KenningKenning

Privacy Policy

Last updated: September 4, 2026

What you type reaches our server as plaintext so the server can search the dictionary. If you create an account and sync, your saved lists, notes, and revision progress are also stored on our server as readable data that we can inspect. This policy covers the service operated at kenning.altan.fyi. Anyone hosting their own copy of the open-source software is responsible for their own installation.

1. The short version

  • You can use the whole app without an account. There is no sign-up wall, and no account is required to search, to save lists, or to revise them.
  • The words you search are sent to our server as plaintext. They have to be, because the server searches the shared dictionary with them.
  • Your saved words, lists, notes, and revision progress remain on your device. If you create an account and sync, a copy is also stored on our server as readable data.
  • Your search history stays on your device. It reaches our server only as part of your synced data if you create an account.
  • There is no payment, no plan, and no advertising, so nothing here is used to sell you anything or to build a profile.

2. Who is responsible

The operator named in the imprint is the controller for this service under the GDPR. You can find the full postal address on the imprint page. The email address for privacy questions is at the end of this page.

3. Using the app without an account

The default mode is anonymous. Search, lists, notes, and revision all work on your device with no account at all, and most visitors never create one.

Accounts exist solely to sync your saved words across devices. An account consists only of an email address and a password. We do not ask for a name, a phone number, or any other personal details.

4. What you type reaches our server

When you search, the word or phrase you typed is sent to our server as plaintext, and the language pair with it. There is no way around this. The server has to read the word to look it up in the dictionary.

The word is stored in the shared dictionary, which every visitor reads from, and not in a record about you. The search route writes no log line naming your query. Our web server keeps standard access logs like any web server, and those record the request, not what you typed into the box.

5. Machine generated explanations

When the dictionary has no explanation for a word yet, we ask a large language model to write one. The model is Google Gemini, reached through the OpenRouter service. The text it writes is stored in the shared dictionary so the next visitor reads it from there rather than generating it again.

The model receives only the dictionary word and the language pair. It never receives an account identifier, an email address, session details, or other personal data. Because the background job queue contains no user fields, this separation is enforced by the software itself rather than mere policy.

Machine generated text is labelled as such on the page, as Article 50 of the EU AI Act requires, and the label names the model that wrote it. Treat it as a helpful draft, not as a checked reference.

6. Voice input

When your browser can recognise speech itself, it does, and the recording never leaves your device. Only the recognised text goes into the search box, and only then is it searched like anything you typed.

When your browser cannot, you may record a short clip and send it to us instead. That clip is passed straight to the same model provider and the words come back. The clip is never written to a disk, a database, or a file on our side, and nothing keeps it after the answer is returned.

7. What stays on your device

Your search history is stored locally in your browser. The log is limited to 500 entries and 90 days, after which older records are deleted automatically. If you create an account and sync, a copy is uploaded to our server along with your other saved data.

Because this data lives in your browser profile, clearing your browser storage for this site deletes it, and it does not follow you to another browser or another device.

8. If you create an account

Your account record stores your email address, a password hash generated with bcrypt, the time of address verification, and the time of your last password update. We never store the plain password.

When you sync, a copy of your lists, entries, notes, study progress, and search history is stored on our server as readable JSON. We can read that data, and database backups include it. Do not write anything in a note that you would not want us to see.

We send only two kinds of email: an address confirmation link upon registration, and a password reset link upon request. We operate no newsletter. Outgoing mail is sent through the mail service we run ourselves, which delivers through Amazon SES in the eu-central-1 region. Each link is single-use, expires, and is stored only as a hash.

Deleting your account removes your account record, any outstanding links, and your synced data simultaneously. Copies inside database backups are deleted when that backup ages out, within the backup retention period. Signing out clears the synced copy from that device.

9. Rate limits and cost control

Generating an explanation costs money, and the service is free, so we count requests. The counter stores a hash of your address and of your session cookie, salted with a secret that is not in the database, plus the number of requests in the current hour. There is also a daily total of what has been spent.

The counter records that a request happened, never what was in it. It is not joined to the word you searched, and there is no table that puts an address and a search term in the same row.

10. Cookies and local storage

The site sets a session cookie so a request can be recognised across a visit, and a cookie holding your chosen interface language. Your lists, notes, and history live in your browser's own storage, which is not a cookie and is not sent with a request. We set no advertising cookies and no tracking cookies.

11. Analytics

This instance measures visits with Matomo, which we run on our own server, so no data reaches an analytics company. It is never told what you searched for. Your searches, your lists, and your notes are not part of what it records.

12. Where your data is and how long we keep it

Our servers are hosted by Hetzner in Germany, inside the European Union. Dictionary entries, including machine-generated explanations, are retained indefinitely because they are shared and non-personal. Hourly rate-limit counters are short-lived. Your account record and synced data remain until you delete your account.

13. Your rights

Under the GDPR you may request access to your personal data, its correction, or its erasure, you may object to processing, and you may complain to a supervisory authority.

A practical limitation. If you use the app without an account, we store nothing that identifies you, so we cannot locate your data and cannot export or delete it. If you have an account, we can export or delete your account record and the synced copy of your data, because we can read both.

14. Changes to this policy

We update this page when the service changes. The date at the top is the date of the last material change, and the history of the page is public in the open source repository.

15. Contact

You can use the email address printed below to ask any question about this policy or about the data we hold.

partners@sportsight.de