legal
Privacy notice
Effective August 20, 2026
Good Enough AI, Inc. ("Good Enough," "we," or "us") provides an AI chat and API service. This notice explains what personal data we collect, why we use it, who processes it, and the choices available to you. It applies to itsgoodenough.ai and app.itsgoodenough.ai.
01Data we collect
- Account data: name, email address, sign-in provider, account status, and preferences.
- Customer content: prompts, responses, files, images, and other content submitted to the service.
- Usage data: model selected, timestamps, token counts, cost, API-key identifier, request status, and diagnostic metadata.
- Billing data: purchases, credit balance, Stripe identifiers, and receipts. Stripe handles card details; we do not store full card numbers or security codes.
- Security data: hashed rate-limit identifiers and hosting-provider logs such as IP address, browser, and request metadata.
- Communications: messages and support requests you send to us.
02How we use data
We use personal data to:
- provide accounts, chat, API access, model routing, and customer support;
- meter usage, maintain credit balances, process payments, and prevent fraud;
- operate, secure, troubleshoot, and improve the service;
- evaluate and improve routing quality, which may include reviewing and labeling logged prompts and responses;
- send transactional messages about accounts, purchases, security, and material service changes; and
- comply with law and enforce our terms.
We do not sell personal data or use it for targeted advertising. We do not use customer content to train third-party foundation models. Customer content may be used internally to evaluate and improve Good Enough's routing and service quality as described above.
03AI processing and service providers
To answer a request, we send its content to the infrastructure and model provider serving the selected model. We also use vendors to operate the service. They process data for the purposes described here and under our agreements with them.
| provider | purpose |
|---|---|
| Amazon Web Services | API infrastructure, managed model inference, operational logging, secrets, and transactional email |
| Modal | managed inference for selected flagship models and limited operational jobs |
| Neon | managed Postgres database for accounts, credits, keys, usage, and operational records |
| Vercel | website hosting and application server routes |
| Google and GitHub | optional account sign-in providers |
| Stripe | payment processing, fraud prevention, and payment records |
We may also disclose data when required by law, to protect users and the service, or in connection with a financing, merger, acquisition, or sale of assets, subject to appropriate confidentiality obligations.
04Cookies and authentication
We use essential cookies to keep you signed in, protect requests, and preserve basic account state. We do not currently use advertising pixels or cross-site behavioral advertising cookies.
05Retention
We retain account, usage, customer content, and operational records for as long as reasonably necessary to provide the service, resolve billing questions, prevent abuse, meet legal obligations, and improve reliability. Payment and tax records may be kept for legally required periods. When data is no longer needed, we delete or de-identify it. De-identified data that cannot reasonably be linked back to you may be retained for analytics and service improvement.
06Your choices and rights
- You can revoke API keys from the console at any time.
- You may request access, correction, deletion, or a portable copy of your personal data, subject to legal exceptions.
- You may object to or restrict certain processing where applicable law provides that right.
- You can stop using the service and request account deletion by emailing us.
We may need to verify your identity before completing a request. Depending on where you live, you may also have the right to appeal our response or complain to a local data-protection authority.
07Security and international processing
We use safeguards including encrypted transport, managed infrastructure, access controls, secret management, and hashed API credentials. No system is completely secure, and we cannot guarantee absolute security. Good Enough and its providers primarily process data in the United States; if you use the service elsewhere, your data may be transferred to the United States and other locations where our providers operate.
08Children
The service is not directed to anyone under 18, and we do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data to the service.
09Changes and contact
We may update this notice as the service changes. We will update the effective date and provide additional notice when a change is material. Questions, privacy requests, and security reports may be sent to hello@itsgoodenough.ai.
Effective August 20, 2026. See also the terms of service.