Gordito is a record of one person’s language learning. It holds the words you are learning and the sentences you wrote while getting them wrong. That is personal data, so here is exactly what happens to it.
Who is responsible
Gordito is run by Quentin Churet, an individual established in France, who is the data controller for the personal data described here. Write to privacy@gordito.app for anything on this page.
What is collected
Who you are
Sign-in is handled by WorkOS AuthKit, not by Gordito. When you sign in, Gordito reads your email address, whether it is verified, your first and last name, your profile picture URL and your locale from the sign-in token, and uses them to name you in the interface. Gordito stores none of them: its own database keeps only the opaque user identifier WorkOS issues. Your password, or your Google or Microsoft credentials if you use them, never reach Gordito.
What you and your agent write
Everything the notebook is for: the language pair you chose, word pairs and example sentences, quiz titles and questions, the answers you typed out in full, the corrections written against them, the class of each mistake and the part of the sentence it points at, and the scheduling state each word carries — when it is next due, how often you have seen it, how often you have failed it.
Technical records
The hosting providers below keep ordinary server logs, which include your IP address, browser user agent, the paths you requested and the time you requested them. The MCP connector records which tools your agent called, together with the user identifier and email address carried on your access token, so that failures can be traced to a session. Gordito also keeps an internal record of notifications it sends, with the outcome of each attempt.
In your browser
The dashboard stores your AuthKit session in your browser’s local storage, so a reload does not sign you out. That is the only thing either site stores on your device. There are no advertising cookies, no tracking pixels and no analytics on this marketing site. Both sites load typefaces from Google Fonts, which means Google receives the IP address and user agent of that request; nothing else about you is sent.
If you write to us
The contact form takes the email address you give, the subject and the message, and nothing else — no account is needed to use it, and it is not tied to your notebook. It is delivered by Web3Forms, a form-delivery service whose own privacy policy governs the submission while it is in their hands. The resulting mail is kept in the Gordito inbox for as long as it takes to deal with your question and to have a record of the answer. Sending the form is voluntary: writing to privacy@gordito.app yourself avoids the intermediary entirely.
Why it is collected
- To run the notebook: store what you save and give it back when you or your agent ask.
- To compute the review schedule. This is arithmetic (FSRS-6) performed on your answer history by the server, not a profile of you, and it makes no decisions about you beyond when to show a word again.
- To authenticate you and keep one learner’s notebook out of another’s.
- To keep the service working: find faults, fix them, and prevent abuse.
The legal basis for the first three is performance of the contract you enter into by using Gordito. The last rests on the legitimate interest of keeping a service secure and functioning. Nothing here is used for advertising or sold to anyone, and no automated decision is made about you with legal or similarly significant effect.
Who else sees it
Gordito uses a small number of providers, each for one job, and no one else receives your data:
- WorkOS
- Sign-in and identity (United States). Holds your account and profile.
- Railway
- Application hosting and the PostgreSQL database that holds your notebook (United States).
- Alpic
- Hosting for the MCP connector, and the usage records described above (France).
- Porkbun and Cloudflare
- Domain, DNS and content delivery (United States).
- Web3Forms
- Delivery of the contact form, and only if you choose to use it. Their own privacy policy governs what they do with a submission while it is in transit.
- Web fonts only (United States).
And the agent you connect
This one matters more than the rest. Gordito is designed to be read and written by an AI client you choose — Claude, ChatGPT, or something you host yourself. Whatever your agent reads out of your notebook, and whatever it writes into it, passes through that provider and is handled under their privacy policy and terms, not this one. If you ask your agent to quiz you, your words and your answers are in that conversation. Gordito cannot see, control or delete what your AI provider keeps. Choose the client accordingly, and disconnect the connector there when you want that flow to stop.
Transfers outside the EU
Some of those providers are in the United States, so your data is transferred there. Those transfers rely on the European Commission’s Standard Contractual Clauses, or on the EU–US Data Privacy Framework where the provider is certified under it.
How long it is kept
- Your notebook — vocabulary, quizzes, answers, corrections, schedule — is kept until you delete it or ask for it to be deleted. It is a record whose whole purpose is to be long-lived, so nothing in it expires on its own.
- There is no self-service delete button yet. Ask at privacy@gordito.app and your notebook and account will be deleted within 30 days.
- Server logs and connector usage records are kept by the providers above under their own retention periods, which are measured in days, and are not copied anywhere else.
- If you ask for deletion, that request itself is kept as proof it was carried out.
What you can do
- See and correct your vocabulary in the dashboard, or tell your agent to fix an entry.
- Sign out at any time, and disconnect the connector inside your AI client.
- Ask for a copy of everything Gordito holds about you, in a portable format, or ask for it to be erased.
- Ask for correction, ask for processing to be restricted, or object to it, and withdraw any consent you have given.
Write to privacy@gordito.app and you will get an answer within one month. If you are unhappy with it, you can complain to your national data protection authority — in France, the CNIL.
Children
Gordito is for learners aged 13 and over. If you are under the age of digital consent where you live — 15 in France — a parent or guardian has to agree to this policy for you. If you believe a child has used Gordito without that agreement, write to privacy@gordito.app and the account will be removed.
Security
Traffic is encrypted in transit, the database is not reachable from the public internet, and every request for your notebook is checked against a signed token issued to you. Gordito is a small project run by one person: it is built carefully, but no service can promise perfect security.
Changes
If this policy changes, the date at the top changes with it, and material changes will be announced in the dashboard before they take effect. The current version always lives at gordito.app/privacy.