Privacy Policy
This Privacy Policy describes how GoodAction (“we”, “us”) collects, uses, and shares information when you use MorningSignal (the “Service”). By using the Service, you agree to this policy. If you do not agree, do not use the Service.
Who we are
MorningSignal is a web application operated by GoodAction. For privacy questions, contact info@goodaction.com.
Information we collect
- Account and profile. Name, email address, password hash (if you register with email and password), profile image URL, and related account fields stored in our database.
- Authentication. If you sign in with Google or GitHub, we receive identifiers and profile information from those providers as permitted by your consent and their policies. Session cookies or tokens are used to keep you signed in.
- Content you provide. Posts, drafts, journal entries, voice recordings you upload for transcription, intelligence sources, interests, competitors, bookmarks, and similar workspace data you create in the Service.
- Connected social accounts. If you connect LinkedIn or Instagram, we store OAuth tokens and related account identifiers needed to publish on your behalf or refresh access, as described at connection time.
- Billing. If you subscribe through Stripe, we process payment-related identifiers (such as Stripe customer and subscription IDs). Stripe handles card data according to its own terms and certifications.
- Technical data. Server logs, IP address, user agent, timestamps, and diagnostic data typical of web hosting—used for security, reliability, and abuse prevention.
- AI processing. When you use AI features, we send relevant prompts and content to OpenAI (or an OpenAI-compatible endpoint you configure) to generate text, images, or transcriptions. Do not submit secrets or regulated data you are not permitted to share with subprocessors.
- Files and media. If you upload images or other files, we may store them in our database or in Amazon S3 (or compatible object storage) as implemented in the product, including keys and metadata needed to serve or delete them.
How we use information
We use the information above to:
- Provide, maintain, and improve the Service;
- Authenticate users and protect accounts;
- Generate briefs, drafts, insights, transcriptions, and images you request;
- Process subscriptions and communicate about billing;
- Comply with law, enforce our terms, and detect fraud or abuse.
Legal bases (EEA/UK users)
Where GDPR or UK GDPR applies, we rely on contract (providing the Service), legitimate interests (security, product improvement, and internal analytics that do not override your rights), consent where required (for example optional marketing or certain cookies if we add them), and legal obligation where applicable.
Sharing and subprocessors
We share information with service providers that help us run the Service, including:
- Hosting and infrastructure (for example AWS Amplify or comparable cloud providers);
- PostgreSQL database hosting as configured for your deployment;
- Stripe, for payments;
- OpenAI (or your configured AI API), for model inference;
- Google, GitHub, LinkedIn, or Meta/Instagram when you choose those sign-in or publishing integrations.
We do not sell your personal information as commonly defined in U.S. state privacy laws. We may disclose information if required by law or to protect rights, safety, and integrity of users and the Service.
Retention
We retain information as long as your account is active and for a reasonable period afterward for backups, security, and legal compliance. Billing records may be retained longer where required for tax or accounting law. You may request deletion as described on our Data deletion page.
Security
We use industry-standard safeguards appropriate to the nature of the Service. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
International transfers
If you access the Service from outside the country where our servers or subprocessors are located, your information may be transferred across borders. Where required, we use appropriate safeguards such as standard contractual clauses.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. Contact info@goodaction.com to exercise these rights. You may also lodge a complaint with your local supervisory authority.
Children
The Service is not directed at children under 16, and we do not knowingly collect their personal information.
Changes
We may update this Privacy Policy from time to time. We will post the revised version and update the “Last updated” date at the bottom of this page. Continued use after changes constitutes acceptance where permitted by law.
Last updated 2026-05-12