◊ Old Elliott Provisions

Your Data Belongs to You

Effective date: May 2026 · Updated September 2026
App version: Waypoint 2.0

The short version: Waypoint stores all of your personal data — goals, behaviors, check-ins, and reflections — on your device only, using your browser’s local storage. We do not collect it, we do not see it, and we do not sell it. If you enable GitHub Gist sync or the AI chat feature, only then does any data leave your device — directly to GitHub or Anthropic, both governed by their own privacy policies. You are in full control at all times.

Section 01

What Data Waypoint Stores

Waypoint is a personal goal-tracking and behavior-change app. Everything you enter is stored locally on your device inside your browser’s localStorage under the key ourgoals-v2. This data never leaves your device unless you explicitly enable a sync feature (described in Section 3).

The following categories of personal information may be stored:

Data Type Details
Names First names of users (e.g., household partners) entered during setup. Used only for display purposes within the app.
Goals Personal and shared goals you create, including goal text, category, status, and notes.
Behaviors Habits and behaviors linked to goals, including name, frequency targets, and functional assessment notes.
Check-ins & Logs Timestamped records of completed or missed behaviors, entered during daily check-ins.
Reflections Weekly and period-based written reflections on your progress.
Values Personal values you identify and track as part of the ACT-based framework.
Wins & Bucket List Milestone celebrations and aspirational items you choose to record.
PINs Optional 4-digit PINs used to protect private goals. Stored on your device as SHA-256 hashes, not the raw PIN. PINs are device-specific and are never included in sync data. Hashing a 4-digit PIN deters casual snooping, but it is not strong encryption.
API Credentials Optional GitHub Personal Access Token and Anthropic API key, if you choose to enable sync or AI chat. Stored in plain text in your browser’s localStorage on your device, and never included in sync data.
Accountability Partners Names and optional contact hints for people you choose to share progress with. The app never contacts them. Their names and contact hints are part of your settings, so they are included in backup files you save and in the sync locker copy (GitHub Gist) if you use sync.
App Preferences Settings such as Simple Mode, daily reminder time, custom categories, and onboarding status.

Waypoint does not collect usage analytics, crash reports, device identifiers, location data, or any information beyond what you directly enter into the app.

Section 02

How Your Data Is Stored

All Waypoint data is stored in your browser’s localStorage on your device. This means:

Data is stored on your device, in your browser. It is not transmitted to Old Elliott Provisions’ servers — because we don’t have any servers. Waypoint is a static web app that runs entirely in your browser.

What this means for you: If you clear your browser data or switch browsers, your Waypoint data will be deleted from that device. This is why we recommend enabling GitHub Gist sync or regularly saving a backup file using More → Your data → Save my data.

A note on device security: localStorage is not encrypted. Anyone with access to your unlocked device or browser profile could read the data stored there. Use your device’s own screen lock and separate user accounts to protect it.

Optional GitHub Gist Sync: If you choose to enable sync, your app data is stored, unencrypted, in a “secret” GitHub Gist you control, using a GitHub Personal Access Token you provide. The data is sent directly from your browser to GitHub’s API. Old Elliott Provisions never handles or sees this data. Your GitHub token, API keys, and PINs are never included in the synced data.

A “secret” Gist is hidden from search engines and public listings, but it is not truly private: anyone who obtains its ID (shown in the app as your Locker ID) can read the data in it. Only share your Locker ID with your partner. The app shows this same warning wherever the Locker ID appears.

Optional backup file: You may save your data as a backup file and keep it anywhere you choose (your computer, cloud storage, etc.). The file is entirely under your control. The next part explains what it holds.

Backups and importing

What a backup contains. Everything you entered in Waypoint (goals, behaviors, logs, values, reflections, bucket list, contracts, wins and reinforcers) plus settings such as your names, your accountability partners’ names and contact hints, custom categories and custom images. The same settings are in the sync locker copy (GitHub Gist) if you use sync. A backup never contains your GitHub token, your Locker ID, your AI key or your PINs. Waypoint copies only a fixed list of settings into a backup, so any private setting added in the future stays off the file unless we decide, on purpose, that it belongs there.

A backup is readable unless you protect it. A backup saved without a passphrase is plain text: anyone who gets the file can read it, the same as a synced Gist. If you choose “Protect with a passphrase,” the file is encrypted on your device before it is saved (AES-GCM with a 256-bit key made from your passphrase with PBKDF2-SHA256, 600,000 rounds). A forgotten passphrase cannot be recovered by anyone, including us. Without it the file cannot be opened.

Damaged files. Every backup carries a checksum so Waypoint can tell when a file was cut off or damaged, and it refuses such a file without changing anything. A checksum does not prove who made a file. Only a passphrase-protected backup also detects changes made on purpose.

Importing happens entirely on your device. When you restore a backup or bring in data from a file, the file is read and checked inside your browser. Nothing is uploaded to Old Elliott Provisions or to anyone else. Before anything changes, Waypoint shows you what is in the file. What was there before is kept in a one-time undo slot, and each import is listed in an import history on this device so it can be undone later. The import history stays on this device and is not included in backups.

Restoring or importing never takes a sync token, Locker ID, AI key or PIN from a file. This device keeps its own. Private goals stay private and open with the PIN set on this device; an owner with no PIN on this device sets one in Settings.

Bringing in a spreadsheet. You can add logs from a spreadsheet (.csv) file, such as an export from another habit or fitness app. The spreadsheet is read and checked inside your browser by code that ships with Waypoint (including the open-source Papa Parse reader, served from Waypoint’s own site); nothing in it is uploaded. You choose where each habit goes and see what will be added before anything changes. A spreadsheet import only adds: it never changes or deletes what is already in Waypoint. It is listed in the same import history and can be undone on its own. If you use sync, imported logs go to your sync locker at this device’s next sync, like anything else you log. Waypoint never matches spreadsheet rows to a private goal that is locked on this device. Text that looks like a spreadsheet formula is kept as plain text with a ’ in front, so it cannot run if you export it again.

No AI in importing. Restoring, bringing in data and bringing in a spreadsheet do not send anything to an AI service.

Section 03

Third-Party Services

Waypoint may interact with the following third-party services. All of these are optional and only activated by your explicit choice, except for CDNjs, which serves the charting library used for progress graphs. Waypoint’s typefaces (Playfair Display and Crimson Pro) are served from Waypoint’s own site, not from Google, so opening Waypoint makes no request to Google.

GitHub Gist API Optional
Used for cross-device data sync. When enabled, your goal and behavior data is stored in a private Gist on your GitHub account. You supply your own GitHub Personal Access Token. Old Elliott Provisions does not have access to your GitHub account or your Gist data.

GitHub’s privacy policy: docs.github.com/privacy
Anthropic Claude API Optional
Powers the AI chat assistant in the Help tab. When you send a message, that message — along with limited context about your goals and behaviors — is sent directly from your browser to Anthropic’s API using your own API key. You control what you share with the AI. Old Elliott Provisions does not see your chat messages or your API key.

Anthropic’s privacy policy: anthropic.com/privacy
Cloudflare CDN (cdnjs.cloudflare.com)
The Chart.js library used for progress graphs is loaded from cdnjs.cloudflare.com. No personal Waypoint data is shared with Cloudflare. Cloudflare may log standard network request metadata (IP address, browser type) as part of CDN operation.

Cloudflare’s privacy policy: cloudflare.com/privacypolicy

We have no financial relationship with any of these services related to your data. We do not receive any payment, commission, or consideration in exchange for routing your data to them.

Section 04

Data Sharing & Sale

Old Elliott Provisions does not sell, rent, license, or share your personal data with any third parties for commercial purposes — ever.

Because Waypoint stores data locally on your device and we operate no servers that receive your data, we have no personal data in our possession to sell or share. The only data that leaves your device is what you explicitly transmit by enabling optional features (GitHub Gist sync or the Anthropic AI chat), and those transmissions go directly to those third-party services, not to us.

We are a small family business making tools for ourselves and people like us. Your relationship data, behavior logs, and personal reflections are sensitive. We built this app to protect that sensitivity, not exploit it.
Section 05

Deleting Your Data

You have complete control over your data and can delete it at any time.

To delete all data within the app: Open Waypoint → tap More (☰) → Settings → scroll to Data Management → tap Factory Reset. This permanently removes all goals, behaviors, values, observations, reflections, and settings from your device’s localStorage.

To delete partially: Settings also offers Clear All Observations (removes logged check-ins while keeping goal structure) and Clear All Goals & Bx (removes goals and behaviors while keeping values).

To delete browser data directly: Clear your browser’s site data for the domain where Waypoint is hosted. This removes all localStorage entries including Waypoint’s data.

GitHub Gist data: If you enabled Gist sync, you can delete the Gist directly from your GitHub account at any time. Disconnecting Gist sync in Settings removes your token from the app but does not automatically delete the Gist on GitHub.

Because we never receive your data on our servers, there is no data to “request deletion” from Old Elliott Provisions — the data exists only where you have placed it.

Section 06

Children’s Privacy

Waypoint is designed for use by adults and is not intended for children under the age of 18. The app tracks sensitive personal behavioral data, relationship dynamics, and values-based goal work that requires adult judgment and consent.

We do not knowingly collect or solicit personal information from anyone under 18. If you believe a minor has used this app and stored personal information, please contact us at the address below so we can provide guidance on removing that data from the device.

Section 07

Contact Information

Waypoint is a product of Old Elliott Provisions, a small family business based in Fox, Alaska.

For questions about this privacy policy, data practices, or the app generally, reach us at:

Email: oldelliottprovisions@gmail.com
Website: oldelliottprovisions.com
Location: Fox, Alaska, USA

We are a small team and respond to all messages personally. We aim to reply within 5 business days.

Section 08

Changes to This Policy

This privacy policy was last updated in September 2026. If we make material changes to how Waypoint handles data, we will update this document and increment the version number displayed in the app’s Settings → Recent Updates section.

Because Waypoint is a local-first app with no user accounts or email list, we cannot notify you of changes directly. We recommend checking this page periodically, especially if you use the optional sync or AI features.

Continued use of Waypoint after changes to this policy constitutes acceptance of the updated terms.