Privacy Policy
Last updated: 1 October 2026
Vocalabs is a browser extension that turns highlighted text into flashcards. This policy describes what data the extension collects, why, and where it goes. Written in plain English because privacy shouldn't be a mystery.
What we collect
On your device only
- Flashcards you create (the word, definition, example sentence, source URL)
- Review history: which cards you've studied and when
- Preferences: target language, review settings, opt-in/out flags
- API keys you provide for AI features (Anthropic, OpenAI, Gemini, or OpenRouter)
- A local dictionary: 44,000 English definitions that ship with the extension, a translation pack downloaded for your language, and any rare words looked up while you read. All of it stays on your device. Settings → Offline dictionary shows what is stored and lets you remove it.
All of this stays on your device unless you explicitly opt into cloud sync.
Sent to our servers (only if you sign in for cloud sync)
- Your email address (for account identification)
- The flashcards described above, encrypted in transit
- A random session token used to keep you signed in
How we use synced cards
Your synced flashcards are stored on our servers so you can access them across devices. We may look at anonymized totals across all users. For example: which words are most commonly saved, or the distribution of languages being studied. This helps us improve dictionary quality and prioritize new features. These totals are never linked to your account. We do not share your personal information or individual card content with third parties.
Where a lookup can go
In the order Vocalabs tries them. Almost every word is answered by the dictionary already on your device, and nothing is sent. What follows is what happens in the cases that are not.
- Chrome's on-device model. Nothing is sent anywhere. If your copy of Chrome can run its own language model, Vocalabs uses it for words the dictionary does not have, and for choosing which meaning of a word fits the sentence you are reading. The model runs on your own computer. The word, the sentence and the answer never leave the machine, no account is involved, and there is nothing for us or anyone else to see. Chrome downloads the model once, when you ask it to from Settings, and the model belongs to Chrome rather than to us: it stays on your computer if you uninstall Vocalabs, and other sites can use it too.
- Dictionary lookups. Most words are answered from your device and nothing is sent anywhere. When you highlight a rare word that is not in your local dictionary, that single word and the two language codes are sent to our own dictionary service to fetch its entry. The answer is saved to your device, so the same word is never requested twice.
That request is a pure lookup: it carries the word, the language pair, and nothing else. It does not carry your name, your email, your account, the page you are reading, or the sentence around the word. We cannot tell who asked, because we are never sent anything that would identify you. No third-party dictionary service is involved at any point. - Translation packs. When you choose your language, the extension downloads a translation pack from our servers. This is an ordinary file download and tells us only that a pack was fetched. The dictionary content itself comes from Wiktionary, extracted via kaikki.org and used under CC BY-SA 4.0; our packs are published under the same licence.
- Device token. On install the extension gets an anonymous token from our server so we can apply fair-use limits and stop abuse. It contains a random identifier and your plan, nothing more. It is not linked to your name or email, it is not a tracking cookie, and it is never shared.
- Your own AI provider (optional, off by default, and the only step that costs money). Most people never need this, and it is the only route that involves anyone outside your computer and us. If you do add an AI provider, then for words our dictionary cannot answer, that word and the sentence around it are sent to the provider you chose (Anthropic, OpenAI, Google, or OpenRouter). This is the only case in which any sentence from a page you are reading leaves your device, and it only happens if you have set a key up yourself. Your API key stays in your browser and goes directly to that provider. We never see the key and we never see those requests.
- Anonymous usage counts (opt-out available): a random installation ID (not linked to your email), extension version, browser family (Chrome, Edge, Brave), and locale. Sent once at install and once per day. No card content, URLs, or personal information is ever included. Disable in Settings → Privacy.
What we never collect
- Browsing history
- Page content beyond the sentence you highlight
- Location data
- Third-party analytics (no Google Analytics, no Facebook pixels)
- Advertising IDs
Who has access
- You: everything, always
- Our servers: only what you've synced, and only if you've signed in
- Our dictionary service: individual rare words and a language pair, with nothing identifying you attached
- AI providers: only if you set one up, and only for words our dictionary could not answer
- No one else
Your rights
- Delete everything on your device: Settings → Reset → Delete everything
- Disable telemetry: Settings → Privacy → uncheck "Send anonymous usage counts"
- Delete your account and server-side data: email hello@vocalabs.app and we'll remove your data within 30 days
- Export your data: Settings → Export → Download cards.csv
Data retention
On-device data: kept until you delete it. Server-side sync data: kept while your account is active; deleted within 30 days of account deletion. Anonymous telemetry: retained for aggregate stats only, no individual timelines.
Children
Vocalabs is not aimed at children, and we do not knowingly collect data from a child below the age at which they can consent for themselves: 16 in Poland, and between 13 and 16 elsewhere in the EU depending on the country. If a teacher invites a student below that age into a class, it is for the teacher to have the parent's or guardian's permission first. If you believe we hold a child's data without that permission, write to us and we will delete it.
Changes to this policy
We'll post updates here. Continued use of Vocalabs after changes means you accept them. For material changes, we'll notify signed-in users by email.
Contact
Questions or suggestions?
Write to us
Thanks. We will reply to that address.
That did not send — please try again in a moment.
Vocalabs is built by an independent maker who cares about doing this right. If any of this looks off or contradictory, tell us and we'll fix it.