HomeData Security Policy

Data Security Policy

Last Updated -August 16, 2026

GoodThought App, Inc.

Effective Date: August 16, 2026

Last Updated: August 16, 2026

GoodThought App, Inc.

221 W 9th St, Ste 1105

Wilmington, Delaware 19801, USA

1. Security Program

GoodThought maintains a security program designed to protect information and Services against unauthorized access, misuse, loss, alteration and disclosure.

GoodThought applies administrative, technical and organizational safeguards appropriate to the nature of the information processed and the risks associated with the Services. No method of transmission, storage or processing is completely secure, and GoodThought does not guarantee absolute security.

2. Administrative Controls

Security practices may include access governance, least-privilege principles, personnel controls, vendor review, incident-response planning, security awareness, confidentiality obligations and access reviews.

Access to personal information and systems is limited according to role, business need and authorization. GoodThought seeks to maintain appropriate separation of administrative responsibilities and audit access where reasonably necessary.

3. Technical Controls

GoodThought may use encryption in transit and at rest where appropriate, authentication, secrets management, logging, monitoring, backups, vulnerability management, network controls, secure configuration, access controls and other reasonable safeguards.

Credentials, API keys and other sensitive secrets are managed using appropriate security controls. GoodThought seeks to limit access to sensitive information and credentials to authorized personnel and systems.

4. Application and Infrastructure Security

GoodThought seeks to protect applications, APIs, cloud infrastructure, storage, credentials and deployment systems using appropriate security controls and ongoing monitoring.

GoodThought may use cloud infrastructure, content delivery, storage, authentication, application security and other technology providers. Security controls may include HTTPS/TLS, access controls, protected application interfaces, infrastructure monitoring, backups, deployment controls and vulnerability management.

GoodThought may use AWS infrastructure and related security services as part of its technology environment.

5. Communications and Data Processors

GoodThought may use third-party providers to deliver communications and related services. These may include Amazon Simple Email Service (Amazon SES) for email delivery, Twilio SendGrid for email delivery and related email communication services, and Twilio for SMS and messaging services.

These providers may process information necessary to deliver authorized communications, including email addresses, mobile telephone numbers, communication preferences, consent records and delivery-related information such as bounce, complaint, unsubscribe and suppression information.

GoodThought applies vendor and contractual controls appropriate to the nature of the services and information processed. Communications providers are expected to maintain appropriate security and privacy safeguards.

GoodThought does not sell or share mobile telephone numbers or SMS opt-in information with third parties or affiliates for their own marketing or promotional purposes. Authorized service providers may process such information on GoodThought's behalf to provide messaging, security, compliance, deliverability and related services.

6. Incident Response

GoodThought maintains procedures intended to detect, investigate, contain, remediate and respond to security incidents.

Where appropriate, GoodThought may assess the scope and impact of an incident, preserve relevant evidence, take steps to contain and remediate the issue, and coordinate with affected service providers.

Where applicable law requires notification, GoodThought will notify affected parties and regulators within the required timeframe and manner.

7. Vendor Security

GoodThought may assess relevant service providers based on the nature of the services and information processed and may use contractual, technical or organizational measures appropriate to the circumstances.

Relevant providers may include infrastructure, storage, authentication, payment, analytics, communications, AI, security, customer-support and other technology providers.

GoodThought may review provider security practices, contractual commitments, access controls, incident obligations and other relevant safeguards where appropriate.

8. Data Protection and Access

GoodThought seeks to apply data minimization, purpose limitation, access controls and retention practices appropriate to the Services.

Personal information is accessed only where reasonably necessary for authorized business, service, security, support or legal purposes. GoodThought seeks to limit administrative access to private user content and maintain appropriate controls over privileged access.

Deletion, retention and privacy rights are addressed in the GoodThought Privacy Policy and applicable policies.

9. User Responsibilities

Users should use strong, unique credentials, protect account access, avoid sharing authentication information, use supported and reasonably secure devices, and report suspected compromise or unauthorized activity promptly.

Users are responsible for maintaining the security of credentials and devices under their control.

10. Legal Requirements and Standards

Security measures, retention practices and incident obligations will be adapted as required by applicable law and recognized standards appropriate to the Services.

Nothing in this Policy creates a guarantee of a particular security certification, audit result or security standard unless GoodThought expressly states that it has obtained such certification or completed such audit.

11. Contact

Security concerns may be reported to:

GoodThought may request information reasonably necessary to investigate and respond to a reported security concern.