Orvoca
FAQBack home

Legal

Privacy Policy

Last updated: August 14, 2026

Privacy Policy and Terms of Service are provided in English only.

1. Scope and controller

This Privacy Policy explains how Orvoca processes personal information for the Orvoca web console, Chrome extension, mobile app, APIs, optional rewarded ads, customer support, email, and notification services. It is prepared for compliance with the Personal Information Protection Act of Korea and related rules.

Privacy contact: privacy@orvoca.app. General support: support@orvoca.app.

Privacy Officer (개인정보 보호책임자) designated under Article 31 of the Personal Information Protection Act: Orvoca Privacy Office — privacy@orvoca.app.

2. Personal information we process

Orvoca processes the following information only as needed to provide the Service.

  • Account information — email address, display name or nickname, authentication provider, Firebase authentication identifier, email verification status, and session tokens stored on your device.
  • Signup consent record — the accepted Terms and Privacy Policy versions, confirmation that you meet the stated minimum age, authentication provider, signup surface, and consent timestamp. Orvoca does not collect a date of birth through this confirmation.
  • Vocabulary and capture data — words, phrases, normalized forms, language guesses, optional surrounding sentence context, the source page URL for a word encountered again, review state, review results, deletion state, and timestamps.
  • Extension data — allowed host settings, capture trigger settings, selected text or phrase, optional sentence context, local retry queue metadata, and the active page URL or hostname needed to verify the site you enabled.
  • Device and notification data — push subscription endpoint, p256dh key, push auth key, FCM token, device type, app-generated device id, notification settings, timezone, quiet hours, and notification open events.
  • Email and marketing preference data — email address, email delivery logs, unsubscribe status, lifecycle email settings, and marketing email or push preference.
  • Service usage and attribution data — product events such as first capture or first review, last active timestamp, UTM source, UTM medium, UTM campaign, referral code, referring user id if applicable, analytics identifiers, browser or device metadata, IP address, app version, surface, and aggregated marketing events.
  • Support and error report data — error code, endpoint, product view, optional memo submitted by you, diagnostic metadata, and related email records.
  • Advertising data (mobile app) — where you choose to watch a rewarded ad, Google AdMob processes an advertising identifier, device and network information, coarse location derived from IP address, and ad interaction events. Orvoca additionally stores a reward token and reward counters against your account.

3. Information we do not intentionally collect

  • Full browsing history or full page content.
  • Keystrokes or clipboard contents beyond a word, phrase, or short context that you explicitly capture or allow through enabled capture triggers.
  • Precise location data, payment card numbers, bank account details, or government IDs.
  • Advertising identifiers, except where you choose to watch a rewarded ad in the mobile app, as described in Sections 2 and 6.
  • Data from websites where you have not granted extension host permission.

4. Purposes of processing

  • Creating, verifying, securing, and maintaining your account.
  • Saving, syncing, reviewing, restoring, and deleting vocabulary records.
  • Detecting language, normalizing words, and enriching approved vocabulary.
  • Operating extension capture, local retry, and allowed-site controls.
  • Sending transactional emails, service notices, review reminders, and opt-in updates.
  • Providing push notifications only where permission and settings allow it.
  • Handling support requests, error reports, abuse prevention, and service reliability.
  • Measuring product usage, acquisition, activation, funnel performance, and retention in production environments.
  • Delivering optional rewarded ads that you choose to watch, granting the resulting allowance, preventing reward abuse, and honoring your advertising consent choices.
  • Complying with legal obligations and enforcing the Terms of Service.

Orvoca does not sell personal information. Rewarded ads served through Google AdMob are the only advertising in the Service; where required, Orvoca asks for your consent through Google's User Messaging Platform before personalized ads are shown, and you can change that choice at any time from the ad card in the app.

5. Chrome extension permissions

The Orvoca Chrome extension requests these permissions:

  • contextMenus — to add a capture option to the right-click menu.
  • storage — to store your token, settings, allowed hosts, and pending capture queue locally.
  • alarms — to retry pending captures when network or login state recovers.
  • activeTab — to identify the current tab when you allow capture on a site.
  • scripting — to register bundled content scripts on allowed sites and show a small success or error toast.
  • Optional capture-site access — requested only for websites you explicitly enable.
  • Required service hosts — limited to the Orvoca API and web app for account pairing and sync, plus the PostHog endpoint when production analytics is enabled.

The extension does not load remotely hosted code. It sends only the selected word or phrase, optional sentence context, the active page URL for source history, and limited sync metadata to the Orvoca API.

6. Service providers and international transfer

The providers listed below process personal information outside Korea. These transfers are processing or storage delegations disclosed under Article 28-8(1)3 of the Personal Information Protection Act, not a sale or sharing of data for the providers' own purposes. Transfers occur continuously over encrypted (TLS) network connections whenever the Service is used. Each provider retains information only for the period needed for the delegated purpose described below, or until account deletion as described in Section 7. You may contact privacy@orvoca.app to inquire about or object to an overseas transfer; objecting may limit or prevent your use of the Service.

  • Neon, Inc. (United States) — the primary production database. Data transferred: account id, vocabulary and capture records, review history, settings, sync events, push subscription records, email logs, and error reports. Delegated purpose: primary database storage for the Service. Privacy policy: neon.com/privacy-policy.
  • Cloudflare, Inc. (United States; traffic is processed across Cloudflare's global network, and the legacy D1 database is hosted in Cloudflare's Asia-Pacific region) — API and web hosting, security, traffic delivery, and the legacy D1 database retained as a rollback snapshot during the database migration. Data transferred: the same categories listed above for the database, plus request metadata. Delegated purpose: infrastructure hosting, database storage, and security/traffic delivery. Privacy policy: cloudflare.com/privacypolicy.
  • Google LLC — Firebase Authentication (United States). Data transferred: email address, authentication identifier, session tokens, and sign-in provider metadata (Google sign-in, Apple sign-in). Delegated purpose: authentication, session issuance, password reset, and email verification. Privacy policy: policies.google.com/privacy.
  • Resend (United States) — transactional and opt-in lifecycle email delivery. Data transferred: email address, delivery identifiers, bounce or complaint data, and unsubscribe headers. Delegated purpose: sending and tracking delivery of account and marketing emails. Privacy policy: resend.com/legal/privacy-policy.
  • PostHog, Inc. (United States — US cloud region, us.i.posthog.com) — production product analytics. Data transferred: account analytics identifier, email address used for product analytics identification, product events, event properties, browser or device metadata, IP address, app version, and surface. Delegated purpose: attribution, funnel, and retention measurement. Orvoca disables PostHog session recording and automatic interaction autocapture, and does not intentionally send vocabulary content or captured text to PostHog. Privacy policy: posthog.com/privacy.
  • Functional Software, Inc. dba Sentry (United States) — application error monitoring. Data transferred: error stack traces and diagnostic metadata, limited where practical. Delegated purpose: error monitoring and service reliability. Privacy policy: sentry.io/privacy.
  • Push platform providers — Google LLC (Firebase Cloud Messaging), Apple Inc. (Apple Push Notification service), and Mozilla (push service), all United States. Data transferred: push subscription endpoint, p256dh and auth keys, and device tokens. Delegated purpose: delivering push notifications. Privacy policies: policies.google.com/privacy, apple.com/legal/privacy, mozilla.org/privacy.
  • AI definition providers — Google LLC, Gemini API (United States). Data transferred: the word, phrase, or sentence you look up, the source and target definition language, and, where provided, the surrounding sentence context or other vocabulary text needed to generate suggestions. Delegated purpose: generating AI-assisted definitions and lexical enrichment. Orvoca does not send your account id to this provider. Privacy policy: policies.google.com/privacy.
  • Google LLC — Google AdMob and the User Messaging Platform (United States), used only in the mobile app and only for optional rewarded ads you choose to watch. Data processed by Google: advertising identifier, device and network information, IP address and the coarse location derived from it, ad requests, impressions, and rewards, plus your consent choice. Delegated purpose: serving and measuring rewarded ads, and recording advertising consent. Orvoca does not send vocabulary content, captured text, or your email address to AdMob. Privacy policy: policies.google.com/technologies/ads.
  • Dictionary and translation providers — FreeDictionary, Wiktionary, Jisho, and MyMemory may receive the word or phrase and language pair required for definition lookup. Orvoca does not send your account id to these providers for lookup.

7. Retention and deletion

  • Account, signup consent, vocabulary, capture, review, settings, sync, push, attribution, and email preference records are retained while your account is active.
  • Email logs, security logs, support records, and error reports are retained only as long as needed for delivery evidence, abuse prevention, dispute handling, and service reliability, unless a longer period is required by law.
  • Local extension queue data remains on your device until synced, deleted, or the extension storage is cleared.
  • Analytics events held at PostHog, email delivery logs held at Resend, and error events held at Sentry are retained under each provider's own retention schedule and are not linked back to a deleted account by Orvoca. You may request earlier deletion of these provider-held records by emailing privacy@orvoca.app.
  • Account deletion permanently removes your Orvoca database records linked to the account, subject to records that must be retained by law or for legitimate dispute and security purposes.
  • Records that must be retained by law are moved to separate, access-controlled storage, used only for the applicable statutory purpose, and destroyed when the retention period ends.

You can delete your account from Settings or request deletion by emailing privacy@orvoca.app.

8. Your rights

You may request access, correction, deletion, suspension of processing, withdrawal of consent, and explanation of processing by contacting Orvoca. You may also update or delete many records directly in the Service. Orvoca may verify your identity before processing a request and may decline a request where retention is required by law.

9. Marketing communications

Orvoca sends marketing email or marketing push notifications only where you have opted in or where applicable law allows the message. You may opt out at any time through settings, an unsubscribe link, or by contacting Orvoca. Transactional messages such as verification, password reset, security, and account deletion notices may still be sent where necessary.

10. Security measures

Orvoca uses HTTPS in transit, provider-managed access control, database access restrictions, authentication checks, input validation, rate limiting, push endpoint allowlists, and operational monitoring. No online service can guarantee perfect security.

11. Cookies and similar technologies

  • Essential storage — Firebase authentication state and session tokens are stored in your browser's local storage to keep you signed in. This storage is required for login.
  • Analytics storage — in production only, PostHog stores analytics identifiers in cookies or local storage to measure product usage. Session recording and automatic interaction autocapture are disabled.
  • No advertising cookies on the web — the Orvoca website, web console, and Chrome extension do not use third-party advertising cookies or trackers.
  • Advertising identifiers in the mobile app — if you choose to watch a rewarded ad, Google AdMob reads the device advertising identifier and stores related local data. Where required, consent is collected through Google's User Messaging Platform before personalized ads are shown, and you can reopen those privacy options at any time from the ad card in the app. You can also reset or limit the advertising identifier in your device settings.

You can clear or block cookies and local storage through your browser settings. Doing so may limit or prevent login.

12. Children

Orvoca is not directed to children under 14 in Korea or under 13 in other jurisdictions. Orvoca does not knowingly collect personal information from children in those age groups.

13. Changes to this Policy

Orvoca may update this Policy as the Service, law, or providers change. Material changes will be announced through the Service, website, or email where appropriate.

14. Contact

Questions, privacy requests, or complaints may be sent to privacy@orvoca.app.

Back to Orvoca