Legal
Privacy Policy
What information Apilingual handles, why, and how it is protected. No tracking, no ads, no selling of data.
Last updated: 1 September 2026
This policy explains what information Apilingual handles, why, and how it is protected. It covers this website, the Apilingual account, and the Apilingual browser extension.
Who is responsible
Apilingual is a personal project. I build and run it myself, and I am the person responsible for the data described here. You can reach me at [email protected].
This website
This site is currently a placeholder. It does not ask for any information from you: there is no account form, no sign-up, no newsletter, and no payment. Like any website, the server receives standard request information such as your IP address and browser type, which is needed to deliver the page and to keep the service secure. No advertising or analytics cookies are set.
The Apilingual account
If you have an Apilingual account, the following is held for it:
- Account and sign-in information. Your user ID, email address, and display name, which is what is needed to identify you and keep you signed in. Passwords are stored only as salted hashes. If you sign in with Google, Google handles the authentication and I never see your Google password.
- Content you import. Text, ebooks, audio, or caption tracks that you explicitly choose to import are saved to your account so they can be turned into lessons.
- Learning data. The vocabulary you are learning, your review history and progress, your learning activity, and your settings.
The browser extension
The Apilingual browser extension lets a signed-in user work with videos they are already watching: importing a video's captions as a lesson, showing a learning layer over the subtitles on supported sites (currently YouTube and Netflix), and, on YouTube, showing a difficulty estimate for a video measured against that user's own vocabulary. It handles:
- Sign-in information. When you sign in, your credentials go to the Apilingual servers to authenticate you. The extension then keeps an authentication token and your basic profile (user ID and email address) locally in your browser so you stay signed in. It does not store the credentials themselves, and it never sees your login for YouTube, Netflix, or any other video service. You sign in to those directly with them.
- Content you choose to import. When you press Import, the extension reads the caption text of the video you are viewing, along with its title and URL, and sends it to your account to create a lesson. This happens only for videos you explicitly import.
- Subtitle text, processed transiently. To colour subtitle words by your vocabulary knowledge and to show word meanings, subtitle lines are sent to the Apilingual servers, analysed in real time, and immediately discarded. Subtitle text is not stored or logged, and no transcripts, translations, or other copies of a title's subtitles are kept, for you or for anyone else. The one exception is under your control: when you deliberately save a word, that word is stored together with the single subtitle sentence it appeared in, as the example context in your private vocabulary. That sentence is visible only to you and is deleted when you delete the word or your account.
- Video difficulty information (YouTube). While you are signed in and on a YouTube video page, the extension sends the video's public identifier to check whether a difficulty estimate already exists. For a video not seen before, and only when its language is one you are learning, it also sends the video's public metadata (title, channel, duration) and a list of the unique words in its captions with how often each occurs. That word list is unordered, so the captions cannot be reconstructed from it, and it is processed and then discarded. What is kept is the video's public metadata and anonymised, aggregate word-frequency statistics that are identical for every learner. Your personal difficulty percentage is computed on request from your own vocabulary and is never stored. None of this happens while you are signed out.
- Word pronunciation. Pressing the speak button on a word card fetches a short audio clip of that word. Clips are generated from dictionary words only and may be cached in your browser for the session.
- Learning activity. Use of the learning features is recorded: session duration, whether the second subtitle line is enabled, which words you look up and save, and which titles you open with the learning layer active (the title's name and the languages involved, nothing more). This runs your review scheduling and study streak and informs which shows, languages, and services to support next. These records never contain subtitle text.
- Preferences. Your most recently used course and language, and your display settings, stored locally in your browser.
- Active tab information. To confirm you are on a supported video page, the extension checks the URL of your active tab. It does not read, collect, or store your browsing history, and it operates only on the page you are actively using it on.
Browser permissions
The extension requests only the permissions the functions above need:
- storage: to keep your sign-in token, last-used course and language, and display settings on your device.
- tabs: to check the active tab's URL, to open and later close a tab for Google sign-in, and to open your finished lesson. Browsing history is never read.
- scripting: to inject the extension's own bundled content script into the active video tab, so it can read the caption or subtitle tracks and display the learning overlay.
- Host access to www.youtube.com: to read the caption tracks of the video you are actively viewing and to display the overlay and the difficulty badge on the page.
- Host access to www.netflix.com: to read the subtitle tracks of the title you are actively watching and to display the overlay on the player.
- Host access to app.apilingual.com: to sign you in, look up your vocabulary, and save lessons and words to your account.
All executable code is packaged inside the extension. No remotely hosted code is used, and network requests retrieve or store data only, never executable code.
What does not happen
- Your browsing history is not collected.
- Your credentials for YouTube, Netflix, or any other video service are never accessed.
- Subtitle files, transcripts, or translations of a title are not stored, reproduced, or shared. Subtitle text is processed transiently and discarded; the only stored fragment is the single sentence attached to a word you deliberately save.
- Nothing is read or displayed on sites other than the supported services listed above.
- Your data is not sold, shared with advertisers, or used for advertising or profiling.
Processing and third parties
To generate the drills, translations, grammar analysis, and word meanings that make up a lesson or the learning layer, the content you import or view is processed using third-party AI and language providers. Account and learning data is stored with infrastructure and hosting providers. If you choose "Continue with Google", authentication is handled by Google. These providers act only as processors under contract and are not permitted to use the data for their own purposes. Copyrighted material is not redistributed.
Security
Data is transmitted over an encrypted (HTTPS) connection. Authentication tokens are held in the browser's protected extension storage and are never exposed to the pages you visit.
Data retention
Locally stored data (token, profile, preferences) persists until you log out or uninstall the extension. Your account and learning data is kept for as long as your account is active. You can delete individual lessons, content, and words from within the app, and you can ask for your account and its data to be deleted. Subtitle text processed for the learning layer is not retained.
Your rights
You can access and update much of your information directly in the app. You can also ask for a copy of your data or for it to be deleted. To make a request, use the contact address below. Depending on where you live, you may have further rights under local data-protection law.
Children's privacy
Apilingual is not directed to children under 13, and personal information is not knowingly collected from them.
Changes to this policy
This policy may be updated from time to time. Material changes will be reflected by updating the date above.
Contact
Questions about this policy or your data can be sent to [email protected].