Goblyn

Goblyn Privacy Policy

Effective date: July 18, 2026

The short version, up front: Goblyn exists to write and publish your blog, not to harvest your data. We collect what we need to run your content team, we encrypt the sensitive parts, we sell nothing to anyone, and when you cancel we keep your work safe so you can come back — unless you tell us to delete it, in which case we actually delete it. The full details follow, and the full text is what governs.


1. Who we are

Goblyn ("Goblyn," "we," "us") is an AI content platform operated by to1 Labs LLC, an Arizona limited liability company doing business as Goblyn, based in Arizona, United States. Goblyn provides an autonomous AI content team that researches, writes, publishes, and optimizes blogs on behalf of its customers ("the Service"), available at goblyn.ai.

Questions about this policy: [email protected].

This policy covers: (a) visitors to goblyn.ai, (b) customers with Goblyn accounts, and (c) — in a more limited way described in Section 8 — visitors to blogs we host on our customers' behalf.

2. Information we collect

The short version: your account details, your card (held by Stripe, not us), the information about your business that your goblyn team needs to write for you, your Google Search Console and Analytics data if you connect them, and ordinary service logs.

Account information. Name, email address, and password (stored as a salted hash — we never store your plaintext password), or your Google account identifier if you sign in with Google.

Payment information. Handled by Stripe. We never receive or store your full card number; we retain only what Stripe returns to us (such as the card brand, last four digits, and billing status).

Your business information (the "fact file"). When you onboard, our crawler reads your public website, and you provide details about your business — what you do, your audience, competitors, differentiators, pricing, voice, and topics to avoid. We store this, along with your logo and brand colors, to ground the content we write for you. We re-crawl your public site periodically to keep it current; our crawler identifies itself and respects robots.txt.

Google data (only if you connect it). If you connect Google Search Console and/or Google Analytics, we receive OAuth tokens and, through them, read-only performance data (impressions, clicks, queries, indexing status, and analytics metrics) for the properties you select. Your OAuth refresh token is encrypted at rest with AES-256-GCM; it is never stored or logged in plaintext. Section 7 covers our Google data commitments in full.

Content and activity. The posts your goblyn team drafts and publishes, your approvals, vetoes, change requests, answers to your team's questions, and your settings.

Service and log data. IP addresses, browser type, pages visited, email delivery and engagement events (via Postmark), and similar technical logs generated by operating a web service.

Cookies. We use strictly necessary cookies only: a session cookie to keep you signed in, and cookies set by Stripe during checkout. We do not use advertising cookies and we do not show ads.

3. How we use information

The short version: to run your content team. Nothing else.

We use the information above to: provide and operate the Service (research, write, publish, and optimize your blog); ground your content in facts about your business; measure how your content performs and adjust strategy; send you the emails that are part of the Service (the weekly report, milestone notices, and transactional messages); process payments; provide support; secure and debug the Service; and comply with law.

We do not sell your personal information, and we do not share it with third parties for their advertising.

AI processing. Content generation and analysis are performed using Anthropic's Claude API. Your fact file, relevant crawled content, and performance context are transmitted to Anthropic for processing to produce your content and reports. This processing occurs under Anthropic's commercial terms, under which API inputs and outputs are not used to train Anthropic's models. We do not use your private data to train models of our own.

4. When we share information

The short version: with the vendors that run the service, and with no one else unless the law makes us.

We share information only with the sub-processors that operate the Service:

| Sub-processor | Purpose |

|---|---|

| Stripe | Payment processing and billing |

| Railway | Application and database hosting |

| Cloudflare | DNS, content delivery, and custom-domain routing for hosted blogs |

| Postmark | Transactional and report email delivery |

| Anthropic | AI content generation and analysis (Claude API) |

| Google | OAuth and the Search Console / Analytics APIs, at your direction when you connect them |

We may also disclose information if required by law, to protect the rights, safety, or property of Goblyn or others, or as part of a merger, acquisition, or sale of assets (in which case this policy's commitments follow the data).

5. Data retention — read this section

The short version: cancel and we keep everything, indefinitely, so you can come back like you never left. Delete your account and we actually erase it. We will never quietly purge your work.

Goblyn's retention model is deliberately different from most services, and we state it plainly:

  • While your account is active, we retain your data to operate the Service.
  • If you cancel, we retain your account data, fact file, posts, and performance history indefinitely — no deadline, no purge — so that if you return, your team picks up where it left off and your content's history is preserved. Your published blog goes offline at the end of your billing period, but nothing is deleted.
  • If you delete your account (a separate, explicit action available in Settings), we permanently erase your account, fact file, content, tokens, and associated personal data within 30 days, except for minimal records we must keep for legal, tax, or fraud-prevention purposes (e.g., invoice records held by Stripe).
  • Google OAuth tokens are deleted immediately when you disconnect Google, when you delete your account, or when the connection is revoked on Google's side.
  • Routine technical logs are retained for up to 90 days. By technical logs we mean ephemeral operational records only: application and error logs (via our monitoring provider, Sentry) and infrastructure request logs (via our hosting provider, on its standard rotation). This does not apply to your account data, fact file, posts, email history, or performance data, which follow the retention rules above (kept while active, kept indefinitely after cancellation, erased on Delete Account).

You can export your content and fact file at any time using Download everything in Settings, whether your subscription is active or not.

6. Security

Sensitive credentials (Google OAuth tokens) are encrypted at rest using AES-256-GCM with keys held separately from the database. All traffic is encrypted in transit (TLS). Passwords are stored as salted hashes. Access to production systems is restricted. No system is perfectly secure, but if we learn of a breach affecting your personal data, we will notify you as required by applicable law.

7. Google user data — API Services User Data Policy

The short version: read-only, encrypted, used solely to run your reports and strategy, never sold, never used to train AI.

Goblyn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We request read-only scopes for Search Console and Analytics.
  • Google user data is used only to provide user-facing features of the Service to you: your performance dashboards, your weekly reports, and the content-strategy adjustments your team makes on your behalf.
  • We do not transfer Google user data to third parties except as necessary to provide these features (see Section 4), to comply with law, or as part of a merger/acquisition with notice to you.
  • We do not use Google user data for advertising, and we do not transfer it to any third party for the purpose of training AI or machine-learning models. Where Google-derived metrics are processed by our AI sub-processor to generate your own reports, that processing serves only your user-facing features and occurs under terms prohibiting use of the data for model training.
  • Humans do not read your Google data except with your consent, for security or abuse investigation, to comply with law, or in aggregated/anonymized form for internal operations.
  • You can disconnect Google at any time in Settings or via your Google security settings; disconnection deletes your tokens immediately.

8. Blogs we host for customers

The short version: your blog's readers are your audience, not ours. We process their data only as your service provider.

Goblyn hosts blogs on customers' own domains (e.g., blog.customer.com). For visitors to those blogs, the customer is the data controller and their privacy practices apply; Goblyn acts as a processor/service provider, handling only the technical data inherent in serving web pages (IP addresses and request logs, briefly retained; caching via Cloudflare). We do not place advertising or tracking cookies on hosted blogs.

9. Your rights

The short version: access, correct, export, delete. The Delete Account button is real.

Everyone: You can access and correct your account data and fact file in the product, export everything via Download everything, and permanently delete your account in Settings. You can also email [email protected] to exercise any right.

European Economic Area / United Kingdom: We process your data on the lawful bases of contract performance (operating the Service you signed up for), legitimate interests (securing and improving the Service), and consent where applicable (connecting Google). You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Our processing occurs in the United States; where required, transfers rely on appropriate safeguards such as standard contractual clauses. We do not make automated decisions producing legal or similarly significant effects about you.

California and other U.S. state privacy laws: You have the rights to know, access, correct, delete, and port your personal information, and to opt out of "sale" or "sharing" — though we do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right to limit. We honor Global Privacy Control signals for opt-out purposes. We will not discriminate against you for exercising your rights.

We verify deletion and access requests via your account email.

10. Children

The Service is for business use by adults. It is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact [email protected] and we will delete it.

11. Changes to this policy

If we make material changes, we will notify you by email and/or a prominent notice in the product before the changes take effect, and update the effective date above. The retention commitments in Section 5 will not be weakened retroactively for data collected under this version without your consent.

12. Contact

to1 Labs LLC (d/b/a Goblyn)

6895 E Camelback Rd, Unit 1015, Scottsdale, AZ 85251

[email protected]