Gozali Privacy Policy
Draft for the pilot. It describes what the app does today and must be reviewed before the public launch. Published at gozali.app/privacy.
Last updated: September 27, 2026
Gozali is an app where a small group of friends (a "pack") raises a shared pet by doing a habit every day and proving it with a photo. This policy explains what we collect, why, who can see it, and how to delete it. Questions: hello@gozali.app.
What we collect
- Account: when you sign in with Apple or Google we receive an account identifier, your email address and, if the provider shares it, your name. Apple may give us a private relay email instead of your real one.
- Profile: the display name you choose, a profile photo if you add one, your time zone and language (so days, reminders and quiet hours match your clock), your evening reminder time and which notifications you want.
- What you do in packs: the packs you create or join, your photos, their captions and time, focus session lengths, rest days, jokers and pauses you take, reactions, nudges, name suggestions and changes to the pet's outfit.
- Safety: reports you send and people you block.
- Devices: a push notification token for each phone you sign in on, and a token that lets your widgets read your packs' state (we keep only a scrambled form of it).
- Errors: when something goes wrong in the app, a short technical report (the error, the screen, the app version and whether it's an iPhone or Android phone) so we can fix it. Reports are deleted after 30 days.
We do not collect your location or contacts, we don't use advertising or tracking identifiers, and we don't sell or rent your data.
Who can see what
- Your photos, captions and reactions are visible only to the members of that pack. Photos are stored privately and shown through links that expire within an hour.
- The 🤨 reaction is shown only as a number, without names.
- Pack members see who fed, rested, used a joker, was paused or missed on each day, because that is how the pack works together. Notifications never say who missed.
- Widgets on your home screen and lock screen show only the pet and numbers, never photos or names.
- A weekly recap you share as a story contains the pet, the pack's numbers and only your own photos.
- You don't see the photos and reactions of people you block, and they can't nudge you. If you share a pack with them, they can still see what you post there; you can leave the pack at any time.
How long we keep it
- Photos are deleted automatically 30 days after they were posted. A photo that appears in a weekly recap collage is kept with the recap until the account that posted it, or the pack, is deleted.
- Records of sent notifications are deleted after 30 days, and a widget token that hasn't been used for 90 days is deleted.
- Everything else stays while your account exists.
- Deleting your account (Settings → Delete account) deletes your account, your profile and profile photo, your photos (including those in recaps), your feeds, reactions, passes, tokens and reports right away. Your packs continue without you. A pack that no one has been in for 30 days is deleted, with its photos and recaps.
Services we use
- Supabase stores the data and runs the server (database, file storage, sign-in).
- Expo delivers push notifications, through Apple's and Google's push services.
- Apple and Google provide sign-in.
- Resend delivers report alerts to the developer.
They process data only to provide these services to Gozali.
Your rights
You can see and change your profile in the app, and delete your account and everything in it from Settings. You can also ask us at hello@gozali.app for a copy of your data or to correct it, and we will answer within 30 days. If you live in the European Union or the UK, you may also complain to your data protection authority. The data is stored in the European Union (Ireland).
Age
Gozali is for people aged 13 and over. You confirm your age when you set up your profile. If you believe a younger child is using the app, write to hello@gozali.app and we will delete the account.
Security
Access to data is enforced in the database, so a member can only ever read the packs they belong to. Connections are encrypted, and tokens for widgets are stored only in scrambled form.
Changes
If this policy changes in a way that matters, we will say so in the app before the change takes effect.
Contact
hello@gozali.app