Your information
Privacy Policy
LabStack LLC operates Goal.fit. This policy explains what information Goal processes, why it is needed, and the choices available to you.
Last updated · September 4, 2026
Information you provide
Optional food estimation
Optional connected health information
Technical and operational information
Optional product analytics
In the iOS and Android apps, Goal uses Google Analytics for Firebase to understand which app screens and actions are used, whether features complete successfully, and which store-provided acquisition source or campaign led to an install. App analytics is enabled by default after your signed-in account preference loads, and you can turn it off at any time in Settings under “Help improve Goal.” While enabled, Google receives a random analytics identifier, a resettable app-instance identifier, coarse region, device model, operating-system and app versions, bounded app interactions and timing buckets, coarse feature-area and failure categories, and bounded store campaign labels or identifiers. Turning app analytics off stops collection, resets the app-instance identifier, and requests deletion of analytics associated with the random identifier.
On this public website, visitors in the EEA, United Kingdom, and Crown Dependencies are asked before Google Analytics loads. Goal uses Cloudflare's same-origin country signal to decide whether that prompt is required; the country result is not stored or sent as an analytics property, and an unavailable or unknown result requires consent. Elsewhere, website analytics starts without a prompt, but you can turn it off below. If your browser sends a Global Privacy Control signal, website analytics does not start and you are not prompted, because you have already answered; choosing “Allow analytics” below overrides that signal on this browser, since your own choice is the more specific one. Do Not Track is not consulted: the specification was withdrawn in 2019 and the browsers that still carry the setting leave it off, so it says nothing reliable about what a visitor wants. The site sends a fixed page path and title, the referring site's origin, Google's basic browser, device, coarse-region, and session information, and standard events for completed scrolls, store and other outbound links, forms, embedded video, and file downloads. It retains only controlled utm_id, utm_source, utm_medium, utm_campaign, utm_content, and utm_term campaign labels from a page URL; all other query parameters and fragments are discarded, and query-based site-search measurement is disabled. Website analytics is not linked to a Goal account.
Checking whether website analytics consent is required in your region.
Across the apps and website, Goal does not send Google logs, stack traces, request or response bodies, your email, phone number, Goal account ID, advertising ID, precise location, food descriptions, nutrition or weight values, connected health information, passkeys, notes, or other free text. Analytics event data is configured for two-month retention.
How information is used
- Provide account access, synchronization, tracking, progress views, and conditional outlook features.
- Send transactional verification or support messages.
- Protect accounts, enforce rate limits, diagnose failures, and improve reliability.
- Honor Goal.fit data-deletion, account-deletion, and other privacy choices.