Privacy Policy
Effective date: 15 May 2026 · Last updated: 15 May 2026
Plain English summary: Good Minutes is a local-first desktop app. Your time entries, contacts, and invoices stay on your machine in a local database — we cannot see them and do not want to. The only data that ever leaves your computer is:
- A one-time licence check when you activate a Pro or Cloud Connect subscription (your email + a machine fingerprint).
- Data you explicitly push through Cloud Connect integrations (Xero, Microsoft 365, MatterX) — and that goes directly to those providers, not to us.
- Optional telemetry you can disable (crash reports + anonymous feature-usage counts).
We do not run ads, we do not sell data, we do not build profiles. If you use Good Minutes Free with telemetry off, we know literally nothing about you.
1. Who we are
Good Minutes is published by DataChef Pty Ltd ATF DataChef Trust, ABN 98 121 229 168, Gold Coast, Queensland, Australia. References to "we", "us", or "our" mean DataChef.
Data protection contact: support@datachef.zendesk.com
2. What this policy covers
This Privacy Policy applies to: the Good Minutes desktop application for macOS and Windows; the Good Minutes website at goodminutes.app; the licence-activation and update services; and the Cloud Connect integration service (when available).
3. Data that stays on your machine (we never see it)
Good Minutes stores all practice data in a local database on your computer. This includes: activity signals (window titles, app names, timestamps); time entries; contacts and organisations; projects and matters; invoices and payment records; and classification rules and AI model preferences.
This data never leaves your machine unless you explicitly export it or push it through a Cloud Connect integration. We have no technical ability to access it.
4. Data we do collect
4.1 Website visitors
When you visit goodminutes.app we collect standard web-analytics data via privacy-focused analytics (no personal identifiers). If you join our waitlist or subscribe to updates, we collect your email address.
4.2 Licence activation (Pro & Cloud Connect)
When you purchase a Pro subscription or Cloud Connect add-on, our merchant of record (Lemon Squeezy) collects payment details. We receive your email, name (if provided), and a machine fingerprint (a hash of hardware identifiers) to validate your licence. We do not receive or store full payment card details.
4.3 Telemetry (optional, off by default in Pro)
If you enable telemetry we collect: crash reports (stack traces, OS version, app version); anonymous feature-usage counts (e.g., "timer started 12 times this week"); and update-check metadata. Telemetry never includes time-entry content, client names, or any text you type.
5. Cookies and similar technologies
The Good Minutes website uses minimal cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Maintains login state for licence portal | Session |
| Analytics (GA4) | Anonymous page-view counts | 13 months |
| Consent preference | Remembers your cookie choice | 12 months |
The desktop app does not use cookies. It makes HTTPS calls to our licence server and (if telemetry is on) our telemetry endpoint.
6. Cloud Connect integrations
Cloud Connect is an optional paid add-on that lets you push data from Good Minutes to third-party services (Xero, Microsoft 365, MatterX). When you enable an integration:
- You authenticate directly with the provider using OAuth.
- Your data travels from your machine to the provider's API — it does not pass through or get stored on our servers.
- We store only the OAuth refresh token (encrypted) so you don't have to re-authenticate every session.
Each provider's privacy policy governs how they handle your data once it reaches them.
7. Legal basis for processing (GDPR)
| Processing activity | Legal basis |
|---|---|
| Licence activation & validation | Contract performance |
| Sending transactional emails | Contract performance |
| Website analytics | Legitimate interest |
| Telemetry (crash reports, usage stats) | Consent |
| Marketing emails / waitlist | Consent |
8. Data retention
| Data type | Retention |
|---|---|
| Licence records | Duration of subscription + 7 years (tax compliance) |
| Crash reports | 90 days |
| Usage telemetry | Aggregated after 30 days; raw deleted |
| Marketing list | Until you unsubscribe |
9. Who we share data with
| Recipient | Purpose | Location |
|---|---|---|
| Lemon Squeezy | Payment processing & merchant of record | USA |
| Vercel | Website hosting & analytics | USA / Global edge |
| Resend | Transactional & marketing email | USA |
| Sentry | Crash reporting (if telemetry on) | USA |
We do not sell personal data. We do not share data with advertisers or data brokers.
10. International transfers
Some processors listed above are based in the United States. Where data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses or the processor's Data Privacy Framework certification.
11. Your rights
Depending on your location you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time.
To exercise any right, email support@datachef.zendesk.com. We will respond within 30 days (or sooner if required by law).
12. California residents (CCPA / CPRA)
We do not sell or share personal information for cross-context behavioural advertising. California residents have the right to know, delete, and opt out of sale/sharing — though we don't engage in those activities.
| Category | Collected? | Sold? |
|---|---|---|
| Identifiers (email, name) | Yes | No |
| Commercial info (purchase history) | Yes | No |
| Internet activity (analytics) | Yes | No |
| Sensitive personal info | No | No |
13. Children's privacy
Good Minutes is not directed at anyone under 16. We do not knowingly collect data from children. If we learn we have, we will delete it promptly.
14. Security
We use HTTPS everywhere, encrypt sensitive data at rest, and follow secure development practices. Because your practice data never leaves your machine, the attack surface is inherently small.
15. Changes to this policy
We may update this policy from time to time. Material changes will be announced via in-app notification or email (if you're on our mailing list). The "Last updated" date at the top tells you when it was last revised.
16. Complaints
If you're unhappy with how we've handled your data, please contact us first at support@datachef.zendesk.com. You also have the right to lodge a complaint with a supervisory authority. In Australia, that's the Office of the Australian Information Commissioner (OAIC).
17. Contact
Questions? support@datachef.zendesk.com
DataChef Pty Ltd ATF DataChef Trust · ABN 98 121 229 168 · Gold Coast, Queensland, Australia