Controller
Frank Habermann
Selma-Lagerlöf-Str. 6
21493 Schwarzenbek
Email: lordlamer@lordlamer.de
Data processed
This website does not set tracking cookies. Server logs (IP address, timestamp, user agent) are processed for technical delivery.
VocabNinja stores vocabulary, learning progress, and settings locally on your device by default. No user account is required. VocabNinja does not operate an app server to which your learning data is transmitted. The only exceptions are transfers that you deliberately start to selected third-party providers or export destinations, as described below.
Optional AI photo import
For the optional photo import, you can configure your own API access to OpenAI, Claude (Anthropic), or Microsoft Azure. The app communicates directly with the selected provider over HTTPS. VocabNinja does not operate an intermediary server and does not receive your API key or the content sent to the provider.
The API key, selected model, and optional Azure endpoint are stored separately for each provider in the operating system's protected credential storage. The key is sent directly to the selected provider for authentication when access is saved or tested, available models are retrieved, and an analysis is requested. Technically necessary connection data, particularly the IP address, is also generated. No photos or OCR text are sent when the model list is retrieved. On Android, stored credentials are excluded from cloud backups and device transfers; portable VocabNinja backups do not contain AI credentials.
Direct photo analysis
After you explicitly confirm, each selected page is resized locally and re-encoded as a new PNG without embedded metadata. The image, source and target languages, selected model, and the instructions required for extraction are sent to the selected provider. The provider returns structured vocabulary suggestions to the app. Only suggestions you confirm are stored in the local vocabulary catalogue.
On-device text recognition (OCR)
Alternatively, VocabNinja can first recognize text on your device: using Google ML Kit for Latin-script text on Android and Apple Vision on iOS. No photo is sent to your selected AI provider during this step. You can review, edit, or remove the recognized text. Only after another explicit confirmation are the visible text, source and target languages, selected model, and required instructions sent to the AI provider; the photo is not included. There is no automatic switch from on-device text recognition to photo upload.
Google states that ML Kit processes input images and OCR results on the device and does not send that content to Google servers. However, the Android library may transmit technical diagnostics and usage data to Google, including device and app information, an installation identifier, performance data, API configurations, and error codes. Google states that this data is transferred over HTTPS and is not shared with third parties. See the ML Kit privacy information and data collection disclosure for details.
Recipients, costs, and provider processing
- OpenAI through
api.openai.com: API data controls and privacy policy - Anthropic through
api.anthropic.com: Anthropic Privacy Center - Microsoft Azure through the HTTPS endpoint you configure under
openai.azure.comorservices.ai.azure.com: Azure privacy information and Microsoft Privacy Statement
Depending on the provider, account, and Azure region you select, data may also be processed outside the EU or EEA, particularly in the United States. The provider's current contract, privacy terms, and account settings govern the purpose, retention period, possible use of content, transfer safeguards, and deletion options. Review those terms before use and avoid including personal or sensitive data in photos or OCR text.
Your selected provider may charge for analysis requests under its pricing plan. Costs depend in particular on the provider, account, model, and amount of image or text data. Before every analysis, the app displays the provider, model, destination host, and data volume.
The transfer for AI import takes place only to provide the feature you actively request, on the basis of Art. 6(1)(b) GDPR. You can delete each provider's credentials separately in the settings. Other configured providers remain available. Local deletion prevents future requests using those credentials, but it does not delete data previously transmitted to the provider or submit a provider-side deletion request.
App font
To display the Nunito typeface, the app may retrieve font files from Google servers if they are not already cached on the device. This sends the IP address and technically necessary connection data to Google, but no vocabulary, photos, or OCR text. Google's Privacy Policy applies.
Backups, import, and export
Backups and export files are created or selected only at your request. If you transfer data through the system file picker or native share sheet to a storage location, app, or cloud service, the terms of your selected destination govern further processing. VocabNinja does not operate a server for this purpose.
Contact
If you contact us, we process your details to handle your request.
Your rights
You have the right of access, rectification, erasure, restriction of processing, and data portability.
Last updated: August 23, 2026