Impossible Goals
Privacy Policy
Effective date: 5 October 2026
Impossible Goals is a place to declare a big goal, see it every day, record small proof of progress, and let people you choose witness and support your journey. This notice explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights you have over it.
1. Who we are
Better Together Technologies LLC (“we”, “us”), a Delaware limited liability company in the United States, runs Impossible Goals — the mobile app, the backend service behind it, and the public web pages it publishes — and is the data controller for the personal data described here.
Privacy contact: hello@bettertogether.technology — write to us there for our postal address, to exercise any right in this notice, or for anything else about your data.
2. Your Better Together account
One account across our apps. The List, Close, Impossible Goals and The Cutting Room are all made by Better Together Technologies LLC, and they share one sign-in system. When you create an account in any of them you are creating a Better Together account. Better Together Technologies LLC is the data controller for that account in every app, and this policy applies to it alongside Impossible Goals’ own sections below.
What the shared account holds. Your sign-in details (email address, phone number, a hash of your password, and any Apple or Google sign-in link) and your @tag are held once, in the shared account, and used by whichever of our apps you sign in to. Your @tag is reserved for you across all of our apps, so nobody else can take it in any of them. Because of that, one of our apps can tell that a tag is already taken; it cannot tell who holds it.
Signing up here does not put you in our other apps. Until you open one of our other apps and sign in to it yourself, that app keeps no profile record for you, and you do not appear in its search, suggestions, follower lists or anywhere else its users can see. The only thing another app knows is that your @tag is reserved.
Carrying your profile over is your choice. When you first open another of our apps, we can pre-fill your display name, profile photo and bio from the shared account so you don’t have to set them up again — but only if you have turned on “Share my tag, name and avatar across Better Together apps”. That setting is optional and off unless you turn it on. You can turn it off at any time in Settings in any of our apps. Turning it off stops us carrying your profile into apps you haven’t joined yet; it does not remove the profile you already have in apps you use, which you can edit or delete in each app.
What stays inside each app. Everything you make in an app — here, your goals and progress — and who you follow, who follows you, your in-app settings and your purchases, belong to that app. We don’t copy them to our other apps.
Deleting. Deleting your account in Impossible Goals removes your data from Impossible Goals only. To delete your Better Together account and your data in every app, email hello@bettertogether.technology and we will do it across all of our apps.
Legal basis (UK and EU). We run the shared sign-in and @tag reservation because they are necessary to provide the account you asked for (contract). We carry your profile between apps only with your consent, which you can withdraw as described above. We keep abuse-prevention records under our legitimate interest in running the service safely.
3. What this notice covers
This notice covers the Impossible Goals iOS app, the backend service that supports it, and the public web pages we publish for goals, profiles, updates and invitations. It does not cover third-party sites or services we link out to, or the apps you share into, which have their own privacy notices.
4. The data we collect, and who collects it
Account and identity (via Clerk)
We use Clerk as our sign-in provider, on the shared Better Together account described in section 2. You sign in to Impossible Goals with a one-time code sent to your email address or phone number, or with Sign in with Apple or Google; this app does not set or store a password for you. Clerk holds the email address and/or phone number you verified, any Apple or Google sign-in link, your name, your @handle and your profile photo (the photo file itself is uploaded to and served by Clerk). Our own database stores the account identifier Clerk issues, a copy of your verified email address and phone number, the time zone your device reports (so “today” and overnight notification holds are worked out in your local time), and the date and version on which you confirmed your age and accepted the Terms of Service.
Your profile
You can set a display name, an @handle, a profile photo, a short bio, a location and a link. The location is free text you type; we never read your device’s location. Your name, @handle and photo, and the goals you have made public, are shown on a public web page for your profile that anyone can open, signed in or not; your bio, location and link are shown to signed-in people who open your profile in the app. Settings → Privacy lets you turn off Discoverable profile (which keeps you out of search and suggestions, but does not hide the web page or stop someone who already knows your exact @handle) and Hide my follower counts.
Goals and proof-of-progress entries
The core of the product is the goals you declare and the entries you add to them. For each goal we store its title, why it is impossible, its category, dates, status, cover photo and visibility, plus the people you invite to co-own it. For each entry we store the note, milestone or photo you upload as proof of progress (with its caption and the date it happened), and the likes and comments it receives. Photos are held in private object storage and served through time-limited links. Every goal has a visibility setting you control — private (only you and any co-owners), supporters (people you, or a co-owner, choose for that goal), or public — and any single entry can be made private on its own. We render goals and entries only to the audience those settings allow. A public goal, and each of its non-private entries, also has a public web page and a share card (including its photos) that anyone with the link can open.
Comments, reactions and the social graph
We store the comments you write, including a photo or GIF you attach and anyone you @mention; the entries you like; the goals you congratulate; the people you Follow, the goals you Support, and the goals you Adopt to start your own version (the adopted goal credits the original). The people you block are recorded so that neither of you sees the other; your block list is visible only to you. When you report a goal, entry, comment or person we store the reason and any note you add; the note is read only by our moderators and is never shown to the person reported. We also record what the feed and Explore showed you (which items, in which order) so we can check that their ranking is working; this is not shown to anyone.
What you do on Explore
To choose and order what Explore shows you, we record on our own servers which goals and people you open from Explore and how long you spend on them, when you share or hide something there, when you tap Not interested or See less from this person, and the searches you run on Explore (the search text, trimmed and lower-cased, with the number of results it found). When you support, follow or adopt a goal or person you found on Explore, we also record that it came from Explore and where it sat in the list, so we can tell which recommendations were useful. To improve how Explore recommends goals, we keep a record of each list we ranked for you: which goals were in it (up to 200), in what order, and the scores our ranking gave each one (for example how popular it was, how closely it matched your interests and how recent it was). We also keep a short-lived copy of the list we ranked for you so that Explore stays consistent while you scroll. None of this is shown to anyone else, and your search text is never sent to our analytics provider.
Goal topics and similar goals (via Anthropic and OpenAI)
To organise Explore, our servers send the text of goals that are public or visible to supporters to two AI providers. Anthropic receives the goal’s title, its “why it’s impossible” text and its category, and returns up to three topic labels from a fixed list (for example “Running & endurance”). OpenAI receives the title and the “why it’s impossible” text and returns an embedding: a list of numbers that lets us find goals that read alike. Nothing else goes with either request — not your name, @handle, account identifier, photos, entries or comments. The text of a private goal is never sent for this. We store the topic labels and the embedding with the goal and redo them when you change its title, why text or category; the embedding is deleted if the goal is made private or hidden, and both are deleted when the goal is.
Invites
Your account has an invite code you can share. When someone opens your invite link we log that the code was viewed, without identifying who viewed it, and when they sign up with it we record that you invited them.
Photos and device permissions
The app asks for access to your photo library only when you choose a photo for a goal cover, an entry, a comment or your profile, and for add-only access when you choose to save a progress photo back to your library. It does not use your camera or microphone, and it does not request your contacts or your device’s location. Uploaded photos are resized and stored for delivery; every image you upload is also run through an automated safety classifier (section 7).
Push notifications
If you allow notifications, we store the push token your device is issued so we can deliver the notifications you have opted into (for example, when someone comments on your entry), together with your per-type notification preferences, the goals you have muted, and any notification held overnight (we do not push between 10pm and 8am in your time zone) until the morning. The notifications you receive are also listed in the Activity tab.
Product analytics and diagnostics (via PostHog)
We use PostHog, on servers in the European Union, to understand how the app is used and to detect and fix errors. It receives the events we send (for example “entry added”, with timings and outcome codes) and crash or error reports (error type and code, app version, device and OS). For a random sample of about one in five times the app is opened, PostHog also makes a session recording: a replay of the app’s screens and the taps and scrolls you make on them, so we can see where the app is confusing or broken. We do not make session recordings when your device’s region or time zone is set to the European Union, the European Economic Area, the United Kingdom or Switzerland. Before a recording leaves your device, everything you type into a text field and every image and photo on screen (yours and other people’s) is masked out; other text shown in the app, such as goal titles, names and comments, can appear in it. A recording covers only the Impossible Goals app, never your camera, microphone or other apps. Our Terms of Service describe session recordings too, and you accept them when you accept the Terms before you continue using the app. Once you sign in, events and recordings are tied to your Impossible Goals user identifier — never your email address or @handle — along with your platform, app version, whether you have Pro, how many days since you signed up, and which build of the app you are running. When a sign-in attempt fails we record a salted one-way hash of the identifier you typed so we can count repeats without storing it. PostHog records the IP address of the connection when it receives an event. See PostHog’s privacy notice for how they process this data.
Pro subscription
If you subscribe to Pro, Apple takes the payment and RevenueCat tells us about it. We store the product you bought, when you first bought it, when your access runs out, and whether there is a billing problem. We never receive your card details.
Security and service records
Our servers keep your IP address for one hour to limit how often a single address can call the service, keep short-lived request identifiers so that a retried request is not applied twice, and keep delivery and error records for the background jobs that send notifications and clean up. If your account is suspended we record when and why.
On your device
The app keeps a local copy of the data it last fetched, your unsent drafts and queued uploads, and your recent searches; your sign-in token is kept in the device’s secure keychain. If you add the home-screen widget, a snapshot of your goals (titles, day count, cover and latest proof) is written to a storage area shared only with the widget. None of this leaves your phone except through the app’s own requests to us, and the app-scoped parts are cleared when you sign out.
What we do not do
We do not sell your personal data. We show no advertising, use no advertising or attribution trackers, do not track you across other companies’ apps or websites, and do not ask for the iOS tracking permission because there is nothing to track.
5. How and why we use your data
- To run your account and show you your goals, entries and progress every day.
- To operate the social graph — letting you Follow a person, Support a goal, and Adopt a goal to start your own version of it.
- To render your goals and entries to the people you have chosen to share them with, according to each goal’s visibility setting, including on the public web pages for public goals.
- To deliver the notifications you have opted into.
- To keep the service safe — automated screening of uploaded images, handling reports, blocks, suspensions and appeals, and preventing abuse.
- To keep the service secure and reliable — rate limiting, duplicate-request protection, and background job delivery.
- To recognise your Pro subscription and to credit invites.
- To choose and order the goals and people Explore shows you, and to improve that ranking over time (see below).
- To understand aggregate feature usage, check that the feed’s and Explore’s ranking is working, and find and fix bugs and crashes.
How Explore is ranked
Explore is ordered automatically. It only ever shows goals and people you are allowed to see, and never anyone you have blocked or who has blocked you. Within that, the main things that decide what comes first are:
- How people are responding to a goal: the supports, adoptions, comments, congratulations and likes it receives, with recent ones counting for more.
- Recent progress: whether the goal’s owner has been adding updates lately.
- Your interests: the topics of the goals you have created, supported, or opened from Explore, and the goals you have told us you are not interested in.
- Similarity: how closely a goal reads like the goals you have created or support.
- Freshness: newer goals and updates get a lift, so Explore does not only show what is already popular.
You can shape it yourself: tap Not interested on a goal, or See less from this person on someone’s goal, and Explore takes that into account from then on. To object to us using your activity to personalise Explore, email us (section 10); deleting your account deletes the activity it is based on.
6. Our legal bases (GDPR and UK GDPR)
Where the EU or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) for the core service: your account, your goals and entries, sharing them with the audiences you choose, the social graph, the Pro subscription and invites.
- Consent (Art. 6(1)(a)) for push notifications, for access to your photo library, and for carrying your profile into another Better Together app (section 2). You can withdraw each at any time in Settings or in your device settings.
- Legitimate interests (Art. 6(1)(f)) in running a safe and reliable service: automated safety classification of uploaded images, moderation and suspension records, rate limiting and other security measures, logging what the feed and Explore showed you so we can evaluate their ranking, and product analytics and crash reporting.
- Legitimate interests (Art. 6(1)(f)) in helping people find goals and people worth following: ranking and personalising Explore, recording what you open, hide and search for there and what you support, follow or adopt from it, keeping the lists we ranked for you to improve its recommendations, and sending the text of public and supporters goals to Anthropic and OpenAI to assign topics and find similar goals. Private goals are never used this way. You can object to processing on either of these legitimate-interest bases (section 10).
- Session recordings (section 4): our legitimate interests (Art. 6(1)(f)) in finding and fixing where the app is confusing or broken. We tell you about them in our Terms of Service, which you accept before you continue using the app; that acceptance is how we inform you and agree the terms of the service with you, and is not a separate consent you can switch off in the app. You can object to them on the basis of legitimate interests (section 10).
- Legal obligation (Art. 6(1)(c)) where we must keep or disclose records, for example purchase records or a lawful request from an authority.
7. Who we share your data with
We share personal data only with the service providers (processors) we use to run Impossible Goals, each bound by contract to use it only as we instruct, and only with what each needs:
- Clerk (sign-in) — your email address and/or phone number, Apple or Google sign-in link, name, @handle and profile photo, on the shared Better Together account.
- Apple and Google (sign-in) — only if you sign in with them; they pass Clerk your identity and see that you signed in.
- PostHog (analytics and error reporting, EU-hosted) — the events, diagnostics and masked session recordings in section 4, tied to your user identifier.
- Railway (hosting and database) — runs our servers and stores the server-side data in this notice.
- Cloudflare (photo storage and delivery) — stores your uploaded photos and GIFs in a private bucket and serves resized copies through links that expire after 24 hours; the links carry no user identity.
- Inngest (background jobs) — runs the queued work behind notifications, safety scans and cleanup; its job payloads carry record identifiers, never your photos or text.
- Expo and Apple (push delivery) — receive your push token and the notification text (which may name the person who acted, for example “Priya liked your update”) and deliver it to your device. Notifications carry no images.
- Expo (app updates) — your device fetches updates to the app’s code from Expo’s servers; the request carries the app version and platform, not your identity.
- Apple and RevenueCat (purchases) — Apple processes the payment; RevenueCat receives your Impossible Goals user identifier and the purchase and entitlement details we need to recognise your subscription. We never receive your card details.
- Klipy (GIF search) — when you search for a GIF in the comment composer, our server sends Klipy the search term (so Klipy sees our server, not your device); the previews in the picker load directly from Klipy’s content network, which therefore sees your device’s IP address. A GIF you post is copied to our own storage, so people reading it never contact Klipy.
- Anthropic (image safety and goal topics) — every image you upload (entry photos, goal covers, your profile photo and comment photos) is sent, as the image alone with a fixed classification prompt, for automated screening against our Community Guidelines; a flagged image is hidden and queued for a human to review. Separately, for goals that are public or visible to supporters (never private goals), the goal’s title, “why it’s impossible” text and category are sent to assign topic labels for Explore (section 4). An image is sent without any of your text or captions, goal text is sent without any image, and neither carries your name, @handle, account identifier or other account details. Under Anthropic’s commercial terms it may not use this data to train its models.
- OpenAI (similar goals) — for goals that are public or visible to supporters (never private goals), the goal’s title and “why it’s impossible” text are sent to OpenAI’s embeddings service to produce the list of numbers we use to find similar goals on Explore (section 4). No name, @handle, account identifier or other account details go with it. Under OpenAI’s API terms it may not use this data to train its models; it may keep it for up to 30 days to monitor for abuse.
- GitHub (moderation alerts) — when a report is filed, an alert to our moderators carries only the report’s identifier, what kind of thing was reported and the reason category — never who reported, who was reported, or the note.
- Instagram, and other apps you share into — only when you tap Share: the card image you chose is handed to the app you pick through your device’s share sheet. We send nothing else, and the app you share into handles it under its own privacy notice.
We do not use any other email, SMS, crash-reporting, advertising or attribution provider. Email us at hello@bettertogether.technology for the current list of providers and the terms we hold with them. We may also disclose personal data where the law requires it, to protect the safety of our users, or as part of a merger, transfer or reorganisation of our business, in which case this notice continues to apply.
8. International transfers
We are a United States company and most of our providers process data in the United States; product analytics is hosted in the European Union, and photo delivery runs on a global content network. If you use Impossible Goals from outside the United States, your personal data is transferred to and processed there. Where personal data leaves the UK or the European Economic Area we rely, where applicable, on an adequacy decision covering the destination (including the EU-US Data Privacy Framework where a provider is certified under it), and otherwise on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, agreed with that provider. Email us at hello@bettertogether.technology for the safeguard that covers a particular provider.
9. How long we keep your data
- Active accounts: we keep your account, profile, goals, entries, comments and social connections for as long as your account exists. A goal, an entry or a photo you delete yourself is removed at once and its stored files are erased. A comment you delete is hidden from everyone and shown as a deleted placeholder so that replies to it still make sense; its attachment is erased, and its text stays in our database, hidden.
- Deleted accounts: when your Impossible Goals account is deleted — by you in the app, or by us when you ask for your Better Together account to be deleted — we erase your stored photos and other uploaded files, delete your push tokens and any notifications held for delivery, delete the record of what the feed and Explore showed you, the lists Explore ranked for you, and of what you opened, hid, searched for, supported, followed or adopted on Explore, and erase the personal details on your account record: your name, @handle, email address, phone number, photo, bio, location, link and invite code. Content you posted where other people can see it (goals, entries and comments shared with others) stays so that other people’s threads and shared goals do not break, attributed to Deleted account. Goals and entries you had kept private stay in our database, invisible to everyone, unless you delete them before deleting the account. We keep, on the anonymised record, your time zone, the date and version of your terms acceptance and age confirmation, your cross-app consent history, your Pro purchase history, any suspension record, and a reference to your former sign-in identifier so the deletion cannot be undone by a replayed event. Reports you filed and reports about you stay in the moderation record for the window below. Your sign-in details, @handle and profile photo in the shared Better Together account are held by Clerk and are deleted when you ask us to delete that account (section 2).
- Push tokens: marked revoked and no longer used when you sign out of a device or when the push service reports the token as expired; deleted when your account is deleted. Push delivery receipts are kept for 7 days.
- Notifications: a notification you have read is deleted 180 days after it was sent; unread notifications stay until you read them or delete your account.
- Feed and Explore impressions: the record of what the feed and Explore showed you is deleted after 90 days, or when your account is deleted.
- Explore activity and searches: what you opened from Explore and for how long, what you shared or hid, your Not interested and See less from this person choices, your Explore searches, and the record of what you supported, followed or adopted from Explore are deleted after 365 days, or when your account is deleted. The record of each list Explore ranked for you, with its scores, is deleted after 90 days, or when your account is deleted. The short-lived copy that keeps Explore consistent while you scroll is deleted after 30 minutes. Separately, the app keeps a copy of the Explore page you last saw on your own device for up to 24 hours, so Explore opens instantly; it is refreshed in the background and cleared when you sign out.
- Goal topics and embeddings: kept with the goal and deleted when the goal is deleted; a goal’s embedding is also deleted when it is made private or hidden, or when its owner’s account is deleted.
- Goal history: the timeline of events on a goal (an entry added, a milestone reached, a supporter joined) is kept with the goal; “entry added” events are pruned after a year.
- Reports and moderation: a report, and the reason an image or post was removed, is kept for 2 years after it is resolved.
- Security and service records: IP addresses used for rate limiting are deleted one hour after the window they count; duplicate-request protection records after 24 hours; background job delivery and webhook records after 30 days; records of failed jobs we may need to repair after 90 days. Links to your photos expire after 24 hours and are re-issued each time you open them. An uploaded file that is never attached to anything is deleted after a day.
- Analytics: product-usage and diagnostic events, and session recordings, are kept by PostHog for the retention windows configured on our project, and are not used to build a profile of you outside the service. Email us to ask what those windows currently are.
- Purchase records: we keep the record of Pro purchases for as long as tax and accounting law requires.
10. Your rights
Depending on where you live, you have rights to access, correct, receive a copy of, restrict, object to, and delete the personal data we hold about you, and to withdraw consent. Here is how to use each:
- Access and correction: your profile, goals, entries, comments, settings and Activity are all visible and editable in the app. For a full copy of everything we hold about you, email us.
- A copy of your data (portability): there is no export button. Email us and we will send you a copy of your data in a common machine-readable format within one month (GDPR) or 45 days (CCPA).
- Deletion: go to Settings → Delete account in the app. This runs the erasure described in section 9 and deletes your Impossible Goals account. Your @handle is released in this app but stays reserved for you across our other apps, because your Better Together account — your sign-in details and your @handle — stays: it is also your account in our other apps, and deleting it from here would remove you from products you never asked to leave. To delete the Better Together account and your data in every one of our apps, email hello@bettertogether.technology and we will do it across all of them.
- Restriction and objection: in the app you can make a goal or an entry private, turn off Discoverable profile, hide your follower counts, block people, mute a goal’s notifications, turn each notification type off, and tap Not interested or See less from this person on Explore. To object to any processing we base on legitimate interests, or to ask us to restrict processing, email us.
- Withdrawing consent: push notifications in Settings → Notifications or your iOS settings; photo library access in your iOS settings; cross-app profile sharing in Settings → Privacy.
- Complaints: if you believe we have mishandled your data you can complain to your data protection authority — in the UK, the Information Commissioner’s Office; in the EU, the authority in the country where you live. We would appreciate the chance to address your concern first.
To exercise a right by email, write to hello@bettertogether.technology from the address on your account, or tell us your @handle. We may ask you to confirm you control the account before we act, and we respond within the time the law requires.
California residents (CCPA/CPRA)
In the last 12 months we have collected the categories of personal information described in section 4: identifiers (name, email address, phone number, @handle, account and device identifiers), the content you create (goals, entries, photos, comments, profile), commercial information (Pro purchase history), internet activity (usage events, crash reports, IP address, and what you open and search for on Explore), and inferences we make from your account for the service (such as feed and Explore ranking, and the topics of your shared goals). We collect it from you, from your device, and from the providers in section 7, for the purposes in section 5. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for anything beyond providing the service, so there is no opt-out to offer. You have the right to know, to delete, to correct, and not to be discriminated against for exercising those rights. Exercise them in the app or by email as above. You may use an authorised agent; we will ask the agent for proof of your permission and may confirm the request with you directly.
11. Children
Impossible Goals is for people aged 16 or older. When you create an account we ask you to confirm you are at least 16 and to accept the Terms of Service, and we record the date you did. We do not knowingly collect personal data from anyone under that age, and we do not otherwise verify age. If you believe someone under 16 has created an account, contact us at hello@bettertogether.technology and we will investigate and delete it.
12. How we protect your data
Connections to the service are encrypted in transit (TLS). Uploaded photos are kept in a private storage bucket and delivered only through signed links that expire after 24 hours. Sign-in is by one-time code or Apple or Google sign-in, so this app holds no password for you; Clerk holds your sign-in credentials, and your session tokens are short-lived and kept in your device’s secure keychain. Every request to our servers checks that you are allowed to see or change the record it touches. No system is perfectly secure; if we learn of a breach that affects you we will tell you and the relevant authority as the law requires.
13. Changes to this notice
If we make a material change to how we handle your personal data, we will update the effective date above and, where appropriate, notify you in the app before the change takes effect. The app records the version of the Terms of Service and this notice you accepted; when that version changes, the app asks you to read and accept the new version before you continue.
14. Contact
Questions about this notice or your data? Email hello@bettertogether.technology.
Effective 5 October 2026. © Better Together Technologies LLC.