Skip to content

Faust Academy

Privacy notice

How Faust uses personal data, who receives it, how long it is kept and what rights you have.

Controller and contact

Controller: not published until verified. Controller contact: not published until verified.

DPO decision: not published until verified. Complaint contact: not published until verified.

Article 13 purposes, bases and recipients

Each implemented data flow is represented by a structured purpose, data-category, legal-basis, recipient, transfer, retention and rights fact with an evidence reference.

Cookies and device storage

Faust uses the first-party cookies and browser storage listed below. Authentication, security, guest allowance, onboarding and exam-date storage can operate without analytics consent. Faust currently presents no analytics choice during normal browsing, so a visitor without an existing consent choice loads no third-party analytics or advertising provider and creates no browser-side measurement storage. Faust’s own aggregate funnel uses no cookie, local storage, session storage or unique analytics identifier.

First-party aggregate conversion measurement

Faust counts a closed list of landing, practice, signup, offer, checkout and paid-activation steps in its own Supabase database so it can find abandonment points and improve acquisition relevance. The browser templates the route before transmission, and the server reduces every accepted occurrence at write time to a UTC day, a closed event and route, external or unknown traffic class, coarse acquisition channel, bounded product dimensions and an integer count.

A landing URL and referrer may be inspected transiently to choose paid search, organic search, campaign or unattributed; those raw values are then discarded. The aggregate stores no IP address, user agent, full URL, query or referrer, click or campaign identifier, analytics visitor identifier, account, guest or session identifier, email, answer, prompt, content or free text. Internal and test-channel traffic is excluded. The coarse channel and one-time milestone receipts can remain with an existing profile, guest identity, session or subscription so signup and paid activation survive authentication and Stripe redirects without a browser identifier.

This limited first-party processing does not load an outside measurement provider and does not depend on an optional analytics choice. Its structured Article 13 record states the legitimate-interest basis, retention criteria, recipients and Article 21 objection right. Optional PostHog, Google, Vercel and Meta measurement remains off unless a valid consent choice already exists.

Optional analytics and advertising

Faust currently presents no analytics choice during normal browsing. Optional PostHog EU Cloud, Google Analytics 4, Google Ads, Vercel Web Analytics and Meta Pixel remain off for visitors without an existing valid consent choice. If such a choice exists, the traffic firewall still permits these providers only for traffic classified as external; internal and unknown traffic sends nothing to them.

PostHog receives only the typed funnel properties listed in the implemented flow, sanitized page and referrer paths, an opaque account UUID after sign-in, and masked interaction geometry. Google, Vercel and optional Meta receive the limited categories stated in their implemented flows. Query values, learner answers, chat text, form values, network bodies, headers, console logs and canvas content are excluded from product replay and typed funnel events.

The storage inventory gives each browser lifetime. Vercel uses no analytics cookie and resets its request-derived visitor hash after 24 hours. Provider-side retention, transfers, recipients and rights are published per structured Article 13 flow.

Rights, retention, transfers and automated decisions

Automated decision-making fact: not published until verified. Retention, transfer and rights facts are published per data flow from the structured Article 13 record.

Requests use the verified privacy or complaints contact. Checkout legal consent, contract snapshots and action confirmations are immutable records; browser URL or query-string state does not change entitlement or legal state.

Updates and official reference

This notice is versioned with the checkout consent record. A changed policy or data-flow decision cannot be replayed against an existing checkout attempt.

Implemented data flows

Supabase Auth and Postgres

Purpose: account, authentication, subscription and learning persistence

Data: account identifiers, email, sessions, learning activity and billing state

Role: configured infrastructure provider

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

OAuth providers through Supabase Auth

Purpose: optional OAuth sign-in (Google on Faust; Apple when enabled; GitHub retained for other products)

Data: OAuth account identifiers and the profile data returned by the selected provider

Role: identity provider selected by the account holder; Supabase handles the callback

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Stripe

Purpose: Checkout, recurring billing, receipts and Customer Portal

Data: purchaser identity, address, payment and subscription identifiers

Role: payment and billing provider

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Resend

Purpose: authentication, billing and durable contract/action confirmations

Data: email address, message content and delivery metadata

Role: configured email provider

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

AI model providers selected by feature

Purpose: chat, marking, image generation and generated practice

Data: user prompts, uploaded practice content, tool inputs and generated outputs

Role: OpenAI, Anthropic, Google, Groq or AWS Bedrock/Anthropic is called only for the selected model and configured request

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

ElevenLabs

Purpose: speech-to-text for the speaking room and text-to-speech for listening and proctor audio

Data: the audio a candidate records in a speaking room, the exam or proctor text to be spoken, and the requested language and voice settings

Role: sole speech provider; recorded speaking audio is sent to it for transcription and the returned transcript and generated audio are stored with the session

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Language reference services used by the chat toolkit

Purpose: dictionary, etymology, pronunciation, frequency, thesaurus and grammar-check lookups requested during chat

Data: only the word or text passage the lookup is performed on, plus the requested language; no account identifier, session identifier or authentication header is sent

Role: LanguageTool, Wiktionary, Wikimedia Commons, DWDS, OpenThesaurus and the Free Dictionary API are public endpoints called per lookup

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Faust first-party aggregate funnel measurement

Purpose: measuring which acquisition channels and product steps lead to practice, signup and paid activation so Faust can improve conversion and advertising relevance

Data: a closed coarse acquisition channel may be attached to an existing profile, guest identity or learning session; event occurrences are reduced at write time to a UTC day, templated route, external or unknown traffic class, closed product, level, plan, interval, surface, outcome and experiment values, and an aggregate count. Landing URLs and referrers are inspected only transiently to select the coarse channel. No IP address, user agent, full URL, query value, referrer, click or campaign identifier, analytics visitor identifier, account, guest or session identifier, email, answer, prompt, content or free text is stored in the aggregate

Role: processed by Faust in its own Supabase database with no analytics or advertising recipient; internal and test-channel traffic is excluded and no browser measurement storage is created

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

PostHog EU Cloud

Purpose: consented product-funnel analytics and a 10% sample of privacy-masked session replays for finding usability and conversion problems

Data: external visitors only: pseudonymous browser and session identifiers, page paths without query values, referrer path, device/browser facts, named funnel events, an opaque account UUID after sign-in, and replay interaction geometry; all page text and inputs are masked and no network bodies, headers, console logs, canvas content, learner answers or chat text are sent

Role: EU analytics processor at eu.i.posthog.com; Faust currently presents no analytics choice during normal browsing, so the SDK loads only when an existing valid consent choice is present and never for internal or unknown traffic

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Google Analytics 4 and Google Ads; Meta Pixel only when configured

Purpose: consented acquisition attribution, aggregate audience measurement and verified signup or purchase conversion measurement

Data: external visitors only: first-party analytics or advertising identifiers, advertising click identifiers, page and referrer paths without query values, browser/device and approximate location data, and named signup or purchase conversion events; no learner answers, chat text or form values are sent

Role: Google and, only when a Meta pixel id is configured, Meta act as measurement or advertising recipients; Faust currently presents no analytics choice during normal browsing, so neither script loads without an existing valid consent choice or for internal or unknown traffic

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Vercel Web Analytics

Purpose: consented aggregate page, referrer, device and custom-event measurement

Data: external visitors only: page path, filtered referrer, coarse location and browser/device facts, plus privacy-reviewed custom event names and properties; Vercel uses no analytics cookie and its request-derived visitor hash resets after 24 hours

Role: privacy-focused aggregate analytics processor; no cross-site identifier is created and internal or unknown traffic is excluded

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Guest allowance limits (no third-party recipient)

Purpose: enforcing the free reading paper and chat-turn allowance for signed-out visitors

Data: a first-party guest identifier and a keyed HMAC-SHA-256 hash of the client IP address; the IP address itself is never written to storage

Role: processed by Faust in its own Supabase database and disclosed to no one; the hash is keyed so it cannot be reversed to an address without the server secret

Legal basis: Not available

Recipients: Not available

Transfers: Not available

Retention: Not available

Rights: Not available

Cookies and device storage

sb-<project>-auth-token

Purpose: Supabase Auth session. Strictly necessary: without it a signed-in request cannot be authenticated.

Lifetime: until sign-out or session expiry

faust_guest

Purpose: signed httpOnly identifier for a signed-out visitor so the free reading paper and chat-turn allowance can be counted. Strictly necessary for the free allowance.

Lifetime: 400 days

faust_oauth_redirect

Purpose: remembers where to return after an OAuth sign-in or reauthentication round trip. Strictly necessary.

Lifetime: 10 minutes

faust_reauth_challenge

Purpose: binds a pending reauthentication to this session and origin before an account export or deletion. Strictly necessary security cookie.

Lifetime: 10 minutes, or until the challenge is consumed

faust_reauth_grant

Purpose: proof that this session reauthenticated, required to export or delete an account. Strictly necessary security cookie.

Lifetime: 5 minutes; cleared as soon as the operation completes

faust_recovery_proof

Purpose: binds a password recovery link to the browser that opened it. Strictly necessary security cookie.

Lifetime: 10 minutes, or until recovery completes

faust_account_delete_continuation

Purpose: lets an interrupted account deletion resume instead of leaving the account half-deleted. Strictly necessary.

Lifetime: until the deletion completes

faust_coach_tour (and its faust.coachTour localStorage mirror)

Purpose: records that the onboarding coach marks were completed or skipped, so they are not shown again.

Lifetime: 400 days

faust.account.pendingReauth (sessionStorage)

Purpose: holds the export or deletion request across an OAuth reauthentication redirect so it can resume on return. Cleared on use and never sent to a server.

Lifetime: until the browser tab is closed

exam_roster and goethe.examDatePromptDismissed (localStorage)

Purpose: the exam roster a visitor entered and whether they dismissed the request for an exam date, so the countdown works before sign-up and the card asks once rather than after every paper. A signed-in account stores the roster in its profile as well.

Lifetime: until the visitor clears site data

faust_consent (localStorage)

Purpose: records whether the visitor accepted analytics and advertising or chose necessary storage only. Measurement providers read this one shared choice.

Lifetime: until the visitor changes the choice or clears site data

ph_faust_posthog* and faust_posthog_consent (localStorage)

Purpose: after consent only, keeps PostHog pseudonymous session continuity and its local opt-in state. It is never created for internal or unknown traffic.

Lifetime: analytics state expires after 180 days; the opt-in record remains until the choice changes or site data is cleared

_ga and _ga_<id> (first-party cookies)

Purpose: after consent only, distinguishes browsers and preserves Google Analytics session state for aggregate measurement.

Lifetime: 180 days from the first consented visit; it is not refreshed

_gcl_* and _fbp (first-party advertising cookies, when configured)

Purpose: after consent only, attributes an advertising click and a verified signup or purchase to the campaign that brought the visitor.

Lifetime: up to 90 days

Related records

See Terms and Impressum for contract and operator details.

Official reference: GDPR Art. 13.

Plan details

Adboard Pro

Charged immediately. There is no trial.

£20.00 per month or £200.00 per year, 16.67% off; annual billing is charged once per year.

Intensiv

Charged immediately. There is no trial.

£59.99 per month or £359.99 per year, 49.99% off; annual billing is charged once per year.

Tax details are temporarily unavailable. Checkout is paused until they are complete. All paid cadences renew automatically; cancellation is available through the public flow and Stripe Customer Portal at the end of the current billing period unless a separately verified statutory withdrawal decision applies.

Fair-use caps pause practice at reset boundaries. There are no overage charges.

Use Stripe Customer Portal to change your plan, billing schedule, payment method or cancellation.

Some legal details are temporarily unavailable. Paid checkout is paused until they are complete. Contact