Skip to content

We use cookies

We use cookies and similar technologies to keep this site working, measure how it performs, and (with your permission) personalise ads. Choose your preferences below.

Goosy BearJoin the waitlist

Legal · Last updated August 25, 2026

Privacy Policy

How Goosy Bear collects, uses, shares, and protects personal data across the Goosy Bear website at https://goosybear.ai and the Goosy Bear application — including the third-party accounts customers connect.

1. At a glance

AI Code That Works LLC, a Texas limited liability company doing business as Goosy Bear ("Goosy Bear," "we," "us," or "our") operates the Goosy Bear website at https://goosybear.ai (the "Site") and the Goosy Bear application at https://app.goosybear.ai (the "Application" — together, the "Service"). This Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it. Plain English wherever plain English will do.

  • You give us data on the Site when you join the waitlist (your email address, plus any optional details you choose to add) or when you email us directly.
  • If you use the Goosy trial — the short conversation that reads your website and builds a growth report — you also give us the link you submit, what you type in the chat, your answers to Goosy's questions, and the email address you enter to receive the report. Section 4 sets out exactly what that involves.
  • If you are a Goosy Bear customer, we hold your account, the content you create in the Application, and your billing records — and, where you connect your own third-party accounts (advertising, social publishing, CRM and email, analytics), section 7 sets out per provider what we access, how it is protected, and what happens when you disconnect.
  • Your browser gives us limited technical data through analytics and error-monitoring tools, which are governed by the cookie banner and by your region's consent rules.
  • We use all of it to provide the Service, to bill for it, to reply to you, to send you the updates you asked for, to keep the Service working, and to stop abuse.
  • We share it only with the named service providers in section 6 and the connected-account providers in section 7 — never with data brokers. The complete platform sub-processor list is published at https://goosybear.ai/subprocessors.
  • We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
  • You can ask us for a copy of your data, a correction, or a deletion at any time by emailing goosy@goosybear.ai. Deletion has its own step-by-step page at https://goosybear.ai/data-deletion.

2. Who we are

Goosy Bear is the controller of the personal data described in this Policy — meaning we decide why and how that data is processed — except where section 3 says we act as a processor for a customer.

Postal address: AI Code That Works LLC, 2303 Ranch Road 620 S., Suite 160-240, Lakeway, TX 78734, United States.

For any privacy question, rights request, or complaint, email us and we will route it to a human:

Talk to Goosygoosy@goosybear.ai

We do not currently maintain a separate EU or UK representative. If you are in the EEA or the UK and would prefer to reach a representative in your jurisdiction, email us at the address above and we will handle your request directly.

3. What this Policy covers

This Policy covers the Site — including the waitlist form and the Goosy trial, the short conversation that builds a growth report from a link you give us (the trial is offered only when it is open; when it is not, the Site offers the waitlist instead and nothing in this Policy's trial passages happens) — and the Application: accounts, the content customers create in it, billing, and the third-party accounts customers connect to it. The Application presents its own in-product notices where a specific feature needs one; those sit alongside this Policy rather than replacing it.

Where a customer's workspace contains personal data about the customer's own contacts, leads, and audience — for example the contacts in a connected CRM, the submissions a lead form collects, or the people who message the customer's social pages — we process that data as the customer's processor, on the customer's instructions, under the Data Processing Addendum at https://goosybear.ai/dpa. If you are one of those individuals, the business you dealt with is the controller of your data: direct your request to them, and we will help them honor it.

Goosy Bear is a general-audience business product. It is not directed to children, and section 13 explains what we do if a child's data reaches us anyway.

4. What we collect

Personal data reaches us in the ways below, and in no others.

4.1 Data you give us on the Site

  • The waitlist form. Required: your email address. Optional: your name, your business name, and your answer to “What should Goosy take off your plate first?”. Alongside your entry we store the page you submitted from, the campaign parameters in the link you arrived on (utm_source, utm_medium, utm_campaign, utm_term, utm_content), the referring URL if your browser sent one, and your consent choices with the time they were made. Your IP address is read momentarily to rate-limit submissions and to run the bot check described in section 6, and is not stored on your waitlist record.
  • The Goosy trial. If you use the Goosy trial, we process what you put into it: the website or social-profile link you submit, whatever you type in the conversation, and your answers to Goosy's questions (your monthly marketing spend band, your revenue or orders band, your growth goal, your timeline, and — if you offer them — what winning would look like and what you would rather not do yourself). At the end you enter an email address to receive your report; that becomes an entry in the same place a waitlist entry goes, with your answers attached to it and your consent choices recorded with the time they were made. Your IP address is read momentarily to rate-limit the trial and to run the bot check, and is not stored on your trial record.
  • What the trial does with the link you submit. We fetch the page at that link through Firecrawl and read what it returns with an Anthropic model, which is how Goosy drafts the brand profile it shows back to you. The conversation runs on the same model provider. Section 6 says what each of them receives.
  • What the trial keeps. Your trial lives as a draft record tied to a first-party cookie in your browser rather than to an account, because the trial has no accounts: it holds the link you gave, the brand profile drafted from it, your answers, the result of the bot check, and a count of the turns you have used. The conversation itself is not attached to that draft — but each turn is written to our internal run log with the message you sent, the model used, and what it cost, which is how we account for the spend and find failures.
  • Email you send us. If you write to us, we hold your address, your name if you sign it, and whatever is in the message, for as long as we need it to answer you.

4.2 Data in the Application

  • Account data. Your name, email address, and authentication credentials (passwords are hashed by our authentication provider and are never readable by us), your role in each account and workspace, and your notification preferences.
  • Customer content. The brand profiles, text, images, video, pages, campaigns, and other material you create, upload, or generate in the Application, and the settings and instructions you give Goosy about your business.
  • Billing data. Your subscription plan, invoices, and payment history. Card details are entered directly with Stripe, our payment processor — we receive a token and the card's last four digits for display, never the full card number.
  • Usage and audit records. The actions taken in your account — what was created, approved, published, or spent — kept as an audit trail you can read, plus usage metering for credit-billed features.
  • Support communications. What you send us when you ask for help.

4.3 Data from connected accounts

When a customer connects a third-party account — an ad platform, a social channel, a CRM, an analytics property — we receive data from that provider inside the access the customer granted. Section 7 is the complete, per-category account of what we access, how it is stored, and what happens on disconnect.

4.4 Technical data your browser reports

Pages viewed, referring page, browser and operating-system family, screen size, a pseudonymous device identifier, and — when something breaks — the error and the short trail of actions before it. What is collected and when depends on your consent choice and your region; section 12 is the detail.

We do not ask for government identifiers, health information, precise location, or any other category that privacy law treats as sensitive. Payment card details go directly to Stripe and never touch our servers. The trial never asks for a card at any point, and only ever reads the link you choose to give it — it does not go looking for anything else about you.

5. Why we use it, and on what legal basis

We process personal data only for the purposes below, each on the legal basis named for it (GDPR Article 6; the equivalent basis applies under the UK GDPR).

  • To provide the Application to you under your subscription — accounts, content creation, publishing, the connected-account features you use, and support. Basis: performance of a contract (Article 6(1)(b)).
  • To bill you and keep required financial records. Basis: performance of a contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c)).
  • To put you on the waitlist and send you the product news and updates you asked for. Basis: steps taken at your request before entering a contract (Article 6(1)(b)), and your consent for the marketing emails themselves (Article 6(1)(a)).
  • To run the Goosy trial and build the report you asked for — reading the link you submit, holding the conversation, keeping your draft so you can come back to it, and sending you a link to the finished report. Basis: steps taken at your request before entering a contract (Article 6(1)(b)), and your consent for the follow-up emails disclosed to you at the point you give us your address (Article 6(1)(a)).
  • To understand which parts of the trial people complete, using the analytics described in section 12. We record that a step happened, never what you typed, the link you gave, or your email address. Basis: your consent where consent is required (Article 6(1)(a)); our legitimate interest in a funnel that works otherwise (Article 6(1)(f)).
  • To bound what the trial costs and to stop it being abused — the bot check, the rate limit, the per-conversation turn cap, and the run log that records each turn's model and cost. Basis: our legitimate interest in abuse prevention and in a service we can afford to keep free (Article 6(1)(f)).
  • To reply to an email you send us. Basis: our legitimate interest in answering people who contact us (Article 6(1)(f)).
  • To understand how the Service is used and improve it. Basis: your consent where consent is required (Article 6(1)(a)); our legitimate interest in a service that works otherwise (Article 6(1)(f)).
  • To find and fix errors and keep the Service secure — including the audit trail of actions in the Application. Basis: our legitimate interest in a functioning, secure service (Article 6(1)(f)).
  • To meet our legal, tax, and record-keeping obligations, and to establish or defend legal claims. Basis: legal obligation (Article 6(1)(c)) and legitimate interest (Article 6(1)(f)).

Where we rely on legitimate interests we have weighed them against your rights and concluded they are not overridden. You can object on grounds relating to your particular situation by emailing us. We do not carry out automated decision-making that produces legal or similarly significant effects on you.

6. Service providers and sub-processors

We share personal data with the service providers below, and only as far as each needs it to do its job for us. Each processes data on our instructions under its published data-processing terms.

  • Supabase, Inc. (United States) — the database that stores accounts, customer content, waitlist entries, trial drafts, and consent records. https://supabase.com/privacy
  • Vercel Inc. (United States) — hosting. Every request to the Service passes through Vercel, including your IP address and request metadata. https://vercel.com/legal/privacy-policy
  • Stripe, Inc. (United States) — payment processing for subscriptions and fees. Your card details are entered with Stripe directly; we never receive the full card number. https://stripe.com/privacy
  • LeadConnector LLC, trading as GoHighLevel (United States) — the CRM and email system that holds your waitlist or trial entry and sends you the emails you opted into, and the CRM transport behind the Application's Grow features (section 7.4). https://www.gohighlevel.com/privacy-policy
  • Mailgun Technologies, Inc., a Sinch company (United States) — the transactional email service that delivers system email, including your Golden Egg report link at the end of the trial. https://www.mailgun.com/legal/privacy-policy/
  • Cloudflare, Inc. (United States) — Cloudflare Turnstile, the privacy-preserving bot check on the waitlist form and on the trial. It runs in your browser to confirm you are a person, and Cloudflare states that it does not use it to track users across sites. https://www.cloudflare.com/privacypolicy/
  • SideGuide Technologies, Inc., trading as Firecrawl (United States) — the page-reading service the trial and the Application's brand-ingestion features use. In the trial it receives the website or social-profile link you submit and fetches that page on our behalf, returning its text to us. It receives that link and nothing else you told Goosy. https://www.firecrawl.dev/privacy-policy
  • Anthropic PBC (United States) — an AI provider behind Goosy. In the trial it receives the text of the page we fetched and the messages you send, and returns Goosy's replies and the drafted profile. https://www.anthropic.com/legal/privacy
  • PostHog Inc. (United States) — product analytics, when you have granted analytics consent. Receives pseudonymous page and interaction events, including which step of the trial a visitor reached — never what you typed, never the link you gave, never your email address. https://posthog.com/privacy
  • Functional Software, Inc., trading as Sentry (United States) — error monitoring and session replay. Receives errors, stack traces, and the short trail of actions before an error. https://sentry.io/privacy
  • Google LLC (United States) — Google Tag Manager and Google Analytics 4, on the production Site only and subject to the consent rules in section 12. https://policies.google.com/privacy

Our current list of platform sub-processors is published at https://goosybear.ai/subprocessors and is generated from the sub-processor register we maintain, so it reflects the providers in use at the time you read it — each with its role, the categories of data it processes, and where it operates. Material additions are notified as section 16 describes.

Beyond those providers we may disclose personal data where a subpoena, court order, or other valid legal process requires it; to protect our rights, property, or safety or those of others; and in connection with a merger or sale of the business, in which case we will give you notice where the law requires it.

7. Connected accounts and platform data

The Application lets a customer connect their own third-party accounts so Goosy can do marketing work on them. This section applies to business customers who have linked an account of their own — not to a visitor to the Site. What we reach depends on the provider and on what the customer chose to connect; the categories below are the complete map.

7.1 How connections work

Every connection is made through the provider's own consent or authorization screen, with the narrowest access that makes the feature work, and we act on the account only inside the access the customer grants there. Connecting an account is itself a consent, and we record it as one: which provider and account, what was granted, and when. Access can be revoked at any time — from the provider's own settings or from the Connections page inside Goosy Bear — and everything described below stops when it is.

Removing a connection, and asking us to delete the data obtained through it, is covered step-by-step at https://goosybear.ai/data-deletion — the same instructions Meta and the other platforms point their users to.

7.2 Advertising platforms

Ad accounts stay customer-owned: the customer creates and owns the account on each platform, pays the platform directly for ad spend, and grants Goosy Bear management access. We never take custody of ad budget, and our fees are never a percentage of spend. Every automated action runs inside the budgets and approval gates the customer sets.

  • Meta Ads (Facebook and Instagram) — the customer's ad accounts under the partner access they grant: campaigns, ad sets, ads, audiences they direct us to use, and performance results.
  • Google Ads — campaign management and reporting on the customer's own Google Ads account, linked to our manager account rather than moved into it: campaigns, budgets they approve, and performance results.
  • LinkedIn Ads — the customer's ad accounts and campaign data, the submissions their lead-generation forms collect, and the conversion events their campaigns record.
  • TikTok Ads — the customer's advertiser account, added to our partner access: campaigns and performance results.
  • Snapchat Ads — the customer's ad account: campaigns and performance results.
  • X Ads — the customer's ads account: campaigns and performance results.

7.3 Social publishing and community

For the channels a customer connects, we publish the content they approve and read back the engagement it earns. Where an inbox feature is on, we also read the messages and comments people send the customer's pages so Goosy can draft replies — and a draft is routed to a human for approval before anything is sent, except where the customer has explicitly turned on auto-send for a channel.

  • Facebook Pages and Instagram — publishing to the customer's Page and Instagram account, the comments and messages on them, and post-level engagement.
  • Threads — publishing to the customer's profile and reading the replies and engagement on those posts.
  • LinkedIn — publishing to the customer's company page and reading the engagement on those posts.
  • TikTok — publishing videos to the customer's account and reading their performance.
  • Pinterest — publishing pins to the customer's boards and reading their performance.
  • X — publishing posts to the customer's account and reading their performance.
  • YouTube — uploading videos to the customer's channel when they ask for one, and reading the channel and video analytics they grant. Section 7.8 carries the YouTube-specific disclosures.
  • Google Business Profile — posts and updates to the customer's business listing, and drafting replies to the reviews on it.
  • WordPress and Webflow — publishing pages and posts to the customer's own site.
  • Transistor — publishing podcast episodes to the customer's show and reading their performance.

7.4 CRM, messaging, and email delivery

  • GoHighLevel — the contacts, conversations, calendars, and pipelines in the customer's own sub-account, and the email and SMS we send from it on the customer's instruction. This is the transport behind the Grow features; the customer's contacts stay in the customer's sub-account.
  • Klaviyo — the lists, segments, campaigns, and subscriber data in the customer's own Klaviyo account, read and written on their instruction.
  • ActiveCampaign — the same: the customer's own lists, contacts, and campaigns, on their instruction.

The personal data inside these systems — the customer's contacts and leads — is the customer's data. We process it as their processor under the Data Processing Addendum (section 3), and we never use one customer's contacts for any other customer or for our own marketing.

7.5 Analytics and attribution

  • Google Analytics 4 — read-only access to the reporting on the customer's own Analytics property, so Goosy can ground its recommendations in what the customer's site is actually doing.
  • Google Search Console — read-only access to the search performance of the customer's own verified site.
  • HYROS — the attribution data in the customer's own HYROS account, where they connect one.

7.6 How connected-account data is protected

Provider data is stored per customer, with row-level isolation enforced by the database itself rather than by application code remembering to filter — the same measure section 14 describes. The access tokens a connection produces live in an encrypted secret vault: they are never written into code, into logs, or into an error message, and every use of one is logged. Automated actions run inside the budgets and the approval gates the customer set, and each one lands in an audit log the customer can read.

7.7 Deletion on disconnect

When a customer disconnects a provider — or deletes their Goosy Bear account — we delete that connection's tokens immediately and the data we obtained through it within 30 days, except anything the law requires us to keep. Backup snapshots that already hold a deleted record expire on their own, on the schedule in section 9.

7.8 Provider-required disclosures

Goosy Bear's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That policy is at https://developers.google.com/terms/api-services-user-data-policy.

Goosy Bear uses YouTube API Services. By using the YouTube features of the Application you agree to the YouTube Terms of Service at https://www.youtube.com/t/terms, and Google's handling of your data is described in the Google Privacy Policy at http://www.google.com/policies/privacy. You can revoke Goosy Bear's access to your Google data at any time via the Google security settings page at https://security.google.com/settings/security/permissions.

8. International transfers

Our providers operate primarily from the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK Addendum to those clauses for UK transfers, and — where the provider has self-certified — the EU-US Data Privacy Framework and its UK extension. You may request a copy of the relevant safeguards by emailing us; copies may be redacted to protect commercially sensitive terms.

9. How long we keep it

We keep personal data only as long as the purpose it was collected for needs it, or as long as the law requires.

  • Application accounts and customer content — for the life of the account, then deleted within 30 days of account deletion (after the 30-day recovery grace period on workspace and account deletion runs out).
  • Connected-account data — deleted within 30 days of the connection being removed, per section 7.7.
  • Billing and tax records — 7 years, because tax law requires it.
  • Audit and usage records — for the life of the account, deleted with it.
  • Waitlist and trial entries — 24 months from your last interaction with us, then deleted or anonymized. If you unsubscribe or ask not to be contacted, we keep your email address on a suppression list indefinitely, because that is the only reliable way to honor the request.
  • Trial drafts — 30 days. Every draft is stamped with a 30-day expiry when it is created, and one that has not become an account by then is deleted. The cookie that points at it expires on the same schedule.
  • Trial run-log entries — the per-turn record of the message, the model, and the cost. We keep these as operational records of what the trial spent, and we delete yours if you ask us to.
  • Email correspondence — for as long as our exchange is live, plus up to 7 years for tax, accounting, and dispute purposes.
  • Analytics events — 14 months from capture. Aggregate, non-identifying summaries may be kept longer.
  • Error events and session replays — 30 days from capture, then deleted under the provider's retention policy.
  • Backups — a deleted record can persist in backup snapshots for up to 35 days, after which the snapshot expires.

Where the law requires us to keep a record for longer — tax records, or anything tied to a live legal claim — we keep it for the statutory period and apply the periods above once that period ends.

10. Your rights

Depending on where you live, you have some or all of the following rights over your personal data. We apply them to everyone who asks, wherever they live, because operating two standards is how mistakes happen.

  • Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Correction — fix data that is wrong or incomplete.
  • Deletion — have your personal data erased, subject to the narrow exceptions in section 9 (a suppression-list entry, and anything the law requires us to keep).
  • Restriction — pause our processing while a dispute about accuracy or objection is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format.
  • Objection — object to processing we base on legitimate interests, and to direct marketing at any time. We stop direct marketing on request, no questions asked.
  • Withdraw consent — withdraw any consent you gave, at any time, without affecting what we lawfully did before you withdrew it.
  • Non-discrimination — we will not treat you differently for exercising any of these rights.
  • Complain — lodge a complaint with your data-protection authority. In the EU, the list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en; in the UK it is the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

California residents have the equivalent rights under the CCPA as amended by the CPRA — to know, to access specific pieces, to delete, to correct, to opt out of sale or sharing (there is nothing to opt out of, as section 6 explains), to limit the use of sensitive personal information (we collect none), and to non-discrimination. Residents of Colorado, Connecticut, Virginia, Utah, and other states with comparable laws have equivalent rights, and we honor them on the same basis.

If your personal data reached us inside a customer's workspace — you are a contact, lead, or audience member of a business that uses Goosy Bear — the business you dealt with is the controller (section 3). Send your request to them; if you send it to us instead, we will pass it to them and help them honor it.

11. How to exercise your rights

Email us and tell us which right you want to exercise and which email address you used with us. That is the whole process — there is no form to hunt for.

Talk to Goosygoosy@goosybear.ai

If what you want is deletion specifically, https://goosybear.ai/data-deletion sets out the steps, the exact subject line to use, and what happens after you send it.

We acknowledge requests within 5 business days and complete them within the window the law gives us — normally one month under the GDPR (extendable by two further months for genuinely complex requests, with notice), and 45 days under the CCPA (extendable by 45 further days, with notice).

We verify you before we act, normally by confirming you control the email address on file. You may use an authorized agent; a California agent must provide written proof of authorization, and we may contact you to confirm it. There is no fee, though we may decline or charge for requests that are manifestly unfounded or repetitive.

12. Cookies, analytics, and your consent

This Site sets its own first-party cookies and browser storage only. It does not host any third-party advertising cookie, remarketing tag, or social pixel. Here is everything that runs.

  • Strictly necessary — a first-party cookie named `revastack_consent`, plus a matching entry in your browser's local storage, recording your cookie-banner choice for one year. It carries the shared platform prefix rather than a Goosy-branded name because the consent component is shared across our family of sites; it holds nothing but your choice. This one is set whichever way you answer the banner, because forgetting your answer would mean asking again on every page.
  • Analytics — PostHog, which sets first-party cookies beginning `ph_`, and Sentry, which uses browser storage rather than a cookie. Both are governed by the analytics category on the banner. PostHog starts opted out and only begins collecting once the analytics category is granted; withdrawing consent opts it back out and resets the identifier it held. Sentry keeps a short rolling buffer that is sent only if an error actually occurs — the software masks text, inputs, and media by default — and starts full session replay only after you grant analytics consent.
  • Google Tag Manager and Google Analytics 4 — loaded only on the live production site, and only through our own tag container. GA4 sets first-party cookies named `_ga` and `_ga_*`. Preview and staging builds of this Site load no tags at all, so our own testing never lands in the analytics data.
  • Strictly necessary — a first-party cookie named `goosy_trial_session`, set only if you start the Goosy trial and only after the bot check has passed. It holds one value: an identifier with no meaning outside this Site, which is what lets the trial recognize your own draft when you come back to it. Your browser cannot read it, and it expires after 30 days along with the draft it points at. No trial, no cookie.
  • Strictly necessary — a first-party cookie named `goosy_trial_rollout`, set the first time you ask to start the trial — including when the bot check refuses, which is deliberate. It holds one random identifier with no meaning outside this Site, used for exactly one thing: keeping our answer to "is the trial open to you yet" stable while we open it up gradually, so reloading the page cannot change that answer. It creates no draft, records nothing you typed, and expires after 30 days.
  • Cloudflare Turnstile — the bot check on the waitlist form and on the trial. It loads in your browser to confirm you are a person and may keep a short-lived challenge token; Cloudflare states that it is not used to track you across sites.

The Application at https://app.goosybear.ai sets its own strictly necessary cookies — the authentication session that keeps you signed in — and nothing in this section's analytics categories runs there outside the same consent rules.

Your default depends on where you are. If you are in the European Economic Area, the United Kingdom, or Switzerland, analytics and marketing consent both start DENIED and nothing beyond the strictly necessary cookie runs until you grant it on the banner. Everywhere else — including the United States, Canada, Australia, and New Zealand — they start GRANTED and the banner is how you turn them off. Your explicit choice on the banner always overrides the regional default, and it applies to that browser until you change it.

We honor the Global Privacy Control signal. If your browser sends `Sec-GPC: 1` or exposes `navigator.globalPrivacyControl === true`, we treat it as a denial of analytics and marketing consent regardless of your region. You can still grant consent explicitly on the banner if you want to, and that explicit choice wins. There is no industry consensus on what the older Do Not Track header means, so we do not act on it on its own.

You can change your mind at any time — clear this site's cookies and site data in your browser (both the cookie and the matching local-storage entry) and the banner will ask you again on your next visit. A Global Privacy Control signal is honored as a denial when you have not yet answered the banner; once you have made an explicit choice, that choice stands until you clear it and answer again.

13. Children's privacy

Goosy Bear is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you are under 16, do not join the waitlist or email us. If we learn that we have collected personal data from a child under 16 without a parent's verified consent, we delete it as soon as we reasonably can. Parents and guardians who believe we hold a child's data can write to goosy@goosybear.ai and we will investigate and respond.

14. How we protect it

We apply technical and organizational measures proportionate to the data the Service holds:

  • TLS encryption in transit for every connection to the Service and between our systems and our providers, and encryption at rest in the database.
  • Row-level security in the database, so customer isolation is enforced by the database itself rather than by application code remembering to filter.
  • Least-privilege credentials — administrative database keys never reach your browser, connected-account tokens live in an encrypted vault with every access logged, and operator access to live data is limited and logged.
  • Approval gates and budgets on every action that publishes content or spends money, with an audit trail the customer can read.
  • Rate limiting and a bot check on the public forms.
  • Automated error monitoring and an audit trail, so unusual activity surfaces quickly.

No measure is perfect and we cannot guarantee absolute security. If a breach occurs that is likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where the law requires it, and notify you without undue delay where the risk to you is high.

The Service may link to third-party websites and services we do not control. This Policy covers only the Service. Read their privacy notices before giving them your data.

16. Changes to this Policy

We update this Policy when what we do changes. The 'Last updated' date at the top always reflects the most recent change. When a change is material — including a material addition to the sub-processor list or a change in what we do with connected-account data — we will tell you by email if we hold your address and the change matters to you, or by a notice on the Service for at least 30 days before it takes effect.

17. Contact us

Questions, requests, or complaints about privacy all go to the same place:

Talk to Goosygoosy@goosybear.ai

AI Code That Works LLC, 2303 Ranch Road 620 S., Suite 160-240, Lakeway, TX 78734, United States. Effective 2026-08-25.