Privacy Policy

Overview

Effective September 18, 2026

We do not sell your information. Goodbye App shows no advertising: there are no ads in the app or on this site, and nothing you write here is used to target ads at you. We do buy advertising elsewhere to reach people who may need this service, and on the website only, a Google Ads tag and a Google Tag Manager container measure whether that worked. The iOS app carries neither. Other companies handle your information in order to run the service, and each of them is named with what it sees under Information Sharing below. There is one circumstance in which your information could pass to another company as that company's own, and it is set out in full under Due to a change in ownership below.

Is Goodbye App secure?

Below is what actually protects your data at Goodbye App , so that you can judge it for yourself rather than take our word for it.

Where your data sits: Everything is stored in Firebase and Google Cloud. We do not run servers or databases of our own, so the machines your letters sit on are Google's, in Google's data centres, under Google's physical and network security.

Encryption: Everything that travels between your device and our servers goes over HTTPS, so it cannot be read on the way. Google encrypts its databases and file storage at rest as a matter of course. What we do not do is encrypt your letters separately with a key that only you hold. They are stored in the form you wrote them, which is what lets us deliver them on a date you may not be here for, and it means that a password you write into a letter is held as the plain text you typed, readable by everyone the letter reaches and by the tools we use to run the service.

Certifications: Google publishes the audits and certifications its cloud holds, among them ISO/IEC 27001 and SOC 1, 2 and 3, and they cover the infrastructure our data sits on. They are Google's, not ours. We hold no certification of our own, and using Google's infrastructure does not make us certified against any standard. What you can rely on is what is written on this page.

Signing in: Sign-in is handled by Firebase Authentication, which is Google's rather than ours. It checks who you are by email and password, or through Google or Apple. We never see or store the password you use, with us or with them.

Dependency Updates: The third-party code this site is built from is tracked against published vulnerability advisories, and we pin or replace the packages those advisories name. The servers and databases themselves are Google’s, and Google patches them.

User Control: You choose who each letter goes to and whether each post is public or addressed to particular people. You can turn notifications off, block accounts, take a copy of your data and close your account yourself, from Settings, without asking us.


This Privacy Policy is issued by Goodbye App Corporation, the company that runs the service. It applies to the website at goodbyeapp.com, which is also what the Android app shows, and to the iOS app, which is a separate build; where the two differ, this page says so.

This Privacy Policy sets out what Goodbye App collects, what we do with it, and who else sees it. We also publish a Data Processing Addendum (DPA), written for an organisation that would have us process personal data on its behalf. No organisation uses the service that way today, and for an account held by a person this policy is the whole of what applies.

What kinds of information do we collect?

Everything below is something you type, choose, upload or do. Nothing is taken from your device without an action of yours behind it. This list, together with the push token under Push Notifications below, is meant to be complete: if a kind of information is not described somewhere on this page, we do not collect it.

Goodbye App requires an account. You can read a letter that was sent to you without one, but writing, posting and following need an account, and you must be 18 or older to have one. The sign-up form asks you to confirm that and does not proceed without it. We do not knowingly hold an account for anyone younger, and if we learn of one we delete it.

Your account

  • An email address. There is no sign-up by phone number.
  • A password, if you set one. It goes to Firebase Authentication, which is where sign-in is checked, and never to our own servers.
  • A username (for example, @calvinjames). It is public, and it is the name other people see you under.
  • The language you chose for the app, so that what we send you is in it.
  • A tick that you are 18 or older. Signing up does not ask for a date of birth, though you can add one to your profile afterwards, as described below.
  • If you sign in with Google or Apple instead of setting a password, the information that service sends us, described below.

Signing in with Google

If you choose Google Sign-In, Google confirms your identity to us and sends us a limited set of information from your Google account. We receive:

  • The email address on your Google account.
  • Whether Google has verified that email address.
  • The name on your Google account.
  • The profile picture on your Google account, if you have one.
  • An identifier that Google uses for your account, so that we can recognize you the next time you sign in.

We never receive or store your Google password, and we do not ask Google for your contacts, calendar, files or any other part of your Google account. We use what we receive to create and identify your account and to reach you about it. The name and the picture stay in the sign-in record that Firebase Authentication keeps: we do not copy them into your profile, which starts with no name and a default picture until you fill it in. You still choose your own username and display language when you finish setting up your account. Google's handling of your information as part of signing in is covered by Google's own privacy policy rather than this one.

In the iOS app, Google's sign-in software runs inside the app when you use it, and Google declares that it may collect a device identifier, a coarse location and usage data of its own for Google's analytics. That is Google's collection, under Google's policy, and it is why those items appear on the App Store privacy label. We do not receive them.

Signing in with Apple

Sign in with Apple is offered in the iOS app. If you choose it, Apple confirms your identity to us and sends us less than Google does. We receive:

  • An email address. This is either the address on your Apple account or, if you choose to hide it, a private relay address that Apple creates for this service and forwards to you.
  • Your name, but only the first time you authorize Goodbye App . Apple never sends it again, and there is no way for us to ask for it later.
  • An identifier that Apple uses for your account with us, so that we can recognize you the next time you sign in.

We never receive or store your Apple account password, and we ask Apple for nothing else. If you hide your email address we cannot see your real one: the relay address is the only address we hold, and it is where everything we send goes, including a letter you have scheduled for a date far in the future. If you later turn off forwarding for Goodbye App , or stop using that Apple account, that mail will stop reaching you and we have no way to know it has. Apple's handling of your information as part of signing in is covered by Apple's own privacy policy rather than this one.

Your agreement to these policies

When you create an account you confirm that you agree to our Terms of Service, this Privacy Policy, our Cookie Use policy and our Community Guidelines, and that you meet our minimum age requirement. We keep a record of that agreement so that we can show what you were asked and when. The record contains:

  • Which policies you agreed to, and the version of their wording.
  • The date and time we received your agreement.
  • Whether you confirmed you meet the minimum age requirement.
  • The language the request was shown to you in, and which screen you gave it on.
  • The browser or app you used, and a fingerprint of the network address you signed up from, made by running that address through a standard hashing function. The address itself is not stored.

That fingerprint is not anonymous, and we will not tell you it is. There is a limited number of network addresses in the world, so anyone holding the fingerprint and enough computing time can work back from it to the address it was made from. What storing it this way does is keep the address out of the account document, where it would otherwise sit in plain sight in every export, backup and support view. It does not make the address unrecoverable. The one thing we use it for is checking an address against the record if one is put to us later.

We keep this record for as long as your account exists. It is deleted along with the rest of your account data when you delete your account. We use it only to show what you were asked and when, and we do not use it to build a profile of you or to send you anything.

Accounts created before 24 August 2026

We began keeping this record on 24 August 2026. If you created your account before that date, we do not hold one for you, and we cannot reconstruct what you personally did. Signing up has always required ticking the box that confirms you agree to these policies, and the form would not submit without it, but we did not write down that you had.

Rather than leave that gap silent, we have added a note to those accounts recording it. It is marked as reconstructed rather than captured, it says in its own text that it was written after the fact by a migration and not at the time, and it carries a flag saying that it asserts no consent, so that it cannot be lifted out and quoted as one. This is what it holds:

  • The date your account was created, marked as the latest moment the tick can have happened rather than the moment it did.
  • Which wording of the four documents was live on the site that day, with the date that wording was published and the commit it came from. That is worked out from our hosting release history, not from anything on your account.
  • What the signup screen required of everyone that day: an agreement box that was not pre-checked and that the form would not submit without, the four documents named and linked, and a box confirming you were 18 or older.
  • Which sign-in providers your account carries today, and from them a statement of which screen the tick was taken on, with the reasoning written out beside it. Where an account carries both a password and Google sign-in and was created after Google sign-in was added, the note says the screen cannot be determined.
  • The date the note was written, and the name of the migration that wrote it.

Every field a real record fills in from what was observed is left empty in this one: the version you were shown, the time your agreement was received, whether you confirmed your age, the language it was shown in, the browser you used, and the fingerprint of the network address. None of that exists for these accounts. So the note is not free of information about you, and we will not tell you it is: it holds when your account was made and how you sign in. Both of those were already on your account, and the note adds nothing about you that we did not already hold.

Your profile

Beyond the username, your profile holds only what you choose to add to it: a name, which can be your real name or a pseudonym, a biography, a quote, a location, a profile picture and a colour for the shadow behind it. The location is a town you type in. As you type, what you have typed so far is sent to Google Maps Platform, which suggests place names, and the place you pick is stored as text. It is never your device's location, which we do not ask for and cannot see.

You can also add your date of birth. It is optional, and you can change it or remove it whenever you edit your profile. If you add one it is shown on your profile, beside your location, to people who are signed in, and the person running the service can also see it through the tools we run the service with. Removing it from your profile removes it from your account. Because the service is only for adults, a date that would make you younger than 18 cannot be chosen.

Your profile page opens only for people who are signed in, and we ask search engines not to index it. Your username, name, picture, biography, quote and the date you joined are nevertheless public: they are returned without any sign-in by the request that lets a letter page show who wrote it, so treat them as visible to anyone. Your location, your date of birth if you added one, and the counts of who follows you and whom you follow are shown to people who are signed in. You can create more than one account.

Your letters

A goodbye letter is made of the sections you choose to fill in, and we store every one of them exactly as you wrote it: a title and a message, a checklist, the people to contact and their phone numbers, where your important documents are, your personal details, which may include your full name, date of birth, your parents' names and your address, the passwords to your devices, where your online accounts are written down, your pets and the people and vets who look after them, your assets and where the keys and deeds are, heirlooms, debts, your wishes for the end of your life and for your funeral, any topics of your own, and an audio recording if you make one. You also give us the people the letter is for, as accounts on Goodbye App or as email addresses, and the date it is to be delivered.

Three things about that deserve saying plainly. First, much of a letter is about other people: a contact's name and number, a caregiver, a lender. You are the one who decides to write it down, and we hold it because you did. Second, a device password you write into a letter is stored as the plain text you typed, not scrambled the way an account password is, because it has to be readable by the person you leave it to; treat the letter accordingly. Third, the address field and the location of an asset are typed the way the profile location is, with suggestions from Google Maps Platform as you type.

A letter is never public. It can be read by you, by the people you addressed it to once it has been delivered, and by the person running the service when a report or a request from you makes that necessary. The tools we run the service with can open any letter, and there is no technical wall in front of them, only that rule.

Your posts and comments

A post is the text you write, a picture, a video or an audio recording, or a picture with a recording, whether it is public or addressed to particular people or email addresses, the date it is to be released, and the accounts you mention and hashtags you use in it. Comments and replies are the text you write and the post they belong to. A file you attach is uploaded from your device straight into Google's storage, and its file name carries your account id, so anyone who has the address of a picture can see which account it came from. Posts carry no location.

What you do

We record the things the service could not work without remembering: which posts you like, whom you follow and who follows you, whom you have blocked, and the comments you leave. We also keep a count of how many posts, comments, likes, follows and reports you have made today, which is how the daily limits are enforced, and it starts again each day. A search you type for a person or a hashtag is sent to our servers to run the search and is not kept. We also keep the date you last used your account, rewritten by anything you do while signed in; it is the clock the inactivity setting counts from, and it is kept whether or not you turn that setting on. The settings you choose are stored on your account: your language, whether you want push notifications, and the inactivity setting, which is the number of days without any use of your account after which your scheduled letters and posts go out.

Reading records nothing. Opening a post, scrolling past it, sitting with it for an hour: none of that is sent to us, and neither is how often you open the app or which parts of it you use. Your place in the feed and the posts you have already seen are kept in your own browser and never reach us. No timings, no durations and no path through the pages are logged against your account.

Playing a post's video or audio is the one exception. If you play the video on a post for thirty seconds, or halfway through it, whichever comes first, or if you let a post's audio play to the end, we write down that you did. The record is a single line under that post holding your account id and the time. Playing it again adds nothing: the line is written once, and a second attempt is refused. This applies to posts. The audio in a letter is not counted.

It exists to count. A post carrying video or audio shows how many people have played it, and that number sits under the post for anyone who can see the post. Holding one line per person is what makes the number honest, because it counts people rather than plays. Nobody is shown the list of who played what, not the person who posted it and not anybody else, and nothing is decided from it. The line is deleted when the post is deleted, which includes when the account that posted it is deleted. It is not deleted when you delete your own account, because it sits under someone else's post rather than on yours, and nothing here sweeps those up by account.

The servers themselves keep ordinary request and error logs, which carry the time a request arrived and the network address it came from. That is how a fault gets found and fixed. It is a log of requests rather than a record kept against your account.

Reports, appeals and the forms

  • A report you make about a post, a comment or an account: the reason you picked, what you wrote, and what it points at. It is recorded against your account and against the account reported.
  • An appeal against something we removed or a suspension: what you wrote, and what it concerns.
  • The contact form: your name, the subject, the topic you chose and what you wrote, and, if you are not signed in, the email address you give us so that we can reply. A refund request also carries the transaction id and amount you enter. If you were signed in, the message carries your account id, and that id stays on it after you delete your account. It is the one thing on this list that does, and it is set out under What is not deleted, and why below.
  • The bug report and feature request forms: the title, what you wrote, and a priority. A bug report also carries whether you are on a computer or a phone, and which browser or which make of phone, worked out from the description your browser sends with every request. The only other device information held against your account is the browser or app recorded when you sign up, described above, and the push token described under Push Notifications below, if you allowed notifications.
  • If the app crashes, it sends us the error message and the part of the app that failed, with no content of yours attached, and keeps a reference number on your device so that a bug report you file afterwards can be matched to it.
  • If you close your account you can leave a note telling us why. It is optional.

You can choose to provide information in your Goodbye App profile fields, posts, and letters about your religious views, political views, who you are "interested in," or your health. This and other information (such as racial or ethnic origin, philosophical beliefs or trade union membership) could be subject to special protections under the laws of your country.

Writing about your own health is the ordinary use of this service, not an edge case, and naming it in the paragraph above does not make it a problem here. A diagnosis, a prognosis, a treatment and what it is doing to you, what you are frightened of, what you want done afterwards: all of that belongs in what you write, and none of it is read to categorise you. It is stored the way everything else you write is stored. A letter goes to the people you addressed it to. A post goes to the audience you chose for it. Nothing sorts you by what is in it, and nothing outside this service is told about it.

We also hold what other people write when it involves you, such as a post that mentions you or a comment left on something you wrote. That content sits on their account rather than yours. Nothing reads through it looking for you.

What we do not collect

Nothing of ours collects an advertising identifier, your contacts or address book, your phone number (the numbers you write into a letter for other people are described under Your letters above), biometrics, a location from your device, anything from Bluetooth, Wi-Fi or the cell network, battery or hardware details, or a record of other apps or sites. What Google's sign-in software declares for itself in the iOS app is set out under Signing in with Google above. The camera and the microphone are used only while you are taking a picture or recording, with your permission, and only the picture or recording you choose to keep leaves your device. Nothing about you is combined across devices: signing in on a second device shows you the same account, and that is all.

There is one identifier that belongs to a device, and we are not going to call it something else. If you allow push notifications in your browser, that browser gives us a token so that a notification can be sent to it, and we store the token against your account. A token that names one browser on one device is a device identifier in the ordinary sense of the phrase. It is used for nothing but sending you notifications, it means nothing to anyone but Google's messaging service, it is replaced every seven days, and it is deleted when it has gone thirty days without being renewed or when you delete your account. It is set out under Push Notifications below. The iOS app holds no such token, because it sends no push notifications.

Information We Receive from Third Parties

Two kinds, and no more. Google or Apple send us the sign-in fields listed above when you sign in through them. Google's reCAPTCHA, which sits on the sign-up, sign-in, forgotten-password, contact, bug-report and feature-request forms, returns a verdict on whether a submission looked automated. Nobody sells us data about you, no other service sends us anything, and there is no way to connect another account to this one. No company is sent your content to assess it for us. There is no outside moderation vendor, and nobody outside this service reads what you write in order to judge it.

We set no cookies of our own. What we keep on your device is listed under Use of Local Storage at the end of this page, and the cookies that other companies' code may set are described in Goodbye App Cookie Use.

How We Use Information

One piece of information often serves more than one purpose, so the sections below are grouped by what a use is for rather than by what is collected. If something you want to know is not answered here, you can contact us.

Operating the service

We use the information we collect to run Goodbye App : to sign you in, to show you your own account and the accounts you follow, to hold what you have written until the date you set, and to send it to the people you addressed it to when that date arrives.

What you write here is not used to train machine learning or artificial intelligence models.

There are no such models on this service and there is no training pipeline. Your letters, posts, comments and profile are not fed to a model of ours, and they are not passed to anybody else to train one either. That is a statement about what exists, not a preference we hold: there is nothing here that could do it.

There is no recommendation algorithm on Goodbye App either. Nothing ranks what you see, scores you, sorts you into an audience, or decides that one person's writing should reach further than another's. Your feed is the posts from the accounts you follow, together with posts addressed to you, newest first. That is the whole of it.

If you signed in with Google or Apple, we use what that service sends us to identify your account when you come back to it. That is the whole of what a connected account does here. There is no cross-posting, and there is no way to link another service to this one.

People find your account by your username, which you chose and which is public. Search here looks at usernames and nothing else. Your email address is not searchable, and we do not hand it to anybody so that they can find you.

Verification and Security: We use this data to verify an email address, to hold accounts to the daily limits on posting, commenting and reporting that keep one account from flooding the service, and to look into a report or a breach of these policies when one is put to us. The one outside company involved is Google, whose reCAPTCHA sits on the sign-up, sign-in and forgotten-password screens and on the bug-report, feature-request and contact forms and tells us whether a submission looks automated. Nothing else about your account is sent to anybody for a reliability or reputation score, and no such score is sent back to us.

Communication: We use your email address to send the things this service has to send: the message that verifies your address when you sign up, a password reset when you ask for one, the notice that a letter or a post has been released to you, the warnings from the inactivity setting if you have turned it on, and a notice if we act against your account. We reply to you when you write to us. We may also write to you about the service itself. We do not send a notice when this policy or the Terms change, which is set out under Changes To This Privacy Policy below.

Keeping the service safe

Nothing is screened before it is posted. No automated system reads what you write, nothing scans it, labels it or limits who it can reach, and nobody looks through the account of a person nobody has reported. There is no outside moderation company. A report is how something wrong reaches us, a person reads every report, and we review reports within 24 hours of receiving them.

When we act on a report we use the information described in this policy to do it: to find the content, to see which account posted it, and to decide what happens to that account. That is also how we enforce these policies and meet the law where it applies to us.

Keeping the service working

The servers keep logs of errors and of how long requests take, which is how a fault gets found and fixed. The Google Ads tag and Tag Manager container described at the top of this page measure, on the website only, whether the advertising we buy elsewhere reached anybody. Those two are the whole of it: nothing else measures how you use the service for any purpose of ours. Other things you do are written down, and they are listed under What you do above: your likes, your follows, your blocks, your comments, the daily counters that hold you to the limits, and the single line written when somebody plays a post's video or audio. Those exist because the service could not work without them, not to tell us how you use it. Reading is not among them.

Research

We do not run research programmes on what people write here, and we have no research partners. What you write is not given to anybody to study, named or pooled with other people's. If we want to know how the service is working for you, we ask you.

Information Sharing

Your information leaves your account in the ways listed here, and in no others.

When you post and share.

Your profile is public in the sense described above. A public post can be read by anyone who is signed in, together with its comments, its likes and, if it carries video or audio, the count of how many people played it. A post addressed to particular people can be read by them and by nobody else. If you addressed it to an email address, and that address has no account, we send that address an email saying you wanted them to see a post, with the post's picture if it has one and a link; to read it they create an account with that address, and the post is waiting for them. If the address belongs to an account, the post is delivered inside the app, and an email goes as well only if that person follows you. A person you mention in a post is told, and shown the post. Your likes, your comments and the list of accounts you follow and that follow you are visible to other signed-in users.

A letter goes only to the people you addressed it to, on the date you set. A recipient with an account is told inside the app and by email, and the email carries the whole letter, with a link to a page of its own that opens without signing in. A recipient with no account receives that same email. Each recipient sees the letter, your username, your name and your picture; they do not see who else received it, only how many. Anyone a letter or a post reaches can copy it, forward it or keep it, and nothing we do can take it back from them. There is no public API and there are no embeds, so the only way something leaves this site is that a person reads it and takes it.

With the companies that run things for us

We do not run servers of our own, so a small number of companies handle your information in order to provide the service. Each is named here with what it sees. None of them is an advertising network, and none of them is sent your content so that advertising can be sold against it. Google appears on this page twice, and the two are separate: it is the cloud the whole service runs on, listed below, and it is also the company whose ads tag measures the advertising we buy, described further down.

We use each of these companies on the standard terms it publishes, and we have negotiated nothing of our own with any of them. So the limits on what each may do with what reaches it are the ones in its own terms and privacy policy, not ones we obtained on your behalf, and those terms are what govern it rather than this page, as set out under General below. What is in our hands is how much reaches them, and that is what this list sets out.

  • Google, through Firebase and Google Cloud: everything. The database, the file storage, sign-in, the code that runs the service and the logs it writes all live in Google's cloud in the United States; the code that runs the service runs in Google's us-central1 region. To tell whether it is online the app fetches a small file of our own, on the website from goodbyeapp.com and in the app from our Google Cloud storage bucket.
  • Mailgun: every email we send goes out through Mailgun, so Mailgun sees the address it is sent to and the whole of the email, which for a letter is the letter itself. We keep our own copy of every email we have sent, as the record that it went, and that copy is not deleted.
  • Google reCAPTCHA Enterprise: on the sign-up, sign-in, forgotten-password, contact, bug-report and feature-request forms, on the website and in the app. Google's code runs on those pages and judges whether the submission looks automated. On sign-up and sign-in your browser sends its token to Google directly; on the other forms the token travels with your submission to our server.
  • Google Maps Platform: the three location fields, which are your profile location and the address and asset-location fields of a letter. What you have typed so far is sent to Google as you type, to fetch place suggestions.
  • Apple and Google, for sign-in: as described above, and only if you choose them. If you signed in with Apple, closing your account tells Apple to revoke this app's access to your Apple ID, so the sign-in you gave us is withdrawn along with the account.
  • YouTube: the home page shows previews of our videos. The preview image is looked up through noembed.com and comes from YouTube's servers, so both see the request, and pressing play loads YouTube's player under YouTube's own policy. Nothing about your account is sent with it.
  • unpkg.com: if you record a voice message in a browser whose recorder cannot produce AAC in an MP4 file, which today means Chrome on most systems, and Firefox, the recording is converted in the browser with code fetched once from the unpkg.com content network. Safari and the iOS app record AAC directly and never contact it. The recording itself is converted on your device and never sent there.
  • dmca.com: the copyright page carries a DMCA protection badge, whose image and script load from images.dmca.com.
  • PayPal: the donate page on the website is a PayPal form. Pressing it takes you to PayPal, and PayPal handles the payment end to end. No card or payment detail passes through us, and there is no other payment anywhere on the service, because there is nothing to buy.

Each of these requests carries your network address to the company that answers it, because that is how a request works. None of them carries your account, your content or anything you wrote, except as stated above for Mailgun, Google Maps Platform and Google's own cloud, and, on the website, the username sent to Google Ads as described in the next section.

Measuring the advertising we buy

On the website only, two pieces of Google's code run: a Google Ads conversion tag and a Google Tag Manager container. They exist so that we can tell whether advertising we bought elsewhere brought anyone here. They report two events to Google Ads: that the home page was opened, and that an account was created. The account-created event sends the username you chose along with it, and nothing else you write on Goodbye App is sent to them. Google may set its own cookies on this site through that tag, as described in Cookie Use. The iOS app strips both tags out when it is built and runs no measurement tag at all. There is no Google Analytics on the site or in the app, and no advertising network.

When required by law, to prevent harm, or in the public interest.

We may retain, utilize, share, or reveal your information if we deem it reasonably necessary to:

  • Comply with applicable laws, regulations, legal proceedings, or governmental requests.
  • Protect the well-being of individuals, and keep the service working, including the limits that stop spam and abuse.
  • Provide explanations for content or account removals from our services (e.g., due to a violation of Our Community Guidelines).
  • Address issues related to fraud, security, or technical matters.
  • Protect our rights, properties, or the rights and properties of those who use our services.

We take various steps to respond to legal requests and prevent harm by accessing, preserving, and sharing your information with regulators, law enforcement agencies, or other entities:

Legal Requests: We respond to legal requests such as search warrants, court orders, or subpoenas where we believe the law requires us to. This includes requests from jurisdictions outside the United States, where we believe the law of that jurisdiction requires the response, the request affects users in that jurisdiction, and it is consistent with internationally recognized standards.

Fraud and Unauthorized Use: We may access, preserve, and share your information to detect, prevent, and address fraud, unauthorized use of our Products, violations of our terms or policies, or other harmful or illegal activities.

Protection of Rights: Our actions may also include protecting ourselves, including our rights, property, or Products, as well as you or others. This protection aspect extends to investigations, regulatory inquiries, and preventing death or imminent bodily harm.

Due to a change in ownership, we may share or transfer your information in connection with activities such as a merger, acquisition, reorganization, sale of assets, or bankruptcy. In such cases, this Privacy Policy will continue to apply to your personal information, whether it's shared with, transferred to, or remains with the new entity (before and after the completion of any transaction).

This is the only circumstance in which your information becomes another company's own, rather than being handled for us by the companies named above, and it comes with a condition. Anyone who takes on Goodbye App takes on the obligation to deliver the letters and posts you have already scheduled, on the dates you chose. If they will not accept that obligation, those items are delivered or returned to you before the transfer completes. We do not sell personal information as a product, to data brokers or to advertisers, in this or any other circumstance.

Push Notifications

On the website, and only if you allow it in your browser, we can send push notifications through Firebase Cloud Messaging, which is Google's. Your browser gives us a token for the device, we store it against your account, replace it after seven days, and delete it when it has gone thirty days without being renewed or when you delete your account. That token is the one device identifier we hold, as said under What we do not collect above. A notification carries the text that caused it, such as the first part of a comment, together with the usernames and pictures of the people involved, and Google carries it to your device. You can turn push notifications off in Settings, and doing so stops them at the source rather than merely hiding them.

The iOS app sends no push notifications in this version. It registers no device for them and holds no token.

The iOS App

The iOS app is the same service and talks to the same servers, so everything on this page applies to it. These are the ways it differs from the website.

  • It contains no tracking, no advertising, no analytics and no measurement tag of ours. The Google Ads tag and the Tag Manager container described above are removed from the app when it is built, and the build fails if they are found in it. Nothing of ours in the app reports how you use it to anybody, us included, beyond the requests that carry out what you asked for and the things those requests record, which are the same in the app as on the website and are listed under What you do above; the one piece of someone else's software that declares collection of its own is Google's sign-in, described under Signing in with Google above. The app does not ask for permission to track you because nothing in it tracks you.
  • Sharing a file out of the app, and choosing a photo or video to attach, both use Apple's own sheets. When you pick a photo, Apple's picker shows you your library and hands us only the item you chose; the app never reads your photo library. The camera and the microphone are used only while you are taking a picture or recording, with your permission.
  • Sign in with Apple is offered in the app. If you hide your email address, the relay address Apple creates is the only address we hold, as described under Signing in with Apple above.
  • The app sends no push notifications in this version.
  • Translations and typefaces ship inside the app, so opening it fetches neither from Google nor from anyone else. Google's reCAPTCHA on the forms, the Google Maps suggestions in the location fields, and the YouTube previews on the home page are the same in the app as on the website.

Retention Periods

The duration for which we retain different types of information varies:

  • Profile information and content are kept for as long as your account exists.
  • A letter you have scheduled is kept until it has been delivered, however far away that date is, and after delivery it is kept so that the people who received it can still read it. This service exists to hold things for decades, and the periods below do not cut that short. The one thing that ends it early is you: if you delete your account, a letter that has not been delivered yet is deleted with it, and a letter that has already reached someone stays with them.
  • A post is not held the same way, because a post lives on your account rather than in someone else’s mail. A post you have scheduled is kept until its release date, and once released it is kept for as long as your account exists. If you delete your account, your posts are deleted with it whether they were released or not, and that is as true of a post that went out years ago as of one that has not gone out yet.
  • The record of your agreement to these policies, your settings, your likes, follows, blocks and comments are kept for as long as your account exists. The record that you played a post's video or audio lives on that post, and goes when the post goes.
  • Reports, appeals and messages sent through the forms are kept. What happens to them when you delete your account is set out under Deleting your Information below.
  • Our copy of every email we have sent is kept and is not deleted, including after the account it was sent to or about is gone.
  • An account whose email address has still not been confirmed 72 hours after signing up is deleted, with everything on it, by a sweep that runs once a week.
  • The counters that hold anonymous use of the forms to a daily limit are kept under a fingerprint of the network address, made the way the sign-up fingerprint described above is made, and they are not cleared.
  • If your account carried a record of policy violations when you deleted it, that record is kept against the email address that was on the account, with no end date, and it is attached to any account later created with that address, so that a suspension cannot be undone by signing up again. That address is the only identifier we hold for this. We do not collect a phone number.

Please note that public content may persist elsewhere even after removal from Goodbye App . For instance, search engines and other third parties may retain copies of your posts longer, according to their respective privacy policies, even after deletion or expiration on Goodbye App .

Certain information may be retained longer than outlined in our policies to comply with legal obligations and for safety and security purposes.

Take Control

Access, Correction, Portability

  • You can see and change what is on your profile by editing it, and your email address, username, password, language, notification and inactivity settings in Settings. A letter can be opened and edited until it is delivered.
  • You can take a copy of your data from Settings, up to five times a day. It is a single file, and it contains your account record in full, including your email address and the record of your agreement to these policies with the fingerprint and browser description in it, your settings, your letters, delivered and scheduled, your posts, released and scheduled, your comments, your likes, the accounts you follow and that follow you, the notifications you received, the reports and appeals you made, any content of yours we removed, and links to your files. Files are given as links rather than copied into the file. It does not contain letters other people sent you, which are theirs and stay readable in the app.

Privacy and Security Measures

  • Everything above is done from inside your signed-in account, which is how we know it is you. Closing the account asks you to prove it is you on the spot, with your password or through Google or Apple, before it proceeds. You are not signed out to do it.
  • If you write to us instead, we verify that a request comes from the holder of the account before acting on it, and we may decline a request we cannot verify.

Deleting your Information.

You close your account yourself. Settings takes you to one page, and the whole of it happens there: what you are about to lose, an optional note telling us why, and proving it is you. You are not signed out part way through, and you are not sent anywhere else to finish. It is not a request we process later; it happens when you confirm it.

Deleting your account is a deletion and not a deactivation. There is no copy kept in case you change your mind, and there is no way for us to put it back. The moment you confirm it, two things go for good: the login itself, so that you cannot sign in again, and the profile document that holds your display name, your picture and the record of what you agreed to when you signed up. We tell you on the screen in front of you when that much is done.

Closing your account destroys every letter you have written and not yet sent.

That holds for a letter whose release date is years away just as it does for one due next week, and for any post you scheduled that has not been released. Nothing is kept back, and nothing is delivered later on your behalf. If you have written letters you still want delivered, do not close the account. A letter that has already been delivered is not affected. It stays with the person who received it, and closing your account does not take it back from them.

The rest of your account does not go in that same instant. Deleting the profile document is what starts a second process, which runs straight afterwards and takes down: your username, which is released so that it can be claimed again, the people you follow and the people who follow you, your posts, including any post you scheduled that has not been released yet, your comments, your likes, your notifications, the photos, videos and audio you uploaded, your profile picture, the record of the devices you were signed in on for notifications, and every letter you wrote that has not yet been delivered. It usually finishes within a few minutes, and until it does, some of what you posted can still be there.

If you signed in with Apple, we also tell Apple to revoke this app's access to your Apple ID, so the sign-in you gave us is withdrawn along with the account. If Apple cannot be reached, the deletion goes ahead anyway: nobody who has asked to be deleted is kept alive because another company did not answer.

If part of it fails, nothing retries on its own. Some of those failures are recorded against the account in our admin data and some appear only in the server logs, and either way what is left has to be deleted by hand. We do not put a number of days on that, because there is nothing in the system that would keep the promise. We do not send you an email afterwards to confirm any of it. The screen in front of you when you confirm is the only confirmation there is.

What is not deleted, and why

  • A letter that has already been delivered stays with the person who received it. It is theirs now. Deleting your account does not reach into their account and take it back, because being able to keep it was the whole point of your writing it.
  • The same holds for what was delivered to you. We keep the list of letters released to your email address, against the email address that was on the account when you deleted it, so that if you ever come back to it you can still read what was written to you. Posts are not on that list.
  • What other people posted about you belongs to their accounts and not to yours, so it is not deleted along with yours. If something they posted troubles you, you can report it.
  • The line recording that you played the video or audio on somebody else's post stays under that post, for the same reason: it belongs to the post rather than to your account. It holds your account id and the time, and it goes when that post goes.
  • If your account carried a record of policy violations, we keep that record against the email address that was on the account when you deleted it, so that the same person cannot begin again with a clean slate.
  • A report you made about a post, a comment or an account stays, and your account id is taken off it as your account goes. The same is done to a bug report, a feature request, a piece of feedback and the record of a crash. What you wrote in them remains, without you attached to it, because a report is often the only record of something that happened to somebody else. A message you sent through the contact form is the exception: it keeps the account id it was sent with, as said under Reports, appeals and the forms above. A report somebody made about you is deleted outright, and so is any appeal you filed against a suspension of your account.
  • A post or comment we removed for breaking these policies is kept, with any appeal you filed about it, as the record of that decision.
  • Copies that have already left us are past our reach. Search engines and other third parties may hold what was public for some time afterwards, under their own policies rather than ours.
  • We keep what the law requires us to keep, for as long as it requires us to keep it, and no longer.

Objecting to, Restricting, or Withdrawing your Consent.

There is no advertising to opt out of and no profiling to object to, so the usual list of opt-outs does not apply here. No advertising is shown on this site or in the app, nothing you write is used to target advertising at you anywhere, and we belong to no behavioural advertising scheme. What you can withdraw is what you gave: push notifications can be turned off in Settings, the inactivity setting can be turned off there too, a scheduled letter or post can be edited or deleted until it goes out, an account can be blocked, and your agreement to these policies as a whole is withdrawn by closing your account, which ends our use of your information, with the exceptions listed above. If you want your information corrected or restricted rather than deleted, or you want to object to a particular use of it, write to us and say so.

Questions About This Policy

One person runs this service and answers questions about this policy. There is no separate data protection officer to be routed to, and we will not pretend there is. Write to legal@goodbyeapp.com, or use the legal desk on our contact page.

Your Rights and Ours

We provide Goodbye App to people all over the world and offer many of the same tools and controls to all of our users, regardless of where they live. However, your experience may differ slightly from users in other countries, because Goodbye App has to meet local requirements.

Why we are allowed to use your information. Everything we do with it is done to run the service you signed up for, under the agreement you made when you created the account, or because the law requires it. Nothing described here is done for a purpose of our own beyond that, except measuring the advertising we buy, which runs on the website only.

People write here from one country to people in another, so information crosses borders. If you are in Australia and the person you are writing to is in the United States, what you wrote has to travel between those countries for them to read it.

Your information is transferred, stored and processed in countries other than your own, including the United States, which is where this service is run from and where Google holds the data. We do not pass your content to a chain of processors beyond that. Where a third party is involved it is named in this policy, and the services it provides are the ones described here.

For these transfers we rely on the standard contractual clauses in the published terms of the companies named above, on adequacy decisions by the European Commission where they apply, and on your consent for transfers to the United States and other countries where consent is the basis we rely on.

Information about our handling of California Consumer Privacy Act (CCPA) requests is available here.

Changes To This Privacy Policy

The most recent version of this Privacy Policy will govern our processing of your personal data, and we may update this Privacy Policy at any time. We do not send a notice when it changes. There is no announcement in the app and no email: this page always carries the current wording, and the date at the top of it is the date that wording took effect, so reading it is how to see what has changed. The version you agreed to when you signed up is recorded on your account. Changes are not retroactive, and by continuing to use Goodbye App after a change has taken effect you agree to the wording on this page.

General

The policies of Goodbye App are written in English, and we do not publish them in any other language. The app itself is translated; these documents are not. If you are reading one of them in another language, it was translated by your browser or by a translation service, and we have not checked what it says. The English on this page is the version that governs, and where a translation differs from it the English is what applies. You acknowledge that English is the authoritative language for interpreting and enforcing all terms and conditions of Goodbye App.

Google, Apple, Mailgun and the other companies named in this policy handle what reaches them under their own terms and policies, not this one.

Use of Local Storage

Local storage is a place in your browser where a site can keep small amounts of data. It is not a cookie, it is not sent to us with each request, and other sites cannot read it. This is the whole of what Goodbye App keeps there, on the website and in the app alike:

  • Your sign-in token, your account id and your username, which are what keep you signed in between visits. They are removed when you sign out.
  • Your language, and whether you chose it yourself or we took it from your device.
  • Your theme, day or night.
  • Your place in the feed and the posts you have already seen, so that coming back does not start you at the top.
  • Where you stopped in a video, so that it resumes there.
  • Your best score in the dove game.
  • Which blog posts you have read recently, so that a reading is counted once.
  • A reference number for a crash, if one happened, so that a bug report can be matched to it.

For the length of a single visit, and cleared when the tab closes, the browser also holds where to send you after you sign in, whether a Google sign-in is in progress, and the name Apple sent once so that the sign-up screen can show it. Firebase Authentication keeps its own session record on your device in the same way, which is how you stay signed in.

None of this decides what you are shown. You can clear all of it in your browser's settings at any time; doing so signs you out. If your browser blocks local storage, you cannot sign in.


If you have any questions that aren't addressed here, you can always contact us.