Privacy Policy — Goami
Last updated: 1 October 2026
Goami is built with privacy as a default. This policy describes, in plain language, how the iOS and Android applications and this website collect, use, and protect your personal data.
1. About us
Goami is an iOS and Android application developed by Stéphan Bordera, independent developer based in France. This is an indie project: no team, no investors, no advertising revenue.
2. What data we collect
Account data
- Username that you choose when signing up
- Unique identifier (UUID) automatically generated for your account
- Email address — optional. Only collected if you choose to register an email for account backup and restoration. You can use Goami fully without providing an email (anonymous account). If provided, the email is used solely to send you authentication magic links. We do not store your email address in clear text: only a non-reversible hashed form is kept in our database, used to recognize your email at sign-in.
- Device language (used to localize notifications and the interface)
Business data (entered by you)
- Groups you create or join: name, currency, member list
- Expenses you record: amounts, descriptions, categories, dates, payer, shares
- Settlements between group members
Technical data
- Push notification identifier (Apple APNs token) to send you push notifications
- Device identifier (internal UUID) to distinguish your devices and sync data across them
- Authentication tokens stored on your device
- IP address, which may appear temporarily in server logs for security and diagnostic purposes (see retention below)
- Action timestamps to enable synchronization between devices and group members
Anonymous usage statistics
To understand how Goami is used and improve it, the app records which screens are shown and for how long, which buttons are tapped, and whether key actions (such as adding an expense) are completed, along with the app version, system version and app language. These statistics are anonymous:
- They are not linked to your account, your device or any identifier that could recognize you, and your IP address is not stored with them.
- Events are grouped only by a random number drawn each time the app is launched and forgotten when it is closed: two uses of the app cannot be linked together.
- They never contain what you enter: no names, amounts, descriptions or group contents.
- They are measured in-house and stored on our servers in France, without any third-party analytics service.
Website data
This landing page is static. It does not use cookies, third-party analytics, advertising trackers, or behavioral profiling. If you email us, we only use your message to reply to you.
What we do NOT collect
- Your phone number
- Your photo or profile picture
- Your GPS or precise location
- Your contacts
- Your web browsing data outside of the app
- Any banking, credit card, or sensitive financial data
- No data is collected for advertising or marketing tracking, and no usage data is linked to you
3. How your data is used
Your data is used exclusively to operate the application:
- Display your groups, expenses, and balances
- Synchronize your data across your devices and with other members of your groups
- Send you push notifications when activity concerns one of your groups
- Send you magic link authentication emails (if you provided an email)
- Ensure service security (authentication, abuse prevention)
We never use your data for advertising or marketing. Usage statistics are anonymous and only serve to improve the app. No data is sold or shared with third parties.
4. Where your data is stored
Your data is hosted on Scaleway servers located in France (European Union). Scaleway is a French cloud infrastructure provider, GDPR-compliant by design.
Data is encrypted in transit (HTTPS / TLS) between the application and our servers.
Authentication emails (magic links) are sent through Scaleway Transactional Email, also hosted in France.
Push notifications transit through Apple's APNs servers (Apple Push Notification service).
5. How long we keep your data
- Your account data and business data are kept as long as your account is active
- Server logs that may contain your IP address are retained only for the short period set by our host Scaleway's default observability retention (currently 7 days for logs), after which they are automatically deleted. We do not extend this retention.
- If you choose to remove your email from your account, it is deleted immediately from our database
- Account deletion is described in detail in the next section
- Anonymous usage statistics are automatically deleted after 13 months. Since they cannot be linked to anyone, they cannot be retrieved or deleted for a particular person.
6. Deleting your account
You can delete your account at any time, directly from the application (in your profile settings). When you delete your account:
- Your account is immediately deactivated and you can no longer sign in. Your authentication sessions and devices are revoked.
- Your personal data is permanently erased right away: your email address (and its stored form), your profile color, and any premium status. Your username is not used elsewhere and is no longer treated as an active profile.
- Important — shared groups: if you took part in expenses within a shared group, your contributions and the amounts involved are kept, because deleting them would break the balances and debts of the other members. In those groups your name stays visible but is clearly marked as a deleted account, so the others can still see who an amount relates to. We keep the minimum necessary for the accounting integrity of the other members, and nothing more.
- Groups you created are transferred to the oldest remaining real member. If you were the only real member, the group is deleted along with any virtual members you had created.
- Unsettled balances remain visible to the other members, under your name marked as deleted, so their accounts stay correct.
This deletion is permanent: a deleted account cannot be recovered. If you later create a new account, it starts fresh and is not linked to the deleted one.
7. Your rights (GDPR)
Under the GDPR (European General Data Protection Regulation) and applicable laws, you have the following rights:
- Access to your personal data
- Rectification of inaccurate data
- Erasure (account and data deletion)
- Portability (export of your data in a structured format)
- Objection to processing
- Restriction of processing
To exercise any of these rights, email hello@goami-app.com. We respond within 30 days.
8. Security
Goami uses several mechanisms to protect your data:
- Encrypted HTTPS / TLS communication between the application and our servers
- Magic link authentication (no passwords stored or transmitted)
- Authentication tokens stored securely on your device using Apple's Keychain
- No banking or sensitive financial data is collected or stored
- Servers hosted within the European Union (Scaleway, France)
9. Children
Goami is not intended for children under 13 years of age. We do not knowingly collect data from children under 13. If you become aware that a child has provided personal data to us, please contact hello@goami-app.com and we will delete the data.
10. Changes to this policy
This policy may be updated to reflect changes in the application (particularly when new features are added). Any significant change will be announced in the release notes of the app on the App Store and Google Play. The "Last updated" date at the top of this page will always reflect the latest revision.
11. Contact
For any question regarding this privacy policy, your data, or to exercise your GDPR rights: hello@goami-app.com
12. Legal information
Publisher: Stéphan Bordera
Application: Goami
Country: France