Privacy Policy
Last updated: 11 September 2026
WordNest is a vocabulary learning app available at wordnestapp.com. This policy explains what data we collect, why we collect it, who processes it on our behalf, and how you can get a copy of your data or delete it. We do not sell your data, we do not run advertising, and we do not use tracking pixels or cross-site trackers.
1. Data we collect
- Account data — email address, password hash, username, display name and avatar. If you sign in with Google or Apple, we receive your email, name and profile picture from that provider.
- Learning data — the words and decks you create, review history, review stages and due dates, XP, coins, streaks, achievements and your garden layout.
- AI Diary entries — the diary text you write and the AI review of it (see section 4).
- Social data — friend requests and accepted friendships, plus decks you choose to share via link.
- Product analytics events — see section 6.
- Push subscription data — only if you turn notifications on (see section 7).
- Technical logs — IP address, browser type and timestamps recorded by our hosting and database provider for security and debugging.
We do not knowingly collect data from children under 13 (or under 16 where local law requires it).
2. Database, authentication and storage (Supabase)
WordNest stores all account and learning data in a managed PostgreSQL database provided by Supabase, which acts as our data processor. Supabase also handles authentication (sessions, password hashing, OAuth token exchange) and file storage.
The following is stored there:
- profiles — username, display name, avatar, level, XP, coins, streak, garden layout;
- cards and decks — your words, translations, examples and review schedule;
- diary entries — your text and the AI-reviewed version;
- friendships — who you are connected with;
- push subscriptions — browser endpoint and keys, if enabled;
- analytics events — see section 6;
- storage buckets — your avatar image and cached pronunciation audio files.
Access is protected by row-level security: your rows are readable only by your authenticated session, except for data you deliberately make visible (your public profile, your garden to accepted friends, decks you share by link).
3. AI features and third-party AI providers
Three features send text to external AI providers through the Lovable AI Gateway. The gateway routes requests to Google (Gemini models) and OpenAI (text-to-speech). We do not send your name, email or user ID with these requests.
- AI example sentences — the word or phrase on the card is sent so a natural example sentence can be generated.
- AI Diary — the full text of the entry you submit is sent for review. See section 4.
- Pronunciation (text-to-speech) — the word or short phrase (up to 100 characters) is sent so audio can be generated. The resulting audio file is cached in our private storage bucket under a hash of the text, with no link to your account, so the same word is not regenerated for other users.
These features run only when you trigger them. If you never press the AI or pronunciation buttons and never write a diary entry, no text leaves our systems for AI processing.
4. AI Diary — a note on sensitive content
AI Diary is free-text writing about your own life. It may contain highly personal information — health, relationships, beliefs, finances, or details about other people. Please read this section before using it.
- When you press the review button, the entire text of that entry is transmitted to an external AI provider (Google Gemini via the Lovable AI Gateway) for grammar and phrasing correction. The provider returns a corrected version, a short title and a list of corrections.
- Entries and their AI corrections are stored in our database, tied to your account, and are readable only by you.
- Nothing you write in the diary is shown to friends, published, or used to train our own models.
- We ask AI providers to process requests for inference only, but we do not control their infrastructure. Please avoid writing information you would not want processed by a third-party service — for example medical records, government identifiers or payment details.
- You can delete any diary entry at any time; deleting it removes it from our database.
The legal basis for processing diary content is your consent, given by choosing to write an entry and submit it for review. You can withdraw it simply by not using the feature and deleting past entries.
5. Text-to-speech (pronunciation)
Pronunciation audio is generated on demand by an OpenAI speech model via the Lovable AI Gateway. Only the word or short phrase being pronounced is sent — never your account details. Generated MP3 files are cached in a private storage bucket keyed by a hash of the text and accent, so they contain no personal data and are shared across users. If speech generation is unavailable, your browser's built-in speech synthesiser is used instead, which processes the text locally on your device.
6. Product analytics
WordNest uses first-party analytics only. We do not use Google Analytics, Google Tag Manager, Meta Pixel, or any other third-party advertising or tracking service, and we do not place advertising cookies.
Analytics events are written to our own database and only for signed-in users. Each event contains your user ID, an event name (for example signup_completed, daily_bonus_claimed, or a study-session event) and a small set of numeric properties such as how many cards were answered correctly. We use this to understand which learning features work and where people get stuck — not to profile you or target advertising. Events are deleted together with your account.
7. Push notifications
Push notifications are optional and switched off by default. Nothing is registered until you explicitly turn reminders on and then grant permission in your browser prompt.
When you turn them on, we store the push subscription your browser generates — an endpoint URL and two encryption keys — together with your notification preferences. We use it only to send study reminders, streak and daily-bonus reminders, and friend activity, according to the preferences you choose. Delivery goes through the push service of your browser vendor (for example Google or Apple), which receives the endpoint and the encrypted message.
You can turn notifications off at any time in your WordNest profile settings or in your browser or device settings; turning them off deletes the stored subscription.
8. Cookies and browser storage
WordNest does not use advertising or tracking cookies. We use the following, all of which are necessary for the app to work:
- Session storage of your login — an authentication token kept in your browser so you stay signed in.
- Preferences — your chosen interface language, whether you have seen the welcome screen or the install hint.
- Local copies of your garden layout — so the app opens instantly and works offline.
- A service worker and its cache — used to serve pages and images offline as a progressive web app.
- Temporary values during sign-in — such as a deck code you opened before signing in, cleared immediately after use.
Web fonts are loaded from Google Fonts, which receives your IP address and browser type when the font file is requested.
10. How long we keep data
Account, learning and diary data are kept for as long as your account exists. Analytics events are kept for up to 24 months. Push subscriptions are removed when you disable notifications or when the browser endpoint stops being valid. Cached pronunciation audio contains no personal data and is kept indefinitely. When you delete your account, everything linked to it is deleted.
11. Your rights and deleting your data
If you are in the EU, EEA or UK, the GDPR gives you the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time. These rights are available to all WordNest users regardless of location.
To exercise them:
- Edit your profile, decks, cards and diary entries directly in the app.
- Turn notifications off in your profile settings to delete your push subscription.
- To request a copy of your data or full deletion of your account, email us at hello@wordnestapp.com from the address on your account. We respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority.
12. Legal basis for processing
We process account and learning data to perform our contract with you (providing the app). AI Diary, AI examples, pronunciation and push notifications are processed on the basis of your consent, given each time you use or enable the feature. Product analytics and security logging rest on our legitimate interest in operating, securing and improving WordNest.
13. Changes and contact
If we make material changes to this policy we will update the date at the top and, where appropriate, notify you in the app. Questions about privacy can be sent to hello@wordnestapp.com.
See also our FAQ and guide to spaced repetition.
