Clever Little Goose

What changed in Version 2

Published 19 August 2026.

Version 1 went up on 4th August.

This version goes up before the event it describes. As the company is about to start publishing open-source software, we're adding a new third-party. §2.3 commits us to changing this policy before a new third party appears, not after it.

One of the changes below makes a promise narrower than it was. That's the kind of thing you should want explained rather than left to find, so it has a section of its own.

This isn't a summary of the new policy. The policy says what is true now and in the present tense. This page describes what moved and why between Version 1 and Version 2.


1. We publish open-source software now

Before: the company did admin and email. Two processors, both in the EEA, and nothing else.

Now: some of our software is published openly at github.com/CleverLittleGoose. The first repository is GooseQuill, a tool for converting PDFs to Markdown.

What that means for you is a new §2.4, covering something the previous version had no subsection for: what happens when somebody opens an issue or sends a pull request. The short answer is that it's a public act on a public page, your GitHub account is your own, and we keep no separate copy of any of it.

GitHub is named in §4 but is deliberately not on the processor list. It is a different kind of relationship, and the section separates it for the same reason it separates the domain registrar. We send GitHub nothing about you; it never sees your correspondence; and if you open an issue you are acting under your own agreement with GitHub, not ours. Those pages are hosted in the United States, which is a property of publishing in public rather than a transfer we make on your behalf.

If you'd rather not be registered on an American platform, none of it is compulsory.
Everything we publish can be read without an account, and email reaches the same
place.

§5 did not change, and that is worth stating explicitly: your correspondence still goes to two processors, both in the EEA, and GitHub is not one of them.

2. "No analytics" now has a qualification

This is the narrowing, and we'd rather point at it than let you notice it.

Before: §3 said "No analytics. Not on the website, not anywhere."

Now: it says the same thing about the website and about anything we ship — and then names the exception. GitHub reports aggregate view and clone counts for public repositories to whoever owns them. We didn't add it, there is no setting to turn it off, and it counts requests rather than people.

Why it's worth a paragraph. "Not anywhere" was an absolute, and absolutes are the sentences that break first. The honest options were to name the exception or to not publish software. Naming it was easier and more useful than the alternative, which would have been to keep the sentence and hope nobody checked.

What it isn't: we have no analytics on the website, still don't know who visits it, and have nothing that profiles anybody. The exception is a counter on a code repository, not a tracker on a page.

3. We're on the ICO's register

§1 now carries our registration reference, ZC213564, so you can look the company up at ico.org.uk rather than take our word for who is answerable for your data.

It isn't a badge and nobody inspected us to grant it. It's a fee every UK data controller pays, and a public entry naming who is responsible. What it gives you is a regulator who already knows who we are, and a reference to quote if you complain about us.

4. A retention row, and some tidying

§6 gained a row for issues and pull requests on public repositories, because they are durable in a way nothing else in that table is: you can edit or delete your own, but anything already forked or archived by somebody else is beyond our reach.

§10 now explains how the version numbers on these documents work. Major numbers when what we do changes, minor ones for edits that don't change the substance.

§2.1 now says we don't transcribe voicemail, as well as not recording calls. Both settings were already off; only the sentence is new.

The rest is wording. A number of sentences were repunctuated for readability, and the Cred Count policy is now linked by address rather than by name alone. No change in this paragraph alters what we do with anything.