Privacy Policy
Last updated: 4 November 2025
Overview
WordBookmark ("we", "us", "our") operates wordbookmark.com, a web application that helps users save English words and practice them using a spaced repetition system. This Privacy Policy explains what information we collect, why we collect it, how we use it, and what choices you have.
Data controller
The data controller for personal data collected via the App is WordBookmark. For privacy requests (access, correction, deletion), please contact us via the contact form at /contact. We aim to respond to requests promptly and within applicable legal timeframes.
Information we collect
- Account information: email address (required), username (optional).
- Usage data & analytics: page views and usage metrics collected by Google Analytics.
- App data: words you add, the practice count for each word, and metadata needed for the spaced repetition system.
- Session data: Flask sessions (secure signed cookies) to maintain authentication and session state.
How we use your data
- Provide and operate the App (saving words, spaced repetition, generating examples).
- Respond to support requests you send via the contact form.
- Improve the App through analytics and usage metrics.
Legal bases for processing (GDPR)
- Performance of a contract: processing is necessary to provide the service you request (saving words, managing your account).
- Legitimate interests: analytics and product improvement. We minimise data and anonymise analytics where possible.
- Consent: where legally required (for optional marketing communications), we will obtain consent.
Cookies and tracking
We and third parties use cookies and similar technologies for session management, analytics, and functionality. The App uses Flask sessions (secure signed cookies) to track logged-in users. We also use Google Analytics for site usage metrics. You may control cookies through your browser settings and can opt out of Google Analytics tracking using browser add-ons or settings.
Third-party services
We may use third-party services to provide, maintain, and improve the App. These providers may process your data as necessary to operate the service.
Each provider has its own privacy policies and safeguards. Where data is transferred outside the UK/EU (for example to hosting or API providers), we rely on appropriate safeguards such as Standard Contractual Clauses and/or the provider's adequacy decisions where available.
Data retention
We retain account and app data as long as your account exists. If you request deletion via the contact form at /contact we will remove your personal data in accordance with applicable law, subject to any legal record-keeping obligations.
Your rights (GDPR)
If you are in the UK/EU you have certain rights, including:
- Right to access the personal data we hold about you.
- Right to correct inaccurate personal data.
- Right to request deletion (where lawful).
- Right to restrict or object to processing and to data portability in certain cases.
- Right to withdraw consent where we rely on it for processing.
To exercise these rights, please contact us via the contact form at /contact. We will respond within applicable statutory timeframes.
Security
We take reasonable steps to protect your data, including using secure connections (HTTPS) and secure, signed Flask session cookies. However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised date. Continued use after changes indicates acceptance.
Contact
For privacy requests or questions please use the contact form at /contact.
Governing law
This policy is governed by the laws of England and Wales.