Privacy Policy
Last updated: August 3, 2026
1. What we store
When you use mVocaby we store:
- Account data — your email address, your chosen native language, and a hash of your password (never the password itself). If you sign in with Google we store your Google account identifier and verified email instead of a password.
- Vocabulary data — the words and phrases you save, their translations and definitions, the sentence and page or video they came from, and your spaced-repetition review history.
- Derived data — text embeddings and topic clusters computed from your saved vocabulary to power the semantic map.
We do not run third-party analytics or advertising trackers, and we do not sell your data.
2. Processors we share data with
Only the minimum necessary text is sent to each provider:
- DeepL — the words/phrases you translate, to produce translations.
- Voyage AI — saved terms and their definitions, to compute embeddings for the vocabulary map.
- Wiktionary — the terms you look up, to fetch definitions.
- Google — only if you choose Google sign-in; we receive your account identifier and verified email, and request no other scopes.
3. Cookies and local storage
The web app keeps your sign-in token in your browser's local storage; the extension keeps it in extension storage. A short-lived cookie is used only during the Google sign-in handshake. We set no advertising or cross-site tracking cookies.
4. Retention and deletion
Your data is retained while your account exists. You can delete individual vocabulary items at any time; deleting your account removes your account and vocabulary data from the live database.
5. Security
Passwords are hashed with bcrypt, transport is encrypted with TLS in production, and each account's data is isolated per user. No method of storage is 100% secure — use a unique password.
6. Changes and contact
We will announce material changes to this policy in the application. Questions or data requests: [email protected]. See also our Terms of Service.