Privacy Notice
Last updated: 23 September 2026
1. Operator and contact
Goethi is operated by Ahmed Ayman Ahmed Fouad Hamam. For privacy questions or rights requests, email support@goethi.online.
2. Data the implementation handles
- Writing checker: the CEFR level, generated or supplied task context, and the full German text you submit.
- Writing progress: for exam-part practice, Goethi stores your level, task part, rubric version, point results, selected bands, word count, time, and short feedback, including brief evidence about your answer. It does not store your full submitted writing or corrected rewrite in the progress tables.
- Accounts: email address, authentication tokens and account identifiers handled through Supabase. Password verification is handled by Supabase; the application does not receive a readable password.
- Legacy purchase records: checkout email, selected level/pack, transaction identifier, environment and account identifier where present. Paddle handles payment and billing details.
- Local browser data: Supabase session information and, for the legacy purchase flow,
goethi_purchase_email. A reusable sidebar component can set a necessary display-preference cookie if that component is used. - Contact messages: content and addressing data in emails you send to the support address.
3. AI processing of submitted writing
The checker sends the task context and your full submitted text from Goethi's server to Google Gemini (gemini-3-flash-preview) through its API. The purpose is to generate corrections and practice feedback. The application code does not insert submitted writing into the Goethi Supabase database and does not deliberately print it to application logs. Structured exam-part assessment history is stored as described above. The AI quota tables store a hashed usage identifier, daily counters and request reservation records, not submitted writing.
Manual confirmation required: the repository does not prove the model provider's logging, retention, region, abuse-monitoring or training settings. Do not submit confidential, identifying or sensitive text until the operator has confirmed and documented those provider settings.
4. Purposes and legal bases
Where the GDPR applies, account and requested checker processing is intended to be necessary to provide the service you request (Article 6(1)(b)); security and abuse prevention is intended to rely on legitimate interests (Article 6(1)(f)); and legally required record keeping relies on Article 6(1)(c). Optional analytics would require consent, but none is implemented in the audited repository. The operator should have these bases reviewed for its actual establishment and service terms.
5. Providers and transfers
- Supabase: database and authentication.
- Google Gemini: AI request processing and response generation.
- Cloudflare: the checked deployment configuration targets Cloudflare hosting.
- Paddle: legacy Merchant-of-Record checkout, webhooks and purchase records.
- YouTube: course videos use the privacy-enhanced
youtube-nocookie.comembed and are loaded after the visitor selects a video.
These providers may process data outside your country. The repository does not establish each provider account's selected region or transfer mechanism; the operator must confirm those account settings and applicable safeguards.
6. Analytics, cookies and consent
Goethi uses Google Analytics 4, provided by Google, to understand how visitors use the website and to improve it. The GA4 script with measurement ID G-81ZM4PZPBE is activated only after you allow analytics. Your choice is stored locally in your browser and can be changed through Analytics settings in the footer.
7. Retention
The application does not store submitted writing in its own database in the checker flow. Structured writing assessments, account and purchase records remain in Supabase until deletion under the operator's account processes or applicable record-keeping duties. The repository defines no verified deletion schedule for accounts, purchase records, support email, hosting logs or Google Gemini. Those periods require manual confirmation; no shorter period is promised here.
8. Training
Goethi's application code contains no feature that adds submitted writing to a training dataset. Whether the model provider may use request data for service improvement or model training depends on provider terms and account settings that are not present in this repository and must be confirmed by the operator.
9. Your rights and withdrawal
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may complain to a competent supervisory authority. Email support@goethi.online. You can change your analytics choice through Analytics settings in the footer. You can sign out to end the current account session and can clear the site's local storage in your browser.
10. Security and changes
Traffic is expected to use HTTPS and Supabase policies restrict database access. No online system is risk-free. This notice will be updated if data flows or verified provider settings change.
