Privacy information
Last updated: 10 September 2026.
LangSail is a local-first reading and vocabulary application. You can use its core learning features without an account. In that mode, your imported texts, learning state, and preferences remain in storage controlled by your browser.
An account is optional. If you choose to sign in, LangSail processes your email address, account session, and the learning data you explicitly connect for backup and cross-device use. Provider-backed features are optional and identify the text that will leave the browser before the first request.
Who is responsible
The service operator is the controller for processing by the deployed LangSail service. The operator's identity and postal contact are provided on the directly accessible operator / imprint page. Privacy questions can be sent using the contact details.
Data kept in your browser
LangSail uses IndexedDB to keep imported source texts and library metadata, reading position, learned words, review state, segmentation choices, local settings, pending sync work, and rebuildable indexes and statistics. Small interface choices and records that a provider notice has already been shown are kept in local storage. The service worker and browser Cache Storage keep the application shell and language assets so supported local features can continue offline.
Importing or opening a text does not by itself upload it. Text parsing, sentence splitting, dictionary lookup, word counting, review scheduling, and reading statistics run in your browser. Browser storage normally remains until you erase it in LangSail, clear this site's data in the browser, or uninstall it in a way that removes site data. Signing out lets you choose whether to keep a detached local copy or remove account data from that device. Verified account deletion keeps the current device's copy detached; you can clear that copy separately.
Account and session data
If you request a sign-in code, LangSail processes the email address you enter. The service stores the address, the sign-in challenge and delivery status, a keyed hash used for request throttling, and keyed hashes rather than the code and session credential themselves. A successful sign-in creates account and device records containing an opaque identifier, a device label, platform and app version, and creation, activity, sync, expiry, and revocation times.
The session credential is held in a Secure, HttpOnly, SameSite cookie and is sent only with account requests. Sessions expire after 30 days without activity and in all cases after 90 days. Signing out revokes the current session; signing out everywhere revokes every session for the account.
Data kept for an account
When you explicitly connect a local workspace to an account, LangSail stores the email and account records plus synchronized library metadata in Cloudflare D1. This includes file names and folders, content hashes and sizes, reading progress, learned and review state, segmentation overrides, revisions, device and transfer bookkeeping, and any optional leaderboard profile or group data you create. D1 also holds short-lived authentication and rate-limit records and, when you request an online enhancement, provider-result caches and usage records. Some of those caches contain the sentence or generated result; accounting records use hashes, counts, timestamps, and provider request identifiers where possible.
The original source text for a connected document is stored as a private, account-scoped object in Cloudflare R2. It is available only through an authenticated, short-lived transfer instruction. Neural-speech audio may also be kept in a private shared cache under a keyed identity that does not contain the source text. LangSail does not expose R2 object addresses publicly.
If you enable reminders on a connected device, LangSail stores that device's push endpoint and encryption keys, timezone, selected days and times, review-card threshold, badge preference, and a copy of the locally selected review intervals. The server uses synchronized review state only to decide whether the threshold has been met. Reminder messages are generic and do not contain imported text, words, or an email address.
Local processing and optional online features
The local learning features described above do not send the text to an AI or translation provider. Synchronization sends connected account data only to the LangSail service. Cloud translation, learner translation, contextual explanation, and neural speech are separate online actions. Before the first such action, LangSail identifies the provider and the exact sentence, nearby context, dictionary evidence, or preload text that will be sent. The external Google Translate fallback likewise opens only after an explicit action and notice. A browser-provided on-device translator may download a model, but failure does not silently switch to a cloud provider.
Service providers and international transfers
Cloudflare. Cloudflare delivers the site and runs its Pages Functions and Worker, D1 database, private R2 object storage, authentication email, Turnstile abuse checks, rate limits, and operational logs. It therefore processes ordinary request data such as IP address, browser and network metadata, the account and synchronized data described above, authentication-email addresses and messages, and text sent through an optional online feature. Turnstile also receives browser and network signals when its challenge is shown. Cloudflare may process traffic on its global network and may use subprocessors outside the EEA; its customer data-processing addendum includes its transfer safeguards.
Browser push service. When reminders are enabled, the encrypted notification is delivered through the push service chosen by the browser or operating system. That provider receives the device's opaque push endpoint, encrypted payload, delivery timing, IP address, and ordinary network metadata. LangSail does not send it an email address or notification history.
Microsoft Azure. Cloud translation sends the normalized current Chinese or Spanish sentence, source and target language, and technical request identifiers from LangSail's Worker to an Azure Translator resource with the Global geography. Neural speech sends SSML containing the current sentence—and, after a requested sentence is synthesized, at most the next sentence for preload—plus the selected language, voice, and speed to an Azure Speech resource in West Europe. Microsoft states that the standard Translator and Speech paths used here are no-trace services: submitted text is not written to persistent storage or used for training. LangSail separately keeps validated translation results and private synthesized audio under the retention rules below. Processing may involve transfers covered by Microsoft's applicable product terms and data-protection addendum.
Fireworks AI. An explicit Chinese or Spanish learner-breakdown request sends the normalized current sentence, its language, and LangSail's instructions and output schema to Fireworks AI. LangSail does not send the user's email or account identifier. Fireworks states that it does not use API inputs to train models without an explicit opt-in and does not persistently log or store prompts or generated data for the open-model inference used by LangSail. Its automatic prompt cache may temporarily retain prompt data in volatile memory. Processing may involve transfers covered by Fireworks' data-processing addendum and international-transfer safeguards.
DigitalOcean. A contextual explanation sends the selected word and exact position, the current sentence, up to one adjacent sentence on each side, and up to four relevant local dictionary entries to DigitalOcean. LangSail does not send the user's email or account identifier. DigitalOcean states that hosted-model inputs and outputs are not used for training and that it does not keep complete inference inputs or outputs as request records. Its separate open-model prompt cache is account-isolated, automatic, cannot currently be disabled, and has no published maximum lifetime. DigitalOcean's data-processing addendum covers customer personal data and its international-transfer safeguards.
Anonymous online actions are limited through a one-day browser entitlement after a Turnstile check. LangSail may keep validated signed-in learner breakdowns and contextual explanations in its own account-scoped cache for up to 90 days; anonymous breakdowns and explanations are returned without being added to that cache.
External Google Translate. This is a direct navigation from the browser, not a Google API called by LangSail. After confirmation, LangSail puts the current sentence, source language, and English target language in the Google Translate page URL. Google then receives the request directly from the browser, including the IP address and ordinary browser, cookie, or signed-in Google account data available to Google. The URL may remain in browser or provider history. LangSail does not receive the resulting translation and does not appoint Google to process this fallback on its behalf.
Operational logs
The hosting platform processes ordinary network information needed to deliver and protect requests, such as IP address, request time, route, response status, and browser or network metadata. LangSail's own operational events use a random request identifier and record failure type, timing, counts, provider path, and upstream request identifiers where relevant. Private source text, generated answers, authentication codes, session credentials, and secret values are not intentionally written to operational logs, and production prompt logging is disabled. LangSail has no separate analytics or advertising profile in this release.
LangSail does not load analytics, advertising, session-replay, or cross-site tracking code in this release. Its browser storage and cookies provide the local, offline, account, and abuse-protection functions described above, so LangSail does not show a tracking-consent banner.
Application events are not copied to a separate LangSail log database; the hosting platform ages them out under the deployment's logging settings. Security and error records are used only to operate, secure, diagnose, and control the cost of the service.
Retention and deletion
Active account data is kept while the account exists. Deleted learning items remain as synchronization tombstones for 90 days so other connected devices can receive the deletion, then become eligible for scheduled removal. Unreferenced source objects are scheduled for removal after a 24-hour safety delay. Incomplete imports expire after one day; terminal import records and mutation receipts are removed after 30 days. Provider-result caches, usage records, and unused neural-speech audio are removed after 90 days. Expired authentication challenges and rate-limit windows are removed after 7 days; expired or revoked sessions after 30 days; and dormant device records after 180 days.
A reminder subscription is removed when you disable reminders on that device, when its push service reports that it has expired, when the associated device or account is deleted, or when you replace it with a new subscription.
A verified account-deletion request revokes sessions and deletes the account's email, D1 learning data, provider-result records, and R2 references. Account-scoped source objects left without D1 metadata are removed by scheduled cleanup; newly uploaded orphan objects are protected from that cleanup for 24 hours. LangSail retains only an opaque keyed account hash and deletion-operation status for up to 90 days so the request can be verified and retried. A local browser copy is separate and is not silently erased by deleting the cloud account.
Your choices and rights
You can use the local product without creating an account, export local learned-word data in Settings, sign out without deleting local browser data, or request verified account deletion from Settings. Subject to the applicable legal requirements, you may request access, correction, deletion, restriction, or portability of personal data, object to processing, and complain to a competent data-protection supervisory authority.
Service terms
LangSail is currently a free public beta. No separate terms are imposed beyond applicable law and the notices shown at the point of optional cloud features.