Privacy Policy
Good Grief is built so that we cannot read your plan, your photos, or your letters. We don’t have them. They live on your phone.
This policy explains, plainly and specifically, what data we do and don’t collect, where it goes, who can see it, and what your rights are. If anything below is unclear, email info@goodgrief.rip and we’ll answer.
This policy describes what the app actually does — not what we’d like it to do. Where the honest answer is awkward, it’s written down anyway. As of September 2026 there is no longer an awkward part: the two optional AI helpers have been removed, and nothing you write leaves your device at all unless you export it yourself.
What Good Grief stores on your device
The Good Grief app stores your plan and all attached media in the app’s own private storage on your phone. We have no access to it. It contains:
- Everything you type into the plan editor (profile, wishes, contacts, etc.)
- Photos, video, and audio files you attach (copied into the app’s media folder)
- A 4-digit PIN hash (PBKDF2-SHA256), used to lock the app at launch
- A record that you’ve unlocked the paid features — kept on your device by the App Store or Google Play, not a key file you paste in
None of this leaves your phone except by your explicit action — for example, when you export a PDF or save an encrypted backup.
What we collect on our servers
Nothing — we run no servers of our own. When you unlock the paid features, the purchase is handled and verified by the App Store or Google Play, right on your device. There is no account to make with us, no activation server, no device tracking, and no “is this still valid?” request travelling to us — ever.
The only outside party in a purchase is the store itself (Apple or Google) — see “What payments touch” below. Nothing about your plan — your photos, your letters, your wishes — reaches us, ever. It leaves your device in exactly one situation, which you start yourself: an export or backup you make, and it goes where you send it. Until September 2026 there was a second: two optional AI helpers that sent part of your plan to Anthropic. Those features have been removed from the app entirely.
What payments touch
Purchases happen through the App Store (Apple) or Google Play (Google). They are the merchant — they take the payment, and we never see or store your card details, name, or billing address. Apple and Google handle your payment data under their own privacy policies (Apple (opens in a new window), Google (opens in a new window)).
What we get back is the opposite of intrusive: anonymised, aggregate sales reports — how many people bought, in which country, and whether a subscription renewed or was cancelled — with no way to tie any of it to you personally. The 1-year plan is an auto-renewing subscription and Lifetime is a one-time purchase, but either way the store manages the money, and we never learn who you are from it.
What email we send you
Almost none, and only ever because you started it:
- Your purchase receipt — sent by Apple or Google, not us. We don’t email you a key, because there isn’t one.
- Replies from support — only if you write to us first.
- The occasional product update — only if you signed up for it on this website. Unsubscribe any time; a few times a year at most.
We do not send marketing to app buyers (a purchase doesn’t give us your email), and we do not sell your email address, ever.
The AI features have been removed
Earlier versions of Good Grief included two optional features — an obituary generator and a plan review — that sent part of your plan to Anthropic’s Claude API, using an API key you supplied yourself. Both ran only when you pressed a button, and only if you had entered a key.
They were removed in September 2026. The app no longer contains the code that made those requests, and the field for the API key is gone. There is now nothing in Good Grief that sends anything you have written to anyone — not to us, not to Anthropic, not to anybody. The only way your plan leaves your phone is an export or a backup that you make and then put somewhere yourself.
What we don’t do
- We do not have a user accounts system. There’s no password to reset because there’s no account.
- We do not run analytics or telemetry of our own inside the app.
- We do not include any third-party trackers on this website.
- We do not sell, rent, or share your data with anyone.
- We do not have a way to access your plan even if a court asked us — we don’t have it.
How long we keep data
- Purchase records — we don’t keep any, because we don’t issue licence keys. Your purchase lives with your App Store or Google Play account; “Restore Purchases” brings it back, and any refund or deletion is handled through the store.
- Website server logs — our static web host keeps standard access logs (IP address, timestamp, page requested) for a short period, as any website does. We don’t link them to you or your plan.
- Support email is kept for as long as needed to maintain a thread, then archived or deleted.
- Store sales data follows Apple’s and Google’s retention policies. It reaches us only as anonymised aggregates, with no customer record for us to delete.
Your rights
Depending on where you live, you may have the right to:
- Access the data we hold about you (support emails — note we hold no purchase or account record)
- Have it corrected or deleted
- Object to processing or withdraw consent
- Lodge a complaint with your data protection authority (in Australia, the OAIC; in the EU/UK, your national supervisory authority)
To exercise any of these, email info@goodgrief.rip. We aim to respond within 30 days. Please note: this mailbox is not active yet — the domain is still being set up — so a request sent today will not reach us. It will be live before the app is on sale. In the meantime almost nothing here needs a request: your plan is on your own device and we hold no copy of it.
Children
Good Grief is intended for adults. We do not knowingly collect data from children under 16.
Changes to this policy
We may update this policy as the product changes. We’ll update the date at the top, and for material changes we’ll post a plain-language summary in the app and on this page.
Contact
Privacy questions, deletion requests, anything else: info@goodgrief.rip.
Who operates Good Grief
Good Grief is operated by [legal entity name — to be confirmed] (ABN / company number: [to be confirmed]), of [registered address — to be confirmed]. That entity is the party responsible for this policy and your point of contact for any privacy request. Where it’s based also determines which privacy laws bind us — this policy is written to sit comfortably with both the Privacy Act 1988 (Australia) and the GDPR.
These operator details are being finalised, with legal review, before Good Grief goes on sale.