Global Access Tip: This document is governed in English to ensure legal consistency. You may use your browser's built-in translation feature to read it in your preferred language.
Privacy Policy
Last updated: September 2026
1. Platform Overview & Non-Custodial Architecture
The GOXA Platform provides decentralized, serverless productivity, gamification, and operational infrastructure. We operate under a strict non-custodial "You Own Your Data" (Zero-DB) architecture. GOXA does not harvest, warehouse, or monetize end-user data, customer rosters, attendee lists, or transaction ledgers. We do not collect or store your email address.
2. Three-Tier Platform Role Model & OAuth Scopes
To ensure forward compatibility across all current and future applications, the Platform governs authentication and storage across three distinct roles:
- Primary Operators (Vault Owners) — The primary account creators (e.g., Captains, Event Hosts, Merchants).
• OAuth Scope Requested:openid profile drive.file.
• Responsibility: Acts as the sole Data Controller. An 8-character GOXA ID (format:ABCD-EFGH) is issued. All operational databases reside exclusively within their personal Google Drive folder (e.g.,/GOXA/[App Name]/). - Delegated Collaborators — Auxiliary personnel explicitly invited by the Primary Operator (e.g., Co-Captains, Event Staff, Cashiers).
• OAuth Scope Requested:openid profile drive.file.
• Limitation & Protection: Collaborators authenticate with Google solely to establish verified identity and cryptographic delegation signatures. The Platform NEVER uses Collaborators' personal Google Drives for storage. Collaborators merely assist in scanning or verifying items directly against the Primary Operator's vault. - Participants & End Users — Members, attendees, guests, or retail customers interacting with an application. Depending on the application's context, participants interact either anonymously via ephemeral tokens / Magic IDs or via authorized OAuth. Participant records are written directly into the Primary Operator's private vault. GOXA servers never maintain a centralized roster of participants.
3. Scope of Data We Access
When authenticating with Google, the Platform requests the absolute minimal scopes required for decentralized operation:
- OpenID & Basic Profile — To cryptographically identify accounts via a secure numeric identifier (Google Sub ID) and display chosen nicknames. We explicitly refuse and strip the email scope.
- Google Drive (drive.file) — Used solely by Primary Operators to read and write application JSON files in their own Drive. The Platform has zero access to your personal photos, external documents, or emails.
4. Data Storage & Ephemeral State
All permanent operational records (task catalogs, member points, attendance logs, loyalty stamps) reside exclusively inside structured JSON files within the Primary Operator's Google Drive. GOXA servers store only:
- Cryptographic routing indexes linking your hashed identifier to your designated Drive folder.
(e.g., GOXA ID: ABCD-EFGH ↔ Storage Vault ID: 1a2b3c4d5e...) - Short-lived, encrypted session tokens with strict TTL expiration for API routing authorization.
(e.g., Ephemeral AES-256-GCM token: gxc_9f8e... purged immediately on sign-out) - Aggregated, anonymous operational metrics for platform capacity and tokenomics monitoring.
(e.g., Daily scans: 42, HMP watermark: 355, 0 personal identifiers collected)
5. Global Privacy & Minor Protection (COPPA & GDPR Guidelines)
The GOXA Platform is engineered around the principle of Privacy by Design and Default, complying with international data protection frameworks, minor safety standards (including the US Children's Online Privacy Protection Act (COPPA) and the EU General Data Protection Regulation (GDPR)), and applicable regional privacy laws worldwide.
Because our architecture is entirely non-custodial and operates without centralized databases, we inherently satisfy international minor protection mandates:
- Zero Minor Identity Harvesting: We do not collect, request, or store names, emails, phone numbers, or biometrics from minors or children under the age of 13 (or applicable local statutory age threshold).
- Pseudonymous Client Identifiers: In family and educational contexts, child/member participants interact solely via pseudonymous, client-generated device identifiers (Magic IDs).
- Parental & Custodial Sovereignty: All records, achievements, points, or milestones reside solely inside the parent/guardian's (Primary Operator's) private cloud storage vault. Guardians retain unilateral custody and immediate deletion authority over all participant records.
6. Cookies & Tracking Technologies
The GOXA Platform employs strictly essential, non-tracking cookies necessary for cryptographic routing and session maintenance. We do not use third-party advertising cookies, marketing pixels, or cross-site tracking scripts. Our essential cookies include encrypted session tokens and timezone preference cookies (scoped strictly to .goxa.app).
7. Account Revocation & Complete Data Autonomy
Under our Zero-DB architecture, you maintain 100% unilateral ownership and physical control over your records at all times. In compliance with international data privacy standards (including statutory rights to erasure, deletion, and consent revocation) and Google API User Data Policies, you can execute full self-erasure at any moment without relying on manual support:
- Instant Token Revocation — Primary Operators and Delegated Collaborators can revoke GOXA's permissions at any time via the Google Account Security Dashboard. Revocation immediately invalidates all server-side session tokens across all GOXA edge clusters.
- Delegation Severance — Primary Operators can unbind Collaborators at any time; Collaborators can independently disconnect from any team without affecting their own Google credentials.
- Complete Vault Erasure — You can permanently delete the
/GOXA/directory and all enclosed application JSON files directly from your personal Google Drive with immediate, irreversible effect. - Local Storage Purge — Signing out from any GOXA application instantly destroys all local browser cookies, cryptographic keys, and cached state.
8. Contact & Governance
For inquiries regarding our decentralized privacy architecture, please contact our privacy desk at: [email protected]