Privacy Policy
Last updated: August 29, 2026
Vocabcord is built around a simple principle: we don't want anything that identifies you. No accounts, no advertising identifiers, no profiles, no third-party trackers. This page explains exactly what the Vocabcord apps for iOS and Android do and do not do with information related to you.
What we collect
No personal data. Vocabcord does not collect, store, or process anything that identifies you. Specifically:
- No account creation or login is required or offered.
- No advertising identifiers, device fingerprints, or tracking pixels.
- No third-party analytics, attribution, ad, or crash-reporting SDKs are embedded in the app.
- No contacts, photos, microphone, or location access is requested.
- We never see your name, email, Apple ID, Google account, payment method, or any other personal information.
The app does send a small amount of anonymous, non-personal information to our own servers, described next. None of it can be tied to you.
Anonymous setup and reliability analytics
To measure how many installs actually reach a working setup (on iOS that means wiring up the Shortcuts automation, the step where people most often get stuck; on Android the trigger works out of the box), the app sends two one-time events to our own servers:
- First open. Sent once, the first time you open the app.
- First phrase played. Sent once, the first time a charger-triggered phrase actually plays, so we know your setup worked.
The app also sends a reliability signal each time the charger trigger fires, and when your phone does its background housekeeping while charging. The whole promise of Vocabcord is that a word plays when you plug in, and both platforms can quietly stop that from happening: iOS stops launching the app in the background for apps you rarely open, and Android can refuse the app permission to make a sound without reporting any error. From inside the app a silenced play looks identical to a successful one, so these signals are the only way we can tell whether the app is still working on real phones. Each one carries:
- The app version, your operating system version, and (on Android) the phone's manufacturer, so we can see if a failure is specific to one OS release or one brand.
- How many hours it has been since the app was last opened, rounded to whole hours, because that is what the throttling is based on.
- Whether the trigger ran, whether the sound was allowed, and which of the app's internal mechanisms handled it, plus the battery-optimisation settings the system reports for Vocabcord.
All of it describes the app and the phone's settings, never you or what you do on the phone. We do not record which words you heard, when you charge, or anything you type.
Every event above carries the same random identifier generated on your device, used only to group one install's events together, plus the app version. That identifier is not your Apple ID or Google account, not your device's advertising identifier (IDFA / Android Advertising ID), and not any hardware ID, and it is never linked to your name, email, or any personal information. No third-party analytics service is involved: these go to our own servers and nowhere else. We also approximate your country from your network connection at the moment of the request, the same coarse signal any web server sees, and we store nothing beyond what is listed on this page.
Separately, if you tap "Request a language" inside the app, that sends us the text you type plus your device language and app version, so we can decide which languages to build next. That happens only when you choose to submit the form.
What stays on your device
Vocabcord stores its working state locally on your device (on iOS inside the app's App Group container, on Android in the app's private storage). None of it leaves the device:
- Spaced-repetition state — a single file (
phrase_state.json) tracking which phrases you've heard, how often, and when each is due to surface again. This drives the weighted exponential decay that decides what plays next. - Selected pack and language pair — the CEFR pack you're currently learning from.
- Purchase status — whether you've unlocked paid packs, managed via Apple's StoreKit framework on iOS and Google Play Billing on Android (see below).
- Bundled audio assets — the phrases and recordings ship inside the app bundle and are read locally during playback.
This data is stored using the platform's standard local-storage APIs (UserDefaults on iOS, SharedPreferences and app-private files on Android). It is automatically removed when you uninstall the app. On Android we explicitly exclude it from Google's cloud backup and device-to-device transfer, so it never leaves the device that way either.
Third-party services
Vocabcord integrates with the platform frameworks below and nothing else. There are no other third-party SDKs, analytics, ad networks, or trackers in either app.
Apple StoreKit (In-App Purchases)
When you subscribe or restore a prior purchase, the app uses Apple's StoreKit framework to process the transaction. Apple handles the payment, verifies the receipt, and tells the app whether you've purchased. Vocabcord never sees your payment method, Apple ID, or billing information. Apple's privacy policy governs that interaction: apple.com/legal/privacy.
Apple Shortcuts (Automation, iOS)
Vocabcord exposes an App Intent ("Play Phrase") that the iOS Shortcuts app can trigger. When your charger is connected and your personal automation runs, iOS asks Vocabcord to pick and play the next phrase. Choosing what plays happens entirely on your device. The only thing that ever leaves your device here is the one-time anonymous "first phrase played" event described above, sent the very first time a charger-triggered phrase plays. You can remove the Shortcut at any time in the iOS Shortcuts app.
Google Play Billing (In-App Purchases, Android)
On Android, subscriptions and the lifetime unlock are processed by Google Play. Google handles the payment and tells the app whether you've purchased; we never see your payment method or Google account. When Google notifies our server that a purchase happened (so subscription status stays accurate), that notification carries the purchase and the same random install identifier described above — never your name, email, or account. Google's privacy policy governs the transaction itself: policies.google.com/privacy.
The Android charger trigger
On Android there is nothing to wire up: the app itself listens for the moment your phone starts charging, using a small always-ready service that Android shows as a quiet notification. That listening happens entirely on your device — connecting a charger sends nothing anywhere. You can switch the service off in the app's setup screen at any time.
Language pack downloads (Android)
Paid language packs are downloaded from our own server (packs.vocabcord.com) when you choose them. A download is a plain web request: like any web server, ours sees your IP address for the duration of the request and nothing else — no identifier, no account, nothing tied to you. Downloaded packs are stored on your device.
Children's privacy
Vocabcord does not knowingly collect personal data from anyone, including children under 13. The anonymous setup events described above contain nothing personal and cannot identify anyone, child or adult.
Your rights (GDPR, CCPA, etc.)
Privacy laws such as the GDPR (EU) and CCPA (California) give you the right to access, correct, or delete personal information held about you. Because Vocabcord holds no information that identifies you, there is nothing personal for us to access, correct, or delete. The anonymous setup events cannot be traced back to you, so they cannot be tied to an individual person. You can remove all on-device data associated with Vocabcord by uninstalling the app.
Changes to this policy
If we ever begin collecting anything that identifies you, we will update this page first and make the change clear in the app. The "Last updated" date at the top of this page reflects the most recent change.
Contact
Questions about this privacy policy? Reach us at our support page.