Privacy Policy
Last Updated: September 30, 2025
This Privacy Policy describes how goon.com ("we", "us", or "our") collects, uses, and shares your personal information when you use our Service.
1. Information We Collect
1.1 Authentication Information: When you sign in using third-party authentication providers, we collect basic profile information including your name, email address, profile picture, and user ID from these platforms.
1.2 Blockchain and Wallet Information: We collect and store your Solana wallet address for processing USDC deposits and referral commission payouts. All blockchain transactions are publicly visible on the Solana network. Your non-custodial wallet is provided through third-party wallet infrastructure providers, and wallet-related data is subject to their privacy policies.
1.3 AI Prompts and Generated Content: We collect and store all prompts, inputs, and text you submit to the Service, as well as all AI-generated content including images, videos, chat messages, and other outputs. This data is stored for:
- Quality assurance and service improvement (analyzing what works and what doesn't)
- Content moderation and safety enforcement
- Training and improving our AI models and algorithms (including fine-tuning and customization)
- Debugging and troubleshooting technical issues
- Compliance with legal obligations and law enforcement requests
- Analytics and understanding usage patterns
Important: You should have no expectation of privacy regarding any content, prompts, or interactions you submit to or generate through the Service. All data may be reviewed by our team and used to improve our systems.
1.4 Usage and Analytics Data: We automatically collect information about your interactions with the Service, including:
- Feature usage and interaction patterns
- Session duration and frequency of use
- Credit usage and purchase history
- Referral activity and commission data
- Device information (type, operating system, browser, screen resolution)
- Network information (IP address, ISP, general location)
- Performance metrics (load times, errors, crashes)
- Access times, pages viewed, and navigation paths
1.5 Cookies and Tracking Technologies: We use cookies, local storage, and similar tracking technologies to:
- Maintain your session and keep you logged in
- Remember your preferences and settings
- Analyze usage patterns and improve the Service
- Track referral sources and affiliate relationships
- Detect and prevent fraud and abuse
1.6 Analytics and Monitoring Data: We use third-party analytics and monitoring services to collect detailed information about how you use the Service:
- Web analytics: Page views, navigation paths, feature usage, click tracking, and user flows
- Event tracking: User actions, interactions, button clicks, form submissions, and custom events
- Session replay: Recordings of your browsing sessions, including mouse movements, clicks, scrolls, and on-screen activity (excluding sensitive input fields)
- Error tracking: JavaScript errors, crashes, bugs, and technical issues you encounter
- Performance monitoring: Page load times, API response times, and performance metrics
- Feature flags: A/B testing and feature rollout tracking
This data helps us understand how users interact with our Service, identify bugs and issues, and improve user experience. Session replays may capture your on-screen activity but exclude password fields and payment information.
2. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: Provide, operate, maintain, and improve our Service and its features
- Payment Processing: Process credit deposits and referral commissions via USDC on Solana
- Account Management: Authenticate your identity, create and manage your account, and provide customer support
- AI Training and Improvement: Train, fine-tune, and improve our AI models and algorithms using prompts and generated content
- Quality Assurance: Review and analyze content, prompts, and interactions to assess quality, identify issues, and improve outputs
- Content Moderation: Monitor and enforce our Terms of Service and content policies, detect prohibited content, and ensure user safety
- Security and Fraud Prevention: Detect, prevent, and address technical issues, security threats, fraudulent activity, and abuse
- Analytics and Research: Analyze usage patterns, conduct research, and understand user behavior to improve user experience
- Communication: Send you service-related communications, updates, security alerts, and support messages
- Legal Compliance: Comply with legal obligations, respond to law enforcement requests, and enforce our agreements
- Personalization: Customize and personalize your experience based on your preferences and usage patterns
3. Content Moderation and Safety
To enforce our content policies and ensure user safety, we:
- Review and analyze content generated through the Service using automated systems and manual moderation
- Store records of content violations and enforcement actions
- May report illegal content to appropriate law enforcement authorities
- Retain moderation data to prevent circumvention of our policies
4. Information Sharing and Disclosure
We may share your information in the following circumstances:
4.1 Service Providers: We share information with third-party service providers who perform services on our behalf, including:
- Authentication providers: Third-party social login services for account creation and identity verification
- Wallet infrastructure: Third-party wallet service providers for non-custodial wallet provisioning and management
- AI and ML services: Third-party AI API providers for content generation. Your prompts, inputs, and usage data are sent to these third-party APIs for processing and may be used by them subject to their privacy policies
- Database and storage: Cloud database and storage providers where your prompts, generated content, account information, and usage data are stored
- Analytics and monitoring: Third-party analytics platforms for web analytics, event tracking, session replay, error tracking, and performance monitoring. These services may collect detailed usage data, session recordings, and diagnostic information
- Cloud infrastructure: Hosting and content delivery network (CDN) providers for Service infrastructure
- Content moderation: Automated and manual content moderation services that review prompts and generated content
- Payment processing: Blockchain infrastructure and USDC transaction services on the Solana network
These service providers have access to your information only to perform specific tasks on our behalf and are obligated to protect your information, though each is subject to their own privacy policies and terms.
4.2 Third-Party AI APIs and Data Processing: When you use our Service, your prompts, inputs, and requests are sent to third-party AI provider APIs to generate content. These third-party APIs receive, process, and may retain your data according to their own privacy policies and terms of service. Specifically:
- All text prompts and inputs you submit are sent to AI provider APIs in real-time for content generation
- These providers may log, store, and use your prompts for their own purposes (training, improvement, compliance)
- Generated content (images, text, etc.) passes through these third-party systems
- We recommend reviewing the privacy policies of the AI service providers we use
- We do not control how third-party AI providers use, retain, or protect your data
4.3 Blockchain Transparency: All USDC transactions on the Solana blockchain are publicly visible and permanently recorded. Your wallet address and transaction history can be viewed by anyone using blockchain explorers. This is an inherent characteristic of public blockchains and cannot be changed or deleted.
4.4 Legal Requirements: We may disclose your information if required by law, regulation, legal process, subpoena, or governmental request, or to protect the rights, property, or safety of goon.com, our users, or others. This includes reporting illegal content (especially CSAM) to law enforcement agencies such as NCMEC and the FBI.
4.5 Business Transfers: If we are involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. Specific retention practices:
- Account information: Retained while your account is active and for a reasonable period after deletion for legal compliance
- Prompts and generated content: May be retained indefinitely for AI training, quality assurance, and service improvement, even after account deletion
- Content moderation records: Retained indefinitely to prevent abuse and comply with legal obligations
- Analytics and usage data: Retained in aggregated or anonymized form indefinitely
- Blockchain transactions: Permanently recorded on the Solana network and cannot be deleted
We may also retain and use your information to comply with legal obligations, resolve disputes, enforce our agreements, prevent fraud and abuse, and maintain security and content moderation records.
6. Data Security
We implement reasonable security measures to protect your information, including:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and monitoring
- Secure hosting and infrastructure
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk. You are responsible for maintaining the security of your authentication credentials and wallet private keys.
7. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information:
7.1 Access and Portability: You may request access to the personal information we hold about you and, where applicable, request a copy in a portable format.
7.2 Correction and Update: You can update certain account information through your account settings. For other corrections, contact us at privacy@goon.com.
7.3 Deletion: You may request deletion of your account and associated personal information. Note that:
- Some information may be retained as permitted by law for legal compliance, fraud prevention, and security
- Prompts and generated content may be retained indefinitely for AI training and service improvement
- Blockchain transactions are permanent and cannot be deleted
- Content moderation records may be retained indefinitely
7.4 Opt-Out of Communications: You can opt out of promotional communications by following the unsubscribe instructions in those messages. We may still send you service-related, transactional, or legal communications.
7.5 Do Not Track: Our Service does not respond to Do Not Track signals due to the lack of industry standards.
7.6 Exercising Your Rights: To exercise any of these rights, contact us at privacy@goon.com. We will respond to your request as soon as reasonably possible, typically within 30 days. For data subject rights requests, we may need to verify your identity before fulfilling your request.
8. International Data Transfers
Your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your jurisdiction. By using the Service, you consent to the transfer of your information to these countries.
9. Children's Privacy
Our Service is not intended for individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@goon.com, and we will take steps to delete such information.
10. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, disclose, and sell
- Right to request deletion of your personal information
- Right to opt-out of the sale of your personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at privacy@goon.com. We will verify your identity before processing your request.
11. European Privacy Rights
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):
- Right of access, correction, erasure, and data portability
- Right to restrict or object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
Our legal basis for processing your information includes:
- Performance of our contract with you (providing the Service)
- Compliance with legal obligations
- Legitimate interests in operating and improving our Service
- Your consent (where applicable)
To exercise your rights, contact us at privacy@goon.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the updated Privacy Policy on the Service with a new "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
13. Third-Party Links and Services
Our Service may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with any information.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Email: privacy@goon.com
For legal or compliance inquiries: legal@goon.com
We will respond to your inquiry as soon as reasonably possible, typically within 30 days. For data subject rights requests, we may need to verify your identity before fulfilling your request.