This page describes, in plain language, what Enkode's browser permissions are used for, what data leaves your device and why, and what Enkode never collects. It mirrors the answers on Enkode's Chrome Web Store privacy-practices listing. For the full policy, see the Privacy Policy.
Single purpose
Enkode translates portions of the pages you read to teach you a language.
Why Enkode requests each permission
| Permission | What it's used for |
|---|---|
| Active tab | Lets Enkode access the current page only after you invoke the extension, so it can run manual translation on that tab. |
| Scripting | Injects Enkode's page script into the active tab after you choose to run Enkode, or into sites where you have granted Auto-Enkode access. |
| Optional site access | Reads article-like text only on sites where Enkode runs so it can replace or mark a portion of that text with translations. Auto-Enkode asks for access to each site you add; you can also run Enkode manually on the current page through active-tab access. |
| Storage | Saves settings, Auto-Enkode site rules, auth session, local word-bank mirror, translation cache, tutor content, quiz progress, reading stats, sync outboxes, study reward state, and short local activity logs so the extension works between sessions and can sync when signed in. |
| Favicon | Shows site icons next to the Auto-Enkode site list in Settings so you can recognize the sites you have added. |
| Side panel | Opens the AI tutor in Chrome's side panel next to the page. |
| Identity | Signs you in with Google so your word bank, topics, quiz progress, reading progress, and usage records belong to your account. |
Enkode does not request required access to every site at install time. Manual translation uses active-tab access after you invoke the extension, and automatic translation uses optional host access for sites you add.
What data leaves your device, and why
| Data | Where it goes | Why |
|---|---|---|
| A portion of the sentences on pages where Enkode runs, plus text you select; page URL and title when classifying a saved word's topic | Our Supabase function → OpenAI | To translate text, explain selected words, lemmatize words, classify topics, generate quiz options, and create tutor lessons. Enkode does not write live request text to its Supabase database unless you save the resulting word or learning item. Token counts are stored for usage accounting, quotas, and rate limits. |
| Words and phrases you save, with their meanings, translations, source sentence, translated sentence, page URL, page title, topic, and review state | Supabase (your account) | To build your word bank and quizzes and sync them across your browsers. |
| Word-bank topic settings | Supabase (your account) | To keep your custom topic list and saved-word topic assignments in sync. |
| Quiz answers | Supabase (your account) | To schedule reviews, score progress, and maintain an answer ledger. Synced rows include correctness, grading reason, quiz style, entry ID, lemma/topic snapshot, and answer time; they do not store your typed guess as a separate field. |
| Daily reading-word counts | Supabase (your account) | To power reading progress and the plant-growth widget. Synced rows include language pair, local date, credited word count, and flush time. |
| Study reward events and point totals | Supabase (your account) | To award points and show progress. Synced rows include reward action, related word-bank entry, points, timestamp, source, and metadata needed to prevent duplicate awards. |
| Your email, Google account ID, and basic Google profile information | Google → Supabase | To create and identify your account when you sign in. |
| Per-request token usage counts, model name, timestamp, and user ID when available | Supabase (your account) | For cost accounting, daily quotas, rate limits, and operational monitoring. |
| Anonymous product-analytics events — which action happened (install, sign-in, enkode a page, save a word, answer a quiz, open the tutor, change languages, export or delete data), app version, surface, timestamp, simple counts, your language pair, and a hashed domain when you add a site to Auto-Enkode | PostHog | To see which features are used and where the experience breaks. Contains no page text, page titles, or URLs. Tied to your account ID when signed in, otherwise to a random per-install ID. Opt out any time in Settings → Account & data → "Share anonymous usage data" — nothing is sent while it is off. |
| Local browser data | Your browser's extension storage | To make the extension fast and resilient. This includes settings, Auto-Enkode site rules, translation cache, tutor content, local word-bank mirror, quiz progress, reading stats, reward state, sync outboxes, auth session, and short activity logs. Some of this local data may include original sentences, translations, selected words, source URLs, and page titles. |
What Enkode never collects
- Your full browsing history or a list of every page you visit. Source URLs and titles are handled only when tied to saved-word context, local reading-session records, or topic classification for a saved item.
- Page content from sites you have not added to Auto-Enkode, unless you manually run Enkode there. Auto-Enkode is an allowlist: it runs automatically only on sites you add.
- Passwords, form entries, or payment card details. Enkode reads page text only; it never reads the contents of input fields.
- Page text, page titles, or URLs in analytics. Product-analytics events carry actions and counts only. Adding a site to Auto-Enkode records a short hash of that one domain — never the domain itself, and never the other sites you visit.
Compliance
Enkode's use and transfer of information received from Google APIs and from the Enkode browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell your data, and we do not use it for any purpose unrelated to teaching you a language.