🇮🇹 Italiano 🇬🇧 English

Privacy Policy – BigGoal

Last updated: August 21, 2026

This policy describes how the BigGoal app collects, uses, and protects users' personal data, in accordance with EU Regulation 2016/679 (GDPR) and applicable data protection laws.

1. Data Controller

The data controller is Angelo Marzocchi, reachable for any privacy-related request at: ososososato@gmail.com.

2. Personal Data Collected

BigGoal collects the following categories of personal data:

The app does not collect location data, biometric data, financial information or device contacts, and never asks for special category data.

User-generated content is free text, however: a goal may contain — because the person writing it chose to — information about health, personal beliefs, or other areas the GDPR treats as special categories of data (Art. 9). Such content is neither requested nor analysed for any purpose beyond operating the service, and section 4 describes the only case in which it is processed by an artificial-intelligence system.

3. Purposes and Legal Basis of Processing

Personal data are processed for the following purposes:

The legal basis for processing is the performance of the contract/service requested by the user (Art. 6(1)(b) GDPR), except for diagnostic data, processed on the basis of our legitimate interest in keeping the app working and secure (Art. 6(1)(f) GDPR).

4. Artificial Intelligence

Some BigGoal features rely on a generative artificial-intelligence model. Processing is carried out through Google Cloud Vertex AI, inside a project controlled by the data controller and in a European region (europe-west4). The content sent is not used to train models.

The features involved, and the data each one sends, are:

Legal basis. For plan generation and rescue it is the performance of the service requested by the user (Art. 6(1)(b) GDPR): processing happens only when the user deliberately starts the feature. For automatic tags, which apply to every goal rather than to one request, the legal basis is consent (Art. 6(1)(a) GDPR and, where the content falls within special categories of data, Art. 9(2)(a) GDPR).

Withdrawal. Consent to automatic tagging can be withdrawn at any time under Settings → Automatic tags. Withdrawal applies across all devices and stops any new processing immediately. The same screen can also delete the labels already generated.

Refused content. The AI features refuse requests involving self-harm, harm to other people, or illegal activity. No plan is produced in those cases; a technical event is recorded containing only the category of the refusal and the account identifier — never the text the user wrote.

Automated decisions. None of these features produces legal effects or similarly significantly affects the user within the meaning of Art. 22 GDPR: generated content is a proposal the user can edit, and labels only serve to filter their own goals in the app.

5. Data Retention

Data are retained for as long as necessary to provide the service, or until the user requests deletion of their account and associated content. In the absence of an explicit deletion request, data are kept while the account remains active.

Diagnostic data follow a lifecycle of their own: Firebase Crashlytics retains them for at most 90 days after the report, after which they are deleted automatically.

6. Data Transfers and Sharing

Data are stored and managed through Google Firebase cloud services (Firebase Authentication and Cloud Firestore), acting as a data processor under the Google Cloud / Firebase Terms of Service.

The artificial-intelligence features described in section 4 rely on Google Cloud Vertex AI, also acting as a data processor, with processing carried out in a European region.

The diagnostic data described in section 2 are processed by Firebase Crashlytics, also a Google service acting as a data processor.

User data are never sold, shared, or disclosed to third parties for marketing or profiling purposes.

7. Security

We implement appropriate technical and organisational measures to protect personal data from unauthorised access, loss, alteration or disclosure, including encrypted transmission (HTTPS/TLS) and Firebase's built-in authentication controls.

8. User Rights

Users have the right to:

To exercise these rights, write to: ososososato@gmail.com.

9. Children

The app is intended for users aged 13 or older. If you become aware that a child under 13 has provided personal data through the app, please contact us so we can promptly remove it.

10. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Any changes will be reflected in the "Last updated" date at the top of this page. Continued use of the app after changes are published constitutes acceptance of the revised policy.

11. Contact

For any questions or requests regarding this Privacy Policy: ososososato@gmail.com