Privacy Policy
The short version
- Your study data lives on your device. Cloud sync is optional and happens only if you sign in.
- AI features send relevant content to your chosen provider. Saved study content, including chat and writing history, may also sync to your account.
- The extension answers most word lookups from a dictionary bundled inside it — on your device, with no network request for the definition. Online lookups, translation, and signed-in saving can send data off your device. Google Translate fallback, dual subtitles, and automatic word saving default to on.
- Study reminders and notifications are generated on your device. There is no push server.
- No ads, no analytics or tracking SDKs, and we never sell personal data.
1. Who we are
Korean by muratodesu is an independent Korean-vocabulary study app operated by its developer ("we", "us"). For anything in this policy, contact yuruzurumu@gmail.com.
2. Data stored on your device
In the app
The app is local-first. Your vocabulary deck, starred and known words, custom lists, spaced-repetition schedules, session history, streaks, achievements, goals, personal word notes, diary entries, and settings are stored in your browser's local storage. A custom background photo, if you set one, and your reminder schedule are stored in your browser's IndexedDB. The background photo stays on your device. Signing in enables cloud sync of supported study data; online features such as AI and article fetching also send the data described below, even without sign-in. You can remove all of it by clearing the site's data in your browser.
In the extension
- Settings are kept in your browser's extension storage. Most settings use the browser's "sync" storage area, which your browser may sync between your own devices through your own browser account. This includes site allowlists, blocklists, and per-site preferences containing hostnames.
- Lookup history (your last 50 lookups) and caches of lookup and translation results are stored locally. Caches expire on their own (roughly 30 days for word lookups, 7 days for sentence translations). Daily lookup/save counts and streaks are also stored locally to show your own usage; they are not sent to an analytics service.
- A local mirror of your deck (your saved words, known words, and review-due dates) is stored so lookups can show your study state instantly.
- If you enter an API key directly in the extension, it is stored in local extension storage only — never in browser-synced storage.
- Your account identifier and access/refresh tokens shared by the app are held in session storage. The extension can retrieve your account's saved AI key and provider settings from Supabase and cache them in session storage to contact that provider directly. These session copies are cleared when the browser closes or the sign-in session changes.
Uninstalling removes the extension's storage from that browser. It does not delete your cloud account, shared dictionary entries, copies on other devices, or records held by service providers.
3. Optional account and cloud sync
You can use the app without an account. Supabase handles email-and-password sign-in, or Google sign-in on the website and installed web app. The native app uses email sign-in. We store your email address and an account identifier. If you choose Google, Supabase also receives basic profile information supplied by Google, which can include your name and profile image; the app does not request access to your Gmail or Drive. We also store the study data the app syncs so your progress follows you across devices: custom vocabulary, starred and known words, custom lists, spaced-repetition data, session history and streaks, achievements, challenge and goal state, writing-practice history, grammar progress, personal word notes, chat sessions and custom personas, story-adventure sessions and history, a cache of AI "related words" answers, and your AI provider choice, model names, and endpoint URL.
If you save an AI API key while signed in, it is stored encrypted at the database level and is readable only through access-controlled functions tied to your account. All synced rows are protected by row-level security, to restrict ordinary app access to the owning account. Authorized service operations also process this data. Sync data is stored with Supabase (managed Postgres).
Account confirmation, password-reset, and other authentication emails are delivered through Resend. This shares your recipient address, the message content (including authentication links or codes), and delivery information with the email provider. These messages are for account access, not a marketing mailing list. Never share their links or codes. See also Supabase’s privacy policy and Google’s privacy policy.
4. AI features and third-party AI providers
AI-powered features (dictionary explanations, reading analysis, chat and roleplay practice, writing feedback, generated exam questions, natural-voice audio, image text extraction, and similar) work by sending the content needed for that feature to the AI provider you configured — OpenAI, OpenRouter, or a custom OpenAI-compatible endpoint — normally using your own API key. Depending on the feature, that content can include: words and sentences you look up (with short surrounding context), text you paste or fetch for reading practice, your chat messages, writing you submit for correction, text to be spoken aloud, transcripts of your speech input, and images you explicitly submit for text extraction.
These requests go from your device to the provider, or through our serverless function for some signed-in extension requests — see section 6. Saved results and conversations can be stored locally and synced as described in section 3. Once content reaches your chosen provider, that provider's own privacy policy governs its processing, so please review it. The extension's Google Translate fallback is enabled by default and can send lookup words and sentence/subtitle text to Google when the applicable AI path is unavailable. You can turn it off under Account → Use Google Translate. Where supported, selecting the on-device translation engine processes translation text locally; downloading its language model may require a connection. Other features, such as account sync and online dictionary lookups, remain separate.
5. Speech input and output
Speech recognition (hold-to-talk, pronunciation practice) uses your browser's built-in speech service. Depending on your browser, audio may be processed on the browser vendor's servers (for example Google's, in Chrome) under that vendor's privacy policy. Speech output uses your device's built-in voices, or — if you enable the natural voice — sends the text to your configured AI provider to generate audio.
6. Our servers and infrastructure
- Web hosting (Vercel). Serves the app. When you use "fetch article from URL", the URL you provide is sent to our serverless function, which retrieves the page and returns its readable text to you; the app can retain the returned article locally, and request metadata may appear in hosting logs.
- Supabase. Provides sign-in, the sync database, and the serverless function the extension uses for signed-in lookups. That function reads your encrypted API key and forwards your request to your AI provider. The extension can also retrieve your saved key to contact that provider directly. Requests are processed to produce answers; saved study data and shared dictionary results are stored as described below. Deck/configuration refresh currently retrieves your account's full synced study-data record, which can include saved chat and writing history, before retaining the deck subset locally.
- Shared dictionary cache (Supabase). When signed in, the app and extension can read and contribute AI dictionary results for reuse by other signed-in users. Entries contain the lookup term, generated dictionary fields, model name, and creation/update timestamps. The dedicated page-context sentence fields are removed before storage; the cache has no account-owner field. This is shared dictionary content, separate from your private deck. Entries have no automatic expiry and are not removed by account deletion. Do not submit private names or confidential text as dictionary terms; contact us if a shared entry needs removal.
- Reading sources and fonts. RSS feeds are requested directly from publishers, with AllOrigins or corsproxy.io as fallbacks when needed. Article import may also use AllOrigins. These services receive the requested URL and standard request information. Article thumbnails and images load from their image hosts. Fonts load from Google Fonts. These hosts can receive your IP address and browser request metadata. Opening an original article takes you to the publisher’s own site and privacy policy.
- Logs. Infrastructure and email providers may retain request or delivery logs, including IP addresses, timestamps, status, and request metadata, for operations and abuse prevention. Their retention periods and backup practices depend on the provider and service configuration.
7. The browser extension, specifically
- It reads the text of pages you visit locally, inside your browser, to detect Korean words and make them tappable. Detecting and highlighting Korean text happens locally. Hover lookup is enabled by default: resting your pointer on a Korean word can start an online lookup if local sources cannot answer it, without a separate click.
- Online lookups send the word and, where needed, surrounding sentence context to the configured AI service, Google Translate fallback, or Supabase. Read mode, transcript translation, and article/subtitle preparation can process multiple paragraphs, subtitle lines, or vocabulary items in batches. Read mode is off by default, but can run automatically after you enable it. Image extraction sends images you select or include in a page-image scan to your AI provider; fetching those images also contacts their original hosts.
- On video sites (YouTube, Netflix, and similar), it reads subtitle data the site has already delivered to your browser and can fetch subtitle tracks from the video service to display transcripts and dual subtitles. Video features and dual subtitles are on by default. Where a translation is needed, current and upcoming Korean lines can be sent to the translation service in batches without clicking each line. Choose Korean-only subtitles or turn video features off to stop this automatic subtitle translation.
- Automatic word saving is on by default when signed in. Eligible looked-up or prepared words, their definitions, and example sentences (which may come from the page or subtitle) can be saved to your private Supabase study deck. Turn off automatic saving to use the manual Save control instead. Account tokens and deck state also refresh in the background while signed in.
- Read in app opens the companion website with the selected page URL in its address, so that URL reaches our hosting service and may appear in request logs. Extracted article text and title are handed to the app through a temporary browser-storage entry: it is consumed once and refused after ten minutes. The app can then analyze the text with your AI provider or fetch the source URL if the handoff is unavailable. It can retain the article locally. This transfers the article you choose, not a log of all pages you visit.
- The extension handles page URLs, subtitle resources, and site-specific settings for these features; it does not maintain a general browsing-history log or track you across sites for advertising. Text you choose to translate on a message or email page can include personal communications. Such content goes to the same translation providers, so avoid using online features on content you do not want to share. Its permissions exist solely to power Korean reading and study features.
Limited Use. Korean Lens by muratodesu uses data obtained through Chrome APIs only to provide or improve its Korean reading and study features, in accordance with the Chrome Web Store User Data Policy, including its Limited Use requirements. We do not sell this data or use it for advertising, creditworthiness, or lending. Transfers support these features through the services described in this policy. Human access to such data is limited to your consent for specific content, security/abuse investigation, legal obligations, or aggregated, anonymized operations permitted by that policy.
8. Notifications
Study reminders are scheduled and shown entirely on your device, using your browser's notification support. We do not operate a push-notification server and no notification data leaves your device.
9. What we don't do
- No advertising.
- No analytics or tracking SDKs.
- No sale of personal data, and no sharing of personal data for marketing.
10. Retention and deletion
Data on your device is under your control: clear the site's data in your browser, use the app's data-management tools, or uninstall the extension. In the extension, Recent lookups → Clear removes local lookup history; the cache-clear control removes local lookup/translation caches; clearing a personal API key removes its local copy. These controls do not delete saved cloud words or the shared dictionary cache. Local lookup and translation caches expire as described in section 2. Site preferences may also be held in your browser account's sync service. A handoff entry is removed when consumed; its ten-minute expiry prevents reuse but is not a promise of timed physical deletion of an unconsumed entry.
Synced cloud data is kept while your account is active. You can delete your account at any time from inside the app: Settings → your signed-in email/account row → Delete account. After you confirm, the app deletes your authentication account and its associated synced database row, including study progress, notes, and the stored API key. It then clears the app’s local and session storage and removes the wallpaper on that device. This cannot be undone; export a backup first if you want to keep your study data. Copies on other devices, extension storage, browser caches, provider logs, and infrastructure backups are not all erased by that action. Clear site/extension data on those devices separately. Provider-held records follow their own retention policies. Signing out stops account syncing but does not delete your account or the local study copy.
If you cannot reach the in-app control for any reason, email yuruzurumu@gmail.com from the address you signed up with for help with deletion or requests to access or correct your data. We may need to verify that the account belongs to you before acting.
11. Security
The production website and configured Supabase services use HTTPS. Synced data has per-user access controls, and cloud-stored API keys are encrypted at the database level. On your device, saved settings, study data, sign-in sessions, and API keys rely on your browser’s storage protections; this is not end-to-end encrypted storage. A custom AI endpoint you configure has its own security practices. No system is perfectly secure, so we also recommend using an API key with a spending cap where your provider offers one.
12. Children
The app is not directed at children under 13, and we do not knowingly collect personal data from them.
13. International processing
The infrastructure named above (including Vercel, Supabase, Resend, Google, reading proxies, and your chosen AI provider) may process data on servers outside your country of residence.
14. Changes to this policy
If we change this policy, we will update this page and the date at the top. Material changes to what the app collects will be called out in the app's release notes.