Skip to content
dannisoft
HomeVoca
← Back to Voca
Voca / Legal

Privacy Policy

Effective date: October 4, 2026· Last updated: October 10, 2026

Privacy PolicyTerms of Use

On this page

  1. Who we are and scope
  2. Information we process
  3. Photo scanning and AI
  4. Why we use information
  5. Service providers
  6. Printing, sharing, and QR codes
  7. Children and adult-managed use
  8. Storage and retention
  9. Your choices and deletion
  10. International processing and security
  11. Website and tracking
  12. Changes and contact

Privacy at a glance

  • Photos are uploaded for remote text recognition; scanning is not entirely on-device.
  • We process scan photos and full page text transiently, rather than saving them as a scan archive.
  • Your word book and review history are stored on your device. Online features still send the information they need to our services.
  • Adults manage Voca; children can learn from the printed materials without using an account.
  • We do not sell personal data, use advertising or cross-app tracking, or train AI models with your scan photos or personal learning records.
  • The dannisoft website uses Google Analytics to measure visits and traffic sources, and loads it without a consent prompt.
  • For privacy or account-deletion requests, email [email protected].

1. Who we are and scope

Voca is operated by Danni Chen, based in China, under thedannisoft brand. In this policy, "we", "us", and "our" refer to Danni Chen. We are responsible for the personal information we process to operate Voca.

This policy covers the Voca iOS app, its supporting services, related pronunciation pages, and the dannisoft.com marketing and legal website. It explains our practices; Apple, Google, and other providers also have their own policies for services they operate.

2. Information we process

Accounts and authentication

Guest access creates an anonymous authentication identity through Supabase. It is not the same as using Voca without contacting a server. If you sign in by email, we process your email address and authentication identifiers. If you use Google sign-in, Supabase receives the identifiers and profile information Google supplies for authentication, which may include your email address, name, and profile image. We do not receive your Google password.

Vocabulary, practice, and preferences

The device stores saved words, dictionary results, learning status, cached exercises, review responses, review dates, and practice scheduling information. Search history and preferences may also be stored locally. Online requests include information needed for the requested feature, such as lookup words, dictionary word identifiers, practice difficulty, and translation language. Our backend stores account preferences, such as translation language and paper size, and scan-usage counts and quota periods. Profile requests also send the device's time zone and preferred system language.

Photos and extracted text

When you choose to scan, the selected or captured image and the text recognized from it are processed as described below. An image may contain personal information even if you only intended to photograph a word. Crop out faces, names, school identifiers, addresses, and unrelated private details before sending it.

Purchases and support

Apple and RevenueCat process purchase information. We receive information needed to manage access, such as your app user identifier, product, entitlement, purchase status, renewal or expiry information, and subscription-management link. We do not receive your full payment-card details. When you contact support, we receive your email address, message, and any information or attachments you choose to send.

Technical and diagnostic information

Our hosting, authentication, purchase, and monitoring providers may process network and device information, such as IP address, request time, app or operating-system version, request metadata, and errors. Backend logs and traces may include request paths, query parameters, account or dictionary identifiers, timings, and error details. A lookup word or word identifier can appear in request metadata.

3. Photo scanning and AI

When you start a scan, Voca prepares the image and uploads it over HTTPS to our backend. The backend forwards it to our text-detection service, which usesMicrosoft Azure for optical character recognition (OCR). The service recognizes page text and identifies vocabulary, then returns the results to the app.

We process uploaded scan photos and full extracted page text transiently to complete the scan. We do not intentionally keep them as a stored scan history after processing. This does not mean there is zero technical caching, logging, or provider-side retention: providers may retain operational or security records under their applicable settings and policies. Saved words and related learning content remain in your device's word book.

Some dictionary, translation, and practice content is generated using AI services. The practice-generation flow uses dictionary words and their meanings, not your complete personal word book or the original scan photo. Requests for exercises still send word identifiers and a selected difficulty to our backend.

We do not use your scan photos or personal learning records to train AI models. Provider processing, retention, and model-use rules depend on the provider's service terms and our service configuration; this statement is not a guarantee of zero retention by every provider.

Camera access is used for the photos you choose to take. Selecting an existing image uses the system image picker. You can control permissions in iOS Settings. Voca's current vocabulary and listening workflow does not require precise location, contacts, or microphone recordings. Listening plays pronunciation audio rather than recording your voice.

4. Why we use information

  • Authenticate users, maintain guest or signed-in sessions, and apply account preferences.
  • Recognize text, identify words, provide dictionary content and pronunciation, and deliver practice.
  • Store learning information locally, schedule reviews, and generate printed materials.
  • Calculate scan allowances and verify subscription access.
  • Respond to support, privacy, and deletion requests.
  • Diagnose failures, secure the service, prevent misuse, and meet legal obligations.

Where a legal basis is required, processing must rely on the basis appropriate to the activity and applicable law: providing a service you request, consent where required, compliance with legal obligations, or legitimate interests such as security and reliability where that basis is recognized and does not override your rights. Accepting our Terms of Use is not a substitute for separate consent where law requires it.

5. Service providers and disclosures

Voca's supporting services use the following providers for the relevant features:

  • Cloudflare: website and API hosting, databases, object storage, content delivery, and infrastructure logs.
  • Supabase: guest and registered account authentication, session records, and authentication-related profile information.
  • Google: authentication when you choose Google sign-in.
  • Render and Microsoft Azure: hosting the text-detection service and recognizing text in uploaded scan images.
  • GitHub/Microsoft AI services and their model infrastructure: generating dictionary-related or practice content through the configured AI integration.
  • Apple and RevenueCat: App Store payments, purchase restoration, and subscription-entitlement management.
  • Sentry: backend error monitoring, traces, and diagnostic logs when configured.

Information is provided to these services as needed for their function. Providers process it under the terms, configurations, and legal obligations applicable to their services. We may also disclose information when required by law, to respond to a valid legal request, or as necessary to protect rights and address fraud or abuse.

We do not sell personal information or share it for advertising or cross-app behavioral tracking. A new provider or a materially different use of data may require an updated notice and, where required, your consent before the change.

6. Printing, sharing, and QR codes

Word lists and exercise PDFs are generated on your device. Printing or sharing uses iOS services and the printer, app, storage location, or recipient you select. Copies you save, share, or print are outside our control.

Print generation also sends dictionary word identifiers and related options to our backend to create a QR-linked pronunciation page. These pages are stored in cloud object storage. Anyone with the QR code or its link can open the page without signing in. The current page contains selected dictionary words, phonetic information, and audio links, not your account profile or review scores. A word selection can still reveal what someone is studying, so treat these links as shareable, not private.

If you use a Voca document-upload feature where offered, the submitted PDF, filename, upload time, and association with your account are stored on the backend to support file listing and downloading. This is distinct from locally generating or sharing a PDF; those actions do not by themselves upload the complete PDF to our document store.

7. Children and adult-managed use

Voca's accounts and online app features are intended to be managed by adults who can enter into a binding agreement. Parents, guardians, and teachers can prepare and print educational materials for children. Children do not need to create an account or interact with the online service to use those printed materials.

We do not invite children to create accounts or provide personal information directly. The current app does not implement age verification or a verified parental-consent process. Adult-managed use does not authorize uploading children's personal data: please avoid photos of children and remove identifying details from their work.

If you believe a child has created an account or that we have received a child's personal information, contact [email protected]. We will investigate and take appropriate steps to remove or restrict the information in accordance with applicable law. We do not rely on this policy alone as consent to process children's personal information.

8. Storage and retention

  • Scan photos and full page text: transient processing as explained in section 3, rather than an intentional scan archive.
  • Local learning data: retained in the app's device storage. Removing a word from the word book hides it from active use; it is not a promise of secure erasure of every local database record.
  • Account, preference, and scan-usage records: retained while your account or guest identity remains active, and removed following a verified deletion request, except information that must be retained for legal, security, purchase, or dispute-resolution purposes.
  • Subscription and transaction records: kept as needed to administer purchases and meet applicable recordkeeping obligations. Apple and RevenueCat control records they are independently required to retain.
  • Uploaded documents and QR pages: stored to support access to those features. Contact us to request removal of information or links associated with you. Shared dictionary-based QR pages may not identify a particular account.
  • Support, logs, and backups: retained only as needed for their purpose and applicable obligations. Provider-managed copies follow the relevant provider's configured retention and deletion processes; deletion from active systems may not immediately remove every backup.

Your word book is stored in a device-level database and is not a private cloud backup. Signing out does not erase it, and changing accounts on the same device does not automatically create a separate word book. People with access to an unlocked device or its backups may be able to access that local data.

9. Your choices and account deletion

You can manage permissions in iOS Settings, change preferences in Voca, remove words from active use, and stop using online features. To remove app-local storage, use iOS's Delete App option rather than Offload App. Device or iCloud backups, exported PDFs, printed copies, and backend records are separate and may remain.

To request account deletion, email [email protected]with the subject "Voca account deletion", preferably from the email address used for your account. For a guest identity or inaccessible account, explain the situation so we can determine a safe verification method. Do not send passwords, one-time sign-in codes, full payment-card details, or unnecessary identity documents.

After verifying the request, we will remove the authentication account and associated backend data under our control, arrange relevant provider-side deletion where applicable, and explain any legally required retention or technical limitations. We handle requests within the time limits required by applicable law.The current in-app "Delete my account" control does not complete deletion; use the email process. Signing out or uninstalling does not delete the authentication account or server records.

Deleting a Voca account does not cancel an Apple subscription. Manage or cancel subscriptions separately at Apple's subscription-management page.

Depending on applicable law, you may have rights to access or correct information, request deletion or a copy, restrict or object to certain processing, withdraw consent, or complain to an appropriate data-protection authority. Contact us to exercise those rights. Withdrawing consent does not undo processing already lawfully completed and may prevent use of features that require that processing.

10. International processing and security

The operator is based in China, and our providers operate infrastructure in different countries and regions. Information may be processed outside your country, including in regions where privacy laws differ. The exact location depends on the provider and deployment configuration.

Where cross-border processing requires specific safeguards, notices, or separate consent, those requirements must be met. This policy or general acceptance of the Terms of Use is not a substitute for them. Contact us with questions about a particular service or transfer.

We use HTTPS for app-service communications, authentication controls for account-based endpoints, and measures to limit access to service data. No service or storage method can guarantee absolute security. Protect your device and sign-in access, and remember that QR pronunciation links are intentionally shareable.

11. Website and tracking

The dannisoft website uses Google Analytics 4, provided by Google, to understand visitor traffic, page views, engagement, and traffic sources. Analytics loads automatically on the production website without a consent prompt and may use first-party cookies to distinguish browsers and sessions. Google processes browser and device information, page URLs (including query parameters such as UTM campaign tags), referring URLs, interaction events, and network information. Do not put personal or sensitive information into website URLs or campaign tags.

We do not send Voca account identifiers or learning records to website analytics. The website tag disables Google Signals and advertising-personalization signals. Other data collection, retention, and sharing depend on the Analytics property settings and Google's policies; disabling these signals does not disable analytics. See Google's Privacy Policy andhow Google uses information from partner sites.

You can block analytics using browser privacy controls, content blockers, orGoogle's Analytics opt-out browser add-onwhere supported. Blocking or deleting cookies alone may not prevent all analytics requests. There is currently no website consent or opt-out control.

The static website has no account sign-in form. Cloudflare may process standard request and security information when serving it. Hosting and security cookies or technical storage are separate from Google Analytics.

The app stores session and preference information needed to function. Authentication, purchase, and QR pronunciation services may have their own technical storage and network processing; the absence of marketing trackers does not mean these services receive no information.

12. Changes and contact

We may update this policy when practices or legal requirements change. The updated date appears at the top. For material changes, we will provide an appropriate notice and seek any consent required before introducing the affected processing.

Privacy contact: Danni Chen, dannisoft, China
Email: [email protected]

See also the Voca Terms of Use.

dannisoft

Thoughtful apps for a better everyday.

HomeVocaPrivacy PolicyTerms of Use

© 2026 dannisoft