👺Goblin

Privacy Policy

1. Data Collection

We collect only the data necessary to operate the service: email address, payment information, user projects and API keys.

2. Sub-processors

We use the following trusted third-party services to operate Goblin:

  • Supabase — database & authentication
  • Stripe — payment processing
  • Backblaze B2 (EU, eu-central-003) — encrypted project & file storage
  • Vercel — web application hosting
  • Railway — API hosting
  • Resend — transactional email
  • DeepInfra (United States) — inference for the Goblin-bundled models. SOC 2 / ISO 27001 certified; zero data retention for the open-source models we use; international transfers covered by EU Standard Contractual Clauses (SCCs).
  • Anthropic, OpenAI and other model providers — only when you connect your own API key (BYOK). Your prompts are sent to the provider you choose, under your own account and their terms.

3. AI Processing & International Transfers

When you use the Goblin-bundled models (no key required), your prompt and the relevant code context are sent to our inference sub-processor for processing. That provider operates in the United States. We rely on EU Standard Contractual Clauses (SCCs) as the transfer mechanism, and use only open-source models configured for zero data retention — your inputs are not retained by the provider and are never used to train models.

When you bring your own API key (BYOK), your prompts go directly to the provider you selected, under your own account and their terms.

Your stored projects and files remain encrypted at rest in the EU (Backblaze B2, eu-central-003). Only the inference step may be processed outside the EU, under the safeguards described above.

4. Data Security

All sensitive data is encrypted at rest. API keys are encrypted with AES-256-GCM before storage. We never train our models on user code.

5. User Rights

You may request export or deletion of your personal data at any time by contacting support.

6. Cookies

We only use strictly necessary cookies for authentication. No tracking, no analytics, no third party cookies.

Last updated: June 2026