Nightspar
Back to home

Privacy Policy

Last updated: 2026-07-26

This policy explains what personal data Nightspar collects, why, and what rights you have over it. We keep it in plain English and try not to collect anything we don't need.

1. Who we are

Nightspar is a language-learning service, available as a web app, a browser extension, and an MCP (Model Context Protocol) server. The data controller responsible for your personal data is Anatolie Turcan, an independent developer based in the Republic of Moldova.

If you have any questions about this policy or want to exercise your rights, contact us at [email protected]. Mail to our contact addresses is routed through Cloudflare to a Google mailbox.

2. What we collect and why

We collect only what we need to run the service. The table below lists each category of data, why we process it, and the legal basis we rely on under the GDPR.

What we collectDetailsPurposeLawful basis
AccountEmail, name, hashed password (and, if you use Google sign-in, your Google account email and name).Create and secure your account and sign you in.Contract (Art. 6(1)(b))
Profile & settingsYour native and target languages, timezone, and learning limits.Personalize the learning experience.Contract (Art. 6(1)(b))
Your contentPhrases you save; AI enrichment (meanings, translations, IPA, examples); collections; generated audio.Provide the core service and store your vocabulary.Contract (Art. 6(1)(b))
Context captureA short snippet of text surrounding a phrase you save, plus the page URL and site name, from third-party websites you choose.Show you where you learned a phrase and improve enrichment accuracy.Contract (Art. 6(1)(b))
Learning dataFlashcard review history, ratings, and daily statistics.Schedule spaced-repetition reviews (FSRS).Contract (Art. 6(1)(b))
FeedbackThe message you send and your account email.Respond to and act on your feedback.Legitimate interest (Art. 6(1)(f))
Technical dataIP address and request metadata (in logs), error events (which may include IP and user-agent), and cookieless product analytics events with no persistent identifiers. Phrase text is never sent to analytics, and page URLs are captured without query strings.Keep the service secure and reliable, prevent abuse, and understand usage in aggregate.Legitimate interest (Art. 6(1)(f))

We do not make any decisions about you by solely automated means that produce legal or similarly significant effects (GDPR Art. 22). AI enrichment produces learning content, not decisions about you.

3. Context capture in the browser extension

When you save a phrase using the browser extension, we also store a short snippet of the text surrounding it, together with the page URL and site name. The URL is sanitized before storage: credential-like query parameters are removed, ordinary fragments are dropped, and hash-based routes keep only their route path. This lets you see where you first encountered a phrase and helps the AI pick the right sense of a word.

This capture happens only when you explicitly save a phrase. The extension does not read, monitor, or transmit the pages you visit in the background, and it does not track your browsing. You can turn this off at any time in the extension's settings — with it off, only the text you select is sent, without the surrounding snippet. Please avoid saving phrases from pages whose content is confidential or sensitive — the snippet is stored with your phrase.

4. AI processing

To generate meanings, translations, example sentences, and pronunciation, the text of a phrase you save is sent to our AI providers (currently OpenAI and Google Gemini — see the Sub-processors table below for the current list). When you save a phrase with the extension and context capture is enabled, the surrounding context snippet is sent alongside the phrase in the same request, and is used only to help the model pick the correct sense of the word — the generated definitions are general and do not quote your snippet back.

If you use smart collections, the description you write for a collection, together with the text and meanings of your phrases (as text and as vector embeddings), is sent to Google Gemini to decide which phrases match the collection.

We use these providers on their paid/API tiers, under which they do not use your data to train their models. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, subject to legal and safety exceptions it states; Google logs paid-tier prompts and responses for a limited period for abuse prevention and where legally required.

If you connect Nightspar to an AI assistant through our MCP server, the data that assistant requests (for example, your phrases) is sent to the AI provider behind your chosen assistant and handled under that provider's terms — choose your assistant accordingly.

5. Sub-processors

We rely on the following third parties to operate the service, under their respective data processing terms. We will update this list when it changes.

ProviderPurposeRegionPersonal data
Google CloudHosting, database, file storage, and text-to-speech.EU (europe-west1)All of the above
OpenAIAI enrichment of phrases.United States (SCCs)Phrase text and context snippets
Google (Gemini API, paid tier)AI enrichment of phrases and smart-collection matching.GlobalPhrase text and meanings, context snippets, collection prompts, vector embeddings
PostHog (EU Cloud)Product analytics.EU (Frankfurt)Cookieless usage events (daily-rotating server-side identifier)
SentryError tracking.EUIP, user-agent, error context
ResendTransactional email (address verification, password reset) and internal notification of feedback.EU (Ireland)Email address, account email content; feedback message and reply address
CloudflareDNS, CDN, proxy, and routing of mail sent to our contact addresses.Global edgeIP, request metadata; contact mail content in transit
Google (Gmail)Mailbox where mail to our contact addresses is delivered.GlobalEmail you send to our contact addresses

6. International transfers

Your account and content are stored in the European Union. Some providers — including OpenAI, Google, Cloudflare, Resend, and Gmail — may process personal data outside the EEA. Where required, these transfers rely on safeguards such as adequacy decisions, Standard Contractual Clauses, or other recognized transfer mechanisms in each provider's data processing terms.

7. Cookies & analytics

We use strictly necessary session cookies (from Keycloak) to keep you signed in. We do not use advertising cookies or cross-site tracking.

Our product analytics (PostHog, EU) run in cookieless mode: no cookies, no browser storage, and no account identifiers. PostHog computes a privacy-preserving server-side identifier that rotates daily — so activity is not linked across days — and the underlying IP address is not stored with analytics events. We process this limited, short-lived analytics data — coarse usage events and page URLs stripped of query strings — under our legitimate interest in improving and securing Nightspar. Phrase text is never sent to analytics. You can object to this processing at any time (see Your rights below).

8. Chrome Web Store Limited Use

Our use of information received from the Nightspar browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

9. Retention

We keep data only as long as we need it:

  • Account and content: until you delete your account. Deletion takes effect immediately; residual copies may remain in encrypted automated backups and point-in-time recovery logs until they expire under our rolling retention schedule (currently seven daily backups and seven days of transaction logs). These copies are isolated from ordinary use and are only restored for disaster recovery.
  • AI enrichment inputs: the phrase and context snippet as sent to the model, together with the model’s raw reply, are kept for up to 30 days for debugging and cost analysis, then stripped automatically. If you delete your account they are unlinked from your account immediately, and the text itself is still deleted by the same 30-day sweep.
  • Aggregate AI usage figures — token counts and cost — are kept indefinitely; they contain no content and cannot be traced back to you.
  • Feedback: unlinked from your account immediately if you delete it; the message itself is kept while we act on it, at most 2 years.
  • Product analytics events (PostHog): up to 12 months.
  • Server logs: roughly 30 days.
  • Error-tracking events (Sentry): about 90 days.
  • AI provider request data: as described in the AI processing section above.

10. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (be forgotten).
  • Restrict or object to certain processing.
  • Data portability — receive your data in a portable format.
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these rights, email us at [email protected]. You can also delete your account and all associated data yourself at any time from your account settings — deletion is immediate; see Retention above for how long residual backup copies persist. You also have the right to lodge a complaint with your local data protection supervisory authority.

11. Security

We serve everything over HTTPS, and data is encrypted at rest by our infrastructure providers by default. Authentication tokens are held in memory in the app, not in browser storage, and your data is hosted in the European Union. No system is perfectly secure, but we take reasonable measures to protect your data.

12. Children

Nightspar is not directed at children under 18, and we do not knowingly collect data from them. You must be at least 18 to use the service.

13. Changes to this policy

We may update this policy from time to time. When we do, we will change the "Last updated" date below and, for material changes, notify you in the app or by email.


Last updated: 2026-07-26. We keep a revision history of this page and will update the date above whenever it changes.Adapted from the Basecamp open-source policies (github.com/basecamp/policies) / CC BY 4.0.