggregated impressions, clicks, and CTR for ads they paid for — never an individual user's activity. We do not build sellable audiences from your data.

Cookies & storage.

We use cookies and similar storage for: authentication (Supabase session), security (CSRF), and remembering your preferences. We don't use third-party advertising cookies.

Sub-processors.

Hosting: Vercel. Database / auth / storage: Supabase. Payments (advertisers only): Stripe. Each handles your data under their own published terms.

Retention.

We keep your account data while your account is open. If you delete a post, it's removed from the product immediately and from backups on a rolling cycle. If you delete your account, we remove identifying profile data within 30 days, except where retention is required by law (for example, billing records).

Your rights.

You can edit or delete your posts and account at any time from Settings. For requests covered by GDPR or CCPA (access, deletion, portability), email privacy@goodkin.app and we'll respond within 30 days.

Children.

Goodkin is not directed to children under 13. Ads cannot target anyone under 18.

Changes.

If we materially change this policy we'll give notice in the product. Continued use after the change means you accept the new policy.

Contact.

privacy@goodkin.app