Privacy Policy
Good Grief is built so that we cannot read your plan, your photos, or your letters. We don’t have them. They live on your phone.
This policy explains, plainly and specifically, what data we do and don’t collect, where it goes, who can see it, and what your rights are. If anything below is unclear, email info@goodgrief.rip and we’ll answer.
This is template language. If you’re a Good Grief user, treat this as the genuine policy. If you’re another business reading this for ideas, please get your own legal review — we’re not lawyers and your jurisdiction’s obligations may differ.
What Good Grief stores on your device
The Good Grief app stores your plan and all attached media in the app’s own private storage on your phone. We have no access to it. It contains:
- Everything you type into the plan editor (profile, wishes, contacts, etc.)
- Photos, video, and audio files you attach (copied into the app’s media folder)
- A 4-digit PIN hash (PBKDF2-SHA256), used to lock the app at launch
- A record that you’ve unlocked the paid features — kept on your device by the App Store or Google Play, not a key file you paste in
None of this leaves your phone except by your explicit action — for example, when you export a PDF, save an encrypted backup, or use the optional AI features described below.
What we collect on our servers
Nothing — we run no servers of our own. When you unlock the paid features, the purchase is handled and verified by the App Store or Google Play, right on your device. There is no account to make with us, no activation server, no device tracking, and no “is this still valid?” request travelling to us — ever.
The only outside party in a purchase is the store itself (Apple or Google) — see “What payments touch” below. Nothing about your plan — your photos, your letters, your wishes — ever leaves your device.
What payments touch
Purchases happen through the App Store (Apple) or Google Play (Google). They are the merchant — they take the payment, and we never see or store your card details, name, or billing address. Apple and Google handle your payment data under their own privacy policies (Apple, Google).
What we get back is the opposite of intrusive: anonymised, aggregate sales reports — how many people bought, in which country, and whether a subscription renewed or was cancelled — with no way to tie any of it to you personally. The 1-year plan is an auto-renewing subscription and Lifetime is a one-time purchase, but either way the store manages the money, and we never learn who you are from it.
What email we send you
Almost none, and only ever because you started it:
- Your purchase receipt — sent by Apple or Google, not us. We don’t email you a key, because there isn’t one.
- Replies from support — only if you write to us first.
- The occasional product update — only if you signed up for it on this website. Unsubscribe any time; a few times a year at most.
We do not send marketing to app buyers (a purchase doesn’t give us your email), and we do not sell your email address, ever.
The optional AI features
Good Grief includes two optional features that send some of your plan data to Anthropic’s Claude API:
- AI Obituary Generator — sends the profile, life moments, and a few related fields to draft an obituary starting point.
- AI Plan Review — sends a summary of your plan to suggest gaps and missing fields.
Both features only run when you click the button. The data sent is described in the app’s tooltip before each call. Anthropic’s API is governed by their privacy policy. If you don’t want any data going to Anthropic, simply don’t use these features. Everything else in the app works without them.
What we don’t do
- We do not have a user accounts system. There’s no password to reset because there’s no account.
- We do not run analytics or telemetry of our own inside the app.
- We do not include any third-party trackers on this website.
- We do not sell, rent, or share your data with anyone.
- We do not have a way to access your plan even if a court asked us — we don’t have it.
How long we keep data
- Purchase records — we don’t keep any, because we don’t issue licence keys. Your purchase lives with your App Store or Google Play account; “Restore Purchases” brings it back, and any refund or deletion is handled through the store.
- Website server logs — our static web host keeps standard access logs (IP address, timestamp, page requested) for a short period, as any website does. We don’t link them to you or your plan.
- Support email is kept for as long as needed to maintain a thread, then archived or deleted.
- Store sales data follows Apple’s and Google’s retention policies. It reaches us only as anonymised aggregates, with no customer record for us to delete.
Your rights
Depending on where you live, you may have the right to:
- Access the data we hold about you (support emails — note we hold no purchase or account record)
- Have it corrected or deleted
- Object to processing or withdraw consent
- Lodge a complaint with your data protection authority (in Australia, the OAIC; in the EU/UK, your national supervisory authority)
To exercise any of these, email info@goodgrief.rip. We aim to respond within 30 days.
Children
Good Grief is intended for adults. We do not knowingly collect data from children under 16.
Changes to this policy
We may update this policy as the product changes. We’ll update the date at the top, and for material changes we’ll post a plain-language summary in the app and on this page.
Contact
Privacy questions, deletion requests, anything else: info@goodgrief.rip.
Who operates Good Grief
Good Grief is operated by [legal entity name — to be confirmed] (ABN / company number: [to be confirmed]), of [registered address — to be confirmed]. That entity is the party responsible for this policy and your point of contact for any privacy request. Where it’s based also determines which privacy laws bind us — this policy is written to sit comfortably with both the Privacy Act 1988 (Australia) and the GDPR.
These operator details are being finalised, with legal review, before Good Grief goes on sale.