Privacy Policy

Last updated: May 17, 2026

Cabbit LLC ("Cabulary", "we", "us") operates the Cabulary vocabulary-learning service at cabularylingo.com. This Privacy Policy explains what we collect, why, who we share it with, and the choices you have. We aim to collect the minimum needed to run the service and never to sell your personal information.

1. Information We Collect

Account information

When you create an account, we collect your email address and (if you sign up with Google) your name and profile picture. You can also tell us your target language, native language, learning goal, and current vocabulary level. This information is stored in our database (Supabase).

Usage data

As you use Cabulary we record your vocabulary progress — which words you've seen, learned, or marked as known — and aggregated counters (sessions completed, AI interactions per week). We use this to run the spaced-repetition system, enforce usage limits, and improve the product.

Payment data

When you purchase a Word Pack, payment is handled by Stripe, Inc. We never see or store your full card number; Stripe sends us a transaction reference, an amount, and a success/failure signal. See Stripe's Privacy Policy for what they collect on their side.

Device & log data

Like most web services, our hosting provider (Vercel) automatically logs basic request metadata (IP address, user-agent, timestamps) for security and reliability. We do not use these logs to build advertising profiles.

2. How We Use Your Information

  • To operate Cabulary and personalize your learning experience.
  • To process Word Pack purchases and provide receipts.
  • To enforce usage limits and detect abuse.
  • To send essential service emails (confirmations, security alerts).
  • To respond to support requests and improve the product.
  • To comply with applicable legal obligations.

3. How We Share Your Information

We share information only with service providers that help us operate Cabulary:

  • Supabase — database hosting for your account, progress, and entitlements.
  • Vercel — application hosting.
  • Stripe — payment processing. Cardholder data goes directly to Stripe.
  • OpenAI — when you use AI features (Ask Tutor, stories, deep-dive sessions, reading tutor), the words and short context strings are sent to OpenAI to generate the response. See OpenAI's Privacy Policy. We do not send your name, email, or unrelated personal data to OpenAI.
  • Google — only if you sign in with Google (for authentication only).

We do not sell or rent your personal information to advertisers or data brokers. We may disclose information to comply with legal process or to protect users' safety or our rights, but only to the minimum extent required.

4. Data Retention

We retain account data for as long as your account is active. If you delete your account, we delete your personal information within 30 days, except where we are required to retain it for legal, tax, or fraud-prevention reasons (e.g., payment records, which we keep for 7 years as standard accounting practice).

5. Your Rights

Depending on where you live, you may have the right to:

  • access the personal information we hold about you;
  • correct inaccurate information;
  • delete your account and associated data;
  • port your data to another service;
  • object to or restrict certain uses of your data.

To exercise any of these rights, email cabulary.contact@gmail.com from your registered address. We'll respond within 30 days.

6. Security

We use industry-standard safeguards: HTTPS for all traffic, encryption at rest for the database, scoped service-role keys, row-level security on user data, and Stripe-handled payment tokenization. No system is perfectly secure; if we discover a breach affecting your account, we will notify you promptly as required by law.

7. Children's Privacy

Cabulary is not intended for children under 13. We do not knowingly collect personal information from anyone under 13. If you believe we have, email cabulary.contact@gmail.com and we will delete it.

8. International Users

Cabulary is operated from the United States. If you use Cabulary from outside the U.S., your information may be transferred to and processed in the U.S. by our service providers. Where required (e.g., for EU/UK residents under the GDPR), we rely on standard contractual clauses or equivalent safeguards.

9. Cookies & Local Storage

Cabulary uses essential cookies and browser local storage to keep you signed in and remember your in-progress session state (e.g., session type, last-selected deck). We do not use third-party advertising or analytics cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify registered users by email or in-app notice at least 7 days before the change takes effect.

11. Contact

Questions about this Privacy Policy or your data? Email cabulary.contact@gmail.com.