Privacy Policy
Last updated: July 19, 2026
PopDict is a macOS dictionary app. This policy explains what data it handles and why. We aim to collect as little as possible.
What stays on your device
- Your recent search history and app settings (hotkey, translation language, preferences).
- A 90-day, 100-entry cache of successful lookups and selected-language translations for offline fallback.
- A local successful-lookup count used to time a one-time feedback prompt.
This data lives only on your Mac and is never sent to us.
What we store (only if you sign in)
Signing in is optional and only needed to save words or use account-based review features. If you sign in with Google, our authentication provider (Supabase) stores:
- Your email address and Google account identifier, to authenticate you.
- The words you choose to save, including their displayed dictionary snapshot, tags, private notes, and review schedule.
Quiz emails (optional)
If you turn on quiz emails, we use your saved words and previously prepared study materials stored in Supabase to assemble a periodic vocabulary quiz and send it to your account email through Resend, our email delivery provider. Your answers are stored to schedule which words repeat. Every quiz email contains an unsubscribe link that takes effect immediately; you can also toggle quiz emails off in the app’s settings.
Dictionary lookups
When you search, the text is sent to the Free Dictionary API (dictionaryapi.dev) to fetch English definitions. Multi-word searches also query PopDict’s read-only Wiktionary-derived phrase table in Supabase. If you select a translation language, PopDict queries its read-only translation table for the successfully resolved English word whether or not you are signed in. Lookups are not tied to your PopDict identity, and PopDict does not send words to a live translation vendor.
Analytics
When anonymous product analytics are enabled, PopDict sends only an allowlisted event name (for example, successful lookup, sign-in started, sign-in completed, first word saved, or feedback submitted), the app version, platform, and random per-app-launch session and event identifiers to Supabase. Event records do not contain the word you looked up, a saved word, your email, or your account ID. You can turn this setting off at any time in Settings.
To protect the public analytics and feedback endpoints from abuse, we derive a one-hour rate-limit key from the request’s network address. We store only the keyed hash, hour, endpoint name, and request count—not the raw network address—and remove old buckets after 48 hours of subsequent endpoint activity.
This website uses privacy-friendly, cookieless Vercel Web Analytics to count visits. When you use a website download button, we also record the release and asset, referring site hostname, coarse country code, and tagged button source; GitHub separately counts delivery of the release asset.
Feedback
You can send feedback privately without an account. We store the category, message, optional contact information, app version and platform in Supabase. If PopDict offers current search context, it is included only when the checkbox in the feedback form is selected. Feedback is not automatically published to a GitHub issue.
Deleting your data
You can remove saved words at any time from the Saved Words window in the app. To delete your account and all associated data, contact us at the address below.
Sharing
We do not sell your data. Data is processed only by the service providers named above (Supabase, Free Dictionary, Resend, GitHub, Vercel, Slack when operational notifications are enabled, and our website host) to operate the app and website.
Contact
Questions? Email sungman.cho@originlayer.net.