Wordhoard

Privacy

Last updated 16 August 2026

The short version, which is accurate:

This policy covers the Wordhoard iOS app, its widget and share extension, the Wordhoard browser extension, and this website. It is written to be read rather than to be defensible, and where something is a trade-off it says so.

What never leaves your phone

These are stored on your device and are not sent anywhere, ever, signed in or out:

What leaves your phone, and when

WhatWhenWhere it goes
The word you looked up Every lookup Wiktionary, and dictionaryapi.dev for pronunciation audio
The word, the sentence around it, and the language Only when you tap “Explain this more simply” Our server, then OpenAI
Your words, meanings, cards, shelves and the sentences you met words in Only while signed in Our server
A book or shelf title, and its author When fetching a cover image Open Library
A book title you search for Only in “Words from a book” Gutendex and Project Gutenberg
An anonymous identifier for this install With rewrite requests Our server

The anonymous install identifier

A random number generated on your phone the first time you open the app. Nothing about it is derived from your device, your Apple ID, or you — it cannot be linked to another app, and it is only sent to our own server. Its one job is counting the ten free rewritten definitions, so that everybody behind one mobile network is not treated as a single person.

Rewritten definitions

When a dictionary definition doesn't help, you can ask for one written for the sentence you are reading. That is the only feature that sends anything to a language model, and it only happens when you tap the button.

What goes: the word, up to 600 characters of the sentence around it, and which language the word is in. What does not go: your name, your account, your other words, your review history, or anything else. Our server passes it to OpenAI, which processes it to generate the definition. We do not send OpenAI anything that identifies you, and under their API terms they do not use it to train models.

Signing in

Signing in is optional. Everything except syncing and family sharing works without it.

Wordhoard uses Sign in with Apple and asks Apple for no personal information at all — not your name, not your email address, not even a private relay address. What Apple gives us is an opaque identifier that looks like 001234.abcdef…, which is meaningless outside Wordhoard and cannot be turned back into you. That is the whole of your account.

We do not know who you are. If you emailed us and asked us to find your account, we could not do it without you telling us the identifier.

What syncing copies

Once signed in, these are copied to our server so your other devices and your browser can read them:

That last one deserves saying out loud, because it is the most personal thing here: a sentence out of a book you were reading, or a line off a web page. It syncs because a word without the sentence you met it in is half a flashcard, and because the browser extension has nowhere else to put it. If you would rather it stayed on your phone, do not sign in — the app is fully functional without an account.

Your review history and folders are not copied, signed in or not.

Making cards for someone

If you make flashcards for a child or a student, here is exactly what our server is told: two opaque account identifiers, the name you asked to be called (“Mum”), and a timestamp.

We are never told the other person's name. The name you type for them is stored on your phone and is not sent anywhere. It is the one piece of information in this feature that would be about a child, and the simplest way to be certain it is never leaked, breached or handed over is to never have it. The cost is that the names do not follow you to a new phone, and we think that is the right way round.

Words you send become that person's words. Either of you can end the connection at any time, on your own, with immediate effect and without the other being told.

The browser extension

The extension reads a word only when you double-click one, and the paragraph around it only in order to find the sentence. It sends nothing while you browse and has no analytics.

When you click Save, it sends the word, its meanings, the sentence, the page's title, and the page's address with the query string removed. That removal is deliberate: query strings are where password-reset links, unsubscribe keys, session tokens and tracking parameters live, and this goes into a library that syncs.

Looking a word up sends it to Wiktionary, exactly as the app does.

Who else is involved

WhoWhat they getWhy
Cloudflare Everything sent to our server, plus your IP address They host it. IP addresses are used to rate-limit abuse and are not stored by us.
OpenAI A word and its sentence, when you ask for a rewrite They generate the rewritten definition.
Wikimedia The word you looked up, and your IP address Wiktionary is where the definitions come from.
dictionaryapi.dev The word you looked up, and your IP address Pronunciation audio and phonetic spelling for English.
Open Library A book title and author, and your IP address Cover images for your shelves.
Project Gutenberg and Gutendex A book title you search for, and your IP address Finding and reading the book in “Words from a book”.
Apple Sign-in, your subscription, and App Store analytics you can switch off in iOS Settings They run the platform and take the payments. We never see your payment details.

That list is the complete set of things Wordhoard can contact. There are no others, and there is no advertising or analytics network anywhere in the app, the extension or this website.

How long things are kept

Deleting everything

In the app: You → Delete account. It takes effect immediately and removes your whole synced library, every sharing connection, and your allowance counters from our server.

It does not touch your phone. Every word, card and review stays exactly where it is — they were always local, and the account was only ever the copy. If you want those gone too, delete the app.

Signing out is different and smaller: it removes the token from your phone and leaves everything else alone.

Children

Wordhoard is a general-audience app for readers. It is not in the App Store's Kids Category and is not directed at children.

It can, however, be given to a child by a parent using the sharing feature, and it is built on that assumption: no discovery, no directory, no way for a stranger to reach anybody, and no personal information collected from anybody. As described above, we are never told a child's name — or anyone's.

We do not knowingly collect personal information from children, largely because we do not knowingly collect personal information from anyone.

Your rights

If you are in the UK, the EU, or a place with comparable law, you have the right to see what we hold about you, to correct it, to delete it, and to object to how it is used.

In practice the app already does most of this better than we could by email: the library we hold is the library on your phone, so you can see all of it there, change any of it there, and delete all of it from You → Delete account. If you would rather ask us, please do — but note that because we hold no name or email address, we can only act on a request if you can tell us your account identifier, which you can find by signing in on the device in question.

We do not sell personal information and never have. We do not share it for advertising. There is nothing to opt out of.

Legal basis, for those who need it

Data is processed in the United Kingdom, the European Union and the United States, depending on which Cloudflare and OpenAI locations serve your request.

Changes

If this policy changes in a way that affects what leaves your phone, the date at the top will change and the app will say so on the account screen. We are not going to quietly widen it: the last time syncing changed what was sent, the wording in the app was rewritten the same day, and the sentence it used to carry — “nothing leaves the phone” — is called out in the source code as a lie that had to be fixed.

Contact

support@wordhoard.app — a person reads it.