WordCore Legal

Privacy Policy

How WordCore handles information in the iOS app and on the WordCore website.

This Privacy Policy explains how Daiki Tokumoto (the “Operator,” “we,” “us,” or “our”) handles information in connection with the WordCore iOS application, the WordCore website, and related API services (collectively, “WordCore”).

WordCore is designed as a local-first vocabulary application. Most learning content stays on the user’s device. Information is sent to external services only when needed for a feature the user invokes, subscription verification, security, or delivery of the website.

1. Information stored on your device

WordCore may store the following information locally on your device:

  • Vocabulary entries, meanings, notes, folders, labels, learning progress, review history, card-visibility times, and notification preferences.
  • App settings such as language, appearance, theme, selected AI voice, and display preferences.
  • Your answers to the onboarding questions: what you want to use WordCore for, and your learning and explanation languages. They stay on your device and are not sent anywhere — see section 5.
  • Whether you have granted AI data-sharing permission.
  • Audio files that you attach and AI-generated audio cached for faster playback. Cached files may be removed by the operating system or when the app is removed.
  • A randomly generated installation identifier stored in the iOS Keychain. It is not an advertising identifier and is used for abuse prevention and rate limiting.
  • Locally scheduled notification content. Vocabulary reminders are scheduled on the device; WordCore does not operate a remote push-notification account system.

2. Information processed when you use online features

  • AI generation requests, and only after you have granted permission in the app (see section 3): text submitted for High-Quality AI Voice or another available server-assisted AI feature; requested language, voice, and generation settings; a random installation identifier; a pseudonymous RevenueCat App User ID; subscription tier; and request metadata such as endpoint, status, timing, input length, and request ID. The promotional clips in the Upgrade screen are the single exception and are described in section 3: they send none of this, including neither identifier.
  • Subscription information: product identifiers, purchase and renewal status, entitlement status, and pseudonymous customer identifiers provided by Apple and RevenueCat. Complete payment-card details are not provided to WordCore.
  • Support communications: your email address and any information you include when you contact support.
  • Website information: IP address, browser and device information, requested pages, timestamps, and security or delivery logs ordinarily processed by the hosting provider.

3. AI features and your permission

WordCore’s AI features are provided using OpenAI. When you use one, the request is sent from your device to the WordCore API Worker, which runs on Cloudflare, and the Worker forwards the generation request to OpenAI’s API. WordCore has no other AI provider.

WordCore asks for your permission in the app before the first such request, and sends nothing to OpenAI unless you grant it. Granting permission is a separate, explicit choice: accepting the Terms of Service, completing onboarding, or subscribing does not grant it, and an app update does not grant it for existing users. If you dismiss the request without answering, nothing is sent and you are asked again the next time you use an AI feature.

  • What is sent to OpenAI: the word or text you submit to an AI feature, together with the language, voice and output format that feature uses. For High-Quality AI Voice, this is the text of the card you asked to hear. Nothing else from your vocabulary, and no identifier, is included in the request to OpenAI.
  • What the WordCore API Worker additionally receives: a randomly generated installation identifier stored in your device’s Keychain, your pseudonymous RevenueCat App User ID, and the ID of a card whose voice is generated. They are used to verify your subscription tier and to apply abuse-prevention and card-allowance limits. They are not forwarded to OpenAI.
  • What the Worker does with the request: it verifies your entitlement with RevenueCat, applies rate and usage limits, and passes the generation request to OpenAI. Generated audio is streamed back to your device without being stored on the Worker. Submitted text is not written to the Worker’s application logs or to its key-value store; those logs record only non-content values such as the endpoint, status, request ID, timing, input length, selected voice and format. Cloudflare processes network-level information, including your IP address, as part of delivering and protecting the service; WordCore uses the IP address only to derive a salted hash for rate-limit counters and does not log or store it.
  • Voice previews in the voice picker are a subscriber feature and are covered by your permission like any other AI request, even though the sentence they speak is written by WordCore rather than by you.
  • The promotional clips in the Upgrade screen are the one exception, and are available without permission and without a subscription. Their request carries no text field and no voice field: the app sends only which of two fixed WordCore-authored samples to play, a language code that selects one of a fixed set of WordCore translations, and a build version used to refresh the shared cache. It carries none of your vocabulary and neither of the identifiers described above — no installation identifier and no RevenueCat App User ID — and the app does not create an installation identifier in order to play one. The clips are generated once and cached on our Worker for all users, so playing one ordinarily reaches the cache rather than OpenAI. Playing one does not grant AI data-sharing permission and does not enable any other AI feature.
  • On-device speech is not an AI feature in this sense: free-plan pronunciation uses your device’s built-in text-to-speech, and an audio file you attach to a card is played locally. Neither is sent anywhere, and both keep working if you do not grant permission.

4. Withdrawing your permission

You can withdraw permission at any time in the app under Settings → Help → About AI Voice. That screen shows the current state and, while permission is granted, offers "Withdraw AI Data Sharing Permission".

Withdrawing takes effect immediately: WordCore stops sending anything for AI features from that point, including background preparation of audio for words you already have. It does not delete any of your data — your words, folders, notes, notification settings and previously generated audio already stored on your device are untouched — and it does not affect any non-AI feature. If you later use an AI feature again, WordCore asks for permission again rather than resuming silently.

Because generation is only performed while permission is granted, withdrawing it does not, by itself, cause deletion of anything OpenAI may hold under its own retention practices. Requests already completed were governed by OpenAI’s terms and privacy policy at the time they were made.

5. Analytics and session recording

WordCore does not collect product analytics and does not record your screen. There is no analytics SDK in the app, no session recording, no pseudonymous analytics identifier, and no analytics provider that receives information about how you use WordCore.

There is therefore no usage-sharing setting in the app: there is nothing for it to switch off.

  • Your answers to the onboarding questions — what you want to use WordCore for, and your learning and explanation languages — are stored on your device and used to set the app up for you. They are not transmitted to us or to anyone else. WordCore does not ask for your age, your gender or how you heard about it.
  • No in-app event is reported anywhere: creating or deleting a word, renaming a folder, answering a test question and exporting or importing a backup are all handled entirely on your device.
  • Crash and error information is not collected by us. Whatever Apple collects and shares under your own device’s analytics settings is governed by Apple, not by this policy.
  • WordCore does not use the Advertising Identifier (IDFA), does not ask for App Tracking Transparency permission, and does not track you across other companies’ apps or websites.
  • The online features in section 2 — AI generation and subscription verification — are unchanged by this. They send what that section describes, and nothing about them is analytics.

Apple / App Store

App distribution, in-app purchase processing, subscription management, refunds, and device-level services such as local notifications.

Apple processes purchase, subscription, device, and account information under its own terms and privacy policy. WordCore does not receive complete payment-card details.

Provider privacy policy

RevenueCat

Subscription purchase orchestration, restoration, and verification of Basic and Premium entitlements.

A pseudonymous RevenueCat App User ID, app and device information, purchase receipts, product identifiers, and subscription status may be processed.

Provider privacy policy

Cloudflare

Hosting and protecting the WordCore API Worker, storing short-lived entitlement and abuse-prevention counters, and caching shared promotional voice clips.

Network information such as IP address, request metadata, pseudonymous salted hashes, request counters, entitlement tier cache entries, and operational logs may be processed. User text and authorization credentials are excluded from WordCore application logs.

Provider privacy policy

OpenAI

Generating High-Quality AI Voice audio and any other server-assisted AI output that WordCore makes available.

The text submitted for generation and generation settings such as voice or language are sent through the WordCore API Worker. Pseudonymous WordCore identifiers are not intentionally included in the prompt sent to OpenAI.

Provider privacy policy

Vercel

Hosting and delivering the WordCore public website and these legal pages.

IP address, browser and device information, requested URL, timestamps, and security or delivery logs may be processed when the website is visited.

Provider privacy policy

6. Backup and data transfer

Backup & Restore is a Premium feature that creates a file on the device at the user’s request. The user chooses whether and where to share or store that file. WordCore does not automatically upload or retain a server copy.

A backup may contain vocabulary, meanings, notes, folders, labels, learning progress, review history, visibility timestamps, notification settings, and transferable app preferences. It excludes device-local audio files, installation identifiers, RevenueCat identifiers, credentials, and purchase entitlements. Anyone who receives a backup file may be able to read its contents, so users should store and share it carefully.

7. How we use information

  • To provide vocabulary study, local reminders, backup and restore, subscription features, and requested AI-generated output.
  • To authenticate paid entitlements, apply the Basic 10-card AI Voice allowance, and restore purchases.
  • To prevent abuse, enforce request and usage limits, diagnose failures, protect service availability, and control operating costs.
  • To respond to support requests and legal obligations.
  • To operate, secure, and improve the WordCore app and website.

8. Third-party services and disclosure

WordCore uses the service providers listed below. Information is disclosed only as reasonably necessary for their stated functions, to comply with law, to protect rights and safety, or in connection with a lawful business transfer. Their own terms and privacy policies govern their processing.

WordCore does not sell personal information and does not use third-party advertising SDKs or third-party product-analytics SDKs of any kind — see section 5.

9. Retention

  • Device data remains until you delete it, clear relevant content, remove the app, or the operating system removes cache files.
  • The WordCore API does not intentionally place submitted user text in application logs or the Worker KV store. It is transmitted to the relevant AI provider to fulfill the request.
  • Entitlement cache entries are generally retained for approximately 30 seconds to 5 minutes. Minute rate-limit counters are generally retained for up to 2 minutes, and daily counters for up to 48 hours.
  • The Basic AI Voice card allowance uses salted hashes of the RevenueCat App User ID and card IDs. Card grants are retained without a monthly expiry so renewals and reinstalls do not issue another 10-card allowance. Failed generation reservations expire or are released without claiming a card.
  • Shared voice-preview and promotional audio caches may be retained for approximately 30 days. These shared clips contain fixed WordCore-authored text, not user-submitted text.
  • There is no analytics or session-recording data to retain, and no analytics provider holds any.
  • Onboarding answers remain on your device and are deleted with the app. Nothing is derived from them and sent anywhere.
  • Operational logs and support communications are retained only for as long as reasonably necessary for security, troubleshooting, support, legal compliance, and dispute handling, subject to provider settings and legal obligations.

10. Website storage

The website uses necessary local browser storage to remember light or dark theme and may use a functional locale cookie to remember language routing. The current website does not use advertising or third-party analytics cookies.

11. Security

We use reasonable technical and organizational safeguards, including encrypted network transport, server-side secret storage, input limits, pseudonymous salted identifiers for server counters, restricted logging, and device Keychain storage for the installation identifier. No system is completely secure, and users should protect their devices and backup files.

12. International processing

WordCore’s providers may process information in Japan, the United States, and other countries where they operate. Those countries may have different data-protection laws. We use providers and safeguards reasonably appropriate to the services being supplied.

13. Your choices and rights

  • You can edit or delete vocabulary and other local content in the app and can remove local app data by deleting the app, subject to iOS behavior and any backup copies you created.
  • You can decline notification permission or disable notifications in iOS Settings.
  • You can decline AI data sharing when asked, and can withdraw permission at any time under Settings → Help → About AI Voice. See sections 3 and 4.
  • There is no usage-sharing setting to turn off, because WordCore collects no product analytics and records no sessions. See section 5.
  • You can manage or cancel subscriptions through your Apple account settings.
  • To request access, correction, deletion, restriction, objection, or information about personal data handled by the Operator, contact daiki.studio9@gmail.com. Applicable rights vary by jurisdiction. We may need to verify the request and may retain information where legally permitted or required.

14. Children

WordCore does not knowingly request a child’s name, address, or direct contact information through an account-registration system. If a parent or guardian believes a child has sent personal information to the Operator, please contact daiki.studio9@gmail.com.

15. Changes to this policy

We may update this Privacy Policy to reflect changes in WordCore, service providers, law, or operating practices. The updated policy will be posted on this page with a revised effective date. Where legally required, additional notice or consent will be provided.

16. Contact

Operator: Daiki Tokumoto

Privacy and support email: daiki.studio9@gmail.com

Privacy Policy | WordCore