Skip to main content
← The journalLibraryLog inSign up free
GoNoGo JournalNº 06
Security27 March 20264 minGoNoGo Team

How we protect your startup idea

How GoNoGo protects your startup idea. Data encryption, session handling, privacy controls, and our no-storage policy explained.

How we protect your startup idea — illustration for GoNoGo blog article

Your startup idea is valuable. Here's exactly how we protect it.

The Short Version

0Ideas stored permanently
E2EEncrypted sessions
GDPRCompliant
SOC2In progress

Our Data Principles

  1. No Permanent Idea StorageVoice sessions are processed in real-time and not recorded. Your idea description exists only during the active session.
  2. Encrypted in TransitAll data between your browser and our servers is encrypted with TLS 1.3. WebSocket connections for voice use WSS (encrypted).
  3. Reports Are YoursGenerated reports are stored in your account and can be deleted at any time. We don't use your data to train models.
  4. No Third-Party SharingYour idea, reports, and session data are never shared with third parties, advertisers, or other users.

Infrastructure

ComponentProviderRegionEncryption
Voice processingGoogle Gemini LiveUS/EUTLS 1.3 + WSS
Report storageFirebase / Google CloudUSAES-256 at rest
AuthenticationFirebase AuthGlobalOAuth 2.0 / Email
Payment processingPolar (MoR)EUPCI DSS compliant
Web hostingVercelGlobal CDNTLS 1.3

What We Store vs. What We Don't

StoredNot Stored
Voice audioRaw audio is never saved
Session transcriptsOptional (your choice)Deleted if you choose
Generated reportsIn your account
Your idea descriptionNot stored after session
Email & authRequired for account
Payment infoHandled by Polar (MoR)

AI Model Usage

We use multiple AI models for cross-verification. Important details:

  • Your data is not used to train any AI models — we use API-only access
  • Sessions use Google Gemini, Anthropic Claude, and other models via API
  • Each model provider's enterprise API terms prohibit training on customer data
Note
Cross-model verification means your data is sent to multiple AI providers for fact-checking. All providers are bound by enterprise API agreements that prohibit data retention and model training on customer inputs.

Your Rights

  • Access: Download all your data at any time from Settings
  • Delete: Remove your account and all associated data
  • Portability: Export reports as PDF
  • Consent: You choose what to store, what to delete

Compliance Roadmap

We're actively working toward formal certifications:

  • GDPR — Compliant (EU data handling, right to deletion, DPA available)
  • SOC 2 Type II — In progress, expected Q3 2026
  • HIPAA — Not applicable (we don't handle health data)

Questions?

Contact us at privacy@gonogo.team for any security or data handling questions. We respond within 24 hours.

After reading

Validate your idea in a 15-minute talk

Pitch it to Alex out loud. He pushes back the way this journal does, then the research runs and you get a written GO, WAIT or NO-GO with the reasoning. Free to start.

Try Alex ↗3 questions · no signup
Next in the journal