Privacy Policy
Introduction
At LingoKeep, we take your privacy seriously. This Privacy Policy explains what we collect — and, just as importantly, what we deliberately do not — when you use our Chrome extension and website. The short version: we store your account, the flashcards and videos you explicitly save, and the ordinary server logs any website keeps, plus the website analytics described below. We do not track what you watch or browse.
Who We Are
LingoKeep is operated by Jun Zhang, a sole proprietor trading as LingoKeep, based in California, United States. For the purposes of the EU and UK General Data Protection Regulation, that is the data controller for the personal data described in this policy, and the person you reach at support@lingokeep.com. LingoKeep has no employees and no offices; there is one person behind this policy, and questions about your data reach him directly.
Information We Collect
Saved Flashcards
When you explicitly save a word or phrase as a flashcard, we store that card on our servers so it can sync across your devices and appear in your review queue. A card contains the word or phrase, the subtitle sentence it came from, its translation and dictionary glosses, the video ID and timestamp it was saved from, and its spaced-repetition scheduling state. We also keep a log of each review you do — the card, the rating you pressed and when — because that history is what your schedule, your streak and your statistics are computed from. Cards are only ever created by your explicit action; nothing is saved automatically.
Starred Videos
When you star a video, we store its video ID, title, channel, duration and the target language you were studying, so it appears on your Videos page across devices. For starred videos only, the extension also records how far into the video you had watched, so the page can offer to resume where you left off. This is the one and only place we keep a playback position, it is written only while a video is starred, and it stops the moment you un-star it. We do not record a position — or anything else — for videos you have not starred.
Account Information
If you create an account, we store your email address (and, for Google sign-in, your name and avatar as provided by Google). We record when a LingoKeep extension last synced with your account and which version it was, so the site can tell whether the account already has a working extension somewhere rather than asking you to install one you already run. If you subscribe to Pro, payment is processed by Stripe; we store your subscription status and Stripe customer ID but never see or store your card details.
Newsletter
If you subscribe to our newsletter we store the email address you gave us, which page you gave it on, the IP address the request came from and when — that pair is the record that you consented — and whether you have confirmed. It is double opt-in: nothing is sent to an address that has not clicked the confirmation link, and every mail after that carries a one-click unsubscribe. We use the list for product news about LingoKeep and nothing else, and we never sell or rent it.
Messages You Send Us
The contact form sends your name, email address and message to our support inbox, so we can answer you; we keep the thread for as long as it is useful for support. The uninstall survey is the opposite — it has no email field and is not tied to your account or to any identifier: the reason you pick and the optional note are the whole message.
Subtitle Translation
LingoKeep prefers translations that never leave your machine: first YouTube's own translated subtitle track, then your browser's built-in on-device translator. Only when a video offers neither do we fall back to translating in the cloud — and then the subtitle text of the cues on screen is sent to our server, which forwards it to OpenRouter, a US model-routing provider, to be translated by the large language model we have selected there (today Google's Gemini). Only the cue text and the two language codes are sent; the video ID, your identity and your account are not. Translations are cached on our servers, keyed by a hash of the text itself and shared across everyone watching the same video, so a popular video is usually translated once for all of us. We separately count how many cues we translated for your account each day, which is how the fair-use allowances in our Terms are enforced; that counter is a number, not a record of what you watched.
Dictionary Lookups
Clicking a word, and building the word list for a video, send that word or list of words — and, for a single click, the subtitle sentence it appeared in, so the dictionary can tell apart words that are spelled the same — to our dictionary so we can return definitions. The dictionary never reads your sign-in and no video ID is sent; neither the words nor the results are stored against your account, so we cannot reconstruct what you looked up or what you were watching from them. Pronouncing a word uses your browser's own text-to-speech; Chrome synthesizes some of its voices in the cloud, in which case the word is sent to Google by the browser itself.
Server Logs
Like any website, our servers keep an access log of the requests they receive. Each entry records the time, the HTTP method, the API path (never the query string, so a looked-up word never lands in a log), the response status, how long it took, your IP address and browser user-agent string, and — if you were signed in — your user ID and email. We use these logs to operate the service, debug failures and investigate abuse. They live on the same EU infrastructure as the rest of the service and are deleted after 90 days (see Data Retention); they are not used to build profiles.
Website Analytics
Our website (not the extension) uses Google Analytics to understand page traffic, sign-ins, and which calls-to-action people press — and it loads only if you allow it at the cookie banner. Decline and no analytics script loads at all; the site works exactly the same. You can change your answer any time via "Cookie preferences" in the footer, or the Privacy tab under Settings when signed in. When allowed, alongside the standard page-view data we record your browser's interface language as a language code only — "es", "zh" — never the country or region variant, for one purpose: to decide whether it is worth offering LingoKeep's interface and translations in languages other than English. The extension itself sends no analytics of any kind.
Cookies
When you sign in we set a session cookie; it is what keeps you signed in, and the service does not work without it. A handful of preference values are kept on your own device — whether the sidebar is collapsed (a cookie, so the page can render right the first time), your study language, theme and similar interface choices, and your analytics answer itself — none of which identify you or leave your browser. Google Analytics sets its own cookies on the website only after you allow it at the banner. We use no advertising cookies and run no ad networks.
What We Do Not Collect
We do not collect your browsing history or your YouTube watch history. The extension does not report which videos you watch, what you search for, or which words you look up. Nothing about a video reaches us unless you save a card from it or star it, and both are deliberate acts. We do not sell your data, share it with advertisers, or use it to train AI models.
Extension Permissions
The extension runs on two sites and no others: youtube.com (to render dual subtitles, the dictionary popup and the capture controls on the player) and lingokeep.com (to sync your saved cards and videos to your account, and to let the site tell that the extension is installed). It does not request access to any other website, and it never uses the wildcard all-sites permission.
Beyond those two sites it requests three Chrome permissions:
- storage — to keep your cards, settings and sync state on your own machine, so the extension works offline and does not have to ask our servers for everything
- alarms — to wake the extension every few minutes to sync
- scripting — used in two places, both on the two sites above. On lingokeep.com, to mark a tab that was already open when you installed the extension, so the install page stops telling you to install it. On a YouTube watch page, to run a small script that reads the player's own caption-track list, which is the only reliable way to know which subtitle languages a video offers. That script talks to the player and to us, never to a server
The extension also fetches one small configuration file from lingokeep.com once a day. It contains nothing but CSS selectors — the names of the YouTube page elements our reading mode hides while you study — so that we can repair them when YouTube changes its markup without shipping you an update. It is data, never code: we keep only the plain-text values and discard everything else, and nothing in it is ever executed. LingoKeep is not an ad blocker and does not block, hide or alter ads: selectors that look like advertising slots are refused, and the reading mode hides the recommendations list itself rather than the sidebar holding it, precisely so YouTube's own ad slot in that sidebar keeps working.
There is one optional permission, for http://127.0.0.1:8765, which is the address the AnkiConnect add-on listens on. It is used only for the one-click push of your cards into a copy of Anki running on your own computer, Chrome asks you for it the first time you use that button, and nothing is sent anywhere but your own machine. If you never push to Anki, you are never asked and the permission is never granted.
How We Use Your Information
- To sync your saved flashcards and videos across devices and schedule your reviews
- To translate subtitles when no on-device translation is available
- To process and manage Pro subscriptions, and to enforce plan limits and fair-use allowances
- To provide customer support
- To notify you about changes to our service or policies
- To detect, prevent and address technical issues and abuse
Our Legal Bases
If you are in the European Economic Area or the United Kingdom, data protection law requires us to name a legal basis for each of those uses. Ours are:
- Performance of a contract — your account, the cards and videos you save, syncing them across your devices, computing your review schedule, subtitle translation, dictionary lookups, and processing a Pro subscription. This is the service you asked us for; without this data there is no service to give you
- Consent — the newsletter, and website analytics. Both are off until you say yes, and you can withdraw either at any time (unsubscribe from any newsletter; "Cookie preferences" in the footer, or the Privacy tab under Settings, for analytics). Withdrawing does not affect anything we did before you withdrew
- Legitimate interests — server logs, enforcing plan limits and fair-use allowances, and preventing abuse. Our interest is keeping a small service running, secure and affordable; we have weighed it against your privacy and kept the data narrow and short-lived to match (see Data Retention). You may object to this processing at any time
- Legal obligation — retaining what tax and accounting law requires us to keep about a payment, and responding to a lawful request
Who We Share It With
We do not sell your data. We share it only with the service providers that make LingoKeep run, and only with what each one needs:
- Stripe — payments and subscription management. Stripe receives your email and handles your payment details directly; we never see them
- Google — sign-in with Google (if you choose it), and Google Analytics on the website
- OpenRouter, and through it the provider of the language model we have selected — cloud subtitle translation, as described above. They receive subtitle text and language codes, never your identity
- Amazon SES — the last hop of every email we send. We render the message on our own mail service and hand it to SES (in the United States) for delivery, so SES processes the recipient address and the message body on our behalf. It is how sign-in links, subscription notices, support replies and newsletters reach you
- Cloudflare — public ingress. Every request between your browser and us travels through a Cloudflare tunnel, so Cloudflare carries the traffic, and the connection metadata that comes with it, in transit
- Hetzner — the servers, database and logs the service runs on, in Falkenstein, Germany
We may also disclose information where the law requires it, or where it is necessary to protect our rights or the safety of our users.
International Transfers
Your data is stored in the European Union: our servers, database and logs run at Hetzner in Falkenstein, Germany. LingoKeep is nevertheless operated from the United States, and the other providers above — Stripe, Google, OpenRouter, Amazon SES and Cloudflare — are US companies, so if you are in the European Economic Area or the United Kingdom, parts of your data are transferred to the US by them even though the copy of record stays in the EU. Where a provider participates in the EU–US Data Privacy Framework and its UK extension, we rely on that; where one does not, the transfer is covered by the European Commission's standard contractual clauses in our agreement with them, together with the technical measures described under Data Storage and Security. Email us and we will tell you which mechanism covers a particular provider and how to obtain a copy.
Data Retention
Your cards, videos and review history are kept for as long as your account exists. When you delete a card or un-star a video, it disappears from your account immediately, but a record that it was deleted is kept for 90 days — that marker is the only way your other devices learn about the deletion instead of restoring the item on their next sync. After 90 days the marker is removed too. Cached subtitle translations expire 90 days after they were created, the daily translation counters after about two months, and server logs are deleted after 90 days. When you delete your account, your account and everything attached to it — cards, review history, starred videos, subscription records, and any newsletter subscription under the same email — are deleted from our database. Our providers' own records (for example the invoices Stripe is required to keep) follow their own retention schedules.
Data Storage and Security
Your cards and account data are stored in our database and are accessible only to your account. That database, the servers it runs beside, and our logs are hosted at Hetzner in Falkenstein, Germany, inside the EU. All communication between the extension, the website, and our servers is encrypted using SSL/TLS. We implement industry-standard security measures to protect your account information.
Your Data Rights
You have the right to access, export and erase your data. Signed in, the Privacy tab under Settings does the first and the last of those for you directly: it downloads everything we hold on your account, or deletes the account outright. Specifically, you can:
- Download a copy of everything we hold on your account — account information, cards, review history, starred videos, subscription records and newsletter subscription
- Export your cards to Anki — a CSV download on Pro, or one-click push from the extension
- Delete individual cards, or your entire account and everything in it
- Opt out of marketing emails, from any newsletter we send
- Ask us anything about how your data is used, and get an answer
Deleting your account is immediate and cannot be undone, so export first if you want to keep your deck.
If you are in the European Economic Area or the United Kingdom you also have the right to correct inaccurate data, to restrict or object to processing we base on legitimate interests, and to receive the data you gave us in a portable form — which the export above already does. Ask us at support@lingokeep.com and we will answer within one month.
If you are unhappy with our answer, you have the right to lodge a complaint with the data protection supervisory authority in the country where you live or work, or where you believe the problem occurred — in the UK, the Information Commissioner's Office. You do not need to come to us first, though we would rather you did, because we can usually fix it faster.
LingoKeep has not designated a representative in the European Union under Article 27 GDPR. Our processing of EEA residents' data is limited in scale and involves no special-category data, and we are reachable directly and promptly at the address and email above. We keep this under review and will appoint a representative if that ceases to be true.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: support@lingokeep.com
- Post: a postal address is available on request — email us and we will provide it