Privacy
In effect from 19 August 2026.
The short version
We never keep the text you upload. Your file is read into memory, analysed, and gone when the request finishes. What we keep is the result — word counts, a difficulty score, a grammar breakdown. Those are facts about a book, not a copy of one, and they cannot be turned back into the book.
We do not sell anything to anyone, we do not run advertising, and there are no third-party tracking scripts on this site.
What we keep
| What | Why |
|---|---|
| Your email address, and whether it is confirmed | To have an account at all, and to reach you about it |
| Your plan, theme, and stated reading level | To give you what you are entitled to, and to remember your settings |
| A fingerprint of each text analysed, with its title, author and length — never the text | So the same book is analysed once rather than once per reader, and so your history can name what you read |
| The results of each analysis: word frequencies and statistics | They are the product. Shared between everyone who analyses the same text |
| Words you have marked as known | To filter them out of future lists |
| Your saved export settings | So you do not re-pick the same fields every time |
| How many words you have analysed today | To apply the daily ceiling, and to stop one person exhausting the service |
| A salted hash of your IP address, if you use the site without an account | To recognise a returning visitor for the same ceiling. The salt is held separately, so the stored value is not reversible and we cannot recover the address |
| Counts of what happened — analyses completed, sign-ups, errors. Numbers and short labels only | To know whether the service works. Never anything you typed |
| Anything you write to us through the feedback form | To answer you. This one is free text, because you chose to send it |
| Your Stripe customer and subscription identifiers, if you subscribe | To know what you are paying for. We never hold card details |
What we never keep
- The text of anything you upload or paste. It exists only for as long as the request takes to answer.
- Your password. Sign-in is handled by Google; we never see it.
- Your card details. Those go to Stripe directly, on Stripe’s pages.
- Your IP address in a form we can read back.
Why we are allowed to hold it
Under the UK and EU GDPR, we rely on two bases:
- Performance of a contract — your account, your settings, your history, your known words and your subscription. You asked us for a service; these are what providing it requires.
- Legitimate interests — the usage counts, the hashed IP and the event counts. The interest is keeping the service working and affordable and stopping abuse; the data is minimal, aggregate, and in the case of the IP deliberately not reversible. You can object to this, and the section below says how.
We do not rely on consent, because we do not do the things consent is usually for: no advertising, no profiling, no selling.
Cookies
No consent banner, because there is nothing to consent to. We use no advertising or analytics cookies and no third-party trackers. Your browser stores two things, both strictly necessary and both first-party: a random session identifier, so work you do before signing up is not lost when you sign up; and, once you sign in, the token that keeps you signed in. Measurement is counted on our own servers, in aggregate.
Who else touches it
Everyone. Not “service providers” — the actual list, with what each one gets.
| Who | For | What they get |
|---|---|---|
| Google (Firebase Authentication) | Sign-in and identity | Email address, and the sign-in credential itself. We never see or store a password. |
| Stripe | Payments and subscriptions | Email address, and the payment details you give them directly. Card numbers never reach our servers — checkout happens on Stripe's own pages. |
| Google Cloud Run | Hosting | Whatever is in a request while it is being served, including a text you upload. |
| Neon | Database | Everything listed under “What we keep”. Hosted in the United States (AWS us-east-2). |
| Sentry | Error reporting, when enabled | The details of a crash: what failed and where. Configured to send no request bodies, no cookies and no credentials, so an uploaded text cannot travel with one. |
Our servers and database are in the United States. If you are in the UK or the EU, that is an international transfer, and it is made under the standard contractual clauses each of the providers above offers.
How long we keep it
Your account lasts until you delete it. There is no expiry and no quiet clear-out: the free tier is meant to be permanent, so treating an inactive account as abandoned would break the promise the tier makes.
Usage counts age out with their daily window. Analysis results are kept indefinitely, because they belong to the text rather than to you — once your account is gone, nothing connects them to you.
What you can ask for
- A copy of your data. Your word lists and statistics are downloadable as CSV from any analysis, without asking. For anything else, write to us.
- Deletion. Self-service in Settings. It is irreversible, it cancels any subscription, and it reaches Google’s systems too — an account that survived at the identity provider would not be deleted in any sense that matters. Anonymous, non-identifying aggregates may remain.
- Correction of anything wrong, and objection to the legitimate-interest processing above.
Write to support@vocabify.xyz for any of these. You do not need an account to write. If you are in the UK or the EU and think we have got this wrong, you may complain to your data protection authority.
Children
This is not a service for children, and it is not designed or marketed for them. If you believe a child has created an account, tell us and we will remove it.
Changes
If we change anything material here we will change the date at the top. If the change affects what we do with data we already hold, we will say so rather than relying on you re-reading the page.