Legal
Privacy Policy
What we collect, why we collect it, and how we handle it. No advertising, no selling your data.
Last updated: August 1, 2026
What we collect
When you use the wordLoot website or Chrome extension, we may collect the following personal data:
Account authentication
When you create an account with email and password, or sign in with Google OAuth, we receive your email address and a unique user ID. These are stored on our servers (Firebase Authentication) to identify and authenticate your account.
Subscription and billing
If you subscribe to wordLoot, payment is processed by Stripe. We store subscription and customer records needed to verify Paid access (for example, customer ID and subscription status). Card details are handled by Stripe and are not stored on wordLoot servers.
Vocabulary and study data
Words you collect while watching — including Japanese text, romaji, English meanings, review progress, and related study metadata — are stored and associated with your account so you can sync and review them across devices.
Episode and show context
Each word you collect is saved with the Crunchyroll episode and show title it came from, and the time it was collected. When you collect every target word in an episode, we also store a record that the episode was completed, together with its date. We use this to show where a word came from, to avoid offering you the same word twice, and to track your progress. We do not record pages you visit outside the episodes where you use wordLoot.
Subtitle content
To line Japanese subtitles up with the episode, the extension reads the episode's subtitle track from the Crunchyroll page in your browser. This text is used only in memory while you watch and is never sent to wordLoot servers or to any third party.
Data stored in your browser
The extension keeps three things in local browser storage (for example via Chrome storage or local storage): your display preferences (subtitle mode, size, position, timing offset, notification sound, active listening); a per-episode list of words you already collected, so reopening an episode does not offer them again; and your sign-in state (whether you are signed in, your subscription status, your account email and user ID) so the extension does not have to contact our servers on every page.
Approximate location for pricing
On the website, we may briefly look up your public IP address through a geolocation service to show an appropriate currency (EUR or USD). This result may be cached in your browser session and is not used for advertising.
Website analytics
The website uses Google Analytics to understand how visitors find and use it. It records pages viewed, the approximate region derived from your IP address, your device and browser type, the site that referred you, and a randomly generated identifier stored in a cookie so repeat visits can be counted. We look at this only in aggregate and never use it for advertising. The Chrome extension contains no analytics: nothing you do on Crunchyroll is tracked by Google Analytics.
Cookies and local storage
We use cookies and browser storage to keep you signed in, to remember session preferences, and for the Google Analytics measurement described above. We do not use cookies for advertising, and we do not allow third parties to use them to build profiles about you.
How we use your data
- To authenticate and manage user accounts.
- To provide Paid access and process subscriptions via Stripe.
- To store, sync, and display your vocabulary and review progress.
- To show which episode a word came from and to avoid offering words you already collected.
- To apply your extension settings on Crunchyroll.
- To display localized pricing where applicable.
- To measure, in aggregate, how the website is used so we can improve it.
We do not use personal data for advertising, and we do not share it with third parties for marketing purposes.
Service providers
We rely on trusted providers to operate the Service, including:
- Firebase (Google) — authentication and database storage.
- Stripe — payment processing and customer billing portal.
- Google Analytics — aggregate website usage measurement.
- IP geolocation providers — approximate region for pricing display.
These providers process data only as needed to deliver their services to us.
What we don't do
We do not sell, rent, or trade user personal data, and we do not use it for advertising. We do not read or collect your browsing history: wordLoot only records the Crunchyroll episodes in which you collect words, as described above. No further information about you or your activities is collected, stored, or transmitted beyond what is described in this policy.
Security
We take appropriate security measures to protect your information from unauthorized access, including secure communication protocols (HTTPS) and restricted access to our systems.
Data retention
We retain account, vocabulary, and subscription-related data for as long as your account is active or as needed to provide the Service and meet legal obligations. You may request account deletion by contacting us.
Your rights
If you are in the EU or the UK, you can request access to your data, correction, deletion, a copy of it in portable form, or object to its processing. Email info@getwordloot.com and we will respond within 30 days. You may also lodge a complaint with your local data protection authority. Your data is processed on Google (Firebase) and Stripe infrastructure, which may involve transfers outside the EU under those providers' standard contractual clauses.
Contact
Questions about this policy? Reach out to info@getwordloot.com.