GOAT Labs — Privacy Policy
Effective Date: July 1, 2026
GOAT Labs ("GOAT," "we," "us," or "our") provides tooling that helps organizations connect approved coding and observability Sources, receive cashback based on eligible usage, and contribute trace data to a deidentified dataset and research program. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information and how we process trace data.
This Policy applies to personal information GOAT processes as a business or controller — including account, website, onboarding, fraud-prevention, payout, and support data — and explains how GOAT handles trace data that may contain personal information when GOAT processes it on behalf of a contributor under a Data Processing Addendum.
1. Notice at Collection
At or before collection, we inform you that we may collect the categories described in Section 2 and use them to provide and secure the Service, calculate cashback, review for and respond to suspected abuse or fraud, comply with law, communicate with you, and — for trace data you connect — create De-Identified Data and Corpus Products. To exercise privacy rights or to opt out of any processing you can opt out of, contact us at privacy@goat.ai (Section 10).
2. What We Collect
Account and organization data: your email address and display name; organization and project names; a coarse company-size selection; and teammate invitation email addresses. Accounts are created via Google sign-in (we request only basic profile and email scopes — not Gmail, Drive, or Calendar) or email magic link. We do not store a profile photo.
Authentication and credential data: login events; the authentication identifier; and API keys, CLI tokens, device keys, and connected-Source credentials — stored only in hashed or encrypted form, never as plaintext (plaintext is shown once at creation).
Trace and telemetry content: prompts, completions, model reasoning, the full content of tool/function calls and their results (which can include complete file contents, source code, diffs, command output, pasted text and images, and attachments), tool and MCP-server definitions and configuration, system prompts, tokens, cost, model and provider identifiers, timing, session and conversation identifiers, provider response identifiers, and repository/file context — including working-directory paths, git branch and commit, and the repository origin/remote (with embedded credentials stripped; the host, organization, and repository name are retained). When you connect a local coding tool, historical (pre-existing) sessions may be uploaded at installation. When you connect an observability Source, we may also collect the end-user identifier supplied by that Source (e.g., your application's customer or user ID) and any user-supplied metadata, tags, or feedback. Unlike contributor identifiers, these source-supplied end-user identifiers are captured and retained as provided (encrypted at rest) and are not pseudonymized by GOAT; the contributor is responsible for the lawful basis and for any notice or consent owed to those end users.
Multi-party collection. Where a contributor installs repository- or organization-level capture, or connects an observability Source, we collect trace data generated by other individuals who use that repository, tool, or Source — including teammates, employees, and the end users of the contributor's own product — even though those individuals have not separately installed our software, signed in, or interacted with us. The connecting contributor is responsible for any required notices and authorizations (Section 10 and the DPA).
Contributor identifiers: for repository/local capture, a one-way pseudonym derived from your git identity (we do not store the raw git email); for anonymous capture, a pseudonymous machine fingerprint (a hash of your operating-system username and home-directory path), used to attribute and rate-limit anonymous capture. Although the raw git email is not stored, we maintain internal mappings that let us associate trace data with an account for attribution, payout, support, and fraud-prevention — including (a) a reverse mapping from a contributor pseudonym to your account where you sign in and link a device, and (b) the association of every project and trace with the organization that owns it and that organization's designated payable account. As a result, trace data is reasonably linkable by GOAT to an organization and, in most cases, to an individual account, and trace identifiers should not be treated as anonymous.
Network and security data: we read your IP address transiently to rate-limit certain requests, and we record the actor IP address on audited security, access, and administrative events (for example, internal data access, exports, key and project management, and payout actions). We do not collect browser fingerprints, web/device tracking profiles, IP-derived geolocation, or application-version telemetry, and we use no third-party analytics or trackers. (The machine fingerprint described above is a single hashed value used to attribute and rate-limit anonymous capture, not a browser or behavioral tracking profile.)
Payout and finance data: your payout destination (a crypto Wallet address or a Coinbase email — stored as you provide it), payout amounts, on-chain transaction references, and payout status. We do not currently collect tax forms or taxpayer identification information, and we do not perform identity, sanctions, OFAC, anti-money-laundering, or KYC screening. We reserve the right to request tax, identity, or sanctions documentation in the future and to condition, delay, or withhold a payout until it is provided.
Support and communications data: contact-form submissions (name, email, and optional provider, domain, monthly-spend, reason, and message), which we receive by email and do not store in our application database; and other records of your interactions with us.
Cookies and local storage: the only cookies we set are strictly necessary authentication session cookies. Our marketing website sets no cookies. We use browser local storage only for interface state. We do not use tracking or advertising cookies.
No category pre-screening. GOAT does not pre-screen, filter, classify, or block trace data by content category before capture, and does not detect or remove special-category, health, payment-card, government-ID, biometric, precise-geolocation, or children's data prior to ingestion. The contributor is solely responsible for ensuring such data is not connected or submitted.
3. Where the Information Comes From
We collect information directly from you; from your organization's administrators and users; from capture agents you install and Sources you connect; from observability providers and code tooling you authorize; and automatically from your use of the Service. Where we use payout, accounting, payment, or (in the future) fraud or sanctions-screening vendors, we may also receive information from them.
4. How We Use Information
We use personal information and trace data to: provide, maintain, secure, and support the Service; authenticate users and manage organizations and access; calculate program metrics and Cashback, process payouts, and review for suspected abuse or fraud (which we do manually and on a best-effort basis; we do not represent that we operate automated fraud, sanctions, or abuse-detection systems); apply automated, best-effort redaction and deidentification techniques to trace data (which are automated and probabilistic, may be partial, are not guaranteed to run on or remove sensitive content from any particular trace, and do not include any human-review step); create analytics, benchmarks, reports, and product features; comply with legal obligations and enforce our agreements; communicate with you; and create and license De-Identified Data and Corpus Products from the trace data you connect.
5. How Our Trace-Data Processing Works
When trace data may contain personal information, GOAT generally processes that raw data on behalf of the contributor that connected the Source, under that contributor's instructions and the DPA. Connecting a Source, installing a capture agent, configuring a project, committing capture configuration, or sending traffic to a project slug you control authorizes and instructs GOAT to ingest and durably capture trace data (including in encrypted, un-redacted raw form) immediately and irreversibly. That capture begins on connection, is not conditioned on any further opt-in, and cannot be reversed for data already captured. You are responsible for the lawful basis and for all required notices and consents for everyone whose personal information appears in trace data you connect — including teammates and end users — and for all traffic sent to any slug you control (including anonymous ingest, which is enabled by default).
Raw trace content is captured and stored in encrypted, access-segregated form at ingestion, before and independently of any redaction or deidentification. GOAT applies an automated, best-effort redaction and deidentification process before content is promoted to its queryable store, but does not warrant that it runs on, detects, or removes data from any particular trace or field, or that it renders any data non-personal; the process is probabilistic, includes no human-review step, and raw content is retained in encrypted, access-segregated storage independently of redaction. Authorized GOAT processing systems and a limited number of authorized personnel may access decrypted Raw Trace Data on a need-to-know, access-logged basis for processing, redaction, validation, support, security, fraud-investigation, and legal-compliance purposes. If and to the extent GOAT transforms trace data into De-Identified Data that it designates as no longer constituting personal information, GOAT may use that data as part of its own commercial corpus and products as described here and in the Terms.
6. De-Identified Data and Licensing of Datasets
A core part of GOAT's business is creating datasets, benchmarks, and research products from De-Identified Data and licensing them to recipients such as frontier AI labs, investment-research and alt-data teams, market researchers, academics, and other approved commercial or research recipients.
We design and operate our pipeline with the goal that outbound products comprise De-Identified Data, but we do not warrant that every record in any dataset meets the deidentification standard, and you acknowledge that residual linkability may remain. De-Identified Data may retain coarse technical metadata — including model identifiers, token counts, timing, cost, content fingerprints, session identifiers, provider response identifiers, observability end-user identifiers, and repository or source labels — that may remain linkable to a contributor or account. We maintain internal mappings linking pseudonymous contribution identifiers to contributor accounts (and resolve traces to the responsible account via organization membership) for attribution, team visibility, payout, audit, and fraud-prevention; these mappings are retained and controlled by us as a controller and are not provided to dataset recipients. For information we treat as deidentified under California law, GOAT (i) maintains reasonable technical and organizational measures intended to prevent reidentification, (ii) commits to maintaining and using such information only in deidentified form and not to attempt to reidentify it except as permitted by law, and (iii) contractually requires recipients of Corpus Products not to attempt to reidentify any individual. We do not warrant that recipients will comply, and we are not responsible for a recipient's breach. You assume the risk of, and agree not to hold GOAT liable for, any reidentification arising from metadata or residual identifiers GOAT was authorized to retain or process.
7. How We Disclose Information
We may disclose personal information to: service providers and subprocessors that host, secure, store, transmit, or support the Service (Section 12); payout, wallet, accounting, and payment vendors, and — where we elect to use them in the future — fraud, sanctions, identity, or tax vendors; professional advisors, auditors, insurers, and financing counterparties; law enforcement and regulators where required or to protect rights or safety; acquirers or counterparties in a merger, financing, acquisition, restructuring, or asset transaction; the contributor organization that controls a workspace (if you are a user under that organization); and approved recipients of Corpus Products, which we intend to comprise De-Identified Data.
8. California Privacy Disclosures
If you are a California resident, you may have rights to know, access, correct, and — subject to the significant limits in Section 10, including that deletion is manual, best-effort, and may be technically infeasible for encrypted raw, immutable, or already-distributed data — delete personal information, and to opt out of its "sale" or "sharing." You have a right not to be discriminated against for exercising these rights.
GOAT licenses De-Identified Data and Corpus Products and does not treat data that satisfies the legal standard for deidentified or aggregate information as personal information. To the extent any disclosure of personal information, or of information that remains reasonably linkable to you, qualifies as a "sale" or "sharing" under California law, you may opt out by emailing privacy@goat.ai; we will honor verified opt-out requests, which will at least stop future inclusion of your information in Corpus Products. We do not currently process Global Privacy Control or other browser-based opt-out preference signals automatically.
Notice of Financial Incentive. The cashback program is a financial incentive tied to your contribution of trace data. Material terms: the personal information implicated is the trace data you connect (Section 2); you opt in by connecting Sources and contributing eligible usage, and you may withdraw at any time by disconnecting Sources or emailing privacy@goat.ai. Good-faith value estimate and method: GOAT calculates cashback from the measured output-token volume of your eligible contributions, multiplied by the model's published output price and an applicable program rate and multiplier, as described in the Terms; GOAT uses this same measure as its good-faith estimate of the value of the data to GOAT, which varies by contribution and is not a guaranteed amount. The incentive is reasonably related to the value GOAT derives because both are computed from the same usage measure. GOAT may revise this methodology. If you opt out of the commercialization-linked processing the program depends on, you may be unable to continue participating or to receive future cashback.
Categories of California personal information we may collect and disclose include identifiers, professional or employment information, internet or network activity, commercial information, account credentials (hashed/encrypted), payout instruments, support records, and inferences for program administration, anti-fraud, or analytics. We do not knowingly sell or share the personal information of children under the applicable age threshold (Section 14).
9. GDPR and UK GDPR Legal Bases
Where GOAT acts as a controller, we rely on one or more of: contract (to create and administer accounts, provide the Service, and process payouts); legitimate interests (to secure the Service, prevent and investigate fraud, improve reliability, support users, enforce agreements, and defend claims, including IP logging on security events); consent (where we rely on it for specific optional processing); and legal obligation (tax, sanctions, accounting, regulatory, or law-enforcement obligations). Where GOAT processes raw trace personal data on behalf of a contributor under the DPA, the contributor is responsible for identifying the lawful basis.
10. Your Rights and Their Limits
Depending on your location and our role, you may have rights to access, correct, delete, port, object to, or restrict processing, or to withdraw consent. Submit requests by emailing privacy@goat.ai. We may need to verify your identity and authority before acting, and we will acknowledge and respond within the timeframes required by applicable law (for example, 45 days under California law and one month under the GDPR/UK GDPR, each extendable as permitted).
These rights are subject to important limits that reflect how the Service works:
- No self-service erasure/export. We do not provide self-service deletion or data export. Requests are handled manually, on a best-effort basis, subject to technical feasibility.
- Immutable records. Certain records (consent, rights, provenance, audit, and payout-ledger records, including the actor IP recorded on audited events) are maintained as immutable, append-only ledgers for security, fraud-prevention, payout integrity, and legal compliance. Where we cannot delete or correct such a record without undermining those purposes, we may restrict processing instead.
- Raw and derived data. Raw trace data is retained encrypted and may not be individually or promptly deletable; De-Identified Data and Corpus Products already derived, and datasets already exported or licensed, are excluded from deletion and return obligations.
- Forward-only revocation. Withdrawing consent or changing settings applies only to data captured afterward and does not recall data already captured or used.
- Where an exception applies, we will delete what we can and tell you what we cannot delete and why.
- Processor role. Where we hold data only as a processor on behalf of a contributor, we may direct you to that contributor, though we may assist where required.
- Third-party data subjects. Where you appear in trace data a contributor connected (for example, as a teammate, employee, contractor, or end user of a contributor's product), the contributor — not GOAT — is the controller and is responsible for receiving and responding to your request; we will direct you to that contributor and our role is limited to commercially reasonable, technically feasible assistance to the contributor.
11. Retention
We retain personal information and trace data for as long as needed for the purposes in this Policy, and in some cases on a long-term or indefinite basis. Encrypted raw trace data is retained for as long as necessary for re-processing, provenance, security, audit, and fraud-prevention, is access-segregated, and is reviewed for deletion when the contributor relationship ends and no legal-hold, fraud-investigation, or audit need remains, or when the data can no longer support re-derivation or provenance. Audited security and access events, including the actor IP recorded on those events, are stored in append-only logs and retained on a long-term basis for security, integrity, and fraud-prevention. We do not operate a fixed deletion timer; only short-lived authentication grants expire automatically. Our subprocessors may maintain their own backups and disaster-recovery copies under their standard practices; GOAT does not operate an independent backup or point-in-time-recovery system, and we may be unable to remove personal information from any subprocessor-maintained copies.
12. Subprocessors and International Transfers
We use the following subprocessors to operate the Service: Supabase (managed Postgres, authentication, and authentication-email delivery; AWS-hosted); ClickHouse Cloud (trace/span data store; AWS-hosted); Cloudflare (R2 encrypted object storage and dataset exports, and edge/CDN; storage region "auto"); Upstash (Redis queues, cache, and rate-limiting); Resend (transactional email); Google (OAuth sign-in identity provider); our compute host (currently Hetzner; an EU-based provider); and Coinbase (used manually, off-platform, to send payouts; GOAT performs no automated integration and no sanctions/KYC screening). We do not currently use a payment processor, third-party analytics, or a third-party fraud/sanctions-screening provider. A current subprocessor list is available on request at privacy@goat.ai, and we provide notice of material changes as described in the DPA.
Personal information may be processed in the European Union, the United States, and other countries, as determined by our hosting and subprocessor configuration. Where a transfer requires a transfer mechanism, we rely on, or will put in place, an appropriate mechanism such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum; a copy of the relevant safeguards is available on request at privacy@goat.ai.
13. Security
We use administrative, technical, and organizational measures designed to protect personal information and raw trace data, including: application-level authenticated encryption of raw trace content at rest (XChaCha20-Poly1305 with per-project key derivation) and TLS in transit; strict database access-segregation and least-privilege roles that prevent the dashboard and analytics systems from reading raw content; hashing of stored credentials; access controls; need-to-know restrictions; and append-only audit logging. Application-level encryption is applied to raw trace content and connected-Source credentials; certain other data (for example, account profile fields, the payout destination, and dataset exports) is stored without additional application-level encryption and is protected by access controls and our subprocessors' at-rest encryption. Encryption keys are held as environment-level secrets within our deployment environment; we do not currently use a hardware security module or managed key-management service, and key rotation is performed manually.
We do not currently operate independent continuous breach-detection, intrusion-monitoring, security-monitoring, or backup/point-in-time-recovery systems of our own, and we rely in part on our subprocessors' managed infrastructure; these capabilities continue to evolve. No system is perfectly secure, and we do not promise absolute security. Where we confirm a security incident affecting personal information, we will provide notice without undue delay after we become aware, to the extent and in the manner required by applicable law and the DPA. No notice is an admission of liability or fault.
14. Children
The Service is directed to businesses and to individuals of legal age in their jurisdiction, and we do not knowingly collect children's personal information. GOAT does not verify the age of any individual and does not have actual knowledge of the age of data subjects appearing in trace data. Because trace data you connect may contain information about your teammates or your application's end users, you are solely responsible for ensuring you do not connect Sources that submit the personal information of children below the applicable age threshold, and for any affirmative consent required for consumers under 16 under California law. GOAT will not have actual knowledge sufficient to trigger child-specific obligations absent your notice.
15. Changes and Contact
We may update this Policy from time to time. For material changes, we will post the revised version and provide additional notice where required. For privacy questions or rights requests, contact privacy@goat.ai or the postal address on our legal page.