Privacy Policy
Last updated: 23 September 2026
This policy explains what Goalfinder collects when you use the API and the dashboard, what we do with it, and — importantly — what happens to your prompts once they leave us. Plain language, no surprises.
1. What we collect
We keep this deliberately minimal. We collect:
- Account data — the email address you sign up with, and an authentication record. We do not ask for your name, phone number or date of birth.
- Billing data — which pack you bought, the amount, and the timestamp. Your card details are handled entirely by our payment processor; they never reach our servers and we cannot see them.
- API keys — stored only as a SHA-256 hash, plus the key's display prefix. We never store the full key after you create it, which means we cannot recover it for you if you lose it.
- Usage metadata — for each request: the model ID, token counts (prompt, completion and cache), the cost deducted, the API key used, and the time of the request.
2. What we do not store
We do not store the content of your prompts or the model's responses.
Your messages are streamed through our gateway to the upstream provider and are not written to our database, our logs or our backups. The usage_logs table records counts and costs — never text.
The one practical exception is the standard web-server logging that any internet service performs (request paths, status codes, IP addresses) for security and abuse prevention. We do not mine that data, and we do not tie it to your prompt content.
3. Your data reaches our upstream model providers
Please read this section before sending confidential material through the API.
Goalfinder is a gateway. To answer your request, we must forward your prompt — in full — to the provider that serves the model you called. Whatever that provider does with your content is governed by its policies, not ours, and we cannot override them.
The provider may retain your prompts and may use them to train its models. That includes Claude, which we serve through a third-party provider rather than Anthropic directly. We keep nothing ourselves, but we cannot make the provider delete anything, and we will not pretend otherwise. If that is not acceptable for what you intend to send, do not use this service.
Every model we sell is served by the same underlying provider, so the position below applies to all of them:
| Provider | Retention | Training on your data |
|---|---|---|
| Anthropic Claude Opus & Sonnet | Retained according to Anthropic's commercial terms. Content may be stored for the life of your account and deleted on request. | May be used for training where your agreement with Anthropic permits it. Requests sent through an eligible zero-data-retention arrangement are handled differently — see Anthropic's current terms. |
In short: the provider behind every model we serve may retain your inputs and may use them to train. We do not add to that, and we do not retain anything ourselves. If your inputs must not be retained or trained on, do not send them to a gateway like this one — use the model provider directly under a contractual arrangement that guarantees it.
4. Choosing the right route for the data
- Do not send secrets, credentials, personal data about other people, regulated data, or material under a confidentiality obligation through this service. Every model we sell is served by a third-party provider that may retain and train on what you send.
- If you need inputs that are never retained or trained on, go to Anthropic directly and contract for zero data retention. We cannot provide that guarantee on our provider's behalf, which is why we do not claim to offer it.
- Provider policies change without notice. We summarise them here in good faith, but the provider's own current policy is the authoritative text — please verify it before relying on this page for a compliance decision.
5. How we use what we collect
Account and usage metadata is used to authenticate your requests, meter and bill usage correctly, run the dashboard that shows your balance and request history, prevent abuse, and provide support when you contact us. We do not sell your data, and we do not use your prompts or responses to train any model of our own.
We share data only with the parties required to run the service: the upstream model providers (your prompt content, as described above), our payment processor (billing details), and our database and hosting infrastructure providers (account and usage records).
6. Retention and deletion
Account, billing and usage-metadata records are kept while your account is open and for as long as we need them for accounting, tax and dispute-resolution purposes. Because we do not store prompt or response content, there is no conversation history to delete — but you may request deletion of your account, API keys and associated metadata at any time by emailing us. We will action the request within 30 days, except where we are required to retain specific records by law.
7. Security
Traffic between you, our gateway and our upstream providers is encrypted in transit with TLS. API keys are stored as one-way hashes. Access to production data is restricted to the operator of the service. No system is perfect, but we do not hold the one thing that would make a breach of this service catastrophic for you: your prompt content.
8. Age requirement
Goalfinder is a developer tool and is not directed at children. You must be at least 18 years old, or the age of majority where you live, to create an account.
9. Changes to this policy
If we change how we handle your data — for example, by adding a model provider with different terms — we will update this page and revise the "last updated" date above. Continuing to use the service after a change means you accept the revised policy.
10. Contact
Questions about this policy, or want your account and data deleted? Email contact@goalfinder.space. Please write from the email address on your account so we can verify the request.