Privacy Notice
Last updated: 13 July 2026
1. Operator and contact
Goethi is operated by Ahmed Ayman Ahmed Fouad Hamam. For privacy questions or rights requests, email support@goethi.online.
2. Data the implementation handles
- Writing checker: the CEFR level, generated or supplied task context, and the full German text you submit.
- Accounts: email address, authentication tokens and account identifiers handled through Supabase. Password verification is handled by Supabase; the application does not receive a readable password.
- Legacy purchase records: checkout email, selected level/pack, transaction identifier, environment and account identifier where present. Paddle handles payment and billing details.
- Local browser data: Supabase session information and, for the legacy purchase flow,
goethi_purchase_email. A reusable sidebar component can set a necessary display-preference cookie if that component is used. - Contact messages: content and addressing data in emails you send to the support address.
3. AI processing of submitted writing
The checker sends the task context and your full submitted text from Goethi's server to Lovable's AI gateway, which the current code configures to use Google Gemini (google/gemini-3-flash-preview). The purpose is to generate corrections and practice feedback. The application code does not insert submitted writing into the Goethi Supabase database and does not deliberately print it to application logs.
Manual confirmation required: the repository does not prove the gateway or model provider's logging, retention, region, abuse-monitoring or training settings. Do not submit confidential, identifying or sensitive text until the operator has confirmed and documented those provider settings.
4. Purposes and legal bases
Where the GDPR applies, account and requested checker processing is intended to be necessary to provide the service you request (Article 6(1)(b)); security and abuse prevention is intended to rely on legitimate interests (Article 6(1)(f)); and legally required record keeping relies on Article 6(1)(c). Optional analytics would require consent, but none is implemented in the audited repository. The operator should have these bases reviewed for its actual establishment and service terms.
5. Providers and transfers
- Supabase: database and authentication.
- Lovable AI gateway and Google Gemini: AI request routing and response generation.
- Cloudflare: the checked deployment configuration targets Cloudflare hosting.
- Paddle: legacy Merchant-of-Record checkout, webhooks and purchase records.
- YouTube: course videos use the privacy-enhanced
youtube-nocookie.comembed and are loaded after the visitor selects a video.
These providers may process data outside your country. The repository does not establish each provider account's selected region or transfer mechanism; the operator must confirm those account settings and applicable safeguards.
6. Analytics, cookies and consent
The audited code contains no Google Analytics, Google Tag Manager or other optional analytics integration. Therefore no analytics script or analytics storage is loaded before or after consent, and there is currently no optional analytics preference to accept or withdraw. Necessary authentication/local-storage mechanisms operate when account or purchase features are used. If optional analytics is added later, it must remain disabled until valid consent and this notice must be updated.
7. Retention
The application does not store submitted writing in its own database in the checker flow. Account and purchase records remain in Supabase until deletion under the operator's account processes or applicable record-keeping duties. The repository defines no verified deletion schedule for accounts, purchase records, support email, hosting logs, the Lovable AI gateway or Google Gemini. Those periods require manual confirmation; no shorter period is promised here.
8. Training
Goethi's application code contains no feature that adds submitted writing to a training dataset. Whether the AI gateway or model provider may use request data for service improvement or model training depends on provider terms and account settings that are not present in this repository and must be confirmed by the operator.
9. Your rights and withdrawal
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may complain to a competent supervisory authority. Email support@goethi.online. Because optional analytics consent is not currently requested, there is no analytics consent to withdraw. You can sign out to end the current account session and can clear the site's local storage in your browser.
10. Security and changes
Traffic is expected to use HTTPS and Supabase policies restrict database access. No online system is risk-free. This notice will be updated if data flows or verified provider settings change.
