Privacy Policy

WordCue for iPhone · Effective September 25, 2026

Who this is from

WordCue is made by an individual developer ("we", "us"). You can reach us at tehon125@gmail.com.

What we do not collect

There are no user accounts, so there is nothing to sign up for and nothing to log in to. We do not ask for or collect your name, email address, phone number, contacts, location, or Apple ID. We do not show ads. We do not use any analytics, advertising, or tracking SDK, and we do not use the advertising identifier (IDFA). We do not sell or share data with data brokers, and we do not track you across other apps or websites.

What stays on your device

The following is stored only in the app's local storage on your device:

On iPhone these values are also mirrored into the app's native preferences, which iOS includes in your own iCloud or computer backup and in the "transfer to a new iPhone" flow. We have no access to your backups. The 1000+ words of the built-in dictionary are on the device as well, so looking them up works without a connection. When you are online, the app also reports each such lookup to our server so it can be counted against your plan: the report contains only the word and the anonymous device identifier, our server does not store the word, and nothing is sent to OpenAI. A lookup made offline sends nothing, so it is not counted.

What is sent to our server and to OpenAI

Explanations for words outside the built-in dictionary, "None of these — add the context", Translate, Similar words, Explain simpler, and photo recognition are AI actions. For an AI action the app sends the following to our server (a Cloudflare Worker), which turns it into a prompt and forwards it to OpenAI's API:

Our server does not store the content of these requests. It keeps only the counters described under "Anonymous device identifier". The content is processed by OpenAI to generate the result. Under OpenAI's API data usage policies, content sent through the API is not used to train OpenAI's models and may be retained for a limited period (OpenAI currently states up to 30 days) for abuse and misuse monitoring before deletion. Please refer to OpenAI's API data usage policies for current details.

Voice input

Voice input uses the speech recognition built into iOS. The app never receives or sends audio: it only gets back the recognized text, which is then treated exactly like a typed word. How Apple handles speech recognition is described in Apple's own privacy policy.

Paste and camera

The app reads your clipboard only when you tap Paste. The camera or photo library opens only when you tap the photo button, and only the photo you confirm is sent. You can revoke camera and microphone access at any time in iOS Settings; the rest of the app keeps working.

Pronunciation

On the Plus plan, tapping the speaker icon plays a pronunciation clip. The first time anyone asks for a given word, our server sends that word to OpenAI's text-to-speech API, stores the resulting audio on our server (Cloudflare) and serves the same clip to everyone who asks later. Along with the word, the app sends the short definition of the meaning on screen (at most 120 characters of dictionary or AI-written text, never anything you typed); our server passes it on to OpenAI only for words with more than one pronunciation, such as "read" or "lead", so that the right pronunciation is generated, and for those words keeps one clip per meaning. Clips are kept indefinitely; they contain the word only and nothing about you. Clip requests carry the anonymous device identifier, which our server uses only to check that your plan includes native-speaker pronunciation and, when a new clip has to be made, for the hourly anti-abuse guard; pronunciation does not count as a request, and no audio is stored per user. On Free, and whenever a clip is unavailable, the app uses the voice built into iOS instead, and that audio never leaves your device. Clips you have listened to are cached on your device so saved words can be played offline.

Anonymous device identifier

On first launch the app generates a random identifier (a UUID). It contains nothing about you or your device. It is sent with every AI action and every dictionary lookup made online, so that our server can count your usage against your plan (5 requests a day on Free; on Plus, unlimited within a fair-use cap of 5,000 a month; plus an hourly anti-abuse guard), and it is used as the anonymous customer ID for purchases (see below). We do not link it to your name, email, or Apple ID — we have none of those. It is stored with your other on-device data, so it survives backups and transfers to a new iPhone. On iPhone it is also kept in the device's keychain, on this device only and never synced to iCloud Keychain, so it also survives deleting and reinstalling the app and stays until the device is erased; it is still random and carries nothing personal.

Our server stores, keyed by this identifier only: usage counters (per hour, per day, and per month) and, for subscribers, which plan is active. The counters are plain numbers; they are never read for anything but counting. Each request also carries your device's time-zone offset (the number of minutes between its local time and UTC), which our server keeps with the identifier so that your daily and monthly limits renew at your local midnight; it reveals nothing about you beyond that offset. Counters from past hours, days, and months are discarded the next time your device makes a request; if the device never comes back, its last counters simply sit unused, as anonymous numbers no one can connect to you.

Purchases and subscriptions

Payments are handled entirely by Apple through the App Store. We never see your payment details. To recognize an active subscription, the app uses RevenueCat, a subscription-infrastructure service: RevenueCat receives the App Store purchase receipt and the anonymous device identifier from the app, and notifies our server which plan is active for that identifier. That is the only information exchanged. You can manage or cancel a subscription in your Apple ID settings; refunds are handled by Apple.

Crash reports

If the app hits an unexpected error, it sends a short report to our own server: the error message, a technical stack trace, and whether it happened on iOS or on the web. No device identifier, no personal data, and no content of what you were looking up is included. At most five reports are sent per session. Reports are written to short-lived server logs; separately, the server keeps only an hourly count of how many reports arrived (not tied to any device), which is discarded after about two days.

Hosting

The website is served by Cloudflare Pages; our API runs on Cloudflare Workers; AI requests are processed by OpenAI. As with any internet service, these providers see your IP address as part of ordinary network traffic and may keep short-lived technical logs. We do not use IP addresses to identify you.

How long data is kept

DataWhereKept for
Saved words (each with a full copy of its card), settingsYour device (and your own backups)Until you delete them or uninstall the app
Recent lookups (last 10) and their resultsYour device (and your own backups)Until newer lookups push them out, or you uninstall the app
Device identifierYour device, on iPhone also its keychain (and your own backups)On iPhone, until the device is erased (reinstalling the app keeps it); on the web, until you clear the site's data
Usage counters (hour / day / month) and the balance of extra requestsOur serverOld periods are discarded on your device's next request; the extra-requests balance is kept until it is spent; the last counters of a device that stops using the app stay as unused anonymous numbers
Active-plan record for subscribersOur serverUntil the subscription period ends plus a few days' grace; a marker that the plan has ended may be kept for up to 30 days more
Content of AI requests (words, context, photos)OpenAINot stored by us; OpenAI's API retention applies (see above)
Crash reportsOur serverShort-lived logs; an hourly count (no device identifier) discarded after about two days
Purchase recordsApple and RevenueCatPer their policies

Your choices

If you email us

The "Send feedback" button opens your own mail app. If you write to us, we receive your email address and whatever you include; the message footer adds only the platform (iOS or web) and your plan name. We use this solely to reply and keep it only as long as needed for that.

Children

WordCue is not directed at children. As a dictionary it explains vulgar and slang senses of everyday words, so we require users to be at least 13 years old (the App Store listing carries the matching age rating). We do not knowingly collect any personal data from children, and, as described above, we do not collect personal data from anyone.

Changes to this policy

If we change how the app handles data, we will update this page and the effective date at the top. Meaningful changes will also be mentioned in the app's release notes. The current version is always at wordcue.pages.dev/privacy.

Contact

Questions about privacy: tehon125@gmail.com.