Privacy Policy
Last updated:
VocabuLens is built by one person, hosted in the EU, and wants your data as little as possible. This page says what's actually collected, why, and what we do with it — in plain language.
1. Who we are
VocabuLens is operated by an independent developer based in Finland. Contact: hello@vocabulens.com.
2. What we collect
When you register an account
- Email address — used to identify your account and to send critical service messages (password resets, security alerts).
- Display name — shown in the app.
- Password — stored only as a one-way hash. We cannot read, retrieve, or reverse it.
While you use the app
- Vocabulary and courses you add — the words, translations, examples, and course structure you create.
- Review progress — which cards you got right or wrong, scheduled for when. This is what makes spaced repetition work.
- Basic usage logs — request timestamps, IP address, user agent, error traces. Kept for debugging and abuse prevention. Rotated out within 30 days.
What we do NOT collect
- No ad trackers. No marketing pixels. No third-party analytics.
- No location beyond whatever coarse location your IP address implies.
- No microphone, camera, or contacts access. (If V2's capture features require these in the future, you'll be asked first and we'll update this page.)
3. Where your data lives
Servers are in the EU (currently Hetzner, Helsinki). Your data never leaves EU jurisdiction unless and until this page is updated to say otherwise. Backups are encrypted and also stored in the EU.
4. Cookies and local storage
The app uses a single localStorage entry to keep you logged in (your auth token) and another
to remember your theme choice (vocabulens:theme). No third-party cookies. No advertising cookies.
5. Sharing with third parties
We do not sell or share your data with advertisers, data brokers, or analytics vendors. Period.
Narrow exceptions, only when strictly needed to run the service:
- Hosting provider (Hetzner, EU) — your data sits on their disks.
- Email delivery — for password resets and service messages, when/if configured.
- AI providers (optional) — if you use AI-assisted features, the specific text you submit for that feature (e.g. a sentence you want explained) is sent to the configured provider (Anthropic or OpenAI). They do not receive your account identity unless you include it.
- Legal compulsion — if compelled by a valid EU legal order, we comply. We will attempt to notify you first unless prohibited.
6. Your rights (GDPR)
If you are in the EU/EEA/UK, you have the right to:
- Request a copy of your data (export).
- Correct or delete your data.
- Withdraw consent and close your account.
- Complain to your local data protection authority.
Email hello@vocabulens.com to exercise any of these. We respond within 30 days.
7. Retention
- Account data: kept while your account exists, deleted within 30 days of account closure.
- Logs: rotated within 30 days.
- Backups: 30-day rolling window; deleted data disappears from backups within 30 days.
8. Children
VocabuLens is not directed at children under 13. If you believe a child has registered, email us and we'll close the account.
9. Changes
If this policy changes materially, we'll update the "last updated" date and, for existing users, show a notice in-app on next login.