Privacy policy
Gosen is a vocabulary learning app for Android. This policy explains what personal data Gosen collects, why, who it is shared with, how long it is kept, and the rights you have over it. Gosen has no advertising, no analytics or tracking SDKs, and does not sell your data.
Who is responsible for your data
The data controller is Caio Azevedo, an individual developer based in France. For any privacy question or request, write to privacy@gosen.app.
What we collect
Account information
- Your email address and username.
- Your password, stored only as a salted hash. We cannot read it.
- Your native language, and whether your email address has been verified.
- Short-lived six-digit verification codes we email to you when you sign up or log in. Each code expires after 15 minutes.
Your learning content
- Your word lists: their names and languages, the words you save, their readings and definitions.
- Your study progress: review ratings, review history, and the scheduling data that decides when each word comes back.
- Content generated for you: example sentences, sentence and grammar explanations, and your personal dictionary lookups.
- Writing exercises: the prompts, the text you write, and the feedback and score you receive.
Credits and purchases
- Your credit balance and a history of credits granted, spent and refunded.
- For purchases made through Google Play: the product, the Google Play order ID and purchase token, the purchase status, and the verification response Google returns to us. Payments are handled entirely by Google. We never see your card or other payment details.
Usage and technical data
- A record of each AI request made for your account: which feature it was for, which model answered, token counts, cost and response time. This lets us price credits and keep costs under control.
- Server logs kept by our hosting provider, which include your IP address, the time of each request and the address requested. We use them to keep the service running and secure.
On your device
The app stores your login session and app preferences on your phone. If Android backup is enabled on your device, Google may include this app data in your device backup under Google's own terms.
Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Creating and running your account, verifying your email, saving your words and progress, generating sentences, explanations and writing feedback | Performance of our contract with you (art. 6(1)(b)) |
| Selling and verifying credit purchases, keeping your credit balance accurate | Performance of contract (art. 6(1)(b)) |
| Preventing fraud and duplicate purchase claims, handling refunds and chargebacks | Our legitimate interest in protecting the service and its revenue (art. 6(1)(f)) |
| Security, abuse prevention, debugging and measuring AI costs | Our legitimate interest in running a secure, sustainable service (art. 6(1)(f)) |
| Keeping records we are required to keep, and answering lawful requests from authorities | Legal obligation (art. 6(1)(c)) |
We do not use your data for advertising or profiling, and we make no decisions about you that have legal or similarly significant effects based solely on automated processing.
AI processing
Gosen uses large language models to look up words, write example sentences, explain grammar and give feedback on your writing. To do this, we send the relevant text to OpenRouter, a service that forwards it to an AI model provider (currently OpenAI; the provider may change as models improve).
- What is sent: the words, definitions, sentences and writing involved in the request, plus your target and native languages.
- What is not sent: your email address, username, password or payment information.
- These providers process the text to produce a response. Under their terms they may keep it for a limited time, for example for abuse monitoring, and we do not allow it to be used to train their models where they give us that choice.
Please avoid putting personal details about yourself or others into the text you write in exercises.
Who we share data with
We share personal data only with service providers that process it on our behalf to run Gosen:
- Railway, which hosts our servers and database.
- OpenRouter and the AI model provider it routes to, as described above.
- Google, for Google Play billing and purchase verification.
- Resend, which delivers verification emails from no-reply@gosen.app and receives your email address and the code to do so.
We may also disclose data where the law requires it. We never sell or rent your personal data.
International transfers
Some of these providers are based in, or process data in, the United States or other countries outside the European Economic Area. Where that happens, transfers rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified, or on the Commission's Standard Contractual Clauses.
How long we keep it
- Account and learning data: for as long as your account exists. When you delete your account it is erased immediately from our live database.
- Credit history: deleted together with your account.
- Google Play purchase records: kept after account deletion, with the link to your account removed, so the same purchase can never be claimed twice and Google refunds can still be matched. We keep them for up to 5 years after the purchase.
- AI usage records: kept after account deletion with the link to your account removed, as cost statistics.
- Server logs: kept for a limited period set by our hosting provider, then deleted.
- Backups: database backups, if any, are overwritten on a rolling basis, so deleted data disappears from them within a short period.
Deleting your account
You can delete your account at any time in the app under Settings > Delete account. If you no longer have the app, see gosen.app/delete-account. Deleting your account does not refund unused credits.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing based on our legitimate interests;
- receive the data you gave us in a portable, machine-readable format.
To exercise any of these rights, email privacy@gosen.app from the address linked to your account. We answer within one month. You also have the right to lodge a complaint with a data protection authority; in France this is the CNIL.
Security
All traffic between the app and our servers is encrypted with HTTPS. Passwords are hashed, verification codes expire quickly and lock after repeated wrong attempts, and access to production systems is limited to the developer.
Children
Gosen is not directed at children. You must be at least 15 years old to create an account, or have the consent of a parent or guardian if your country sets a higher age for consenting to online services. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If we change this policy, we will update the date at the top of this page. If the change is significant, we will also tell you in the app before it takes effect.