mVocaby
ExtensionPricingSign inGet started

Privacy Policy

Last updated: August 8, 2026

1. What we store

When you use mVocaby we store:

  • Account data — your email address, your chosen native language, and a hash of your password (never the password itself). If you sign in with Google we store your Google account identifier and verified email instead of a password.
  • Vocabulary data — the words and phrases you save, their translations and definitions, the sentence and page or video they came from, and your spaced-repetition review history.
  • Derived data — text embeddings and topic clusters computed from your saved vocabulary to group it by meaning.
  • Usage data — product events such as signing in, looking up a word, saving a word, or completing a review, with timestamps and the term involved, tied to a pseudonymous account identifier (or a random install identifier when you are not signed in — it carries no personal data). On our website we also record which of our own pages you visit. We use these to understand how the product is used and to improve it. The pages you browse with the extension never enter analytics — no page URLs or page content — and your translated sentences and email address are never included anywhere. You can turn extension usage statistics off at any time in the extension's settings.

We do not run advertising trackers, we do not track you across other sites, and we do not sell your data.

2. Processors we share data with

Only the minimum necessary text is sent to each provider:

  • DeepL — the words/phrases you translate, to produce translations.
  • Google Cloud Translation — the words/phrases you translate, to produce translations. Which of the two translation providers handles a given request depends on your plan; each receives only the text of that request.
  • Voyage AI — saved terms and their definitions, to compute the embeddings your words are grouped by.
  • Wiktionary — the terms you look up, to fetch definitions.
  • Google — only if you choose Google sign-in; we receive your account identifier and verified email, and request no other scopes.
  • Stripe — only if you subscribe to Pro: your email, and the payment details you enter on Stripe's own checkout page. Card numbers never reach mVocaby; we store Stripe's customer and subscription identifiers and the subscription's status, and nothing else about your payment method.
  • PostHog (EU Cloud) — the pseudonymous usage events described above: a random account or install identifier, the action performed, and for dictionary and vocabulary actions the term involved. Extension events reach PostHog only via our server. On the website, PostHog's script also reports visits to our own pages with standard web context (referrer, browser type) directly from your browser — configured without cookies and without session recording. Never your email, password, or translated text.

3. Cookies and local storage

The web app keeps your sign-in token and a random analytics identifier in your browser's local storage; the extension keeps its token and install identifier in extension storage. A short-lived cookie is used only during the Google sign-in handshake. We set no advertising or cross-site tracking cookies.

4. Retention and deletion

Your data is retained while your account exists. You can delete individual vocabulary items at any time; deleting your account removes your account and vocabulary data from the live database. Usage events are kept in pseudonymous form — after account deletion they are no longer connected to your email or any account data.

5. Security

Passwords are hashed with bcrypt, transport is encrypted with TLS in production, and each account's data is isolated per user. No method of storage is 100% secure — use a unique password.

6. Changes and contact

We will announce material changes to this policy in the application. Questions or data requests: [email protected]. See also our Terms of Service.

mVocaby · Learn from what you watchPricingContactTermsPrivacy