What information do we collect?
Information you provide directly
When you use GoVocab, the information you actively provide is your native language preference and English experience level, both selected during onboarding. These are stored on your device and used to tailor definitions and explanations to your level and language background.
We do not ask for your name, email address, or any account credentials. No account is required to use GoVocab.
Information you share into GoVocab from other apps
GoVocab includes an iOS Share Extension, so you can select a word in another app — an e-book, a browser, a messaging app — and send it to GoVocab to look up. We only ever receive text you explicitly choose to share with GoVocab through your device's share sheet. GoVocab cannot read other apps, your clipboard, or anything on your screen.
What happens to shared text depends on what you share:
- A single word is looked up straight away, exactly as if you had typed it into the search bar. It is handled the same way as any other search — see Section 4 and Section 6.
- Anything longer than a single word (a sentence or a passage) is only placed into the search bar on your device so you can pick the word you want. It is not sent to our servers, to the AI, or to any third party unless you then choose to search for a word from it.
Shared text is used once, for that lookup, and is not stored separately from your normal search history.
Information stored on your device and synced to our servers
The following data is stored on your device (using AsyncStorage and a local SQLite database), and is also synced to our servers (Google Cloud Firestore) under an anonymous device identifier so it can be restored if you reinstall the app:
- Your native language preference
- Your English experience level
- Words you have saved as favourites, including the definitions, examples, and synonyms generated for them
- Your search history
This data is tied to an anonymous identifier, not to your name or any personal account. See "Anonymous authentication" below.
Information sent to our analytics provider
When you search for, save, or review a word, the word itself is sent to our analytics provider (PostHog) as part of an anonymous usage event, so we can understand which features are used and fix problems. This is described further in Section 4.
Information collected automatically
When you use GoVocab, certain technical information is collected automatically to keep the app running and to help us fix problems:
- Device data: Device model and operating system version
- Usage data: Words searched, saved, and reviewed; features used; timestamps; and session information
- Log data: Error reports, crash logs, and diagnostic information
- Language preference: Your device language setting
We do not store your IP address. Our crash-reporting provider is configured to discard IP addresses rather than retain them.
Information collected when you visit our website
This applies to govocab.app, not to the app. When you read a word page or any other page on our website, we use Cloudflare Web Analytics to count page visits. It records the page you viewed, the site you arrived from, your approximate location at country level, and your browser and device type.
This is aggregate traffic measurement only. It sets no cookies, does not fingerprint your browser, and does not follow you to other websites. It is not connected to the anonymous identifier used by the app, so we cannot tell that a website visitor and an app user are the same person. You can read the website without installing the app, and we do not collect anything else if you do. See Section 5 for the one functional cookie our website does set.
Anonymous authentication
GoVocab uses Firebase Anonymous Authentication. This assigns your device a persistent anonymous identifier so the app can function without requiring you to create an account, and so your saved words and history can sync across app restarts. This is not a user account — no email, password, or personal information is associated with it. This identifier resets if you delete and reinstall the app.
How do we process your information?
We process your information only for the following purposes:
- To deliver the service: Processing word searches, generating AI-powered definitions, and returning results to your device
- To improve the app: Analysing usage patterns to understand how the app is performing and where it can be improved
- For security and fraud prevention: Detecting unusual activity and protecting the integrity of the service
- To comply with legal obligations: Where required by applicable law
We do not use your information for advertising, profiling, or any purpose beyond what is listed above.
What legal bases do we rely on?
We only process your personal information when we have a valid legal reason to do so. Depending on where you are located, this may include:
- Consent: Where you have given us permission, for example by choosing your native language and experience level during onboarding
- Legitimate interests: To operate, maintain, and improve the app in a way that does not override your rights
- Legal obligations: Where we are required to process information to comply with applicable law
If you are located in the EU or UK, the above applies under GDPR and UK GDPR. You may withdraw consent at any time by contacting us at govocab@sakurahaus.com.
When and with whom do we share your information?
We share your information only with the third-party services required to operate GoVocab. We do not sell your personal information.
AI Service Providers
When you search for a word, the word (and your selected native language) is sent to Groq's API to generate an AI-powered definition. Groq does not use this data to train or fine-tune any AI models. Groq does not retain this data by default, except in narrow cases — such as investigating a platform error or suspected abuse — where it may be temporarily logged for up to 30 days. Groq processes this data in accordance with their privacy policy.
Search & Predictive Text
As you type a word in the search bar, queries are sent to the Datamuse API to provide word suggestions. Datamuse does not collect personal information beyond the query string.
Reference Data
The Free Dictionary API is used as a supplementary data source for word lookups, providing pronunciation and parts-of-speech data. This request is made by our backend server, not directly from your device, only when a word isn't already available in our cache. Only the searched word is sent. No personal information is transmitted.
Translation
When displaying definitions or explanations in your native language, GoVocab sends the English definition text and your selected language code to a Google Translate web service to provide translations. No personal identifiers, user ID, or device ID are sent alongside this text. Google processes this data in accordance with their privacy policy.
We also use a Google text-to-speech web service to generate the pronunciation audio for a word. Only the word itself is sent, by our backend server rather than from your device, and only the first time that word is looked up by anyone. No personal identifiers are sent with it.
Infrastructure & Caching
AI-generated definitions are cached in Firestore to reduce repeated processing and improve performance. Your saved words and search history are also stored in Firestore under your anonymous identifier. Firebase Cloud Functions handle the routing between your device and the AI service.
Pronunciation audio clips are generated once per word and stored in Firebase Storage, so every user hears the same clip without it being regenerated. These files are named after the English word alone and contain no user data — they are shared across all users and are not linked to you or your anonymous identifier.
Authentication
An anonymous, persistent identifier is assigned to your device so the app can function and your data can sync. No personal information is linked to this identifier.
Analytics
We use PostHog to understand how the app is used — for example, which words are searched, saved, or reviewed, and which features are used. This data is tied to an anonymous device identifier, not to your name or any personal account. PostHog processes this data on servers located in the European Union.
Website Analytics
This applies to govocab.app, not to the app. We use Cloudflare Web Analytics to measure website traffic — which pages are read, and roughly where visitors come from. Cloudflare receives this as aggregate data. No cookies are set, no browser fingerprint is taken, and nothing is linked to your app identity or used to track you across other websites. Cloudflare also processes the standard connection information any web host receives in order to serve the page to you.
Crash & Error Reporting
We use Sentry to detect and diagnose technical errors and crashes. Crash reports may include your native language and experience level (to help us understand if a bug affects a specific group of users) but do not include your search history, saved words, or IP address.
Business transfers
If GoVocab is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you if this occurs.
Do we use cookies and tracking technologies?
The GoVocab app does not use browser cookies. We do use mobile analytics and crash-reporting SDKs (PostHog and Sentry) which collect usage and diagnostic data as described in Section 4. This data helps us understand app performance and behaviour, and is not linked to your name or any personal account.
Our website (govocab.app) sets one functional cookie, govocab_redirected, when we detect you're visiting from a country where one of our translated languages (currently Vietnamese, Korean, Japanese, Spanish, or French) is the clear majority language, and send you to that version instead of the English homepage. This cookie only remembers that this redirect already happened, so we don't send you there again if you choose to switch back to English. It contains no personal information, isn't used for advertising or analytics, and isn't linked to your app identity. It expires after one year.
We do not use tracking technologies for advertising, and we do not track you across other apps or websites.
Do we offer AI-based products?
Yes. GoVocab's core feature — generating word definitions, example sentences, and synonyms — is powered by artificial intelligence via Groq's API (using the gpt-oss-120b model).
What is sent to the AI (Groq)
- The word you searched for
- Your selected native language (to tailor the explanation)
Definitions, example sentences, and synonyms are generated by Groq. Translations into your native language are handled separately by Google Translate — see Section 4 for details.
What is not sent to the AI
- Your name, location, or any account information
- Your full search history or the complete list of your saved words (only the single word currently being looked up is sent)
AI-generated responses are not used to build an advertising profile about you. You must not use GoVocab's AI features in any way that violates Groq's terms of service.
Is your information transferred internationally?
Yes. GoVocab's infrastructure is hosted across the European Union (Google Cloud, Firestore) and the United States. If you use GoVocab from outside these locations, your information will be transferred to and processed in these locations.
If you are located in the European Economic Area (EEA), UK, or Switzerland, please be aware that other countries in our processing chain may not have data protection laws equivalent to your own. We take all reasonable steps to protect your information in accordance with this Privacy Policy and applicable law, including relying on Standard Contractual Clauses where required.
How long do we keep your information?
We keep your information only for as long as necessary to provide the service:
- On-device data (favourites, history, language preference): Kept until you uninstall the app or clear app data
- Synced data in Firestore (favourites, history, tied to your anonymous identifier): Retained until you clear it in-app or contact us to request deletion
- Cached word definitions in Firestore: Retained to improve performance for all users; not tied to any individual user
- Pronunciation audio in Firebase Storage: Retained to improve performance for all users; contains no user data and is not tied to any individual user
- PostHog analytics data: Retained in accordance with PostHog's data retention settings
- Website analytics data (govocab.app): Retained by Cloudflare as aggregate traffic statistics; not tied to any individual visitor
- Language-redirect cookie (govocab.app): Expires after 1 year; contains no personal information
- Sentry crash/diagnostic data: Retained for a limited period to allow us to investigate and fix issues
- Groq request data: Not retained by Groq by default; may be logged temporarily (up to 30 days) only for error troubleshooting or abuse investigation
- Anonymous identifiers: Persist until you uninstall the app
When data is no longer needed, we delete it or anonymise it so it can no longer be linked to you.
How do we keep your information safe?
We implement technical and organisational measures to protect your information, including:
- Firestore security rules that restrict data access to your own anonymous account
- Firebase Anonymous Authentication to avoid storing personal credentials
- Server-side functions hosted on Google Cloud infrastructure with industry-standard security
- Configuration of our crash-reporting provider to avoid storing IP addresses or other unnecessary identifying data
- No storage of sensitive personal information on our servers
However, no method of transmission or storage over the internet is 100% secure. We cannot guarantee absolute security, and you use the service at your own risk.
Do we collect information from minors?
GoVocab is not directed at children under the age of 13, or the equivalent minimum age in your jurisdiction. We do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at govocab@sakurahaus.com and we will take steps to delete that information promptly.
What are your privacy rights?
Depending on where you are located, you may have rights including:
- The right to access the personal information we hold about you
- The right to request correction or deletion of your personal information
- The right to restrict or object to our processing of your information
- The right to data portability (where applicable)
- The right to withdraw consent at any time
Since GoVocab uses anonymous authentication, much of your data is already under your direct control within the app. To exercise any of the above rights for data stored on our servers, contact us at govocab@sakurahaus.com.
If you are in the EEA or UK and believe we are unlawfully processing your information, you have the right to complain to your local data protection authority.
Do-Not-Track features
Some mobile operating systems include a Do-Not-Track or Limit Ad Tracking setting. GoVocab does not currently respond to these signals as there is no uniform standard for how they should be implemented. We will update this policy if that changes.
Some browsers send a Global Privacy Control (GPC) signal when you visit a website. GoVocab does not sell or share personal information, and our website sets no advertising or tracking cookies (see Section 5 for the one functional cookie it does set), so there is nothing for this signal to opt you out of.
US residents — specific privacy rights
If you are a resident of California or certain other US states, you may have additional rights under applicable state privacy laws.
Categories of personal information collected (last 12 months)
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Anonymous device ID | YES |
| Personal info (CA statute) | Name, contact info, financial info | NO |
| Protected characteristics | Gender, race, ethnicity, religion | NO |
| Commercial information | Purchase history, financial details | NO |
| Biometric information | Fingerprints, voiceprints | NO |
| Internet / network activity | Browsing history, ad interactions | NO |
| Geolocation data | Precise device location | NO |
| Audio / visual data | Images, recordings | NO |
| Professional information | Employment, job title | NO |
| Education information | Student records | NO |
| Inferences / profiles | User profiles derived from data | NO |
| Sensitive personal information | SSN, financial account, health data | NO |
We collect only an anonymous device identifier and usage data (including searched/saved words and language/level preferences) as described in this policy. We do not sell personal information or use it for targeted advertising.
Your rights
- Right to know what personal information we collect and how it is used
- Right to request deletion of your personal information
- Right to opt out of the sale of personal information (we do not sell data)
- Right to non-discrimination for exercising your rights
To exercise these rights, contact us at govocab@sakurahaus.com. If we decline your request, you may appeal using the same email address.
California Shine The Light
California residents may request information about personal information shared with third parties for direct marketing purposes. GoVocab does not share personal information for direct marketing purposes.
Other regions — specific rights
Australia and New Zealand
We collect and process your personal information in accordance with Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020. You have the right to request access to or correction of your personal information by contacting us at govocab@sakurahaus.com. If you believe we are in breach of applicable privacy principles, you may lodge a complaint with the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.
South Korea
GoVocab is operated from South Korea. We process personal information in accordance with South Korea's Personal Information Protection Act (PIPA). You have the right to request access to, correction of, or deletion of your personal information. To make such a request, contact us at govocab@sakurahaus.com.
Under PIPA, we are required to name the person responsible for personal information. GoVocab is run by one person, who is also the personal information protection officer:
- Personal Information Protection Officer: Lavana — govocab@sakurahaus.com
Do we make updates to this policy?
Yes. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The updated version will always show a revised date at the top of this page.
If we make material changes, we will notify you through the app or by other reasonable means. We encourage you to review this policy periodically.
How to contact us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
GoVocab — Seoul, South Korea
How to review, update, or delete your data
- Favourites and search history: Can be cleared directly within the app
- Language or experience level preference: Can be updated directly within the app, or by contacting us at govocab@sakurahaus.com
- On-device data: Deleted automatically when you uninstall the app
- Synced data on our servers (Firestore, cached under your anonymous identifier): You may submit a deletion request to govocab@sakurahaus.com and we will respond in accordance with applicable data protection law