Privacy Policy
Last updated: 18 May 2026 Effective date: Phase 1 launch (2026-05-22)
GOX ("we", "us", "the platform") respects your privacy. This policy explains what data we collect, why we collect it, how we use it, and how you can control it.
Draft notice: This document is a Phase 1 starter draft. A formal review by qualified counsel is scheduled before public launch (D14 ship gate). Any inconsistency with the laws of your jurisdiction (GDPR / CCPA / Vietnam PDPL) is unintended and will be corrected before that review concludes.
1. Who we are
GOX is operated by GOX Inc. (Delaware C-Corp) and its Vietnam subsidiary GOX Vietnam Co., Ltd. Contact: privacy@gox.life. EU representative + DPO contact will be published before EU launch.
2. Who can use GOX
GOX is for users aged 13 and over. We collect a year-of-birth on signup to enforce this. If you are under 13 (or under the digital-consent age in your country), do not create an account; if you have, contact privacy@gox.life and we will erase the account.
3. What we collect
We collect the minimum necessary to operate the platform.
You give us directly:
- Account info: email, name, year-of-birth, password (hashed; we never see plaintext).
- Optional profile data you add later: birth month/day, public birthday flag, notification preferences.
We collect automatically:
- Session identifiers (cookies — see §7).
- Approximate region and country inferred from your IP at signup: the region (one of: us / eu / asia / other), the country (a two-letter code) and, if you are in the US, the state. They are used to apply the right consent flow and tax rules, the age limit for your country, and which country's law sets how long we keep your data (§5). They are deleted when you delete your account. (Pending counsel review.)
- A log of when you sign in (the access log) and of actions on your account. Your signed-in sessions keep the IP address and device you used. Kept for the periods in §5. (Pending counsel review.)
You opt-in to share:
- Saved tools, ratings, comments, posts you publish (Phase 1.5+).
- Analytics events (page views, clicks) — only if you accept analytics cookies.
We do not sell your data. We do not display third-party ads. We do not use third-party trackers for advertising.
4. Why we collect it (legal basis)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the service (auth, content delivery) | Contract |
| Comply with legal obligations (audit, AML, age gate) | Legal obligation |
| Improve the product (analytics, A/B tests) | Consent |
| Communicate with you (transactional + opt-in newsletter) | Contract / consent |
5. How long we keep it
Work data in a Space belongs to that Space. Records, assignments in Person fields, comments on work, change history and the Space's activity log are the Space's data: the Space is the controller and GOX processes them for it. They stay as long as the Space keeps them. If you delete your account, your work in other people's Spaces stays with those Spaces and shows as "Deleted user". Your account (name, @handle, email, password) and your profile are removed. Some copies are not removed yet †: the name or @handle someone typed when they mentioned you in a Page or post, and invitations or waitlist entries addressed to your email (for example, an invitation to a shared Page), and the email of a verification link you have not used yet, until its token expires. (Pending counsel review.)
Your personal data (your profile, your personal Space, your settings, Spaces you own with no other members) is deleted when you delete your account (§8). Copies in our database backups expire within our hosting provider's restore window. (Pending counsel review: confirm the backup window.)
What stays after you delete your account. Messages you sent stay with the people you sent them to, shown as from "Deleted user". @handles you used before stay reserved, so no one can take them to impersonate you. The record that your deletion was carried out keeps an internal account number, without your name or email. Other records we keep without an end date (see the last row of the table below) can also carry your internal account number. (Pending counsel review.)
What GOX keeps for itself, and for how long. Where your country's law sets a different period, that period applies to your account. (Pending counsel review.)
| What | How long |
|---|---|
| Access log: when you signed in ‡ | 12 months |
| IP address and device details stored with other entries in our activity log (for example, data requests and consent changes) ‡ | 90 days |
| IP address and device kept with your signed-in sessions and with security events about your account † | no set period yet; removed when you delete your account |
| GOX's own operations log (for example, changes to your profile); after that, only a count per kind of action ‡ | 12 months |
| A Space's activity log and work history, after the Space is deleted ‡ (some entries are kept longer †) | 12 months |
| Sealed record after you delete your account (email, handle, sign-up details), for legal requests only † | 30 days; India: 180 days |
| Copy of content removed for breaking the law or our rules † | 6 months |
| Reports of child sexual abuse material † | 12 months after the report |
| Analytics events (page views, clicks, searches), only if you accept analytics cookies | 13 months, then counted without your identity ‡ |
| Age-check images or scans | deleted immediately (we do not collect them today) |
| Records that a deletion or data request was carried out, consent records, moderation cases, permission grants and removals, topic and steward decisions, our own retention receipts, and any other action we have not yet sorted into a period; each can carry the account number of the person who acted | until counsel sets their period |
† Not built yet. Today we keep no sealed record and no copy of removed content (your account is erased at once); reports are kept as moderation cases until counsel sets their period. Mention names and email-addressed invitations are not yet removed when you delete your account, nor is the email of a verification link until its token expires. No scheduled deletion exists yet for the IP address kept with sessions and security events. In a deleted Space's history, entries about items deleted together with it cannot yet be linked to that Space, so they are kept.
‡ The scheduled deletion that applies this period is built but not switched on yet. Until it is, these entries are kept longer than the period shown.
6. Who we share it with
- Infrastructure providers acting as processors under our control: Neon (database, US East 1), Vercel (hosting, US), Cloudflare (CDN + WAF + geo-routing), Resend (transactional email), Together AI (AI inference for Cal tool summaries —
deepseek-ai/DeepSeek-V4-Promodel; no user PII passed to model inference). - Authorities, when legally compelled.
- A buyer or successor, if GOX is sold or merged. We will notify you 30 days in advance.
We do not transfer your data to processors outside the EU/UK without an adequate-decision country, SCCs, or your explicit consent.
7. Cookies
| Name | Purpose | Required | Lifetime |
|---|---|---|---|
gox_session | Better Auth session token | Yes | Per-session |
gox_locale | Remember your locale preference | Yes | 365 days |
gox_cookie_consent | Remember your cookie choices | Yes | 365 days |
| Analytics cookies (Phase 1.5+) | Product improvement | No (opt-in) | 13 months |
EU/EEA/UK/CH users see a consent banner on first visit (detected server-side via Cloudflare's geographic IP header cf-ipcountry). You can change your choice anytime from Settings → Privacy. Users outside GDPR scope still receive only essential cookies by default; analytics + product cookies require opt-in regardless of geography.
8. Your rights
Under GDPR (EU/UK), CCPA (California), and Vietnam PDPL:
- Access — see what we have on you.
- Correct — fix inaccuracies.
- Erase — delete your account + data.
- Export — get a machine-readable copy.
- Object — opt out of analytics/marketing.
- Restrict — pause processing while we investigate a complaint.
Use Settings → Privacy in the dashboard, or call the API endpoints directly when signed in. Both endpoints require an explicit confirmation in the POST body and are rate-limited to one request per 24 hours per account:
POST /api/user/erase— permanent account deletion (GDPR Art. 17). The request must also name the account being deleted, and is refused if it does not match the account signed in for that browser tab, or while you are acting as a Space.POST /api/user/export— JSON bundle of all your data (GDPR Art. 15)
Rate-limit responses include a Retry-After header (seconds). The confirmation protects against accidental abuse, browser autofill replay, and drive-by curl. Every DSR attempt that reaches your account — success, rate-limited, or rejected — is logged to our audit trail; a deletion request refused because it named a different account is not attributed to any account.
Or email privacy@gox.life. We respond within 30 days.
9. Children
We do not knowingly collect data from children under 13 (or under the digital-consent age in your country). If you believe we have, contact privacy@gox.life.
10. Security
- Passwords are hashed with industry-standard algorithms (Better Auth default — argon2id or bcrypt).
- All connections are TLS 1.2+ end-to-end.
- Database access is gated by Postgres row-level security.
- Audit logs are written by the system. They are changed only to remove personal details: IP addresses, device information and old entries on the schedule in §5 ‡, and your handle and email when you delete your account. (Pending counsel review.)
We follow a coordinated disclosure policy. Report vulnerabilities to security@gox.life.
11. Changes to this policy
We will post material changes here and email signed-in users at least 14 days in advance. Continued use after the effective date constitutes acceptance.
12. Contact
- General privacy:
privacy@gox.life - Security:
security@gox.life - DPO (EU): pending appointment, published before EU launch