Privacy policy
This describes what VocNova actually does with your words, as built. It is written to be read rather than to be defensible.
What we collect
Your email address, and a password we never see in the clear — it is stored as an argon2id hash. Signing in with Google gives us your address from Google instead.
A display name, a gender and a year of birth, if you answer those questions. All three are optional.
The two languages you chose, because every meaning and example is written between them.
The words you keep, their meanings, an example each, and how well you have been remembering them. For a word met in your messages or notifications, the example is the one sentence it arrived in — that sentence lives on the card, as part of your vocabulary, until you delete it.
Messages from any chat account you connect, and notifications from the apps you tick — only those apps, and only after you grant Android's permission yourself.
Photographs you take in the app, while they are being read. Every one of them is read by the language model, so every one of them leaves your phone. The app says so at the shutter.
Recordings of your own voice, if you use the listening exercises that ask you to read a passage aloud. Those never leave your phone — there is no way to send them to us and there is not meant to be one, so we do not have them and cannot listen to them. They are deleted when the passage goes and when you sign out. Nothing here scores your pronunciation.
A count of the minutes you spend on listening that is not marked. Only the minutes, only on your phone, and nothing about what you listened to.
Fault reports when something goes wrong: the kind of error, a scrubbed message, a stack trace and the build. The scrubbing happens on your phone, because your phone is the only side that knows which strings came out of your messages.
Your diary
There are two kinds of entry. An ordinary one opens with no PIN, on any device you are signed in on: it is encrypted on your phone and in transit with a key we issue to your account, which means we could read it. It has exactly the protection your messages have and no more.
An entry you lock is different. You choose a six-digit PIN; your phone derives a key from it with argon2id, and that key wraps the random key those entries are actually encrypted with. Only the wrapped key is uploaded, and the PIN never leaves your phone. Reading a locked entry needs both your account and your PIN, and we hold one of the two.
For entries you keep in the cloud we store the encrypted bytes and the dates. No title, no preview, no language, not whether you marked an entry for study, and not whether it is locked. Entries you do not keep in the cloud never leave your phone.
If you forget your PIN, the locked entries are gone. There is no recovery, no reset link, and nothing we can do — that key exists nowhere but in your PIN. Your ordinary entries are unaffected. The app says so before it accepts a PIN, and the only way forward is a reset that destroys the locked ones.
An entry you mark for study is read for vocabulary, and only that entry. Your phone removes email addresses, phone numbers, payment cards, links, handles and long numbers first, and shows you the result in a field you can edit before anything is sent. That text is not stored afterwards, and no sentence from it appears on a card — cards from a diary carry the word, its meaning and its kind, and nothing else.
The phrasings you are shown are not stored either. The one thing you can keep is a phrase you tap to keep, and what is saved is the reusable expression with your own detail taken out — “run into a problem”, not “run into a problem with the Hanoi office”.
That is true even for an entry kept on your phone only. Where an entry lives and whether it may be read are two separate choices, and the app says so at the switch.
While a locked entry is open on screen — being read, or being written — the app is set not to appear in screenshots, screen recordings, or the picture Android keeps of it in the app switcher.
Sharing a word list
You can hand a folder, or a single word, to another person. What travels is decided by you, and this section says exactly what that means — because the alternative is a switch nobody reads.
A share is a copy, taken at the moment you make it. Words you add to the folder afterwards do not join it, and words you delete afterwards do not leave it. Withdrawing the list is what takes it back.
Nothing from a private source goes unless you say so. Words you typed in, photographed off a page or named with the camera travel by default: you chose them when you made them. Words that arrived — from your messages, from your diary, or from before the app recorded where a word came from — are left out unless you tick them, each time, and the screen tells you how many there are before you decide.
The sentence a word was met in travels only if you turn it on, and it is off when the screen opens. The name of whoever wrote that sentence never travels, and there is no setting for it — nor does the name of the conversation. The word is yours to pass on; the sentence was written by somebody who is not part of your decision and was never asked.
Who can open a list is your choice: anybody with the link who has a VocNova account, which is the default; only the people you send it to; or anybody at all, with no account. That last one is served as a plain web page — closing the link stops it opening, and anything already copied, screenshotted or saved by somebody else is beyond anyone's reach. The page is never cached and asks search engines not to index it, but neither of those is a promise about what a reader does with it.
Anybody who opens your list sees a handle and a display name, never your email address — including a reader of a public page, who is told who made the list for the same reason the recipient of a link is: a list of somebody's words arriving from nobody is worse, not safer. You can be found by an exact email address, and you can turn that off; there is no partial or approximate search, and accounts that existed before this setting did are off until they choose otherwise.
A list you report stops reaching you, and we keep a record of the report. Reports are now read: what is reported is either dismissed or taken down, and a list taken down stops opening for everybody. It is closed rather than deleted, so the words are not destroyed and there is a record of the decision.
What we never collect
No advertising identifiers, no location, no contacts, and nothing about what you tap. There is no advertising in this product and no third party receives your data for their own purposes.
Where it goes
Our server, over TLS, hosted in the European Union (Ireland). Our database is hosted by Aiven, in Amsterdam, the Netherlands — that is where your cards, your profile, the messages we hold for up to a week and the sealed diary bytes are stored, encrypted in transit and at rest.
A language model — DeepSeek or OpenAI, or your own provider if you have supplied your own API key — which reads your text and your photographs, in order to produce your cards and for no other purpose.
OpenAI, and only if you ask, for one thing: turning a recording of your own voice into text. This is the single place in VocNova where your voice leaves your phone, it is off until you turn it on, and the app asks before the first recording is sent. What goes is the audio and nothing else — not your name, not the passage, not what you wrote down. The words come straight back to your phone; we do not store the recording or the transcript on our server, and what OpenAI keeps is governed by their terms rather than ours. Turning it off stops every future upload, though it cannot call back a recording already sent.
Google Firebase Cloud Messaging, to deliver a notification while the app is closed. It carries a preview of up to 120 characters so Android can display it. Turning notifications off stops the preview being sent at all — there is no separate switch that keeps the alert and drops the text.
Brevo, which delivers the only email we send: a code you asked for, to set a password. It receives your address and that message and nothing else, and we send nothing you did not ask for.
Google, if you sign in with Google: it tells us the email address on the account and that it has been proved, and we store the address. Nothing about your use of the app goes back to Google by this route.
Cloudflare hosts this site and the browser version of the app, and stores the waitlist. Your messages, cards and diary do not pass through it — the app talks to our server directly.
Nothing else. Your phone used to read photographed pages itself, without sending anything to anybody; that was removed because it read handwriting badly, so a page now goes to the model like any other photograph.
What is encrypted
The tokens that let us read a connected account, and your own model key, are encrypted at rest with per-record keys wrapped by a master key held outside the database.
Your phone's copy of your messages and captured notifications is encrypted with AES-256-GCM. The key is issued by the server after you sign in, so this is not end-to-end encryption and we do not claim it is — the server fetches those messages and has to read them to build your cards. What it means is that the file on your phone is useless to anybody who takes the phone, roots it, or reads it from another app.
Notifications captured while the app is closed are sealed with a key held in your device's own keystore, which never leaves the device.
Pictures on your cards stay on your phone unless you ask otherwise. A word taken off a photograph of the world keeps a picture of the thing it names, and you can put one on any card yourself. On your phone it is sealed with a key made on the device and stored in its keystore, alongside your diary's photographs and under the same rule.
Cloud pictures are off until you turn them on, in Settings, and turning them on is the only thing that ever sends one — a photograph already on your phone is not uploaded by an app update. Off, there is no route that would upload one, so signing in on another phone brings your words but not your pictures, and uninstalling loses them, because backups are off. On, a copy is kept with your account so a new phone gets them back, and turning it off asks you separately whether to remove the copies. Deleting a word deletes its picture in both places; deleting your account deletes all of them.
A diary photograph follows its entry. On an entry you keep on your phone it stays there. On an entry you keep in the cloud it is uploaded already sealed with that entry's own key — the bytes we hold are ones we cannot open, and for a locked entry that means your PIN opens the photograph exactly as it opens the words.
A locked diary entry is different, and it is the only part that is: locked entries are encrypted with a key derived from your PIN, which we never receive. The copy we hold cannot be opened by us, by anybody with our database, or by anybody we are compelled to hand it to. An ordinary diary entry is not an exception — it is protected the way your messages are, with a key we issue.
Backups are turned off for this app: nothing is copied to Google Drive or taken off by a device transfer.
How long we keep it
Messages: about a week on our server, and only until your devices have them. They are deleted once every active device has confirmed storing a copy, and in any case seven days after we received them. After that your phone holds the only copy of the conversation — a sentence quoted on one of your cards stays on the card.
Notification text: never written to our database as messages. It is read for vocabulary and dropped; what can outlive it is a card you keep, which carries the one sentence its word was met in.
Photographs sent to be read: not stored. They are read and dropped.
Photographs you keep in the cloud: until you remove them. Only if you turned cloud pictures on. A picture goes when you take it off the card or the entry, when you turn the setting off and choose to remove the copies, or when you delete your account.
Diary entries: until you delete them, or your account. They are encrypted throughout, and deleting one removes it from your phone and from our server.
Asking to connect, cheering, and inviting somebody to a share: a request nobody answers is forgotten after thirty days, and so is a cheer on a streak that has passed. An invitation goes ninety days after the share it belongs to expires or is withdrawn — the list stays, because it is your record of what you shared; the address of the person you sent it to does not.
Recordings of your own voice: on your phone, until the passage goes or you sign out. We never receive them, so there is nothing on our side to keep.
Minutes of free listening: on your phone, until you sign out.
Fault reports: fourteen days.
Your cards, folders and profile: until you delete them, or your account.
Your choices
Delete your account from inside the app, under Settings. It removes your profile, cards, folders, connected accounts and their credentials, devices, study history, fault reports and anything still held for a device. It is immediate and cannot be undone. To ask for deletion without the app, write to privacy@vocnova.com — the request is confirmed and completed within 30 days, in practice within a few working days.
Disconnect a chat account at any time. The stored credential is destroyed and we ask the provider to revoke it.
Turn off notification reading, or untick individual apps, at any time.
Keep a diary entry on your phone only, per entry, or delete it from our server without deleting it from your phone.
Change your diary PIN without losing anything: the entries stay readable, only the lock changes.
Use your own model key, so the reading of your words is billed to you.
Turn off new-message notifications, which also stops their previews leaving for Google.
Change your password, which also signs out every other device.
The website, and the waitlist
vocnova.com carries no analytics, no advertising and no third-party scripts of any kind — there is nothing on the page to track you with, which is checkable by reading the source.
If you join the waitlist we store the address you typed, the date, the language you were reading the site in, and the country Cloudflare reports for the connection — so the launch email can go out in a sensible order. Nothing else, and no cookie is set.
It is used for exactly one email, on the day the app opens. To be taken off the list before then, write to hi@vocnova.com and the record is deleted; the list is destroyed once that email has been sent.
Children
VocNova is not directed at children under 13 and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects what happens to your data, the app will say so before the change takes effect.
Contact
Write to hi@vocnova.com for a question, or anything on this page that is not clear.
Write to privacy@vocnova.com for a deletion request made without the app — see Your choices above.
Groups, and what a group’s analysis is drawn from
A group has a library of word lists its members put there, and the app tells the group what it is discovering and what it keeps getting wrong. Both are drawn from a deliberately narrow place.
What the group is discovering is counted over the group library — the lists members chose to share into it — and nothing else. Somebody with two thousand private words contributes nothing to it unless they shared some.
What the group is getting wrong reads review outcomes, and it reads them only for words a member took from that group library. Taking a copy is the action that agrees to it. A word that came from your messages, your notifications, a page you photographed or your diary is never counted towards any group statistic, whatever it is and however many people have it.
No group statistic is shown that is drawn from fewer than three members. With two, “the group gets this wrong” is one identifiable person’s mistake wearing a plural.
Nothing is published into a group by the app. A weekly collection is assembled from words already in the group library and offered to an admin, who publishes it or ignores it. If nobody publishes it, it expires.
