Contextale app and browser extension
Privacy Policy
The short version
Without an account, everything stays on your device. We sync nothing. With an account, we sync what you make: saved words with the sentence they came from, study progress, reading statistics, word cards, pages and books you send to your phone.
The extension reads a page only when you act. Nothing is sent while you just browse. Anonymous analytics and crash reports are off in the app until you turn them on, and on in the extension until you turn them off in Settings. They never contain a word you saved, a page you visited or your e-mail. We never sell your data, run ads, or use ad tracking. You can export everything and delete your account at any time.
Who we are
Contextale is a language-learning app and browser extension operated by Katrin (Kalina) Krasner, Tel Aviv, Israel. This policy covers the mobile app (iOS, Android), the browser extension (Chrome and other Chromium browsers) and the contextale.com website. Questions go to contextale@gmail.com.
Account data
Signing in is optional. If you do sign up, we store the minimum needed to run an account: your e-mail address and an authentication identifier from your sign-in method (e-mail and password, Sign in with Google, or Sign in with Apple on iOS). Authentication is handled by Supabase.
With Google sign-in, Google sends us a signed identity token containing your Google account ID, e-mail address and name. We keep the ID and the e-mail. We don't store your name or profile picture, and we get no access to anything else in your Google account. If you use Apple's "Hide My Email", we only ever see the relay address.
What you make, and what syncs
When you're signed in, the following syncs to our backend so it's there on your other devices:
- Saved vocabularyWords, translations, the example sentence each word appeared in, and where it came from: page title, site name and address
- Study progressReview schedules, quiz results, learning statistics
- Reading statisticsPer device and calendar day: engaged reading seconds and words credited as read. The device is a random ID made once per install, not anything about the device itself.
- Contextale cardsThe AI-generated reference card for a word, once you ask for one
- Read-later pagesThe address and title of a page you send with "Read on phone"
- Books you uploadThe file, a hash of its contents (so the same file isn't stored twice) and its metadata, kept private to you
- Reading positions and foldersWhere you stopped, and how you filed things
Signed out, all of it stays on your device only. Signing out stops syncing and leaves the local copy where it is.
What the extension reads on web pages
The extension runs on the pages you visit so it can highlight words you've already saved. That highlighting is computed locally in your browser. The page content is not sent anywhere.
When you select text and press Translate, the extension collects the selected word, the sentence around it, the page title, the site name and address, and up to three of the site's theme colours (used to colour the word's card). That goes to a translation service, and if you press Save, it's stored with the word. Text you type into forms, search boxes and editors is never picked up.
The PDF reader fetches a PDF you open from a link and renders it in your browser. Files you open from your own computer stay in your browser. Send a book to your phone uploads the file you pick to your own private storage in your account, so the app can download it. It works the same way as an upload from the app, and it needs a Pro plan.
Translations, AI cards, pronunciation
Free translations
The selected word or sentence and the language codes go to Google Translate (translate.googleapis.com). No account identifiers are attached. Results are cached on your device.
Paid translations, when you're signed in
The selected text and its language codes pass through our server, which forwards them to the paid provider with our key and counts the request against your plan. In the app, the request also carries the surrounding paragraph and the title and address of the page or book (for fan fiction, also its fandom), so the provider can pick the right sense. That provider is DeepL (Germany) or Qwen, served by Alibaba Model Studio (Singapore) or through OpenRouter (openrouter.ai, USA), depending on which one our server is set to use. Your identity is not attached to the text.
Contextale cards
When you ask for a card, the request goes through our server to Google Gemini, with Anthropic (Claude) as a fallback. It carries the word, its sentence and the surrounding paragraph, the page or book title and author, the kind of text, the language codes, and signals about how common the word is. If you saved the same word before, it also carries that earlier meaning and sentence. It can include up to two other sentences from the same text and up to three other words you've saved. Neither provider uses data sent through its API to train its models. The finished card is stored with your word.
Pronunciation and read-aloud
For a word's definition and audio the app asks the Free Dictionary API (dictionaryapi.dev), and for many languages falls back to Google's public text-to-speech endpoint. The word and its language code are sent, with no account identifiers. Reading a whole page or book aloud uses your device's own speech engine, governed by Apple's or Google's policy for it.
Our server counts how many paid translations and AI cards your account uses in a period, to enforce plan limits. It keeps counters, not the text of your requests.
Analytics and crash reports
We use Google Analytics 4 (Firebase) to see which features get used. From the app and the extension we send only the name of the event (word saved, first word, signed in, book sent to phone, card requested, study session finished, paywall viewed, extension updated, and the like), coarse parameters (language pair, sign-in method, card tier, study mode, a result or a bucketed count, the app version) and a random installation ID so Google can count unique users.
We never send the word itself, the sentence, the page address, the page content or your e-mail. As with any request on the internet, Google sees the IP address the request came from and derives a country from it.
The app also uses Firebase Crashlytics for automatic crash reports: stack traces plus device model and OS version, no reading content and no saved words. Crashlytics comes with Firebase Sessions, which records app session and performance events, and keeps its own random Crashlytics installation ID.
One switch governs all of it. In the app it's off until you turn it on, during onboarding or in Settings, Data, "Anonymous Analytics". In the extension it's on by default and can be turned off in Settings, "Anonymous analytics". Nothing is sent while the switch is off.
Payments
Subscriptions are sold and processed by Apple (App Store) and Google Play. We never receive or store your card number. What we store is the record the store hands us: its transaction identifier, the product, whether the purchase is production or sandbox, the status and renewal date, and the store's last answer as we received it. That record is what unlocks Pro. Cancelling or switching plans happens in the store, not here.
If you signed up for the early-bird list
The signup form on this site stores the e-mail address you gave, the language of the page you filled it in on, which of the listed use cases you picked, and your own short answer if you typed one. So the form can't be used as a spam sink, we also store a salted hash of your IP address for that day, which we can't turn back into an address.
Addresses are mirrored into Resend, which is what we'll use to send the launch e-mail, with an unsubscribe link in every message. The list exists to tell you when Contextale launches. Write to contextale@gmail.com and we'll take you off it.
Browser permissions the extension asks for
| Permission | Why |
|---|---|
| Access to all websites | To offer Translate on any page you read, and to highlight saved words there. It runs locally; nothing is sent until you press Translate or Save. |
| Identity | To open the Google sign-in window. |
| Storage, unlimited storage | To keep your words and settings in the browser without a size cap once you have many cards. |
| Active tab | To read the address and title of the current page when you press "Read on phone". |
| Alarms | To sync your words with your account in the background every 20 minutes. |
| Network request rules | For the optional "Open PDFs in the reader" setting, off by default: it redirects PDF links to the Contextale reader. |
Where your data is stored
Account and synced data live on Supabase, hosted in the EU (Frankfurt). Uploaded books sit in a private storage bucket reachable only by you, through short-lived signed links. On your own devices, data lives in the app's local database and in the browser's extension storage. The app's built-in browser keeps the cookies of sites you sign in to on your device, the way any browser does, so you stay signed in to them. Those are never synced.
Backups. The database is backed up several times a day. Every backup is encrypted before it leaves the server and stored in two European buckets (Backblaze B2 and Cloudflare R2). Daily copies are deleted after about a month; one copy per month is kept for up to a year.
Signing out of the extension keeps your words in that browser, so nothing unsynced is lost. Settings, "Clear all words" removes them. Signing in with a different account clears the previous account's words from that browser first.
Who else touches it
| Service | Purpose | Data shared |
|---|---|---|
| Supabase (EU) | Auth, database, file storage | Account and synced data |
| Google, Sign in with Google | Authentication | Identity token: Google ID, e-mail, name |
| Apple, Sign in with Apple | Authentication on iOS | Identity token |
| Google Translate | Free translations, pronunciation audio | Selected word or sentence, language codes, no identifiers |
| DeepL (Germany), Qwen via Alibaba Model Studio (Singapore) or OpenRouter (USA) | Paid translations | Selected text, surrounding paragraph, source title and address, language codes, through our server |
| Google Gemini | AI word cards | Word, sentence, paragraph, source title and author, an earlier save of the same word, a few other sentences and saved words, frequency signals, language codes, through our server |
| Anthropic (Claude) | AI word cards, fallback provider | The same, through our server |
| dictionaryapi.dev | Definitions and pronunciation audio | The word, no identifiers |
| Google Analytics 4, Firebase (Analytics, Crashlytics, Sessions) | Optional analytics and crash reports | Event names, coarse parameters, crash traces, session events, random install IDs |
| Apple App Store, Google Play | Payments and subscriptions | Subscription record, no card data |
| Backblaze B2, Cloudflare R2 (EU) | Encrypted backups | The database, encrypted |
| Resend | Launch e-mail to the early-bird list | E-mail address, page language |
| Cloudflare, GitHub Pages | DNS and website hosting | Standard request metadata |
The app loads websites in an embedded web view, like a browser. Your dealings with those sites are governed by their terms and privacy policies, not ours. Contextale doesn't scrape or redistribute their content.
Books you upload
You're responsible for having the right to store any book you upload. Uploaded files are private to your account and used only to provide reading and sync. Deleting a book removes it from our storage.
Keeping book files in the cloud is part of Pro. If your subscription ends, we hold those files for 30 more days and write to you twice in that window: a week after it ended, and again a week before the date, each time saying what will be removed and when. Then we delete the copies on our servers. We delete the files, not your library: titles, authors, reading positions, words and notes all stay, and a book already downloaded to a device stays on that device and keeps working. Renewing Pro before the date stops it. An account still in payment retry with Apple or Google isn't treated as ended.
What we do not do
- No advertising, no ad tracking, no selling of data
- No reading of your books or your vocabulary by humans
- No collection beyond what's listed here
Your rights
Export: your saved data (vocabulary, bookmarks, folders) exports as a JSON file at any time, from the app and from the extension, and imports back.
Correct: edit anything in the app.
Delete: delete your account from the app's account settings, or from the account deletion page. That erases your synced data, uploaded books included, from our servers. Encrypted backups made before the deletion age out on the schedule above. Local data on your device is untouched, and clearing the app's storage in your device settings removes it.
Object: turn analytics and crash reports off in Settings. You can also lodge a complaint with your local data protection authority.
Under the GDPR we rely on performance of a contract for accounts, sync and Pro features; on legitimate interest for analytics in the extension and for security; and on consent for analytics and crash reports in the app, and for the early-bird list. For anything that isn't self-service, write to contextale@gmail.com.
How long we keep it
We keep account and synced data until you delete your account or the individual items. Book files in cloud storage are the exception: they're kept while Pro is active and for 30 days after it ends, with two e-mails in that window (see Books you upload). If an account sits inactive for 24 months, we may notify you and then delete it. Translation and AI requests aren't logged with your identity; the usage counters for your plan are kept per period.
Children's privacy
Contextale isn't directed to children under 13, or 16 where local law requires it, and we don't knowingly collect data from them. If you believe a child has created an account, tell us and we'll delete it.
Changes to this policy
Changes appear on this page with a new date at the top. If a change is material and you have an account, we'll tell you in the app or by e-mail.
Contact
contextale@gmail.com, Contextale, Tel Aviv, Israel.