Data Security Center

Privacy Policy & Data Security

Last updated: 9/26/2026 · Transparency-first policies

1Our Commitment

Susume Nihongo is structured to prioritize learning above all. We are entirely free to use. There are no trackers, no analytics SDKs, and no advertisements embedded in this application.

Because we operate on a local-first architectural model, your database remains localized on your computer. We do not monetize, evaluate, or aggregate your learning histories, cards, or speech conversations.

2Data Storage Audit

Here is an exact audit of where each piece of data is kept and when it is transmitted.

Data Element

AI Provider API Keys

Your Gemini, OpenRouter, Anthropic or OpenAI keys

Storage: LocalStorage Only
LOCAL ONLY — NEVER SYNCED

Learning History

Recent translation results & inputs

Storage: LocalStorage
LOCAL ONLY

Flashcards & Memory States

Vocabulary cards & scheduling stats

Storage: LocalStorage & Supabase
OPTIONAL CLOUD SYNC

Quizzes & Study Progress

Chapter marks, streaks, and scores

Storage: LocalStorage & Supabase
OPTIONAL CLOUD SYNC

Payment Customer Status

Stripe link (Only if subscribed to sync)

Storage: Stripe Servers
EXTERNAL PAYMENT SERVERS

3API Key Sandboxing

Your AI provider API keys (Google Gemini, OpenRouter, Anthropic or OpenAI) are stored only inside the browser local sandbox. Each key is sent only to its own provider, and is never routed through, processed, or logged on our servers.

API Stripping during Sync: If you activate Cloud Sync Pro, our system automatically strips every AI provider API key, and your choice of provider, from the settings payload before it leaves your browser. Syncing saves your progress and metrics, but your keys will always remain localized on each device.

4Authentication & Optional Cloud Sync

Signing in with a Google account is optional. Translation, text-to-speech, guides, and quizzes work without an account. Signing in enables Cloud Sync and enhanced word highlighting in the listening-practice player.

  • Supabase Authentication: Authentication is handled by Supabase OAuth with Google. We store your account ID, display name, and email. We do not store passwords.
  • Listening-practice alignment: For signed-in users, generated audio and its expected Japanese text are sent through our authenticated Supabase function to Google Cloud Speech-to-Text. This transfer is used only to calculate word timestamps; the player still works with estimated timings if alignment is unavailable.
  • Row Level Security (RLS): Our database utilizes strict RLS keys, ensuring that your synced flashcards are readable and writable solely by you.
  • Stripe Checkout: Payments for Cloud Sync Pro are routed through Stripe. Stripe holds Level 1 PCI protection. We record your subscription status, but never see or store billing numbers.
  • Ask Susu sync: For subscribers, Susu's memory, your "About you" profile and your 30 most recent chats (each capped in size) sync to your account so they follow you across devices. Without a subscription they stay in this browser. API keys are never synced.

5Third-Party Integrations

We connect directly with trusted services to deliver the application:

Google Gemini AICore Engine

Processes Japanese queries and grammar details when Gemini is your AI provider, and always powers native TTS pronunciations and Live Voice coach sessions.

SupabaseSync Database

Manages optional Google logins, securely relays authenticated timestamp-alignment requests, and hosts synchronized client database snapshots with RLS protection.

StripeBilling Gateway

Secures Stripe checkout cards. No raw credit cards are handled on Susume Nihongo servers.

Google OAuthAuthentication

Authenticates sync profiles using external redirects. Your passwords remain entirely unknown to our databases.

Google Cloud Speech-to-TextWord Alignment

Receives generated listening-practice audio and expected Japanese text for signed-in users to return word timestamps. This is not used for accountless playback.

OpenRouter, Anthropic & OpenAIOptional AI Providers

If you choose one of them in Settings, your Japanese queries go directly from your browser to that provider with your own key. Connect OpenRouter signs you in on openrouter.ai and returns a key billed to your OpenRouter credits.

6Service Workers (PWA)

Susume Nihongo runs as a Progressive Web App (PWA) on your devices. We register a client service worker (sw.js) to load page shells and CSS files offline.

This script does not collect, record, or share telemetry. Its sole role is optimizing resource speeds and providing complete offline compatibility for local pages.

7Browser Extension

The SusumeNihongo Chrome extension shows an action bar next to text you select on any page. It has no account and no API key of its own, and we operate no server that it talks to.

  • The text you select. Sent out only when you press a button: Translate and Listen use Google’s public translation and speech endpoints, and AI uses the AI provider you chose in the app (Google Gemini, OpenRouter, Anthropic or OpenAI). Nothing is sent while you are only reading.
  • Your AI provider keys. Read from this site’s own browser storage and cached in the extension’s storage on your machine. Each key goes only to its own provider — never to us.
  • Cards you save. A saved card keeps the title and address of the page it came from. It stays on your device, and reaches your own account only through the same Pro sync as cards made in the app.
  • Your extension settings. Whether the bar appears by itself, your keyboard shortcut, which side it opens on, and the sites you told it to leave alone — held in Chrome’s synced extension storage.

It contains no analytics, no advertising and no trackers, it reads nothing from a page until you select text there, and you can switch it off for any site — or every site — from its own settings.

8Data Deletion & Extraction

You hold complete control over your local records. You can download or completely wipe your data at any time:

Delete Local Data

Wipe all cached vocab, FSRS metrics, and configurations by clearing your browser's localStorage or using the App Settings modal.

Delete Sync Profile

If you hold a logged-in account, you can request a complete profile wipe within settings. This instantly drops all Supabase cloud records.