Legal

Privacy Policy

Last updated: February 17, 2026

1. Introduction

Blindspot ("we", "our", "us") is a language learning platform that helps users improve their grammar and vocabulary through writing practice. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website at blindspot.study and our Chrome browser extension (collectively, the "Service").

2. Information We Collect

We collect the following information when you use our Service:

  • Google Account Data: When you sign in with Google, we receive your name, email address, profile picture, and locale.
  • Language Preferences: Your selected native and target languages.
  • User Content: Texts you submit for grammar review, vocabulary words you save, grammar exercise answers, and writing proficiency scores.
  • Payment Information: When you purchase credits, payment processing is handled by Stripe. We store your transaction history (package type, amount, status) but do not store your credit card details.
  • Browser Extension Data: When using the Chrome extension, we process text you explicitly select on web pages to translate and save words to your vocabulary. We do not track your browsing history or collect any data from pages you visit beyond the specific text you choose to save.

3. How We Use Your Information

  • To authenticate your identity and manage your account
  • To check your writing for grammar errors and provide AI-powered feedback
  • To translate and store vocabulary words
  • To generate personalized grammar exercises based on your mistakes and skill level
  • To track your learning progress (writing score, grammar rule confidence, vocabulary mastery)
  • To process payments and manage your credit balance

4. AI Processing

We use OpenAI's language models to analyze your writing, generate grammar feedback, create exercises, and translate vocabulary. When you submit text, it is sent to OpenAI's API for processing. OpenAI's data usage policies apply to this processing. We do not use your content to train AI models.

5. Third-Party Services

We use the following third-party services:

  • Google OAuth 2.0: For user authentication. Google receives your login request and provides us with your basic profile information.
  • OpenAI: For AI-powered writing analysis, grammar feedback, exercise generation, and vocabulary translation.
  • Stripe: For secure payment processing. Stripe handles all credit card information directly and is PCI-DSS compliant.
  • Vercel: For hosting the web application.
  • Railway: For hosting the backend API and database.

We do not sell, trade, or rent your personal information to third parties.

6. Data Storage and Security

Your data is stored in a PostgreSQL database hosted on Railway. We use industry-standard security measures including encrypted connections (HTTPS), secure authentication tokens (JWT), and one-time authorization codes for the OAuth flow. The Chrome extension stores your authentication token locally in your browser using Chrome's storage API. Payment data is processed and stored securely by Stripe.

7. Data Retention

We retain your data for as long as your account is active, including your writing history, vocabulary, grammar rules, and exercise results. Payment transaction records are kept for accounting purposes. You can request deletion of your account and all associated data at any time by contacting us.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data
  • Withdraw consent for data processing at any time
  • Export your vocabulary and learning data

To exercise any of these rights, contact us at the email address below.

9. Cookies

We use a minimal number of cookies strictly for authentication purposes (storing redirect URIs during the OAuth login flow). We do not use tracking cookies, advertising cookies, or any third-party analytics services.

10. Children's Privacy

Our Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at convert.tonoise@gmail.com.