Privacy
Wordfold Privacy Policy
What Wordfold handles, why, and how you can control it.
Effective 24 September 2026
Who is responsible
Wordfold is provided by Jozef Majzel. For privacy questions or requests, email support@wordfold.app.
Information Wordfold handles
On your device and in your account
Without an account, your vocabulary, translations, collections, learning progress, preferences and reminders remain on your device unless you explicitly share word content in a feedback report. When you sign in, Wordfold processes your email address, authentication identifier, collections, words, translations and learning events through Supabase and PowerSync to synchronize them between your devices.
Optional cloud pronunciation
If you are signed in, explicitly enable optional cloud neural pronunciation, and tap its sound control, the exact displayed word or phrase and selected locale are sent through a Wordfold Supabase server function to Microsoft Azure Speech. The resulting MP3 is stored in an account-private Supabase area and may be cached on your device. Wordfold pronunciation metadata and audit records do not contain the raw word or phrase.
Optional AI suggestions
When you request an AI vocabulary suggestion, Wordfold sends the word, selected languages and any context you provide through a Supabase server function to OpenAI. The request and generated suggestion are stored privately with your account so interrupted requests can be recovered without charging twice. Credit grants and usage are recorded on the server. Pending suggestions and unfinished bulk reviews are stored locally for the current account and course.
Purchases and feedback
If you buy the lifetime unlock, Google Play processes the payment. RevenueCat processes product, transaction, entitlement, store-account and technical identifiers needed to validate and restore it. Wordfold does not receive your payment-card details. An opaque RevenueCat identifier is linked to your signed-in Wordfold account to verify the one-time paid AI credit allowance.
If you submit feedback, Wordfold sends your message, category, optional contact email, language pair, basic app and device details, and any word content shown in the report preview to Supabase. A random installation identifier and hashed network address help limit abuse. Reports are stored privately and forwarded through Resend to the developer’s Gmail inbox. Feedback does not attach your vocabulary library. Reports waiting for connectivity are stored on your device and retried while the app is open. Sent reports remain in My feedback as local history until you remove them or clear the app’s data. This history does not synchronize between devices; removing a local entry does not delete its server or email copies.
Technical data
Cloud providers may process limited request and security metadata, such as timestamps, IP addresses and error logs, to operate and protect their services. Cloudflare serves these public pages and may handle technical request data to deliver and protect them. The pages have no account form or analytics script.
How information is used
Wordfold uses this information to provide authentication, synchronization, cloud pronunciation, AI suggestions and credit accounting, purchase validation and restoration, security, support, feedback review, product and content improvements, and account deletion. Wordfold has no advertising, does not sell personal data, and does not include a separate behavioral analytics SDK.
Service providers
Wordfold uses Supabase for authentication, database, storage and server functions; PowerSync for synchronization; Microsoft Azure Speech for optional real-time speech synthesis; OpenAI for optional vocabulary suggestions; RevenueCat for purchase entitlements; Google Play for app distribution and payments; Resend and Gmail for feedback email delivery and review; and Cloudflare to host these pages. According to Microsoft, its real-time text-to-speech service does not retain input text or generated audio. See Azure Speech data privacy and security. Each provider processes information under its own security and retention obligations.
Retention and deletion
Device data remains until you delete it or uninstall the app, subject to Android backup behavior. Synchronized account data remains until you delete your cloud account. Account-private pronunciation MP3s expire automatically 30 days after their latest use, and pronunciation audit records are retained for no more than 30 days. Device pronunciation files are cache data and may be removed earlier by the operating system or Wordfold’s cache limit.
Turning off cloud neural pronunciation stops new cloud pronunciation requests and asks Wordfold to delete that account’s saved private audio, pronunciation metadata, audit records and local private pronunciation cache. If deletion cannot finish while offline, Wordfold keeps the feature off and offers a retry. In-app account deletion removes the Supabase account and associated synchronized and private pronunciation data while preserving a local vocabulary copy on that device.
Cloud AI requests, generated suggestions, credit history and the account linkage are removed when you delete your cloud account. An unlinked, one-way purchase fingerprint remains to prevent repeated claims of bonus credits. Local AI drafts are removed on in-app account deletion. Google Play and RevenueCat may retain purchase records for transaction, fraud-prevention, tax or legal reasons.
Feedback is independent of your cloud account and is not automatically removed when you delete that account. Reports and notification emails remain available for support and improvement review until removed by the developer. You can remove an unsent local report in the feedback screen. To request deletion of a submitted report and its email copy, contact support@wordfold.app with its report ID or enough details to locate it.
See how to request account deletion with or without the app.
Your choices and rights
Cloud neural pronunciation is optional and off until you enable it. Device pronunciation remains available without sending the word or phrase to Azure. AI generation is also optional; dictionary lookup and manual entry remain available without it. You can use Wordfold without an account, delete individual words, turn off cloud pronunciation and delete its private audio, or delete your cloud account. Depending on your location, you may also request access, correction, restriction, portability, objection or deletion by emailing support@wordfold.app.
Security
Cloud communication uses encrypted HTTPS connections. Access to synchronized data is restricted by authenticated account rules. No method of storage or transmission is completely risk-free.
Changes to this policy
If this policy changes materially, its effective date and published content will be updated before the changed processing is used.