Vocatale web extension privacy notice
1. Scope and controller
This notice covers the Vocatale Context Lookup web extension wherever it is published: for Mozilla Firefox through addons.mozilla.org, and for Google Chrome through the Chrome Web Store. It applies equally to Chromium-based browsers that install the Chrome build, such as Edge, Brave, Opera and Vivaldi. There is one notice because there is one extension: the builds share their source, handle data identically, and send it to the same places. Where a browser genuinely differs, this notice names the browser rather than describing only one of them. The broader Vocatale website and service are also covered by the Vocatale privacy notice.
The controller is Wen-Tao Wu. Privacy questions and requests may be sent to contact@vocatale.com.
2. The extension’s single purpose
The extension lets a learner look up a selected word or short phrase in its sentence context and, when the learner chooses, save the resulting vocabulary entry to a Vocatale Learning list. It does not monitor browsing for advertising, analytics, profiling, or an unrelated purpose.
3. Data the extension handles
Selected website content
When you press the extension’s Look up chip or choose Look up with Vocatale from the browser’s selection menu, the extension processes:
- the selected word or phrase, limited to 120 characters and 12 words; and
- up to 360 characters from the surrounding sentence, so the requested definition matches the context.
A normal selection or double-click only displays the Look up chip. It does not transmit the selected text. The extension’s content script runs on ordinary HTTP and HTTPS pages so it can display this selection control, but it does not transmit page content until you explicitly request a lookup. The page URL, page title, browsing history, cookies, browser storage, and full page are not sent. Text in a form or editable field is ignored by the selection control.
Account and authentication data
If you use built-in AI or save a word, Google sign-in is handled through Supabase using OAuth with PKCE. The extension stores the resulting email address, internal account ID, access token, refresh token, expiry time, credit balance, and account tier in the browser’s local extension storage. That storage area is private to the extension and cannot be read by the scripts of any website you visit, on either browser. Raw tokens are never handed to the part of the extension that runs inside web pages. On Chrome the browser additionally enforces that boundary, because extension storage is marked readable only by trusted extension contexts; Firefox offers no equivalent control, so there the restriction rests on the extension’s own design rather than on a guarantee from the browser.
Learning data
A successful lookup contains the selected text, bounded sentence, language, lemma, pronunciation, part of speech, definitions, synonyms, and limited grammar fields. This result remains in the lookup card unless you press Add to Learning. When you press that button, the entry is sent to Vocatale and stored in your account. A failed save may remain locally in a pending queue and be retried for up to 30 days; the queue is limited to 200 entries per account.
Local settings and provider credentials
The browser’s local extension storage holds language settings, voice preferences, AI provider, model and endpoint settings, and any API key that you enter for your own provider. Your own API key is not sent to Vocatale or synchronised to the Vocatale cloud. It is sent only to the provider endpoint you selected as required to authenticate your direct request. You can remove it by clearing the API-key field or the extension’s stored data. Uninstalling the extension causes the browser to remove its local extension storage.
Technical service data
Network providers necessarily receive technical connection data such as an IP address. For built-in AI, Vocatale also processes a request ID and limited metadata such as feature type, provider, model, token amounts, cost, and response status for billing, abuse prevention, security, and troubleshooting. Full lookup prompts and complete AI outputs are not stored in the operational AI request ledger.
4. Where data is sent
Built-in AI
The selected text and bounded sentence are sent over HTTPS to auth.vocatale.com. Vocatale uses Supabase for authentication and service data and sends the managed lookup directly to DeepSeek to generate the requested dictionary result. Managed dictionary lookups do not use OpenAI moderation or OpenRouter. Their privacy notices also apply: Supabase and DeepSeek.
Your own AI provider
If you select your own provider, the selected text and bounded sentence are sent directly from the extension to that provider and do not pass through Vocatale. Remote endpoints must use HTTPS. Cleartext HTTP is allowed only for localhost or 127.0.0.1, for a model running on the same device. The chosen provider’s terms and privacy notice apply.
Google sign-in and speech
Google and Supabase exchange the data needed to complete sign-in only after you choose Continue with Google. Each browser completes that flow through its own secure web-auth window, which returns to an address reserved by the browser vendor so that the return leg cannot be claimed by a third party: chromiumapp.org on Chrome and extensions.allizom.org on Firefox. The browser reads the sign-in result out of that address itself and never sends a request to it, so neither Google nor Mozilla receives your sign-in data by way of the redirect. Pronunciation uses the browser’s Web Speech interface. A voice marked as online by the browser or operating system may send the word to that platform’s speech service; Vocatale does not receive an audio copy.
5. Purposes and legal bases
- Contextual lookup, sign-in, and saving vocabulary: to perform the service you request (Article 6(1)(b) GDPR).
- Local settings and pending saves: to provide the requested extension features (Article 6(1)(b) GDPR).
- Security, abuse prevention, billing integrity, and troubleshooting: Vocatale’s legitimate interest in a secure and reliable service (Article 6(1)(f) GDPR).
6. Extension permissions
- Website access: displays the selection chip and reads only the selection and bounded sentence needed for a lookup you request.
- Storage: keeps the session, settings, provider configuration, and bounded pending saves described above.
- Identity: completes Google OAuth sign-in through the browser’s secure web-auth flow.
- Context menus: adds Look up with Vocatale for selected text.
- Alarms: retries a save that you requested but that failed temporarily.
- Optional provider access: connects only to the AI origin you select; that optional permission is requested when the provider is selected and released when you switch away from it.
On Firefox you can also review, and withdraw, the extension’s access to websites at any time from the Add-ons Manager without uninstalling it. Withdrawing it stops lookups from working until it is granted again.
7. Retention and deletion
Local settings and credentials remain until you change them, clear the extension’s data, or uninstall it. A sign-out removes the local Vocatale session; pending saves remain scoped to the same account so they cannot be shown or submitted for another account, and expire after 30 days. Vocabulary saved to Vocatale remains until you delete the entry or your account. Signed-in users can export or delete account data from My data in Vocatale. Account deletion and server-retention details are described in the general Vocatale privacy notice.
8. Limited use and sharing
User data is used only to provide or improve the extension’s disclosed single purpose and related security and reliability. It is not sold, used for personalised advertising, transferred to data brokers, or used to determine creditworthiness. Vocatale does not permit humans to read user data except with the user’s explicit consent for specific support, when necessary for security or legal compliance, or when data is aggregated and anonymised for permitted internal operations.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. The Firefox build additionally follows Mozilla’s Add-on Policies, and the categories of data described here are declared in the extension itself, so Firefox shows them to you before you install it.
9. Security
Remote user-data transmission uses HTTPS. Provider access is granted per origin at runtime. Remote redirects are rejected for direct provider requests, Gemini credentials are sent in a request header rather than a URL, OAuth uses PKCE, extension pages execute only packaged code, and raw credentials are kept outside content scripts. No internet service can guarantee absolute security.
10. Your choices and rights
You choose whether to request each lookup, whether to sign in, which AI provider to use, and whether to save each result. Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing. Contact contact@vocatale.com. You may also complain to a competent data-protection authority.
11. Changes
This notice will be updated before materially different data practices are introduced. Material changes will also be disclosed in the extension interface as required by Chrome Web Store policy, and re-declared in the extension for Firefox, which asks for your consent again when the declared data categories grow.