Enkode is a Chrome extension and companion website that teaches vocabulary by replacing portions of the pages you read with translations, saving words you choose, and quizzing you on them over time. This policy explains what data Enkode collects, who processes it, how long it is kept, and the choices you have. It applies to the Enkode browser extension and this website.
What we collect
Enkode collects only what it needs to translate text and track your learning:
- Page text sent for translation. When Enkode runs on a page, it reads article-like text blocks and sends the subset of sentences it needs to translate through our Supabase Edge Function to OpenAI. The subset is based on your replacement-rate settings and sentence limits; it is not intended to be the whole page. Enkode may also send selected words or phrases, the sentence around them, and generated translations for word lookup, tutoring, lemmatization, topic classification, and quiz-option generation. For saved-word topic classification, Enkode may also send the page URL and page title. Enkode does not write these live translation requests to our Supabase database unless you save the resulting word or learning item, but token usage is logged for cost accounting, quotas, and abuse prevention.
- Saved words and learning context. When you save a word or phrase, we store the saved text, its meaning or translation, lemma, part of speech, generated forms, accepted answers, topic, review state, source sentence, translated or enkoded sentence, page URL, page title, and language pair so we can build your word bank, sync it across browsers, and quiz you later.
- Word-bank topics. If you manage custom topics, we store the topic list and the topic assigned to each saved word.
- Quiz answers. We store quiz-answer history, including the word-bank entry, whether the answer was correct, grading reason, quiz style, topic, part of speech, and answer time. We do not store your typed guess as a separate quiz-answer field.
- Daily reading-word counts. We store daily counts of enkoded words credited as read, language pair, local date, and flush timestamps to power progress views.
- Study rewards and points. We store reward events for actions such as saving a word, playing pronunciation, or mastering a word, including the related word-bank entry, reward action, points, timestamp, source, and small metadata needed to prevent duplicate awards and show progress.
- Account identity. When you sign in with Google, we receive your email address, Google account ID, and basic profile information returned by Google OAuth, such as your name and profile image. We use this to create your account, show account UI, and associate your data with you.
- Usage metering. For each LLM request, we store model name, prompt-token count, completion-token count, timestamp, and user ID when available. We use this for cost accounting, quota limits, rate limiting, and operational monitoring.
- Product analytics. Unless you turn it off, Enkode records anonymous events about how the extension is used — install, sign-in, enkoding a page, saving a word, answering a quiz, opening the tutor, changing languages, exporting or deleting your data — each with the app version, the surface it happened on (popup, options, page, background), a timestamp, and simple counts. These events carry no page text, no page titles, and no URLs. The one exception is adding a site to Auto-Enkode, which records a short irreversible-by-design hash of that site's domain (not the domain itself, and not any other site you visit) so we can count how many distinct sites people enable. Events are tied to your account ID when you are signed in, and otherwise to a random per-install ID that is discarded when you sign out. On sign-in we also record your native/learning language pair. You can turn all of this off in Settings → Account & data → "Share anonymous usage data"; nothing is sent while it is off.
- Data stored locally in your browser. Settings, a translation cache, word bank mirror, sync outboxes, auth session, tutor content, quiz progress, reading stats, Auto-Enkode site settings, and short local activity logs are kept in browser storage. The local translation cache can include original sentence text, translated text, word lookups, lemmas, generated quiz options, and tutor outputs so repeated lookups do not always need another API request. Signed-in word-bank, quiz, reading-credit, topic, and usage data is mirrored to your account in Supabase.
What we never collect
- Your full browsing history or a list of every page you visit. We handle source URLs and titles only when they are part of saved-word context, local reading-session records, or topic classification for a saved item.
- Page content from sites you have not added to Auto-Enkode, unless you manually run Enkode on that page. Auto-Enkode is an allowlist: it runs automatically only on sites you add.
- Passwords, form entries, or payment card details.
Who processes your data
We rely on a small number of third-party processors, each for a specific purpose:
- Supabase — authentication, database, and server functions. Your account, word bank, topic settings, quiz answers, reading counts, study reward events, point totals, usage records, and account-deletion/export workflows are handled through our Supabase project.
- OpenAI — performs the translations and AI tutoring. Text you choose to translate or analyze passes through OpenAI's API. Source page URL and title may also be sent when they are needed to classify a saved word's topic. OpenAI states that API inputs and outputs are not used to train or improve OpenAI models by default unless the API customer opts in. OpenAI may retain API data for abuse monitoring or other purposes described in its platform data controls.
- Google — provides sign-in (OAuth). Google authenticates you and returns your email and account ID; we do not receive your Google password.
- PostHog — product analytics. If you leave "Share anonymous usage data" on, the events described above are sent to PostHog, which also receives the IP address the request came from (used for coarse country-level geography and then discarded from the event). PostHog never receives page text, page titles, URLs, or the contents of your word bank. Turning the setting off stops all transmission.
- Stripe (only if you subscribe). Enkode does not currently process payments. If paid plans are introduced, Stripe will handle all payment information. Stripe sees your payment details; Enkode never does.
How long we keep it, and deletion
Your account data is kept for as long as your account exists unless you delete it or ask us to delete it. The extension includes self-serve data export and account deletion in Settings. You can also request deletion by emailing us at the address below. When your account is deleted, your Supabase account and associated rows — word bank, topic settings, quiz answers, reading counts, study reward events, and usage records — are removed along with it. The extension also clears local account-scoped browser data after account deletion. Live translation request text that was not saved to your word bank is not stored as a Supabase database row by Enkode, so account deletion mainly removes the saved learning data, ledgers, and usage records described above.
Your rights
You can access the words and progress we hold for you at any time through the extension or the Saved Words page. The extension includes a self-serve export for primary learning data, including word-bank entries, quiz answers, study reward events, and reading-credit events. You may request a broader copy of your data or its deletion by contacting us. Depending on where you live, you may have additional rights (access, correction, deletion, portability) under laws such as the GDPR or CCPA; email us to exercise them.
You can opt out of product analytics at any time in the extension's Settings → Account & data, under "Share anonymous usage data". The toggle takes effect immediately and applies to every surface of the extension.
Chrome Web Store Limited Use disclosure
Enkode's use and transfer of information received from Google APIs and from the Enkode browser extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes to this policy
We may update this policy as Enkode evolves. When we do, we'll revise the "Last updated" date above; material changes will be highlighted on this page.
Contact
Questions or requests about your data? Email privacy@enkode.xyz.