Effective September 8, 2026

Privacy Policy

S&S Open Dev LLC dba Golden Navigator (“company,” “us,” “we,” or “our”) is committed to the privacy of those who visit and interact with www.golden-navigator.com (Site) and our mobile applications.

1. Information We Collect

We collect personal data about individuals when they specifically and knowingly provide this information for purposes disclosed or otherwise known to them at the time they provide their information or for the wider purposes set out below. This includes voluntary submission of an email address and sending Golden Navigator an email which includes the individual’s personal information. Providing personal information that we request is optional and disclosures are made voluntarily. When you engage with our Services, we may collect the following categories of personal information from and/or about you.

  • Identifiers, including your name, address, phone number, email address, and date of birth.
  • Sensitive Personal Information (SPI): Health markers, insurance information, and financial accounts, etc.
  • Technical Data, including internet protocol (“IP”) address, cookies, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Services.
  • Usage Data on how you navigate our website, including the content and features you use or view on the website, the pages of our website that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
  • Device Access — with your explicit permission, we may access your Camera, Photos, or Contacts to facilitate record uploads or family invitations.

2. How Information is Used

We use your identifiable data for the following business purposes:

  • Primary Service Delivery: Managing your guided preparedness experience, document organization, and AI-assisted task navigation.
  • Company Operations: Quality control, security monitoring, and fraud detection.
  • Product Improvement: Internal analytics to improve organizational tools.
  • Communication: Sending email alerts and service updates.

Note: We DO NOT use your identifiable data to develop marketing materials for our products or for sale to outside entities.

De-Identified Data: We may aggregate and de-identify personal information so that it can no longer reasonably be used to identify you. De-identified data may be used to develop, train, and improve our AI systems and Services, and is not subject to the restrictions in this Policy that apply to personal information. We do not attempt to re-identify de-identified data except as necessary to test the effectiveness of our de-identification methods.

3. How Information is Shared

Golden Navigator DOES NOT sell, lease, or rent your personal information. We may disclose your personal information to the following categories of entities for the business purposes described above:

  • Infrastructure Vendors: Necessary sharing with partners required to provide the Primary Service, including but not limited to AWS (storage), Inngest (workflow orchestration), Plaid (bank and credit card transactions) and PostHog (product analytics service).
  • Authorized Trusted Stewards: We share information with individuals you designate as “Trusted Stewards” or “Power of Attorney” holders with your explicit permission.
  • Required by Law: Where needed to comply with the request of law enforcement or a regulatory agency or other legal process, or to protect our interests or safety of our clients or the safety of other visitors to our website and app.

Golden Navigator will not share identifiable data with third parties for independent research or marketing. We do not sell identifiable data to brokers or advertising firms. We do not allow the sharing of health or legacy data with social media platforms like Facebook.

4. Storage, Security, & Encryption

The security of your data is important to us. We have in place commercially reasonable physical, technical, organizational and administrative safeguards appropriate to the type of personal information we process to protect the security and privacy of your personal information. Your data is automatically encrypted at rest on our servers and in transit between your device, our servers, and our AI processing partners. While we strive to use commercially acceptable means to protect your personal information, no business can fully eliminate the security risks associated with collecting and processing information via the internet.

5. Two-Factor Authentication

Golden Navigator verifies your identity when you sign in using a one-time code sent to the email address on your account, delivered through Amazon Web Services (AWS) Simple Email Service (SES). You may also register a passkey — a sign-in method built into your device, such as a fingerprint, face scan, or device PIN. Golden Navigator does not send SMS (text) messages; phone numbers previously collected for SMS verification are retained only as a consent record and are not used.

  • Verification codes are temporary and expire shortly after being sent, and are used solely for authentication.
  • Passkeys never leave your device — we store only the public key needed to recognize it.
  • For questions about sign-in verification, contact us through our contact form.

6. Retention & Deletion

We will only retain your personal information in identifiable form for as long as needed for the purposes for which it was collected and processed. In determining retention periods, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements. When we no longer need personal information, we either anonymize, securely delete, or destroy it.

When an account is deactivated, data is retained until you explicitly request deletion. You may request full deletion of your data at any time through your account settings. Your data will be recoverable for 30 days after request for deletion, after which it will be deleted, except to the extent we are required to retain certain information to comply with applicable law or legal process.

7. Links To Other Sites

Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of the websites you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.

8. Breach & Policy Updates

In the event of an unauthorized disclosure, we will notify you via your primary email with a description of the protection steps taken. We will notify you of material changes to this policy at least 30 days in advance via email.

9. Contact Us

If you have questions regarding this policy, please contact us:

Contact us