Privacy Policy
Last updated: April 29, 2026
1. Introduction
VocabForge is a language learning service for vocabulary collection, practice, immersion study, analytics, and classroom workflows. This Privacy Policy explains what information we collect, how we use it, and the choices you have when you use the web application or browser extension.
This page is intended to describe the product accurately. It is not a substitute for legal advice, and privacy rights can vary by location.
2. Information We Collect
Account and profile information
- Email address, username, password hash, display name, roles, enabled status, target language, and definition-language preference.
- Email verification, password reset, session, access-token, refresh-token, and CSRF security data needed to keep accounts protected.
- Subscription status and Stripe customer or subscription identifiers when you use paid features.
Learning and practice data
- Vocabulary, grammar items, example sentences, tags, definitions, item usage, review logs, SRS progress, lesson progress, and study-session analytics.
- Practice answers, scores, weak points, activity history, TOPIK forms, TOPIK attempts, attempt answers, section scores, and adopted TOPIK vocabulary.
- Dialogues, scenarios, difficulty settings, generated target/native text, grammar analysis, and saved words from dialogues.
- Imported vocabulary files or pasted text that you choose to submit for parsing, enrichment, or saving.
Immersion and classroom data
- Media titles, video URLs, thumbnail URLs, subtitle text, parsed subtitle segments, difficulty labels, and media ownership data.
- Classroom names, invite codes, memberships, teacher/student relationships, assignments, templates, categories, progress, gradebook rows, quiz attempts, quiz answers, announcements, and roster data.
- Classroom messages, message threads, read receipts, live-session participation, agenda state, timers, votes, challenge prompts, challenge responses, and session history.
- Teacher-shared classroom uploads, including file name, content type, size, file bytes, uploader, classroom, and upload time.
- Whiteboard content is currently stored in your browser local storage for the classroom, not on the backend server.
Browser extension data
- Korean words, selected text, and nearby sentence context captured from a page only when you use the configured capture gesture or save flow.
- Extension settings, recent saved words, pending captures, and session tokens stored by the extension so it can connect to your VocabForge account.
- The extension content script can run on pages you visit because it needs to detect your explicit capture gesture, but it does not send page text to VocabForge unless you choose to save or analyze captured text.
Technical and usage data
- Request metadata such as IP address, user agent, timestamps, endpoint paths, rate-limit counters, logs, and security events.
- Frontend usage events collected through Vercel Analytics and local browser preferences such as theme, selected classroom module, reload guard state, and cached whiteboard state.
3. How We Use Information
- Provide authentication, account security, email verification, password reset, session refresh, and CSRF protection.
- Save and sync vocabulary, grammar, media, practice, TOPIK, dialogue, classroom, upload, and analytics data across devices.
- Generate practice material, language analysis, dictionary enrichment, subtitle study, and text-to-speech audio when you request those features.
- Operate classrooms, including assignment delivery, gradebook views, messaging, live sessions, uploads, and teacher/student visibility.
- Process subscriptions, trials, checkout, billing portal access, and Stripe webhook events.
- Monitor reliability, prevent abuse, enforce rate limits, debug errors, and improve the service.
4. Legal Bases Where Required
- Contract: to provide the VocabForge service you request, including accounts, learning features, classrooms, subscriptions, and support.
- Legitimate interests: to secure the service, prevent abuse, understand aggregate usage, debug issues, and improve product quality.
- Consent: where local law requires consent for optional analytics, communications, or similar features.
- Legal obligations: to keep records required for tax, billing, fraud prevention, dispute handling, or legal compliance.
5. Cookies and Local Storage
- The web app uses HttpOnly authentication and refresh cookies, plus an XSRF-TOKEN cookie that JavaScript can read to submit CSRF-protected requests.
- The web app uses local storage or session storage for non-sensitive UI state such as theme, selected classroom module, whiteboard restore data, and one-time reload guard state.
- The browser extension uses Chrome extension storage for settings, pending captures, recent words, and extension authentication state.
6. Third-Party Services and Sharing
We do not sell personal information. We share information only as needed to run VocabForge, provide requested features, process payments, comply with law, or protect the service.
Service providers
- Railway and PostgreSQL infrastructure host the backend, database, and related services.
- Cloudflare hosts and protects the frontend deployment.
- Resend sends account emails such as verification and password reset messages.
- Stripe handles checkout, customer portal, payment processing, subscription status, and billing events.
- KrDict data shipped with the app powers dictionary and lexical enrichment features; lookups are performed locally on our servers and do not contact third parties.
- Gemini or ElevenLabs may receive text to synthesize speech when text-to-speech is enabled and requested.
- Public video URLs or caption identifiers may be used to retrieve subtitles for immersion study.
Classroom visibility
- Teachers can see classroom roster information, assignment progress, quiz results, gradebook data, messages, uploaded files, live-session participation, and related classroom activity for their classes.
- Students in a classroom may see classroom-level content such as announcements, assignments, uploads, live-session state, and participant display names where the product shows them.
7. Security
- We use HTTPS for production traffic, BCrypt password hashing, JWT-based authentication, refresh-token rotation, HttpOnly cookies for the web app, CSRF protection, CORS restrictions, rate limiting, security headers, and log masking for common secrets.
- No online service can guarantee absolute security, but we design VocabForge to reduce unnecessary access to personal data and to keep controllers and services behind authenticated routes where required.
8. Data Retention
- We keep account, learning, classroom, media, and subscription records while your account is active or as needed to provide the service.
- You can delete many user-created items directly in the app, such as vocabulary, media, classrooms you own, classroom uploads, and related classroom content where deletion is supported.
- You can request account or data deletion by contacting us. Some limited records may be retained when required for security, billing, dispute resolution, legal compliance, backups, or abuse prevention.
- Local browser or extension data remains on your device until you clear it, uninstall the extension, or use browser controls to remove it.
9. Your Rights and Choices
- Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal data.
- California residents may have rights to know, delete, correct, opt out of sale or sharing, limit certain sensitive personal information uses, and avoid discrimination for exercising privacy rights. VocabForge does not sell personal information or share it for cross-context behavioral advertising.
- The use of information received from Chrome extension permissions adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use extension data only to provide or improve VocabForge user-facing features, and we do not use it for personalized advertising or creditworthiness decisions.
- If GDPR or UK GDPR applies, you may also have the right to lodge a complaint with your local data protection authority.
- You can update display name and language preferences in the app, export analytics data from the analytics area, manage paid subscriptions through Stripe, and contact us for other requests.
10. Children and Classroom Use
- VocabForge is not directed to children under 13. We do not knowingly collect personal information from children under 13 without appropriate consent.
- Teachers, schools, parents, or guardians who use VocabForge with students are responsible for ensuring they have any required permissions and for contacting us if student data needs to be reviewed or deleted.
11. International Processing
VocabForge and its providers may process information in the United States, Europe, or other countries where infrastructure and service providers operate. Data protection laws in those places may differ from the laws where you live.
12. Automated Decision-Making
VocabForge personalizes practice queues, analytics, and learning recommendations. We do not use automated decision-making intended to produce legal or similarly significant effects about you.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date on this page and provide additional notice when appropriate.
14. Contact Us
For privacy questions or data requests, contact us at: vocabforgeapp@gmail.com