Biblical Hebrew Vocabulary
Last updated: August 2026
This privacy policy describes how the "Biblical Hebrew Vocabulary" application collects, uses, and protects your personal data. The application is published by Jean-Noël Blécuit (hereinafter "the publisher").
Without Google sign-in: the application does not collect any personal data. All data (progress, favorites, settings) is stored solely on your device, in the browser (localStorage). The publisher does not have access to it.
With Google sign-in (optional): if you choose to sign in with your Google account to enable cloud synchronization, the following data is collected and stored on Firebase (Google) servers:
— Your Google email address (automatically provided by the Google authentication service)
— Your Firebase user ID (generated automatically)
— Your progress data: knowledge status of each word, spaced repetition (SRS) data, favorites list
Technical error reports (optional, enabled by default): if the application hits a JavaScript error, an anonymous technical report may be sent to a Cloudflare Workers server operated by the publisher. Such a report contains only: the error message, the file and line involved, the first three lines of the call stack, the application version, the display language, the platform type (installed app or browser) and the browser's technical identifier ("user agent", which indicates the device model and browser version). It contains no personal data, no account identifier, no email address and none of your progress data. These reports cannot be used to identify you or to track your use of the application. They are kept for at most 90 days and then deleted automatically, and are used exclusively to fix failures that only occur on certain devices. You can turn this off at any time under Settings → Options → Privacy → Report technical errors and usage. To keep the volume of data down, only a fraction of sessions send reports.
Anonymous usage measurement (optional, enabled by default): the application sends, once per session, an anonymous count of which screens it opened (level-based reading, great texts, verb paradigms, etc.), aggregated monthly on the same Cloudflare Workers server as the error reports. This measurement contains no individual timestamp, no session or device identifier, and no personal data: the server only receives a per-screen count, added to a monthly counter shared by all users. It is impossible to reconstruct any single user's journey from it. This measurement is used exclusively to know which features are actually used, in order to prioritize what to improve. It shares the toggle described above: turning it off disables both the error reports and this usage measurement.
Data collected via Google sign-in is used exclusively to:
— Back up your progress in the cloud to protect it against accidental loss
— Allow you to retrieve your progress if you change devices or reinstall the application
No other use is made of your data.
The application:
— Does not collect any data for advertising purposes
— Does not use any tracking or behavioral analytics tools
— Does not share, sell, or transmit your data to any third parties
— Does not send any commercial emails or newsletters
— Does not use cookies for tracking purposes
The technical error reports and the usage measurement described in section 1 are no exception: the former is sent only when something breaks and describes no user action; the latter is an aggregated count, with no identifier or individual timestamp, that cannot be used to track any particular user's audience or usage.
The processing of your data is based on your consent (Article 6.1(a) of the GDPR). Google sign-in is entirely voluntary. The application works fully without signing in. You can withdraw your consent at any time by signing out from the application settings.
Technical error reports and the usage measurement rest on the publisher's legitimate interest (Article 6.1(f) of the GDPR) in keeping the application working on devices they do not own and in knowing which features are worth developing further. They are enabled by default, contain no data that could identify you, and you may object at any time by turning the corresponding option off in the settings.
Progress data is stored in Cloud Firestore (Google Firebase), on servers located in Europe (europe-west region).
Authentication data (email address, user ID) is managed by Firebase Authentication, a Google service that may process certain data in the United States. This transfer is governed by Standard Contractual Clauses (SCCs) and Google's EU-US Data Privacy Framework. For more information, see the Firebase Privacy Policy.
Your data is retained as long as your account is active (i.e., as long as you do not request its deletion). If you sign out of the application, your data remains on Firebase servers until you explicitly request its deletion.
Under the GDPR, you have the following rights:
— Right of access: you can request what data is stored about you
— Right to rectification: you can request the correction of inaccurate data
— Right to erasure: you can request the complete deletion of your data
— Right to data portability: you can export your data via the application's export function
(Data tab)
— Right to withdraw consent: you can sign out at any time, which stops synchronization
To exercise any of these rights, contact the publisher at the email address below.
Access to data is protected by Firebase security rules: each user can only access their own data. Authentication is managed by Google via the OAuth 2.0 protocol. Communications between the application and Firebase servers are encrypted (HTTPS/TLS).
The application is not specifically targeted at children under 16 years of age. If a minor uses the Google sign-in feature, it is assumed to be under the responsibility of their legal guardian.
This privacy policy may be updated. In the event of substantial changes, a notification will be displayed within the application. The date of the last update is indicated at the top of this document.
Email: jnblecuit@gmail.com