Kote's Vocab App
Privacy Policy
Last updated: September 5, 2026
This policy explains how Kote's Vocab App browser extension handles data on your device and what limited data is sent to Kote's Vocab App feedback service when you explicitly confirm a missing-word or dictionary-correction report.
Scope
This policy applies to Kote's Vocab App Chrome extension, the dictionary feedback service used only after an explicit user action, and these public privacy and support pages. Kote's Vocab App currently has no user accounts, cloud synchronization, payments, advertising, or cross-site tracking.
Local data
Kote's Vocab App uses Chrome storage.local for the following data.
It remains in your browser by default. Only the report fields described
below are sent to Kote's Vocab App feedback service after your confirmation:
- Saved words, phrases, or sentences, plus compact dictionary snapshots and root analysis saved with them.
- Custom collection names, descriptions, and Favorite membership.
- App state, feature-visibility and page-mark preferences, Chrome translation preferences, speech voice/language/rate/volume/pitch and the speech-after-copy preference, automatic favorite preference, and local missing-word collection preference.
- The active exam, up to 100 recent completed exam records, and answer snapshots.
- Up to 400 Chrome translation cache records, limited to 512 KiB and expiring after 30 days by default.
- Up to 1,000 unique items in the local missing-word report queue.
- Up to 200 locally retryable or deletable word/root correction reports.
A JSON backup you explicitly download contains Favorites, custom collections, selected settings, and completed exam history. A separate study pack contains only the Favorite content you choose to share plus its name and description, not settings or exam history. You are responsible for storing these files; Kote's Vocab App does not upload or publicly distribute them automatically.
How selected text is used
When you select English text on a web page, the content script reads that selection in the current page's memory to perform an offline dictionary lookup, root analysis, and popup display. Ordinary lookups use the dictionary bundled with the extension. They are not sent to Kote's Vocab App Worker, and Kote's Vocab App does not build a complete browsing history.
Automatic saving of selected text is off by default. When enabled, a single English word is checked against the local dictionary; multi-word text or a sentence is stored as one complete Favorite rather than split into separate words. Manual or automatic Favorites are not sent to the feedback Worker and do not automatically upload missing words.
Marking saved words while reading is also off by default. When enabled, the content script locally compares ordinary readable text on an allowed site with word Favorites and marks complete matches in the user's chosen color (light green by default). It skips inputs, code, editable content, phrases, and sentences. Page text, URLs, and surrounding context are neither stored nor uploaded, and the temporary marks disappear when the feature is disabled or the page closes.
A candidate enters the separate local missing-word queue only when the dictionary explicitly returns not found, the selection passes format and length validation, and local collection is enabled. Technical errors, URLs, email addresses, numbers, ordinary sentences, and overly long selections are excluded.
Chrome translation
Chrome translation is optional. When a dictionary definition has no Wiktionary Chinese translation, Kote's Vocab App can call Chrome's Translator API according to your settings and actions. Chrome manages the language model and translation capability. Kote's Vocab App does not operate a translation server and does not send definitions to its missing-word feedback Worker.
You can disable Chrome translation or clear its cache. If the browser or language pair is unsupported, the offline English dictionary, Wiktionary Chinese, root analysis, and Favorites remain available.
Speech playback
Speech playback uses voices exposed by your browser or operating system through Web Speech. Kote's Vocab App does not use a paid TTS API, operate a speech server, or store speech text or generated audio.
Local voices synthesize on the device. Remote voices may require a network connection, and your browser, operating system, or its speech provider may process the text. The Kote's Vocab App developer does not receive or store speech text. You can inspect local/remote status in Settings, choose a local voice when available, or stop playback.
Automatic speech after copying is off by default. When enabled, it reads only the current page selection during a user-initiated copy action and passes it to the selected voice. The extension does not use the Clipboard API, request clipboard permissions, or process input, password, textarea, or editable fields. Text is not stored or logged, and new playback stops the previous utterance.
When dictionary reports are uploaded
Missing words are never uploaded automatically. A batch is sent over HTTPS only after you open the Favorites page, select queue items, review the upload preview, and explicitly confirm the upload.
The confirmed request may contain only:
- Batch and report IDs.
- The raw candidate text, normalized word, and lookup word when needed.
- Word or phrase type, first and last seen times, and a capped seen count.
- App version, dictionary version, batch time, and schema version.
A missing-word report does not contain:
- Page URL, page title, surrounding context, or full page content.
- Email, Google account data, a permanent device ID, or OAuth tokens.
- Favorites, dictionary definitions, translations, exam history, or browsing history.
- JSON backups, Chrome language models, or other credentials.
You can also select one displayed word or root on the dictionary data page, choose an issue type, add an optional note of up to 500 characters, and confirm a preview. This individual report contains only a random report ID, word/root target and key, issue type, optional note, app/dictionary versions, and creation time. It excludes page URLs, reading content, Favorites, quiz history, Google identity, and credentials. If the service is unavailable, the report remains local for retry and can be deleted locally.
Server retention
Accepted raw missing-word batches are stored in Cloudflare D1 for 365 days by default and then removed by scheduled or administrative cleanup. Aggregated normalized-word records may be retained longer to rank and manually review dictionary candidates. Report counts do not represent unique users and do not automatically modify the dictionary.
Accepted word/root correction reports are stored in a separate D1 review table under the same default 365-day raw retention. Every report is an input for human verification and never edits or publishes the dictionary automatically.
To limit abuse, the Worker may use a server-only secret to calculate a short-lived HMAC day hash from the source IP and UTC date. D1 does not store the raw IP. Rate-limit rows older than three days are removed. The hash is not treated as a user ID and is not copied into the long-term aggregate.
Reports do not use an account or permanent device identifier, so there is currently no per-user deletion portal that can map an accepted server batch back to a particular user. Removing a sent local queue item does not withdraw a batch already accepted by the Worker.
User controls and deletion
- Edit or delete individual Favorites, or clear Favorites from the Favorites page.
- Create, edit, or delete custom collections; deleting a collection does not delete its Favorites.
- Delete one completed exam record, clear all completed history, or abandon an active exam.
- Delete selected missing-word items, clear sent items, or disable new local missing-word collection.
- Retry or delete an individual local correction from the dictionary data page.
- Disable Chrome translation or clear the translation cache from the popup or settings.
- Remove the extension or clear its stored data to remove the remaining local storage.
- Delete JSON backup or study-pack files you downloaded to your file system.
Security measures
Kote's Vocab App uses HTTPS for user-confirmed missing-word batches and dictionary corrections, and checks formats, field lengths, and request sizes on both client and server. The feedback service also uses an exact origin allowlist, idempotent processing, and basic abuse controls. No system can guarantee absolute security; please use the contact address below to report a concern.
Data-use commitments
Kote's Vocab App does not sell user data and does not use it for advertising. It has no third-party analytics, tracker, or advertising SDK. Missing-word and correction reports are only maintenance signals and require additional format, inflection, source verification, and controlled human review before they can affect a future dictionary build.
Information received from Chrome APIs is used and transferred in accordance with the Chrome Web Store User Data Policy, including the Limited Use requirements. It is used only to provide or improve visible lookup, translation, saving, review, and user-confirmed dictionary reporting features—not for advertising, data sales, credit assessment, or unrelated purposes.
This static policy site has no JavaScript, cookies, analytics, remote fonts, or trackers. Its hosting provider may still create ordinary service logs for infrastructure and security purposes; consult the hosting provider's policy as well.
Policy updates
If product data handling or applicable requirements change, this page and its last-updated date will be revised. Material changes will be described in product documentation or store information when practical.
Contact
For privacy or support questions, email kote.vocab.app@gmail.com. See the Support page for guidance on what to include.