Privacy Policy

Last Updated: December 24, 2024

Introduction

Oryx Data Incubator ("us", "we", or "our") operates the https://vocabkit.web.app website and the VocabKit Chrome Extension (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). By using our Service, you consent to the data practices described in this policy.

Data Controller: Oryx Data Incubator
Address: Contact us for mailing address
Contact Email: support@vocabkit.app
Data Protection Officer: privacy@vocabkit.app

1. Information We Collect

We collect information necessary to provide and improve our Service.

Types of Data Collected:

a. Personal Data

When you create an account, we collect the following personal data:

  • Email Address: Used for account creation, authentication, and communication.
  • Display Name (Optional): To personalize your experience.
  • Payment Information: If you subscribe to a premium plan, our payment processor, Stripe, collects your payment information. We do not store your full credit card details on our servers.

b. User Content (Your Vocabulary Data)

When you use the Service, you generate content which we store to provide our core features:

  • Saved Words: The words you save, their translations, example sentences, and alternative meanings.
  • Metadata: This includes your personal notes, favorite status, and word frequency. This data is stored to provide the vocabulary management features and is synchronized across your devices if you have a premium account.

c. Translation Data

To provide our core feature, we process the text you select for translation:

  • The specific text you highlight on a webpage is sent securely through our backend service (Firebase Cloud Functions) to our AI language provider (OpenAI) to generate the translation.
  • We do not log or permanently store the text you translate. The only data retained is what you explicitly choose to save to your vocabulary list.

d. Technical & Usage Data

We automatically collect technical data to ensure the security and functionality of our service:

  • Usage Data: We collect anonymized data about feature usage (e.g., number of translations, words saved) to understand how our Service is used and where to make improvements.
  • Technical Information: This includes your IP address (for security and rate limiting), browser type, and device information to help us diagnose and fix technical issues.
  • Chrome Extension Storage: Settings, preferences, and cached data stored locally in your browser.
  • Session Data: Temporary session information to maintain your logged-in state.

e. Cookies and Similar Technologies

We use cookies and similar tracking technologies to track activity on our Service and hold certain information:

  • Essential Cookies: Required for authentication and core functionality.
  • Analytics Cookies: Help us understand how users interact with our Service (only with your consent).
  • Firebase Authentication Cookies: Used to maintain your session across browser restarts.

For detailed information about cookies and how to manage them, please see our Cookie Policy.

2. How We Use Your Data

Oryx Data Incubator uses the collected data for the following purposes:

  • To provide, maintain, and improve the Service.
  • To manage your account, including processing subscriptions and payments.
  • To enable cloud synchronization of your vocabulary data (a premium feature).
  • To communicate with you, including sending transactional emails (e.g., welcome emails, password resets) and responding to support requests.
  • To monitor and analyze usage to improve user experience and service performance.
  • To prevent fraud, enforce our terms, and protect the security of our Service.

3. Legal Basis for Processing (GDPR)

Under the GDPR, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide our Service under our Terms of Service.
  • Legitimate Interests: Processing for our legitimate business interests (e.g., improving our Service, preventing fraud).
  • Consent: Where you have given explicit consent (e.g., for marketing communications or analytics).
  • Legal Obligations: Processing necessary to comply with legal requirements.

4. Data Storage and Security

Your account information and saved vocabulary are stored securely using Google Cloud Platform's Firebase services (specifically Firestore Database). Data is encrypted at rest and in transit using industry-standard encryption protocols.

Data Location: Your data is stored in Firebase data centers located in the United States. By using our Service, you consent to the transfer of your data to the United States.

Security Measures: We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data at rest and in transit
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements
  • Regular backups and disaster recovery procedures

For users who are not signed in, data is stored locally on your device using your browser's secure storage. This data is not sent to our servers.

5. Third-Party Services

We rely on trusted third-party services to operate VocabKit. These services have their own privacy policies, and we encourage you to review them.

  • Firebase (Google): For authentication, database, cloud functions, and hosting.
  • Stripe: For secure payment processing.
  • OpenAI: For generating translations via our secure backend.
  • Resend: For sending transactional emails.

6. Your Data Rights

You have control over your personal data. Under GDPR and CCPA, you have the following rights:

GDPR Rights (for EU/EEA residents)

  • Right to Access: Request a copy of your personal data we hold.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data.
  • Right to Restrict Processing: Request limitation of processing your personal data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
  • Right to Lodge a Complaint: File a complaint with your local data protection authority.

CCPA Rights (for California residents)

  • Right to Know: Request information about personal data collected, used, disclosed, or sold.
  • Right to Delete: Request deletion of personal data we collected from you.
  • Right to Opt-Out: Opt-out of the sale of personal data (we do not sell personal data).
  • Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights.

How to Exercise Your Rights: You can exercise most of these rights directly through your account settings. For other requests, contact us at privacy@vocabkit.app. We will respond to your request within 30 days (or 45 days for CCPA requests).

7. Data Retention

We retain your personal data only for as long as necessary to provide our Service and fulfill the purposes described in this Privacy Policy:

  • Account Data: Retained for the duration of your account and up to 30 days after deletion (for recovery purposes).
  • Vocabulary Data: Retained as long as you have an active account. Deleted immediately upon account deletion.
  • Transaction Records: Retained for 7 years for tax and legal compliance.
  • Technical Logs: Retained for 90 days for security and debugging purposes.
  • Marketing Communications: Until you unsubscribe or withdraw consent.

8. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.

For transfers from the EU/EEA to the United States, we rely on:

  • Standard Contractual Clauses approved by the European Commission
  • Your explicit consent to the transfer
  • Other legally compliant transfer mechanisms

9. Children's Privacy

Our Service is not intended for use by children under the age of 13 (or 16 in the EU). We do not knowingly collect personally identifiable information from children under these ages. If you are a parent or guardian and believe we have collected information from your child, please contact us immediately at privacy@vocabkit.app.

10. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach. We will provide you with information about the breach and steps you can take to protect yourself.

11. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

12. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:

For EU/EEA residents: You have the right to lodge a complaint with your local supervisory authority if you believe we have not adequately addressed your concerns. In France, you may contact the CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr.