Privacy Policy

Last updated: December 16, 2025

At GoalBox, we take your privacy seriously. This Privacy Policy explains how we collect, use, protect, and share your personal information when you use our mobile application. We are committed to GDPR (EU) and CCPA (California) compliance.

1. Information We Collect

We collect the following types of information:

1.1 Personal Financial Data

  • Financial Goals: Your savings goals, target amounts, deadlines, and goal descriptions
  • Transactions: Income and expense records, transaction amounts, dates, categories, and notes
  • Attachments: Photos and receipts you upload with transactions (may contain personally identifiable information)
  • Currency Preferences: Your selected base currency and gold karat preferences

1.2 Device Information

  • Device Details: Device model, operating system version, app version
  • Security Status: Root detection status (for fraud prevention)
  • Unique Identifiers: Device IDs (used for AdMob and billing)

1.3 Usage Data

  • App Interactions: Features used, screens viewed, app crashes
  • Performance Data: App loading times, error logs

2. How We Use Your Information

We use your information to:

  • Provide core GoalBox functionality (goal tracking, transaction management)
  • Fetch real-time currency exchange rates and gold prices
  • Process in-app purchases and subscriptions
  • Display personalized advertisements (via Google AdMob)
  • Improve app performance and fix bugs
  • Detect and prevent fraud, abuse, or unauthorized use
  • Comply with legal obligations

3. Third-Party Services

We share limited data with the following third-party services:

Google AdMob (Advertising)

Data Shared: Device IDs, app usage data, approximate location (if permission granted)

Purpose: Display personalized advertisements

Privacy Policy: https://policies.google.com/privacy

User Control: You can manage ad personalization via device settings or app consent dialog

Google Play Billing (In-App Purchases)

Data Shared: Purchase history, subscription status (managed by Google)

Purpose: Process premium feature purchases

Privacy Policy: https://play.google.com/intl/en_us/about/play-terms/

Google Drive (Optional Backup)

Data Shared: Encrypted backup files (only if you enable Google Drive backup)

Purpose: Secure cloud backup of your financial data

Privacy Policy: https://policies.google.com/privacy

User Control: You must explicitly grant permission to upload backups to Google Drive

ExchangeRate-API (Currency Data)

Data Shared: Currency codes (e.g., USD, EUR) - NO personal data

Purpose: Fetch real-time currency exchange rates

Privacy Policy: https://www.exchangerate-api.com/terms

GoldAPI.io (Gold Price Data)

Data Shared: Currency code for gold prices - NO personal data

Purpose: Fetch real-time gold prices per gram for different karats

Privacy Policy: https://www.goldapi.io/terms-of-service

4. Data Storage and Security

4.1 Local Storage

  • Primary Storage: All financial data is stored locally on your device in an encrypted SQLite database
  • App-Private Directory: Data is stored in the app's private directory, inaccessible to other apps
  • No Automatic Cloud Sync: We do NOT automatically upload your data to cloud servers

4.2 Security Measures

✓ Enhanced Security (Updated December 2025):

  • Database Encryption (NEW): Your database is now encrypted at rest using SQLCipher with AES-256 encryption
  • Secure Key Storage: Database encryption keys are stored in Android Keystore (hardware-backed encryption)
  • Encrypted Backups: Backup files use AES-256-GCM encryption with user-provided password protection
  • Password-Protected Exports: When exporting data (JSON format), you must provide a strong password to encrypt the file
  • HTTPS Only: All network communications use HTTPS with TLS 1.2+
  • Certificate Pinning: API connections use certificate pinning to prevent man-in-the-middle attacks
  • No Cleartext Traffic: Network security config blocks all HTTP connections
  • Root Detection: Billing features disabled on rooted devices (fraud prevention)

4.3 Backup & Export Features

GoalBox provides multiple options to backup and export your data:

  • Local Backup: Create encrypted backup files stored on your device (requires password)
  • Google Drive Backup: Upload encrypted backups to your personal Google Drive account (requires Google Drive permission and password)
  • Data Export: Export your data as encrypted JSON files (requires password)
  • Data Import: Restore from local backups or Google Drive backups (requires correct password)
  • Encryption: All backup and export files are encrypted with AES-256-GCM using your password-derived key

🔒 Password Protection:

When creating backups or exporting data, you must provide a strong password. This password is used to derive an encryption key (using PBKDF2 with 100,000 iterations). We do NOT store your backup password - if you lose it, your backup data cannot be recovered. Choose a strong, memorable password and store it securely.

5. Data Sharing

We do NOT sell, trade, or rent your personal information to third parties. We may share data only in these circumstances:

  • With Your Consent: When you explicitly approve data sharing (e.g., Google Drive backup)
  • Legal Compliance: To comply with laws, subpoenas, or court orders
  • Fraud Prevention: To protect our rights, prevent fraud, or ensure user safety
  • Third-Party Services: As described in Section 3 above

6. Your Privacy Rights

6.1 Rights for All Users

  • Right to Access: Export your data via the backup/export feature (Settings > Backup & Export)
  • Right to Delete: Clear all data via Settings > Clear Data, or uninstall the app
  • Right to Correct: Edit your goals and transactions directly in the app
  • Right to Opt-Out: Manage ad personalization via device settings or consent dialog
  • Right to Data Portability: Export your data in JSON format

6.2 GDPR Rights (EU/EEA/UK Residents)

If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under GDPR:

  • Right to Data Portability: Request your data in a machine-readable format (use export feature or contact gdpr@goalbox.app)
  • Right to Restriction: Request we restrict processing of your data
  • Right to Object: Object to data processing for direct marketing or legitimate interests
  • Right to Lodge a Complaint: Contact your local data protection authority
  • Data Protection Officer: Contact our DPO at gdpr@goalbox.app

6.3 CCPA Rights (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request details about the personal information we collect, use, and share
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out of Sale: We do NOT sell your personal information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights
  • Contact for CCPA Requests: ccpa@goalbox.app

Do Not Sell My Personal Information

GoalBox does NOT sell your personal information as defined by CCPA. We only share data with third-party services as described in Section 3 for functional purposes (ads, currency rates, billing).

7. Data Retention

We retain your data as follows:

  • Local Database: Data is retained until you delete it or uninstall the app
  • Backup Files: Retained until you delete them (user responsibility)
  • Google Drive Backups: Retained in your Google Drive until you delete them
  • AdMob Data: Google retains advertising data for 90-180 days (see Google's policy)
  • Billing Data: Google Play retains purchase history per their retention policy
  • API Logs: Our custom ads server does NOT log personal data

8. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including:

  • United States: Google AdMob, Google Play Billing, Google Drive servers
  • European Union: Some API providers may use EU servers

We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.

9. Children's Privacy

GoalBox is rated 3+ and suitable for all ages. However, we comply with COPPA (Children's Online Privacy Protection Act) requirements for users under 13 years of age.

  • Parental Supervision: We recommend that parents or guardians supervise children's use of the app
  • No Data Collection from Children: We do not knowingly collect personal information from children under 13 without verifiable parental consent
  • Data Stored Locally: All financial data is stored locally on the device, not on our servers
  • Parental Rights: Parents can review, delete, or request information about data stored in the app by accessing the device

If you are a parent or guardian and believe we have collected data from a child under 13 without your consent, please contact us immediately at privacy@goalbox.app, and we will provide guidance on how to delete the locally stored data.

10. Cookies and Tracking Technologies

GoalBox uses the following tracking technologies:

  • AdMob SDK: Uses advertising IDs and cookies for ad targeting
  • Analytics: We may use anonymized analytics to improve app performance
  • No Web Cookies: The app does NOT use browser cookies (it's a native mobile app)

You can reset your advertising ID or opt out of personalized ads in your device settings:

  • Android: Settings > Google > Ads > Reset advertising ID or Opt out of Ads Personalization

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of changes by:

  • Posting the updated policy on this page
  • Updating the "Last updated" date
  • Sending an in-app notification for material changes

Continued use of GoalBox after changes constitutes acceptance of the updated policy.

12. Automated Decision-Making and Profiling

GoalBox does NOT use automated decision-making or profiling that produces legal or similarly significant effects.

Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, please contact us:

Support: alialfayed.official@gmail.com

Terms & Conditions

Last updated: December 16, 2025

By downloading, installing, or using GoalBox, you agree to be bound by these Terms and Conditions. If you do not agree, please do not use the app.

1. Acceptance of Terms

By accessing and using GoalBox, you accept and agree to be bound by the terms and provision of this agreement. If you do not agree to abide by the above, please do not use this service.

2. Use License

Permission is granted to download and use GoalBox for personal, non-commercial use only. This is the grant of a license, not a transfer of title, and under this license you may not:

  • Modify, reverse engineer, decompile, or disassemble the software
  • Use the app for any commercial purpose or public display
  • Remove any copyright or proprietary notations
  • Transfer the app to another person or device (beyond normal device migrations)
  • Attempt to circumvent security measures or premium features

3. Premium Features and Subscriptions

3.1 In-App Purchases

GoalBox offers premium features through one-time purchases and/or subscriptions. By purchasing premium features, you agree to:

  • Pay the displayed price (including applicable taxes)
  • Automatic renewal for subscriptions (unless cancelled before renewal date)
  • No refunds for partial subscription periods (except as required by law)

3.2 Subscription Terms

  • Billing Cycle: Subscriptions renew automatically (monthly, yearly, or as specified)
  • Cancellation: Cancel anytime via Google Play Store > Subscriptions
  • Price Changes: We reserve the right to change subscription prices with 30 days' notice
  • Free Trials: If offered, billing begins after the trial period ends (unless cancelled)

3.3 Refund Policy

Refunds are subject to Google Play Store policies:

  • Refunds within 48 hours of purchase may be requested via Google Play
  • Subscription refunds follow Google's refund policy
  • We reserve the right to deny refunds for violations of these Terms

4. User Responsibilities

You are responsible for:

  • Maintaining the confidentiality and security of your device and app data
  • All activities that occur within the app on your device
  • Backing up your data regularly (we are not liable for data loss)
  • Using the app in compliance with all applicable laws and regulations
  • Ensuring transaction data accuracy (GoalBox is a personal finance tracker, not a bank)
  • Remembering your backup passwords (we cannot recover encrypted backups if you lose your password)

5. Prohibited Uses

You may NOT use GoalBox:

  • For any unlawful purpose or to solicit unlawful acts
  • To violate any international, federal, provincial, or state laws
  • To infringe upon intellectual property rights
  • To harass, abuse, insult, harm, defame, or discriminate
  • To submit false or misleading information
  • To interfere with app security features or other users' experience
  • To use the app for money laundering or illegal financial activities

6. Limitation of Liability

GoalBox is provided "AS IS" without warranties of any kind, express or implied. We shall NOT be liable for:

  • Data Loss: Loss, corruption, or deletion of your financial data
  • Financial Decisions: Any financial decisions made based on app data
  • Third-Party Services: Errors or downtime from ExchangeRate-API, GoldAPI, Google Drive, or other services
  • App Malfunctions: Bugs, crashes, or incorrect calculations
  • Security Breaches: Unauthorized access to your device or data
  • Backup Recovery: Inability to recover encrypted backups if you lose your password
  • Indirect Damages: Lost profits, business interruption, or consequential damages

Maximum Liability: In no event shall our liability exceed the amount you paid for premium features (if any) in the past 12 months.

7. Disclaimer of Warranties

GoalBox is provided without warranties of any kind, including:

  • No guarantee of uninterrupted, error-free operation
  • No guarantee of data accuracy (especially currency rates and gold prices)
  • No guarantee of compatibility with all devices or Android versions
  • No guarantee of fitness for a particular purpose
  • No guarantee of successful backup recovery (especially if passwords are forgotten)

8. Indemnification

You agree to indemnify and hold harmless GoalBox, its developers, and affiliates from any claims, damages, or expenses arising from:

  • Your use of the app
  • Your violation of these Terms
  • Your violation of any third-party rights
  • Your violation of applicable laws

9. Termination

We reserve the right to terminate or suspend your access to premium features immediately, without prior notice, for:

  • Breach of these Terms
  • Fraudulent activity or payment disputes
  • Abuse of app features or third-party services
  • Any reason at our sole discretion

Upon termination:

  • Your right to use premium features will cease immediately
  • You may still access free features
  • No refunds will be provided for remaining subscription periods

10. Intellectual Property

All content, features, and functionality of GoalBox are owned by us and protected by:

  • Copyright, trademark, patent, and other intellectual property laws
  • You may not copy, modify, distribute, or create derivative works
  • GoalBox logo, name, and design are our trademarks

11. Third-Party Links and Services

GoalBox integrates with third-party services (AdMob, ExchangeRate-API, GoldAPI, Google Drive). We are not responsible for:

  • Content, accuracy, or availability of third-party services
  • Privacy practices of third parties (see their privacy policies)
  • Charges or fees imposed by third parties

12. Changes to Terms

We reserve the right to revise these terms at any time. By continuing to use GoalBox after changes are posted, you agree to be bound by the revised terms. Material changes will be notified via:

  • In-app notification
  • Email (if you provided one)
  • Updated "Last updated" date on this page

13. Governing Law and Jurisdiction

These Terms shall be governed by and construed in accordance with applicable local laws, without regard to conflict of law provisions. Any disputes shall be resolved in accordance with local jurisdiction.

14. Severability

If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

15. Entire Agreement

These Terms, along with our Privacy Policy, constitute the entire agreement between you and GoalBox regarding use of the app, superseding any prior agreements.

16. Force Majeure

We shall not be liable for any failure to perform due to circumstances beyond our reasonable control, including natural disasters, government actions, internet outages, or third-party service failures.

Contact Us

If you have questions about these Terms, please contact us:

Support: alialfayed.official@gmail.com