Privacy
Effective September 22, 2026
Goose is a place to build a website, so there are two kinds of people here: the owner of a site, and the people who visit it. This page says what we collect from each, what it is used for, which other companies handle it, and how to get it back or have it deleted.
It describes what the software does today. Where something is not built yet, or not tidy yet, it says so instead of describing the intention.
Who we are
Goose is made by Off-Leash, the software studio of Michael Craig Group, LLC, which operates it from Tucson, Arizona, and is responsible for everything described here. Write to hello@michaelcraig.group about any of it. A person reads every message.
The short version
- We collect what the product needs to work. There is no advertising here, and nothing follows anyone from site to site.
- We do not sell, rent or lend anyone's information, and never will.
- A site's audience belongs to the site's owner. We hold it for them and use it to run their site.
- Everything a site holds can be exported at any time, in open formats.
- Nothing expires on its own: what we hold stays until it is deleted, and deleting is a real erase, not a hidden flag.
If you have a Goose account
What we hold about a site owner, and the people they work with:
- Your account. Your email address, and your name if you give one. Your password goes to Supabase, which runs sign-in for us; Goose passes it on and keeps none of it. If you sign in with Google or GitHub instead, we keep the name, email address and profile-picture link that account hands over.
- Your sites. Everything you put on them — pages, words, photographs, events, prices, settings — and a change log that records who changed what, and when.
- Your team. The email addresses of people you invite to work on a site, and the role you gave each of them.
- Your plan. Which plan a site is on and whether it is paid, with Stripe's reference numbers. Your card belongs to Stripe; it never reaches us.
- Your connections. The tokens and keys for services you connect — a payment account, an email platform, a social account, a calendar link. Disconnecting deletes them.
- Your API keys. Stored as a hash and shown to you once. We cannot read one back to you; we can only revoke it.
- What you send us. Email, and anything typed into the feedback button, which is encrypted in your browser before it leaves.
We use it to run your sites, to send you what you ask for — sign-in links, receipts, notices about your own sites — to bill you, and to answer you. Visits to gooseitup.com's own pages, including the admin, are counted by the analytics described below, which sets no cookie.
If you visit a site built on Goose
Every site here belongs to somebody. The site's owner decides what their forms ask for and what happens to the answers; Goose stores it for them and does what the site is set up to do with it. Depending on the site, that can be:
- A signup. Your email address, your name where the form asks for it, the tags and the page, form or campaign the signup came from — including any
utm_values in the link you followed — and a consent record: the time you submitted it and the IP address it came from. That record is the evidence that you asked for the email, and it is why we keep it. A list the owner brings with them from somewhere else records instead how they say consent was obtained. - A purchase, a ticket, a donation, a deposit. Your name and email address, what you bought or gave and when, and whether it was paid. Payment details go straight to Stripe. If you download a file you bought, we record the time and the IP address of the download.
- An inquiry, a booking request, a volunteer sign-up, a message. Whatever the form asks — usually a name, an email address, a phone number, dates, and what you wrote — and whether you ticked the separate box to hear from the site by email.
- A class or a course. What you have access to, what you have completed, and any class credits you hold.
- A private album. The photographs you chose and the notes you left about them.
- Feedback. Encrypted in your browser, so it passes through Goose unreadable.
Goose also counts page views and clicks, a day at a time, per page: a number, with nothing attached about who. No cookie is involved. An owner can also switch on Analytics, which adds top pages, referrers and countries — served through their own site's address, cookieless.
Who can see it. The site's owner, the people they give access to, and our administrators, who can open any site to run and support the service. If a site is handed to a new owner, its audience goes with it, and the new owner takes it from there.
What we don't do with it. We don't use a site's audience for anything of our own, don't share it between sites, and don't sell it. One thing does cross sites: if an address bounces, or somebody reports email sent from Goose as spam, Goose stops its newsletters and automated emails to that address from every site — it marks the address on each list it appears on, and keeps a hash of the address, rather than the address, to check later sends against.
Cookies
Goose sets no cookie for advertising and none for analytics. These are the ones it does set, all of them doing a job you asked for:
| Cookie | Where | What it does | How long |
|---|---|---|---|
| sb-access-token, sb-refresh-token | gooseitup.com | Keep you signed in. | 7 days |
| goose_site_id | gooseitup.com | Which of your sites you were last working on. | 1 year |
| goose_site_view | gooseitup.com | Whether a site opens as a preview or as its admin view. | 1 year |
| goose_intent_vertical | gooseitup.com | The kind of site you picked before signing up. | 7 days |
| goose_intent_plan | gooseitup.com | The plan you picked before signing up. Spent on the first site you create. | 7 days |
| goose_facebook_oauth, goose_instagram_oauth, goose_twitter_oauth, goose_linkedin_oauth, goose_ep_oauth, goose_facebook_pages | gooseitup.com | Hold a connection open while you approve it at Facebook, Instagram, X, LinkedIn or Constant Contact. | 10 minutes |
| pf_album_…, v_album_… | a site with private albums | Remember that a private album is open to you, so its photographs load. | 30 days |
A site on Goose sets nothing else. Two things an owner can put on a page bring cookies of their own: a payment page loads Stripe's script, which Stripe uses to detect fraud and which sets its own cookies, and an embedded video or audio player is loaded from the service it lives on. A link to a map, a calendar or a share dialog is only a link — nothing is sent until you follow it.
What we never do
- No advertising network, no ad technology, no tracking pixel on any page Goose serves.
- No selling, renting or lending of anyone's information, to anyone, for anything.
- No profile of a person built across sites, and no third-party analytics script.
- Every typeface is served from Goose itself, so no font service is told who is reading.
Who else handles it
Goose is built on other people's services, and this is all of them. The list lives in Goose's own source code, where each entry names the code that uses the service, so it moves when the product does.
Services we use to run Goose
-
Cloudflare
Hosts Goose and every site on it: serves the pages, stores site content in its D1 database and uploaded files in its R2 storage, resizes images, plays video for class libraries, and answers for the domains site owners connect.
Receives: Site content and settings, every uploaded file, the email addresses of site owners and the people they invite, and — as any web host sees — the IP address and browser of every request.
-
Supabase
Runs sign-in, and holds the private records: accounts, subscribers, orders, donations, inquiries, volunteer sign-ups and bookings.
Receives: A site owner's email address and password (which Goose passes on and never stores itself), the record Supabase keeps of each sign-in, and everything people give a site through its forms and checkouts.
-
Stripe
Bills site owners for their plan, and for the one-time premium looks.
Receives: The owner's email address and payment details, typed into Stripe's own page. Card numbers never reach Goose; it keeps Stripe's reference numbers and whether the plan is paid.
-
Resend
Sends Goose's email: sign-in links and security codes, receipts and notices, and the newsletters and automated emails a site sends its own subscribers.
Receives: Each recipient's email address and the message itself, and — where a site sends from its own domain — the DNS records that domain needs.
-
Anthropic
Drafts text when someone working on a site asks for it — a suggested social post, a translation, an audition notice, or a reading of a performance schedule written in prose. Nothing is sent unless that button is pressed, and the buttons are dead unless Goose has an Anthropic key configured.
Receives: The site's own text the draft is about. No subscriber, buyer or visitor records are sent.
-
Plausible (ours)
Counts visits to gooseitup.com's own pages, and to a site's pages when its owner switches Analytics on. It is open-source software we run ourselves; a tenant site's counts are sent through the site's own address rather than to a third party.
Receives: The page visited, the site that linked to it, and the visitor's browser, device and country. The IP address is used to tell one visit from another for a day and is not stored; no cookie is set.
-
Eddy (ours)
Receives feedback sent with the feedback button — to us, or to a site owner who has connected their own Eddy project.
Receives: What was written, an email address if the sender adds one, the page it was sent from and the browser. It is encrypted in the sender's browser with the project's public key, so Goose passes it on without being able to read it and stores none of it.
-
Tempo (ours)
Holds the appointments made through a Goose booking page and keeps them in the owner's calendar. A booking page works only where Tempo is configured for that site.
Receives: The booker's name and email address, the time booked, and any note they leave.
-
GitHub
Runs the nightly backup job, and is one of the two ways a site owner can sign in with an account they already have.
Receives: For the backup: a copy of both databases, made on GitHub's machines and encrypted there before it is stored; GitHub keeps the encrypted copy for 30 days, or 90 for the copy taken on the first of the month. For sign-in: the name, email address and profile-picture link on the GitHub account.
-
Google
The other way a site owner can sign in with an account they already have.
Receives: The name, email address and profile-picture link on the Google account.
-
Backblaze
Keeps the off-site backups, in a different account from everything they protect.
Receives: The encrypted database copies, which it cannot read, and a copy of the files uploaded to Goose's sites, which is not encrypted. The file copy is never deleted from, so a file removed from Goose stays in it until we remove it by hand.
Services a site owner connects
None of these is involved until the owner of a site connects their own account, and disconnecting ends it.
-
Stripe, on the site owner's own account
Takes the payment when someone buys from a site — a ticket, a product, a class, a donation, a deposit. The site owner is the seller, through their own Stripe account.
Receives: The buyer's email address and payment details, typed into Stripe's own form. Card numbers never reach Goose; it records what was bought, for how much, and whether it was paid.
-
Constant Contact
A site owner can connect their Constant Contact account, and Goose copies the site's subscribers into it.
Receives: Each subscriber's email address and name, their tags, where they signed up, and the consent recorded with the signup.
-
Meta (Facebook and Instagram)
Publishes to a connected Facebook Page or Instagram account the posts a site's admins write or schedule.
Receives: The post, and its image where there is one. Goose keeps the access token Meta issues and the Page's or account's id and name; it reads no followers, messages, comments or insights. What Goose keeps, and how to remove it, is set out at /data-deletion.
-
X
Publishes a site's posts to a connected X account.
Receives: The post. Goose keeps the tokens X issues and the account's name.
-
LinkedIn
Publishes a site's posts to a connected LinkedIn account.
Receives: The post. Goose keeps the token LinkedIn issues and the account's name.
-
Bluesky
Publishes a site's posts to a connected Bluesky account.
Receives: The post. Goose keeps the account's handle and the app password created for it, which the owner can revoke at Bluesky.
-
Telnyx
Would carry a site's text messages to people who asked for them. Not live: no site sends text messages through Goose today.
Receives: When it is live: the recipient's phone number and the message.
-
OvationTix
For a theatre whose box office runs on OvationTix, Goose reads the theatre's public performance list so its site can show what is still available.
Receives: Nothing about anyone. Goose reads performance times and seat counts; a ticket buyer follows a link and deals with OvationTix directly.
-
Booking-calendar feeds (Airbnb, Vrbo and the like)
A venue owner can paste the calendar-export link from a listing elsewhere, so their own site shows which nights are taken.
Receives: Goose reads the feed and keeps the booked dates only; guest names and anything else the feed carries are dropped as it is read.
Players a site owner can embed
A site owner can drop a video or an audio player into a page by pasting its address. Your browser then loads it from YouTube, Vimeo, SoundCloud or Spotify, which sees your IP address and may set its own cookies under its own policy. Goose sends them nothing. A picture a site owner links from another website works the same way.
How long we keep it
Nothing expires on its own. What a site holds stays until its owner deletes it, deletes the site, or asks us to.
Deleting a site offers an export first, then erases everything belonging to it from both of our databases in one go — its pages and content, and its audience: subscribers, orders, donations, inquiries, volunteer sign-ups and the rest — and cancels its plan. It is not a flag; the rows are gone. The owner does it from the site's Your data page, whatever kind of site it is. Four things outlive it, and we would rather say so:
- Uploaded files. Photographs and downloads stay in storage when a site, a gallery or a single photograph is deleted, and anyone holding a file's address can still load it. We remove them by hand on request, and a proper erase is on the list of things to build.
- Backups. Encrypted copies of both databases are kept for up to 30 days, and the copy taken on the first of a month for about 13. Copies we take by hand before risky work last until we delete them. The off-site copy of uploaded files is never deleted from.
- What other services hold. Stripe keeps its payment records, which tax and card rules require; Resend keeps its delivery logs; anything already sent to a connected email platform or posted to a social account belongs to that account.
- Appointments and feedback. Bookings sit in our calendar server and feedback in Eddy; neither is reached by a site's deletion. Ask us and we will clear them.
Closing your account is not a button yet. Email us and we will delete it, and every site you own, with the same exceptions above.
Taking it with you
Export is free, on every plan, and always has been the point. Every site has a Your data page where its owner downloads the whole site as one file, plus its subscribers, its orders and whatever list that kind of site collects — a venue's guest inquiries, a portfolio's commission inquiries, a theatre's volunteers — as spreadsheets. Photographs are not inside the export file, so keep your originals.
If a site holds something about you and you are not its owner — you subscribed, bought a ticket, sent an inquiry — ask the site, which controls it. Or ask us at hello@michaelcraig.group: we can tell you what is held, correct it, or delete it, and we will tell the site's owner that we did.
How it is protected
- Every page and every form is served over HTTPS, and browsers are told to accept nothing else.
- Passwords are Supabase's to hold. API keys are stored as a hash. Feedback is encrypted in the sender's browser.
- Backups are encrypted before they leave the machine that makes them, with a key the backup system itself cannot read.
- Beyond the encryption Cloudflare and Supabase apply to what they store, Goose adds none of its own: its software can read what it stores, which is how it builds a page and sends an email. Encrypting private data so that only its owner can read it is where this is meant to go, and it is not there yet.
Children
Goose accounts are for adults running a website. We don't knowingly collect anything from a child; if you believe a site on Goose holds something about one, write to us and we will deal with it.
Legal requests
We hand information to anyone else only to run Goose, as set out above, or where the law requires it of us.
Changes
When this page changes, the date at the top changes with it, and what changed is listed here. Nothing is edited quietly.
- September 22, 2026 — first version.
Connecting Facebook or Instagram to a site has its own page: what Goose keeps, and how to delete it.