Privacy Policy

Last updated: March 18, 2026

1. Data Controller

The data controller for personal data collected through the Go Finish It application is:

2. Data Collected

We collect the following categories of data in connection with your use of our service:

a) Identification data (via Google OAuth)

  • Email address
  • First and last name
  • Google ID
  • Profile picture URL

b) Usage data

  • Goals created and their description
  • Tasks and subtasks
  • Progress metrics
  • Weekly and monthly notes
  • Weekly review responses

c) Calendar data (Google Calendar, optional)

  • Event titles
  • Event times and duration
  • OAuth tokens (stored encrypted)

d) Technical data

  • Connection logs (timestamps, errors only)
  • Authentication cookie (JWT httpOnly)

3. Purpose of processing

Your data is collected for the following purposes:

  • Service delivery: account creation, goal management, action plan generation, progress tracking
  • AI personalization: analysis of your goals and generation of personalized tasks through artificial intelligence models
  • Calendar synchronization: scheduling your planned tasks in your Google Calendar to facilitate your daily organization
  • Communication: sending transactional emails (account confirmation, weekly review notifications)
  • Subscription management: payment processing and management of your subscription
  • Security: detection and prevention of unauthorized access, maintaining the security of the service

4. Legal basis for processing

  • Consent (Article 6.1.a of GDPR): for access to your Google account (OAuth) and your Google Calendar. You may revoke this consent at any time from your Google account settings.
  • Performance of contract (Article 6.1.b of GDPR): for the provision of the service, management of your account and your subscription.
  • Legitimate interest (Article 6.1.f of GDPR): for the security of the service, fraud prevention and service improvement.

5. Sub-processors and data transfers

We use the following sub-processors to provide our service:

Sub-processor PurposeLocation
GoogleAuthentication (OAuth) and Calendar synchronizationEuropean Union
OpenRouterAI processing (goal analysis, task generation)United States
LemonSqueezyPayment and subscription managementUnited States
BrevoTransactional email deliveryEuropean Union
OVHServer and data hostingFrance
Google Ads Advertising conversion measurement (anonymized tracking of signups and payments) United States

No banking data is stored on our servers. Payments are entirely managed by LemonSqueezy. Only your user identifier and subscription type are transmitted.

6. Use of artificial intelligence

Go Finish It uses artificial intelligence models (via OpenRouter, using the Gemini and Claude models) for the following features:

  • Analysis and structuring of your goals
  • Generation of personalized action plans (monthly and weekly)
  • Suggestion of daily tasks adapted to your constraints
  • Analysis of your weekly reviews to adjust the plan

Data sent to AI: your goals, tasks, notes and progress metrics are sent to AI models for analysis. Data is transmitted securely (HTTPS).

Data NOT sent to AI: your Google Calendar data (events, schedules) is never transmitted to artificial intelligence services. This data is used solely for synchronizing your planned tasks.

No training: your data is not used to train or improve AI models. It is only processed to generate responses as part of your use of the service.

No sale or sharing: your data is neither sold nor shared with third parties for advertising or commercial purposes.

7. Google API Services — Limited Use Disclosure

Go Finish It's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only request access to the Google Calendar scopes necessary to synchronize your planned tasks with your calendar events.
  • Google Calendar data is used exclusively for displaying your schedule and synchronizing your planned tasks. It is not sent to AI services, not used for advertising, and not shared with third parties.
  • We do not sell Google user data or use it for serving advertisements.
  • We do not use Google user data to train machine learning or AI models.
  • Access to Google user data is limited to the practices disclosed in this Privacy Policy.

8. Cookies and tracking

Go Finish It uses the following cookies and trackers:

a) Strictly necessary cookies

  • Authentication cookie: a JWT token stored in an httpOnly and Secure cookie, used to maintain your session. This cookie does not contain any personal data readable on the client side.
  • Language preference: stored in the browser's localStorage to remember your language choice (French or English).
  • Consent preference: stored in the browser's localStorage to remember your choice regarding advertising and analytics cookies.

b) Advertising and analytics cookies (subject to your consent)

The following cookies are only activated if you give your consent via the cookie banner displayed on your first visit:

  • Google Ads: used for advertising conversion tracking. Allows us to measure the effectiveness of our Google advertising campaigns. Uses Google consent mode v2 (ad_storage and analytics_storage denied by default).
  • PostHog: used for visitor behavior analysis on public pages (before login) to improve user experience. PostHog is automatically disabled on authenticated pages. Hosted in the European Union.

c) Consent mechanism

On your first visit, a consent banner allows you to accept or decline advertising and analytics cookies. Your choice is recorded and respected. No advertising or analytics cookies are set before your explicit consent. You can change your choice at any time by deleting the cookie_consent key from your localStorage.

9. Data retention

  • Active account: your data is retained as long as your account is active.
  • Account deletion: upon deletion of your account, all your personal data is erased within 30 days.
  • Technical logs: error logs are retained for a maximum of 12 months, then automatically deleted. These logs do not contain sensitive personal data.

10. Your rights (GDPR)

In accordance with the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access (Article 15): obtain confirmation that your data is being processed and receive a copy of it.
  • Right to rectification (Article 16): correct inaccurate data or complete incomplete data.
  • Right to erasure (Article 17): request the deletion of your personal data.
  • Right to data portability (Article 20): receive your data in a structured, machine-readable format.
  • Right to object (Article 21): object to the processing of your data on legitimate grounds.
  • Right to restriction (Article 18): obtain the restriction of processing in certain cases.

To exercise these rights, send an email to privacy@gofinishit.com specifying your request and the email address associated with your account. We will respond within a maximum of one month.

You also have the right to lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr.

11. Security

We implement the following technical and organizational measures to protect your data:

  • Encryption of all communications via HTTPS/TLS
  • Authentication via JWT tokens stored in httpOnly and Secure cookies
  • Hosting on OVH servers located in France
  • No banking data stored on our servers
  • Google OAuth tokens stored securely on the server side
  • Production logs limited to errors, without sensitive personal data

12. Data transfers outside the European Union

Some of our sub-processors are located in the United States:

  • OpenRouter (AI processing): data sent for AI analysis is transmitted to servers in the United States. These transfers are governed by Standard Contractual Clauses (SCC) approved by the European Commission.
  • LemonSqueezy (payments): only your user identifier and subscription type are transmitted. No banking data passes through our servers. These transfers are governed by Standard Contractual Clauses (SCC).

All other data (account, goals, tasks, calendar) is hosted in France on OVH servers.

13. Changes to this policy

We may update this privacy policy to reflect changes in our practices or for legal reasons. In the event of a substantial change, we will notify you by email at the address associated with your account, at least 30 days before the changes take effect.

14. Contact

For any questions regarding the protection of your personal data or to exercise your rights, contact us: