Privacy Policy
Last updated: January 7, 2026
This Privacy Policy describes how Violingo ("we", "us", or "our") collects, uses, and shares your information when you use our Chrome extension and related services.
Privacy at a Glance
- We never access your Netflix/YouTube passwords or full watch history
- Payment details are handled securely by Stripe—we never store card numbers
- Your vocabulary and learning data are stored securely and encrypted
- You can export or delete all your data anytime by contacting us
- We do not sell your personal information to third parties
- We notify you of material policy changes before they take effect
Information We Collect
Account Information
When you create an account through our authentication system (Supabase), we collect:
- Email address (required for account creation and authentication)
- Account credentials (passwords are encrypted and never stored in plain text)
- Account preferences and settings
- Authentication tokens (with expiration, encrypted in transit)
Learning Data
To provide our language learning services, we collect and store:
- Vocabulary words you save and their translations
- Your flashcard review history and spaced repetition progress
- Learning statistics (words learned, study streaks, session duration)
- Study preferences and learning goals
- Progress tracking data (mastery levels, review schedules)
Subtitle and Video Interaction Data
When you use Violingo with video platforms:
- Subtitle text extracted from videos you watch (for translation and word breakdown)
- Video metadata (title, episode information, timestamp) associated with saved words
- Playback interactions (when you pause to save a word, timestamp of learning)
- Language preferences for subtitles
Important: We only access subtitle text and metadata you actively engage with for learning. We do NOT collect your full viewing history, video streams, audio, or content you haven't interacted with for learning purposes.
Usage Analytics and Technical Data
We automatically collect information about how you use our extension:
- Feature usage patterns (which tabs you visit, features you use)
- Click events and user interface interactions
- Session duration and frequency of use
- Error logs and crash reports (automatically anonymized)
- Browser type, operating system, and extension version
- Device identifiers (for multi-device sync)
- IP address (for security and fraud prevention, not for tracking)
Subscription and Billing Information
If you purchase a paid subscription:
- Subscription tier and billing cycle
- Credit balance and transaction history
- Billing email address
- Country/region (for tax purposes)
- Last 4 digits of payment card (provided by Stripe for reference)
Note: Full payment card details are processed and stored exclusively by Stripe. We never have access to your complete credit card number.
How We Use Your Information
We use the information we collect for the following purposes:
To Provide and Improve Our Services
- Authenticate users and maintain secure accounts
- Process and display subtitle translations
- Save and sync your vocabulary across devices
- Implement spaced repetition and review algorithms
- Track your learning progress and statistics
- Improve our AI-powered features and translation accuracy
- Optimize extension performance and fix bugs
For Billing and Subscription Management
- Process payments and manage subscriptions
- Track credit usage and balances
- Send billing receipts and renewal reminders
- Handle refund requests and payment disputes
- Comply with tax regulations
For Communication
- Send important service updates and security notices
- Respond to your support requests
- Notify you of significant feature updates (you can opt out)
We do NOT send marketing emails without your explicit opt-in consent.
For Security and Fraud Prevention
- Detect and prevent fraudulent activity
- Protect against security threats and unauthorized access
- Enforce our Terms of Service
- Comply with legal obligations
Third-Party Services and Data Sharing
We do NOT sell your personal information. We share data only with trusted service providers necessary to operate our service:
Supabase (Authentication and Database)
- Purpose: User authentication, account management, and data storage
- Data shared: Email, encrypted passwords, learning data, vocabulary, progress
- Privacy: SOC 2 Type II and GDPR compliant
- Location: Data stored in secure cloud infrastructure
- Policy: supabase.com/privacy
Stripe (Payment Processing)
- Purpose: Secure payment processing and subscription management
- Data shared: Billing email, subscription details, payment amount
- Privacy: PCI DSS Level 1 certified, highest security standard
- Card storage: Stripe stores payment card details, not us
- Policy: stripe.com/privacy
OpenAI API (Optional AI Features)
- Purpose: Enhanced word definitions and explanations (only if you enable this feature)
- Data shared: Subtitle text and vocabulary words for processing
- Control: You can disable AI features anytime in settings
- Retention: OpenAI may retain data according to their policy
- Policy: openai.com/privacy
Third-Party Platform Compliance
Important Disclaimer: Violingo is an independent extension and is not created, endorsed, or maintained by Netflix, Google, or YouTube.
- By using Violingo, you agree to comply with Netflix and YouTube's Terms of Service
- We respect content provider restrictions and DRM protections
- Extracted subtitle content is for personal educational use only
- You may not redistribute or use subtitles for commercial purposes
How We Protect Your Data
We implement industry-standard security measures to protect your information:
Encryption and Secure Transmission
- HTTPS/TLS encryption for all data in transit
- Encryption at rest for sensitive data in our database
- Secure authentication tokens with expiration
- Password hashing using industry-standard algorithms
Access Controls
- Limited employee access to personal data (need-to-know basis)
- Multi-factor authentication for administrative access
- Regular security audits and penetration testing
- Automated monitoring for suspicious activity
Data Minimization
- We collect only data necessary to provide our services
- Error logs are anonymized before storage
- IP addresses are not used for tracking or profiling
- Session data is aggregated and cannot identify individual users
Important: While we implement robust security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data. If you become aware of any security breach, please contact us immediately at security@violingo.ai.
Data Retention and Deletion
How Long We Keep Your Data
- Account information: Retained while your account is active
- Learning data: Retained for the duration of your account unless you request deletion
- Usage analytics: Aggregated data retained for up to 12 months
- Billing records: Retained for 7 years (required by law for tax purposes)
- Support communications: Retained for 3 years for quality assurance
Account Deletion
When you delete your account:
- Personal data is deleted within 30 days
- Anonymized analytics may be retained for service improvement
- Billing records are retained as required by law
- Backups are purged within 90 days
To delete your account, contact us at support@violingo.ai with "Account Deletion Request" in the subject line.
Your Privacy Rights
For All Users
- Access: You can view your personal data through your account settings
- Export: Request a copy of your data in machine-readable format
- Correction: Update incorrect information through account settings
- Deletion: Request deletion of your account and associated data
- Opt-out: Disable analytics and optional data collection in settings
For California Residents (CCPA)
If you are a California resident, you have additional rights:
- Right to know: What personal information we collect and how it's used
- Right to delete: Request deletion of personal information (with exceptions)
- Right to opt-out: We do NOT sell personal information
- Right to non-discrimination: Equal service regardless of exercising rights
For EU Residents (GDPR)
If you are in the European Union, you have these rights:
- Right of access: Obtain confirmation and access to your personal data
- Right to rectification: Correct inaccurate personal data
- Right to erasure: Request deletion ("right to be forgotten")
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive data in structured format
- Right to object: Object to processing based on legitimate interests
- Right to lodge a complaint: File complaints with supervisory authorities
Legal basis for processing: (1) Performance of contract (providing service), (2) Legitimate interests (improving service), (3) User consent (optional analytics).
How to Exercise Your Rights
Contact us at:
- Data requests: privacy@violingo.ai
- Security issues: security@violingo.ai
- General support: support@violingo.ai
We will respond to verified requests within 30 days (or as required by applicable law).
Chrome Extension Permissions Explained
Our extension requests the following permissions. Here's exactly why we need each one:
storage
Cache your vocabulary, preferences, and session state locally so the extension works offline and syncs when you're online.
scripting & activeTab
Inject translation features into Netflix and YouTube video players. This allows you to click words in subtitles for definitions. We only access subtitle text—never video/audio streams.
sidePanel & tabs
Open the learning dashboard in Chrome's side panel and keep your progress synced across tabs.
host_permissions (netflix.com, youtube.com)
Required to interact with subtitle elements on these platforms. We only access pages you actively navigate to while using the extension.
offscreen
Process subtitles and sync data in the background without interrupting your browsing.
Children's Privacy
Violingo is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@violingo.ai, and we will delete such information.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or for legal, operational, or regulatory reasons.
- We will update the "Last Updated" date at the top of this policy
- For material changes, we will notify you via email or through a notice in the extension
- Your continued use after changes take effect constitutes acceptance of the updated policy
- If you disagree with changes, please discontinue use and contact us to delete your account
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
Violingo
- General inquiries: support@violingo.ai
- Privacy requests: privacy@violingo.ai
- Security issues: security@violingo.ai
This Privacy Policy is effective as of January 7, 2026 and applies to all users of Violingo's Chrome extension and related services.