Privacy Policy
Privacy at Vocabao.
Effective August 23, 2026
What Vocabao handles
Search terms are sent to the Vocabao API so it can return dictionary results. Search requests are anonymous, but operational request logs may contain the requested URL and are retained for 30 days.
Sentence ladders store the submitted text, generated sentence and steps, status, failures, and provider request metadata under a random lesson identifier. OpenAI processes sentence requests with provider storage disabled.
If you use Sign in with Apple, Vocabao stores Apple’s account identifier and any name or email Apple provides. Account sessions may remain valid for up to 180 days. Deleting the account removes its account and session records.
Website analytics
The mobile app does not include an analytics client or send product analytics events. The website uses Cloudflare Web Analytics for aggregate traffic and performance measurement.
Cloudflare Web Analytics does not use cookies, local storage, persistent visitor identifiers, or fingerprinting. It measures page views, page paths, referrers, country, device type, browser, operating system, and page performance. It omits URL query strings and does not give Vocabao raw IP addresses or individual visitor profiles.
Vocabao does not add search terms, words, characters, sentences, lesson identifiers, language names, names, email addresses, account identifiers, authentication data, or error details as analytics properties. Vocabao does not use analytics for advertising or cross-company tracking.
Retention and requests
Vocabao keeps account data until account deletion, sessions for no more than 180 days, and operational logs for 30 days. Sentence and aggregate analytics data are kept only while they are reasonably needed to operate, secure, understand, and improve Vocabao, then deleted or further aggregated.
For privacy questions or deletion requests, email hello@vocabao.com.