Goodword privacy

What we collect.
How it works.

Goodword is operated by Immense Technologies LTD. This notice explains data handling for Goodword website claims, the Goodword AI connector and the first-party visitor analytics on websites hosted through our API tenant service.

Last updated September 29, 2026 · Contact: mosh@getgoodword.ca

01 / ACCOUNTS & ACCESS

Information that connects
you to your website.

When you claim a website, Goodword stores your name, email address, website identifier, claim and payment status, relevant dates, and any applied promotion. For Stripe payments, our records also include customer, checkout or invoice references, amounts and associated links. Payment details entered on Stripe’s pages are processed by Stripe.

For AI access, Goodword stores your normalized email address and a salted, hashed representation of the six-digit PIN, rather than the PIN itself. Connection records identify the authorized website, claim, AI client, granted permissions and expiry. Access and refresh tokens are stored as hashes in Goodword’s authentication database. The AI app receives the token values needed to make authorized requests.

Temporary sign-in records, authorization codes, client registration metadata and rate-limit records support authentication and help limit misuse. Requests may involve processing an IP address, including for rate limiting. Infrastructure and access logs may also contain IP addresses and request information.

02 / YOUR WEBSITE

Content you ask us
to host and change.

Goodword stores website files, uploaded images and other supplied assets, menu and popup settings, website metadata, and revision history with change reasons and timestamps. These records let us serve your website, carry out authorized edits and restore an earlier version.

Files published to your website are public. Earlier revisions are retained for restoration. Removing information from the current page does not automatically erase it from previous revisions, an AI app’s conversation, browser caches or other copies.

The connector receives the tool inputs your AI app sends for an operation and returns the requested files, results or analytics. It has no tool to retrieve your AI app’s full conversation history or memory. Text you or your app put in a file, popup or change reason may become part of the stored website or revision record.

03 / VISITOR ANALYTICS

Counting visits,
with clear limits.

Goodword’s detailed tenant analytics stores a website-specific visitor identifier derived from a browser cookie using a keyed hash (HMAC), a page pathname, referring hostname, approximate country, region and city, and a UTC timestamp. Page paths have query strings and fragments removed, and some obvious identifiers are redacted. Referrers retain the hostname, rather than the full referring URL.

The browser identifier is pseudonymous: it does not require a visitor’s name or email. It measures browsers, not reliably distinct people. Clearing or blocking cookies, using another device, or changing browsers can create another visitor identifier.

We process the request’s IP address to look up approximate location in a locally imported DB-IP City Lite database. This lookup does not send the visitor’s IP to an external geolocation API. The detailed tenant page-view table stores the resulting location fields, not the raw IP address. This does not exclude IP addresses from infrastructure or access logs.

Claim-funnel records separately track events such as site and claim-page opens, video interactions, form submission, checkout progress and completed claims. They contain website and session references, event types, timestamps and short event details. Available analytics can be read by Goodword operators and by AI apps authorized for that website.

IP Geolocation by DB-IP. Locations can be inaccurate or unavailable. Analytics results include their tracking start date; earlier detailed history is unavailable.

04 / COOKIES & EXPIRY

What your browser keeps.

The production service uses the cookies below where the related feature is active. They are first-party cookies. A cookie’s expiry is separate from the retention of records already saved on the server.

Cookie or credentialPurposeCurrent lifetime
__Host-gw_visitorApproximate unique visitor counts for a tenant website.One year, renewed on visits.
__Host-gw_visitGroup claim-funnel activity into visits.30 minutes.
__Host-gw_claim_…Access a website’s private claim page and downloads.One year.
__Host-gw_mcp_authComplete the browser-based AI sign-in flow.10 minutes.
OAuth authorization codeExchange a completed sign-in for app credentials.Five minutes; single use.
OAuth access tokenAuthorize an AI app’s tool requests.Up to one hour.
OAuth refresh tokenRenew an app’s access token.Rotates on use; connection expires after 30 days.

OAuth tokens are app credentials, not visitor cookies. Blocking or deleting browser cookies can affect sign-in, private downloads and visitor counts. The __Host- prefix is omitted in non-HTTPS development environments.

Tenant sites can include additional scripts, cookies or external resources chosen by their owners. Those features may have separate data practices and notices.

05 / CONNECTED SERVICES

Where information goes.

  • Your connected AI app. After you authorize it, the app receives tool results and can access or modify the website within the granted permissions. This can include website files and analytics. Its handling of returned information and conversations is governed by that provider’s policies.
  • Hosting and infrastructure suppliers. Goodword’s hosting, storage and network services process requests and stored information needed to run the service. Operational logs and backups may contain service data.
  • Stripe, when used for payment. Goodword sends claim-related customer and transaction information, such as name, email, amount and identifiers, to Stripe and receives payment status and references. See Stripe’s privacy policy.
  • External content on a page. Some Goodword or tenant pages load resources such as fonts, images or embedded media from third parties. Your browser connects to those providers to load the content. For example, some Goodword pages use Google Fonts. A tenant’s page content and privacy notice may describe additional services.
  • Support. Information you email to Goodword is used to respond to your request and investigate the issue. Include only what is needed and leave out PINs, private access links and tokens.

For AI-provider privacy information, see OpenAI’s privacy policy or Anthropic’s privacy policy, as applicable to the app you choose. Other apps have their own policies.

06 / RETENTION & YOUR REQUESTS

Ask about your information.

Account and claim records, website files and revisions, visitor analytics and funnel history currently have no fixed automatic deletion schedule in the application. They remain until an operator removes them. Expired OAuth flows, codes, tokens and rate-limit records are cleaned up when the OAuth service handles requests; expiry prevents their continued use even before cleanup. Registered client metadata remains until removed.

The production web server is configured to rotate non-empty access and error logs daily and retain 14 rotated logs. Other operational logs and backups can have separate retention settings; application deployment backups currently have no automatic deletion schedule. Contact Goodword for the information applicable to your account and request. This notice does not promise that every copy is erased immediately.

To request access, correction or deletion, or to ask a privacy question, email mosh@getgoodword.ca with your website address and request. We may need to verify your authority over the account before acting. If you are a visitor to a customer’s website, include that website address so the request can be directed appropriately.

Disconnect Goodword in your AI app to stop using its connection. Changing the website’s PIN on the private claim page invalidates all existing AI connections for that website. Neither action by itself deletes saved website data, analytics, or information already held by the AI provider.

A direct line to Goodword.

Privacy, access or deletion questions: mosh@getgoodword.ca.

Visit support