Privacy Policy
Last updated: December 16, 2025
At GoalBox, we take your privacy seriously. This Privacy Policy explains how we collect, use, protect, and share your personal information when you use our mobile application. We are committed to GDPR (EU) and CCPA (California) compliance.
1. Information We Collect
We collect the following types of information:
1.1 Personal Financial Data
- Financial Goals: Your savings goals, target amounts, deadlines, and goal descriptions
- Transactions: Income and expense records, transaction amounts, dates, categories, and notes
- Attachments: Photos and receipts you upload with transactions (may contain personally identifiable information)
- Currency Preferences: Your selected base currency and gold karat preferences
1.2 Device Information
- Device Details: Device model, operating system version, app version
- Security Status: Root detection status (for fraud prevention)
- Unique Identifiers: Device IDs (used for AdMob and billing)
1.3 Usage Data
- App Interactions: Features used, screens viewed, app crashes
- Performance Data: App loading times, error logs
2. How We Use Your Information
We use your information to:
- Provide core GoalBox functionality (goal tracking, transaction management)
- Fetch real-time currency exchange rates and gold prices
- Process in-app purchases and subscriptions
- Display personalized advertisements (via Google AdMob)
- Improve app performance and fix bugs
- Detect and prevent fraud, abuse, or unauthorized use
- Comply with legal obligations
3. Third-Party Services
We share limited data with the following third-party services:
Google AdMob (Advertising)
Data Shared: Device IDs, app usage data, approximate location (if permission granted)
Purpose: Display personalized advertisements
Privacy Policy: https://policies.google.com/privacy
User Control: You can manage ad personalization via device settings or app consent dialog
Google Play Billing (In-App Purchases)
Data Shared: Purchase history, subscription status (managed by Google)
Purpose: Process premium feature purchases
Privacy Policy: https://play.google.com/intl/en_us/about/play-terms/
Google Drive (Optional Backup)
Data Shared: Encrypted backup files (only if you enable Google Drive backup)
Purpose: Secure cloud backup of your financial data
Privacy Policy: https://policies.google.com/privacy
User Control: You must explicitly grant permission to upload backups to Google Drive
ExchangeRate-API (Currency Data)
Data Shared: Currency codes (e.g., USD, EUR) - NO personal data
Purpose: Fetch real-time currency exchange rates
Privacy Policy: https://www.exchangerate-api.com/terms
GoldAPI.io (Gold Price Data)
Data Shared: Currency code for gold prices - NO personal data
Purpose: Fetch real-time gold prices per gram for different karats
Privacy Policy: https://www.goldapi.io/terms-of-service
4. Data Storage and Security
4.1 Local Storage
- Primary Storage: All financial data is stored locally on your device in an encrypted SQLite database
- App-Private Directory: Data is stored in the app's private directory, inaccessible to other apps
- No Automatic Cloud Sync: We do NOT automatically upload your data to cloud servers
4.2 Security Measures
✓ Enhanced Security (Updated December 2025):
- Database Encryption (NEW): Your database is now encrypted at rest using SQLCipher with AES-256 encryption
- Secure Key Storage: Database encryption keys are stored in Android Keystore (hardware-backed encryption)
- Encrypted Backups: Backup files use AES-256-GCM encryption with user-provided password protection
- Password-Protected Exports: When exporting data (JSON format), you must provide a strong password to encrypt the file
- HTTPS Only: All network communications use HTTPS with TLS 1.2+
- Certificate Pinning: API connections use certificate pinning to prevent man-in-the-middle attacks
- No Cleartext Traffic: Network security config blocks all HTTP connections
- Root Detection: Billing features disabled on rooted devices (fraud prevention)
4.3 Backup & Export Features
GoalBox provides multiple options to backup and export your data:
- Local Backup: Create encrypted backup files stored on your device (requires password)
- Google Drive Backup: Upload encrypted backups to your personal Google Drive account (requires Google Drive permission and password)
- Data Export: Export your data as encrypted JSON files (requires password)
- Data Import: Restore from local backups or Google Drive backups (requires correct password)
- Encryption: All backup and export files are encrypted with AES-256-GCM using your password-derived key
🔒 Password Protection:
When creating backups or exporting data, you must provide a strong password. This password is used to derive an encryption key (using PBKDF2 with 100,000 iterations). We do NOT store your backup password - if you lose it, your backup data cannot be recovered. Choose a strong, memorable password and store it securely.
5. Data Sharing
We do NOT sell, trade, or rent your personal information to third parties. We may share data only in these circumstances:
- With Your Consent: When you explicitly approve data sharing (e.g., Google Drive backup)
- Legal Compliance: To comply with laws, subpoenas, or court orders
- Fraud Prevention: To protect our rights, prevent fraud, or ensure user safety
- Third-Party Services: As described in Section 3 above
6. Your Privacy Rights
6.1 Rights for All Users
- Right to Access: Export your data via the backup/export feature (Settings > Backup & Export)
- Right to Delete: Clear all data via Settings > Clear Data, or uninstall the app
- Right to Correct: Edit your goals and transactions directly in the app
- Right to Opt-Out: Manage ad personalization via device settings or consent dialog
- Right to Data Portability: Export your data in JSON format
6.2 GDPR Rights (EU/EEA/UK Residents)
If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under GDPR:
- Right to Data Portability: Request your data in a machine-readable format (use export feature or contact gdpr@goalbox.app)
- Right to Restriction: Request we restrict processing of your data
- Right to Object: Object to data processing for direct marketing or legitimate interests
- Right to Lodge a Complaint: Contact your local data protection authority
- Data Protection Officer: Contact our DPO at gdpr@goalbox.app
6.3 CCPA Rights (California Residents)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request details about the personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out of Sale: We do NOT sell your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
- Contact for CCPA Requests: ccpa@goalbox.app
Do Not Sell My Personal Information
GoalBox does NOT sell your personal information as defined by CCPA. We only share data with third-party services as described in Section 3 for functional purposes (ads, currency rates, billing).
7. Data Retention
We retain your data as follows:
- Local Database: Data is retained until you delete it or uninstall the app
- Backup Files: Retained until you delete them (user responsibility)
- Google Drive Backups: Retained in your Google Drive until you delete them
- AdMob Data: Google retains advertising data for 90-180 days (see Google's policy)
- Billing Data: Google Play retains purchase history per their retention policy
- API Logs: Our custom ads server does NOT log personal data
8. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including:
- United States: Google AdMob, Google Play Billing, Google Drive servers
- European Union: Some API providers may use EU servers
We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.
9. Children's Privacy
GoalBox is rated 3+ and suitable for all ages. However, we comply with COPPA (Children's Online Privacy Protection Act) requirements for users under 13 years of age.
- Parental Supervision: We recommend that parents or guardians supervise children's use of the app
- No Data Collection from Children: We do not knowingly collect personal information from children under 13 without verifiable parental consent
- Data Stored Locally: All financial data is stored locally on the device, not on our servers
- Parental Rights: Parents can review, delete, or request information about data stored in the app by accessing the device
If you are a parent or guardian and believe we have collected data from a child under 13 without your consent, please contact us immediately at privacy@goalbox.app, and we will provide guidance on how to delete the locally stored data.
10. Cookies and Tracking Technologies
GoalBox uses the following tracking technologies:
- AdMob SDK: Uses advertising IDs and cookies for ad targeting
- Analytics: We may use anonymized analytics to improve app performance
- No Web Cookies: The app does NOT use browser cookies (it's a native mobile app)
You can reset your advertising ID or opt out of personalized ads in your device settings:
- Android: Settings > Google > Ads > Reset advertising ID or Opt out of Ads Personalization
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of changes by:
- Posting the updated policy on this page
- Updating the "Last updated" date
- Sending an in-app notification for material changes
Continued use of GoalBox after changes constitutes acceptance of the updated policy.
12. Automated Decision-Making and Profiling
GoalBox does NOT use automated decision-making or profiling that produces legal or similarly significant effects.
Contact Us
If you have questions about this Privacy Policy or want to exercise your rights, please contact us:
Support: alialfayed.official@gmail.com
Terms & Conditions
Last updated: December 16, 2025
By downloading, installing, or using GoalBox, you agree to be bound by these Terms and Conditions. If you do not agree, please do not use the app.
1. Acceptance of Terms
By accessing and using GoalBox, you accept and agree to be bound by the terms and provision of this agreement. If you do not agree to abide by the above, please do not use this service.
2. Use License
Permission is granted to download and use GoalBox for personal, non-commercial use only. This is the grant of a license, not a transfer of title, and under this license you may not:
- Modify, reverse engineer, decompile, or disassemble the software
- Use the app for any commercial purpose or public display
- Remove any copyright or proprietary notations
- Transfer the app to another person or device (beyond normal device migrations)
- Attempt to circumvent security measures or premium features
3. Premium Features and Subscriptions
3.1 In-App Purchases
GoalBox offers premium features through one-time purchases and/or subscriptions. By purchasing premium features, you agree to:
- Pay the displayed price (including applicable taxes)
- Automatic renewal for subscriptions (unless cancelled before renewal date)
- No refunds for partial subscription periods (except as required by law)
3.2 Subscription Terms
- Billing Cycle: Subscriptions renew automatically (monthly, yearly, or as specified)
- Cancellation: Cancel anytime via Google Play Store > Subscriptions
- Price Changes: We reserve the right to change subscription prices with 30 days' notice
- Free Trials: If offered, billing begins after the trial period ends (unless cancelled)
3.3 Refund Policy
Refunds are subject to Google Play Store policies:
- Refunds within 48 hours of purchase may be requested via Google Play
- Subscription refunds follow Google's refund policy
- We reserve the right to deny refunds for violations of these Terms
4. User Responsibilities
You are responsible for:
- Maintaining the confidentiality and security of your device and app data
- All activities that occur within the app on your device
- Backing up your data regularly (we are not liable for data loss)
- Using the app in compliance with all applicable laws and regulations
- Ensuring transaction data accuracy (GoalBox is a personal finance tracker, not a bank)
- Remembering your backup passwords (we cannot recover encrypted backups if you lose your password)
5. Prohibited Uses
You may NOT use GoalBox:
- For any unlawful purpose or to solicit unlawful acts
- To violate any international, federal, provincial, or state laws
- To infringe upon intellectual property rights
- To harass, abuse, insult, harm, defame, or discriminate
- To submit false or misleading information
- To interfere with app security features or other users' experience
- To use the app for money laundering or illegal financial activities
6. Limitation of Liability
GoalBox is provided "AS IS" without warranties of any kind, express or implied. We shall NOT be liable for:
- Data Loss: Loss, corruption, or deletion of your financial data
- Financial Decisions: Any financial decisions made based on app data
- Third-Party Services: Errors or downtime from ExchangeRate-API, GoldAPI, Google Drive, or other services
- App Malfunctions: Bugs, crashes, or incorrect calculations
- Security Breaches: Unauthorized access to your device or data
- Backup Recovery: Inability to recover encrypted backups if you lose your password
- Indirect Damages: Lost profits, business interruption, or consequential damages
Maximum Liability: In no event shall our liability exceed the amount you paid for premium features (if any) in the past 12 months.
7. Disclaimer of Warranties
GoalBox is provided without warranties of any kind, including:
- No guarantee of uninterrupted, error-free operation
- No guarantee of data accuracy (especially currency rates and gold prices)
- No guarantee of compatibility with all devices or Android versions
- No guarantee of fitness for a particular purpose
- No guarantee of successful backup recovery (especially if passwords are forgotten)
8. Indemnification
You agree to indemnify and hold harmless GoalBox, its developers, and affiliates from any claims, damages, or expenses arising from:
- Your use of the app
- Your violation of these Terms
- Your violation of any third-party rights
- Your violation of applicable laws
9. Termination
We reserve the right to terminate or suspend your access to premium features immediately, without prior notice, for:
- Breach of these Terms
- Fraudulent activity or payment disputes
- Abuse of app features or third-party services
- Any reason at our sole discretion
Upon termination:
- Your right to use premium features will cease immediately
- You may still access free features
- No refunds will be provided for remaining subscription periods
10. Intellectual Property
All content, features, and functionality of GoalBox are owned by us and protected by:
- Copyright, trademark, patent, and other intellectual property laws
- You may not copy, modify, distribute, or create derivative works
- GoalBox logo, name, and design are our trademarks
11. Third-Party Links and Services
GoalBox integrates with third-party services (AdMob, ExchangeRate-API, GoldAPI, Google Drive). We are not responsible for:
- Content, accuracy, or availability of third-party services
- Privacy practices of third parties (see their privacy policies)
- Charges or fees imposed by third parties
12. Changes to Terms
We reserve the right to revise these terms at any time. By continuing to use GoalBox after changes are posted, you agree to be bound by the revised terms. Material changes will be notified via:
- In-app notification
- Email (if you provided one)
- Updated "Last updated" date on this page
13. Governing Law and Jurisdiction
These Terms shall be governed by and construed in accordance with applicable local laws, without regard to conflict of law provisions. Any disputes shall be resolved in accordance with local jurisdiction.
14. Severability
If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
15. Entire Agreement
These Terms, along with our Privacy Policy, constitute the entire agreement between you and GoalBox regarding use of the app, superseding any prior agreements.
16. Force Majeure
We shall not be liable for any failure to perform due to circumstances beyond our reasonable control, including natural disasters, government actions, internet outages, or third-party service failures.
Contact Us
If you have questions about these Terms, please contact us:
Support: alialfayed.official@gmail.com