Privacy Policy
1. Data Collection
We collect only the data necessary to operate the service: email address, payment information, user projects and API keys.
1a. Usage events / Nutzungsereignisse
We record usage events — which feature was used and when (for example: a project created, a message sent, an app published, an upgrade clicked) — to understand where the product works and where people get stuck. These events contain metadata only: never your message content, never your file contents, and never the code that is generated. They are personal data, retained only as long as your account exists and erased when you delete your account.
Wir erfassen Nutzungsereignisse — welche Funktion wann verwendet wurde (z. B. ein Projekt erstellt, eine Nachricht gesendet, eine App veröffentlicht, ein Upgrade angeklickt) — um zu verstehen, wo das Produkt funktioniert und wo Menschen hängen bleiben. Diese Ereignisse enthalten nur Metadaten: nie Inhalte deiner Nachrichten, nie Inhalte deiner Dateien und nie den generierten Code. Sie sind personenbezogene Daten, werden nur so lange gespeichert, wie dein Konto besteht, und mit der Löschung deines Kontos entfernt.
1b. Support & feedback / Support & Feedback
When you chat with the Goblin Hilfe support agent or send feedback, we process what you write to help you and to improve the product. If your request is handed to a human, a bounded transcript of that conversation plus context (your plan, whether Vercel is connected, the last error) is emailed to us and stored as a support ticket so we can reply. Feedback is stored with metadata only (current page, project ID, last error) — never your chat content or files. All of this is deleted when you delete your account.
Wenn du mit dem Goblin-Hilfe-Agenten chattest oder Feedback sendest, verarbeiten wir, was du schreibst, um dir zu helfen und das Produkt zu verbessern. Wird dein Anliegen an einen Menschen übergeben, werden ein begrenzter Gesprächsverlauf sowie Kontext (dein Plan, ob Vercel verbunden ist, die letzte Fehlermeldung) an uns per E-Mail geschickt und als Support-Ticket gespeichert, damit wir antworten können. Feedback wird nur mit Metadaten gespeichert (aktuelle Seite, Projekt-ID, letzte Fehlermeldung) — nie deine Chat-Inhalte oder Dateien. All das wird mit der Löschung deines Kontos entfernt.
1a. Formulare in veröffentlichten Apps / Forms in published apps
Wenn eine über das Goblin-Hosting veröffentlichte App ein Formular enthält, speichert Goblin, was Besucherinnen und Besucher dort absenden. Für diese Daten ist die Person verantwortlich, der die App gehört (Verantwortliche im Sinne der DSGVO); Goblin verarbeitet sie in deren Auftrag.
- Was gespeichert wird: die Feldinhalte des Formulars — also genau das, was die absendende Person selbst eingetragen hat —, der Zeitpunkt, die Kennung des Formulars, die Größe der Einsendung und ob sie bereits gelesen wurde.
- Was ausdrücklich NICHT gespeichert wird: keine IP-Adresse, kein Browser-Kennzeichen (User-Agent), keine Verweisseite, keine Cookies, keine Kennung, die eine Person über mehrere Besuche hinweg wiedererkennbar machen würde.
- Wo: in einer eigenen Datenbank pro App (Cloudflare D1, EU-Jurisdiktion). Die Daten einer App liegen physisch getrennt von denen jeder anderen App.
- Spam-Schutz: vor dem Speichern läuft eine Prüfung über Cloudflare Turnstile. Cloudflare sieht dabei die Verbindung der absendenden Person; Goblin übermittelt dafür keine zusätzlichen Daten.
- Benachrichtigung: der App-Eigentümerin oder dem App-Eigentümer wird der Inhalt der Einsendung per E-Mail zugestellt (Versand über Resend). Das lässt sich pro App abschalten.
- Aufbewahrung und Löschung: es gibt keine automatische Löschfrist — die Daten bleiben, bis sie gelöscht werden. Der oder die App-Eigentümer:in kann einzelne Einsendungen oder alle auf einmal löschen und sie vorher als CSV exportieren. Mit der App gehen sie mit: Wird die App oder das zugehörige Projekt gelöscht, wird die gesamte Datenbank dieser App gelöscht. Wer eine Einsendung gemacht hat und sie gelöscht haben möchte, wendet sich an die Betreiberin oder den Betreiber der App; erreicht man niemanden, hilft support@justgoblin.com.
- Was Goblin NICHT tut: die Inhalte von Einsendungen werden nicht inhaltlich geprüft, nicht durchsucht und nicht an ein KI-Modell übergeben. Die automatische Missbrauchsprüfung weiter unten betrifft ausschließlich die App selbst zum Zeitpunkt der Veröffentlichung, nicht das, was später jemand einsendet.
If an app published via Goblin hosting contains a form, Goblin stores what visitors submit through it. The person who owns the app is the controller of that data; Goblin processes it on their behalf. Stored:the form’s field contents — exactly what the sender typed — plus the time, the form’s identifier, the size of the submission and whether it has been read. Deliberately not stored: no IP address, no user agent, no referrer, no cookies, no identifier that would make a person recognisable across visits. Where:in a separate database per app (Cloudflare D1, EU jurisdiction), physically separate from every other app’s. Spam protection:Cloudflare Turnstile runs before storage; Cloudflare sees the sender’s connection, and Goblin transmits no additional data for it. Notification: the app owner receives the submission by e-mail (via Resend); this can be switched off per app. Retention and deletion:there is no automatic retention period — data stays until it is deleted. The owner can delete individual submissions or all of them, and export them as CSV first. Deleting the app or its project deletes that app’s entire database. If you sent a submission and want it removed, contact whoever runs the app; if you cannot reach them, write to support@justgoblin.com. What Goblin does not do: submitted content is not checked, searched or passed to any AI model. The automated abuse check described below applies to the app itself at publish time, never to what somebody submits afterwards.
2. Sub-processors
We use the following trusted third-party services to operate Goblin:
- Supabase — database & authentication
- Stripe — payment processing
- Backblaze B2 (EU, eu-central-003) — encrypted project & file storage
- Vercel — web application hosting
- Railway — API hosting
- Cloudflare — Hosting und Auslieferung der von Nutzern veröffentlichten Apps (
*.justgoblin.app); genutzte Dienste: Workers, R2, KV, D1. Der R2-Speicher und die D1-Datenbanken sind in der EU-Jurisdiktion konfiguriert; Workers und KV laufen auf Cloudflares global verteiltem Edge-Netz, sind also nicht auf die EU begrenzt. Betrifft nur Apps, die über das Goblin-Hosting veröffentlicht werden — derzeit eine eingeschränkte Beta für ausgewählte Konten.
Cloudflare — hosting and delivery of user-published apps (*.justgoblin.app); services used: Workers, R2, KV, D1. R2 storage and D1 databases are configured in the EU jurisdiction; Workers and KV run on Cloudflare’s globally distributed edge network and are therefore not EU-confined. Applies only to apps published via Goblin hosting — currently a limited beta for selected accounts. - Resend — transactional email
- DeepInfra (United States) — inference for the Goblin-bundled models. SOC 2 / ISO 27001 certified; zero data retention for the open-source models we use; international transfers covered by EU Standard Contractual Clauses (SCCs).
Seit AKT 2 · Phase 3 zusätzlich: Beim Veröffentlichen auf dem Goblin-Hosting (*.justgoblin.app) wird der Text und das Markup der zu veröffentlichenden App einmalig an dieses Modell übergeben — als automatische Missbrauchsprüfung vor dem Livegang (Nutzungsrichtlinie, „Was Goblin prüft"). Das geschieht ohne Eingabe des Nutzers und betrifft nur den gehosteten Weg, nicht den Vercel-Weg und nicht die übrigen Projektdateien.
Since ACT 2 · Phase 3, additionally: when publishing on Goblin hosting (*.justgoblin.app), the text and markup of the app being published are passed once to this model as an automated abuse check before it goes live (AUP, “What Goblin checks”). This happens without any user input and applies only to the hosted path — not the Vercel path, and not your other project files. - Anthropic, OpenAI and other model providers — only when you connect your own API key (BYOK). Your prompts are sent to the provider you choose, under your own account and their terms.
3. AI Processing & International Transfers
When you use the Goblin-bundled models (no key required), your prompt and the relevant code context are sent to our inference sub-processor for processing. That provider operates in the United States. We rely on EU Standard Contractual Clauses (SCCs) as the transfer mechanism, and use only open-source models configured for zero data retention — your inputs are not retained by the provider and are never used to train models.
When you bring your own API key (BYOK), your prompts go directly to the provider you selected, under your own account and their terms.
Your stored projects and files remain encrypted at rest in the EU (Backblaze B2, eu-central-003). Only the inference step may be processed outside the EU, under the safeguards described above.
4. Data Security
All sensitive data is encrypted at rest. API keys are encrypted with AES-256-GCM before storage. We never train our models on user code.
5. User Rights
You may request export or deletion of your personal data at any time by contacting support.
6. Cookies
We only use strictly necessary cookies for authentication. No tracking, no analytics, no third party cookies.
Last updated: June 2026