GOL Productions
Check Envie Exnos Nova Notepad Console
Legal

Privacy Policy

Last updated 30 July 2026

The headline: GOL has three products. Check and Envie process only the data you explicitly send, plus minimal operational data; command, code, and message content is processed in memory and discarded immediately. None of it is written to storage. Exnos runs entirely on your machine and sends nothing to us. We never sell your data. We do not share your data for cross-context behavioural advertising. Here is everything else, plainly.

1. What we collect, exactly

DataWhyWhere it livesRetention
Your email addressSign-in, license, receipts and the emails you ask forCloudflare KV (encrypted at rest)Until account deletion
Single-use sign-in codesVerifying it is really youCloudflare KVDeleted on use or expires in 5 minutes
Session tokens and license keysKeeping you signed in and metering usageCloudflare KVSessions: 30 days. Keys: until account deletion.
Credit balance, usage counts, and transaction logBilling: deducting the per-use price, providing your transaction historyCloudflare KVUntil account deletion
Payment recordsCrediting your top-upsStripe. We never see or store card numbers.Per Stripe's retention policy
IP address and user agentLogin notifications, session tracking, rate limiting, abuse preventionCloudflare KV (login records), Cloudflare standard server logsLogin records: until account deletion. Server logs: per Cloudflare's policy.
Device fingerprint (hashed)Preventing duplicate accounts per device and enforcing free daily check limitsCloudflare KVIndefinite (hash only, not reversible to device identity)
Usage analytics for customer keysNone collected. Command content and message prompts are processed in memory and never written to storage: not a truncated copy, not a hash, nothing. What survives a request is your billing record only: the time, the cost, and whether it passed.NowhereNot retained
Usage analytics for one internal test key we ownProducing published case studies of what Check catches on our own machine. Retention is hard-coded in the server to that single key; a customer key cannot be retained.Cloudflare KVRolling event windows on our own key only
Lifecycle events (install, uninstall, key created, key re-issued, free-limit reached, top-up) with the tool channel, OS, architecture, and the first 12 characters of the account ID. No command content.Understanding adoption and where the product loses people, aggregate statisticsCloudflare KVAggregate counters kept indefinitely; individual events only in the rolling 200-event feeds above
Feedback you submit from the console (message, category, your email, IP)Reading and acting on your feedbackCloudflare KV, and delivered to us by email via ResendUntil account deletion, or on request
Terms-acceptance record (timestamp, terms version, IP)Evidence that you accepted the TermsCloudflare KVUntil account deletion
Envie: machine fingerprint (hashed) sent with render-grant requestsAuthorising the render. The fingerprint is bound into the signed grant so a grant issued to one machine cannot be replayed on another. Processed per request, never stored.Not retainedNot retained beyond the request

2. What we do not collect

  • Your source code. GOL products never request, receive, or store your source code. Check operates on individual commands and code snippets you submit, not your repository. Envie renders videos locally on your machine; the HTML templates and output videos never leave your device.
  • Your commands or messages, at all. Check intercepts two kinds of content: message prompts you submit (which it annotates with verified environment facts before your AI sees them) and commands an AI generates (which it validates before they run). Both are processed in memory and discarded the moment the verdict or annotation is returned. Nothing of either is written to storage for customer keys: not a truncated copy, not metadata, nothing. What survives a request is your billing record only: the time, the cost, and whether it passed.
  • Anything from Exnos. Exnos runs entirely on your local machine. It communicates only between a Chrome extension and a server on 127.0.0.1 (localhost). It never contacts GOL servers, never phones home, never sends telemetry, and never collects or transmits any data. We have no way to know you are using it.
  • Advertising or cross-site tracking profiles. No advertising pixels, no cross-site tracking, no sale of data to anyone, ever. We do not sell or share your personal information for cross-context behavioural advertising.

3. Website analytics

The golproductions.com website uses Google Analytics 4 (measurement ID: G-4E865XW6LD) to understand how visitors interact with the site. Google Analytics collects anonymised data such as page views, session duration, approximate geographic location, device type, and referral source. This data is processed by Google under its own privacy policy. Google Analytics does not have access to your GOL account data, API key, or any data you send through the Check API.

If you prefer not to be tracked by Google Analytics, you can use a browser extension such as the Google Analytics Opt-out Browser Add-on or enable your browser's "Do Not Track" setting.

4. Cookies and local storage

The GOL website uses:

  • Google Analytics cookies (_ga, _ga_*): website analytics as described above.
  • Local storage: your session token is stored in your browser's local storage to keep you signed in. It is not sent to any third party.

We do not use advertising cookies or third-party tracking cookies beyond Google Analytics.

5. Services we rely on

Four providers touch slivers of your data so the product can work:

  • Cloudflare: hosting, Workers runtime, KV storage, and standard server logs (IP addresses for security and uptime).
  • Stripe: payment processing. We never see or store card numbers.
  • Resend: transactional email (sign-in codes, login notifications, low-balance alerts).
  • Google: website analytics via Google Analytics 4, and web fonts served from Google Fonts. When a page loads, Google's font servers see your IP address and browser user agent. Both apply to the website only, not the API.

Each processes data under its own privacy policy and our instructions. Your data may be transferred to and processed in countries outside Australia by these providers. Cloudflare, Stripe, Google, and Resend each maintain standard contractual clauses and/or certifications for international data transfers.

6. Emails

We send transactional email only:

  • Sign-in codes (on your request).
  • Login notifications (when a new session is created).
  • Low-balance alerts and spending notifications (if you enable them in settings).
  • Payment-related notices.

No marketing lists unless you explicitly opt in, and anything optional will have a working unsubscribe.

If you email us for any business reason, we keep that correspondence as ordinary business records for the life of the engagement and as required by Australian tax and record-keeping law. We do not share it with anyone except the service providers listed in section 5, and never for marketing.

7. How long we keep things

DataRetention
Sign-in codesDeleted on use or auto-expires in 5 minutes
Rate limit countersAuto-expires in 60 seconds
Daily spending recordsAuto-expires in 48 hours
SessionsUp to 30 days
Usage analytics eventsCustomer keys: none, ever. Our own internal test key: rolling event windows for published case studies
Lifecycle event counters (installs, uninstalls, key issuance, top-ups)Aggregate counts kept indefinitely. Individual lifecycle events sit in a rolling 200-entry feed carrying a truncated account ID; no command content in either.
Feedback and terms-acceptance recordsUntil account deletion, or on request
Transaction logRolling window of last 200 entries per account
Account records (email, keys, balance)Until you close your account
Webhook idempotency keysAuto-expires in 7 days
Envie render-token request fingerprintNot retained beyond the request

Ask us to delete your data and we will remove your account records. Unused credits are non-refundable and, if you have not requested full deletion, remain honoured in your account records indefinitely as described in the Terms.

8. Your rights (Australia)

Under the Australian Privacy Principles and applicable law, you have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate personal information.
  • Delete your account and associated personal information.
  • Complain to the Office of the Australian Information Commissioner if you believe we have breached the Australian Privacy Principles.

Email support@golproductions.com for any of the above. We handle requests in line with the Australian Privacy Principles, and we will respond like humans, not like a ticket queue. We aim to respond within 14 days.

9. Your rights (United States)

If you are a resident of a US state with a comprehensive privacy law (including California, Virginia, Colorado, Connecticut, Texas, Oregon, and others), you may have additional rights:

  • Right to know. You can request a copy of the personal information we hold about you and the categories of third parties we share it with.
  • Right to delete. You can request deletion of your personal information. We will comply unless a legal exception applies.
  • Right to correct. You can request correction of inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising. There is nothing to opt out of.
  • Non-discrimination. We will not discriminate against you for exercising any of these rights.

To exercise any of these rights, email support@golproductions.com. We will verify your identity using your account email and respond within 45 days.

10. Automated decision-making

GOL products use automated processing in the following ways:

  • Check, command validation: automated validation of commands and code against your project environment. The result (pass/fail) is deterministic and based solely on whether the checked item exists in your environment. No profiling or behavioural scoring is involved.
  • Check, message annotation: messages you submit are automatically annotated with verified facts about your live environment (port states, file modification times, referenced path stats) before your AI model sees them. This annotation is purely additive; it adds context the model can use, does not filter or block messages, and stores nothing of their content. No profiling or behavioural scoring is involved.
  • Envie: each render request returns a cryptographically signed authorisation grant. Renders are free, so the grant is always issued; the signature exists so the renderer cannot be run detached from the service, not to decide whether you may render. No profiling is involved and no rate limits apply.
  • Exnos: no automated decisions. Exnos reads browser state and returns it verbatim.

None of these automated processes make decisions that produce legal effects or similarly significant effects on you. If you believe an automated decision has affected you unfairly, contact us at support@golproductions.com.

11. Children's privacy

GOL products are not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a user is under 18, we will delete their account and associated data.

12. Security

We take reasonable steps to protect your personal information:

  • Sign-in requires a single-use emailed code, with optional TOTP two-factor authentication.
  • API secrets are stored in Cloudflare's encrypted secret store, not in source code.
  • Payments are processed entirely by Stripe and card details never pass through our servers.
  • Command, code, and message prompt content is processed in memory and not persisted to storage.
  • Timing-safe comparison is used for all authentication token validation.
  • Stripe webhook signatures are verified with HMAC-SHA256 to prevent forgery.
  • OTP attempts are capped and codes are deleted after use or expiry.

13. Data breach notification

In the event of a data breach that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), as promptly as practicable.

14. Changes

If this policy changes, the date at the top changes with it. Material changes will be flagged in the console or by email at least 14 days before they take effect.

15. Contact

Privacy questions, access requests, or complaints: support@golproductions.com.

GOL Productions
Check Envie Exnos Nova Notepad Terms Privacy Contact
© 2026 GOL Productions. All rights reserved.