Goodword

Privacy policy

This describes what Goodword actually stores and does, not what a template says a SaaS company usually stores and does.

Last updated 5 September 2026.


Who we are

Goodword is testimonial software. There are two different relationships in it, and they matter for this policy.

What we store

For an account holder:

For someone submitting a testimonial:

We also keep short-lived counters to stop flooding of the sign-up, sign-in and submission forms. These are stored as a SHA-256 hash of the IP address, never the address itself, and they are deleted once the window expires.

What we do not store

The embedded widget

When a Goodword widget loads on someone elses website, the visitors browser requests a JavaScript file and any avatar images from us. That request carries an IP address and user agent, as every HTTP request does. We use it to serve the file and to increment a per-day view count for the widget. We do not set a cookie, do not fingerprint the visitor, and do not build a profile across sites.

Legal bases

How long we keep it

Testimonials and account data are kept until they are deleted, because a testimonial is content our customer is actively using on their site. You can delete any testimonial from the dashboard at any time, and it is removed from the database rather than flagged as hidden. Sessions expire after 30 days. Rate-limit counters last minutes to an hour. Ask us to close your account and we will delete it and everything in it.

Getting your data out

Every space has a JSON and a CSV export in the dashboard, available on the free plan, with no cap and no waiting period. That is deliberate: the entire premise of this product is that your testimonials are yours. You do not need to make a formal request to get them.

Who else can see it

Two suppliers, and no one else. Hosting is Vercel, and the database is hosted libSQL run by Turso. We do not sell data, and we do not share it with advertisers or data brokers. Data may be processed outside the UK by those two suppliers under their standard contractual clauses.

Your rights

Under UK GDPR you can ask for a copy of your data, ask for it to be corrected or deleted, ask us to restrict how it is used, and object to processing. Write to hello@goodword.site. If you are not satisfied you can complain to the Information Commissioners Office.

Security, stated plainly

Passwords are scrypt-hashed and compared in constant time. Sessions are random 32-byte tokens held in an httpOnly cookie and checked against the database on every request. Uploaded images are re-encoded rather than served back as supplied. Public endpoints are rate limited.

What we will not claim: Goodword has not been penetration tested, is not certified against any standard, and is run by one person. If that is not an acceptable risk for the data you were going to put in it, do not put it in.

Changes

If this policy changes materially we will change the date at the top and, for account holders, say so in the dashboard. See also our terms of use.