Danskify Privacy Policy

Last updated: November 2025

TL;DR, Your privacy in plain Dansk

  • We never track, sell, or share your personal data.
  • Translations are handled via Cloudflare Workers and encrypted HTTPS.
  • We only send the sentence containing the translated word to DeepL or OpenAI.
  • Cached translations in Cloudflare KV auto-delete after 30 days.
  • You control your data, and future accounts will be optional and transparent.

1. What Danskify does

Danskify is a browser extension that helps you learn Danish by translating small portions of text on pages you already visit. We aim to make language exposure effortless while keeping your privacy intact. Most processing happens directly in your browser.

2. Data stored locally

Danskify stores your learning data in browser.storage.local. This includes:

  • Words you’ve encountered or learned
  • Daily streak progress and milestones
  • User preferences (theme, difficulty, source selection)

This data never leaves your device. You can clear it anytime via the extension settings or by uninstalling Danskify.

3. Translation requests and processing

When Danskify replaces a word on a webpage, it first checks a local dictionary. If the word isn’t found locally, we send the surrounding sentence to a translation service through our secure Cloudflare Worker API.

We only send:
  • The minimal sentence around the target word
  • No webpage URL or personal identifiers
  • No cookies, tokens, or login info

The Cloudflare Worker acts as a secure proxy, anonymizing and routing requests to either:

Danskify’s Cloudflare Worker ensures all requests are encrypted via HTTPS and strips all metadata before contacting either service.

Example translation request

{
  "text": "responsible",
  "context": "I was also responsible for converting over our boilerplate to..."
}

Caching

Translated sentences are cached in Cloudflare KV for up to 30 days to improve performance and reduce repeated lookups. Cached data:

  • Contains only the original word, the source of the translation and its translation
  • Includes no personal identifiers
  • Automatically expires after 30 days

Cache example

{
  "Hello": {
    "text": "Hello",
    "translation": "Hej",
    "source": "DeepL"
  }
}

Text-to-Speech (TTS)

When you use the play functionality to hear a Danish translation, Danskify checks for existing audio in Cloudflare R2 using a hash of the text stored in Cloudflare KV. If no audio exists, the Danish translation text is sent to Google Cloud Text-to-Speech API through our Cloudflare Worker to generate the audio file.

Generated audio files are stored in Cloudflare R2 and linked via hashed text entries in Cloudflare KV. This ensures:

  • Only the Danish translation text (not the original) is sent to Google
  • No personal identifiers are included in TTS requests
  • Audio files are reused for the same translations, reducing API calls
  • Hashed text entries in KV include no personal identifiers

4. When data is sent

Data leaves your device only in these cases:

  1. You load a page while having API translations enabled in your user settings. The extension will then translate up to 10 parts of the page using the API.
  2. You sign up for the waitlist, in which case, your email goes to FreeWaitlists.
  3. Using the play functionality sends the Danish translation text to Google Cloud Text-to-Speech API (via our Cloudflare Worker) to generate audio for words not yet in our storage. Generated audio is cached in Cloudflare R2 for future use.

Danskify never sends your browsing history, URLs, or full page text to any third party.

5. Beta signup and waitlist

If you sign up for the beta, your email is collected via FreeWaitlists. It’s used solely for Danskify communications (updates, invites, feedback) and deleted upon request via privacy@danskify.com.

6. Future account-based features

In future versions, Danskify may offer optional account-based features such as:

  • Cross-device sync of progress and settings
  • Friend streaks and leaderboard comparisons
  • Usage limits and fair API management

When accounts become available, we may collect limited personal data (e.g., email, hashed credentials, progress sync data). Account participation will remain optional, with all data encrypted in transit and at rest. This policy will be updated transparently before that system launches. When this launches features like DeepL & AI translations might be locked behind account-based features.

7. Security

Danskify uses encrypted HTTPS for all traffic. Cloudflare Workers handle all API requests with rate limits and authentication, and Cloudflare KV and R2 enforce access control on stored items. Browser data is isolated in your local sandbox environment.

8. Data retention

  • Local data persists until cleared by you or upon uninstall
  • Cached translations expire automatically within 30 days
  • TTS audio files in Cloudflare R2 and their hash entries in KV are retained indefinitely to improve performance, but contain no personal identifiers
  • Waitlist emails are stored by FreeWaitlists until deletion request

9. GDPR information (EEA/UK)

This section explains how Danskify complies with the EU/UK GDPR when you use the extension from the EEA or UK.

Controller

The data controller is Danskify. You can contact us at privacy@danskify.com.

What we process & purposes

  • Local learning data (streaks, words, preferences): processed locally in your browser to provide the service.
  • Translation text (the minimal surrounding sentence): sent via Cloudflare Workers to DeepL or OpenAI to return a translation and pronunciation.
  • Waitlist email: collected via FreeWaitlists to send beta updates and invitations.
  • Cache entries: translated sentences stored in Cloudflare KV to improve performance (auto-delete after 30 days).
  • TTS text: Danish translation text sent to Google Cloud Text-to-Speech API (via Cloudflare Worker) to generate audio for words not yet cached.
  • TTS audio & hashes: generated audio files stored in Cloudflare R2, with hashed text entries in Cloudflare KV linking to the audio files (retained indefinitely, no personal identifiers).

Lawful bases (GDPR Art. 6)

  • Legitimate interests (Art. 6(1)(f)): processing translation text and TTS text, along with limited Worker-side anti-abuse measures strictly to deliver core functionality and reliability; you can disable external sources in settings.
  • Consent (Art. 6(1)(a)): collecting your email for the beta waitlist via FreeWaitlists.
  • Contract (Art. 6(1)(b)): (future, if accounts are launched): processing necessary to provide account features such as sync, friend streaks, and usage limits.

Recipients & processors

  • Cloudflare Workers, KV & R2: translation proxy, caching (30-day expiry for translations), and TTS audio storage. Privacy
  • DeepL API: dictionary-style translations. Privacy
  • OpenAI API: contextual translations. Privacy
  • Google Cloud Text-to-Speech API: audio generation for Danish translations. Privacy
  • FreeWaitlists: waitlist management. Privacy

International transfers & safeguards

Translation providers and infrastructure may process data in the EEA and/or other jurisdictions. When data leaves the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) or UK IDTA (as applicable) provided by our processors. Where regional processing options are available, we aim to use EU regions.

Retention

  • Local learning data: remains on your device until you clear it or uninstall.
  • Cloudflare KV cache (translations): auto-deletes within 30 days.
  • Cloudflare R2 (TTS audio) and KV (TTS hashes): retained indefinitely to improve performance, but contain no personal identifiers.
  • Waitlist email: retained by FreeWaitlists until you unsubscribe or request deletion.

Your rights

You have the right to access, rectify, erase, restrict, object to processing, and data portability (Arts. 15–21 GDPR). To exercise these rights, contact us at privacy@danskify.com. We may need to verify your identity and will respond within one month.

You also have the right to lodge a complaint with your local supervisory authority. If you are in the Netherlands, this is the Autoriteit Persoonsgegevens.

Note: If optional account features launch in the future, this section will be updated to reflect any additional processing, purposes, and retention specific to accounts, with clear opt-in controls.

10. Additional privacy & compliance details

Cookies and tracking

Danskify does not use cookies, analytics scripts, or web beacons. Any persistent data uses your browser’s isolated extension storage (browser.storage.local), which cannot be accessed by websites you visit.

Security measures

All communication between your browser, Danskify’s Cloudflare Workers, and external APIs is encrypted using HTTPS. API keys and secrets are stored securely as Cloudflare environment variables, never shipped to clients. Danskify follows the principle of least privilege for all permissions, and dependencies are reviewed monthly for vulnerabilities or security advisories.

Legal disclosure

Danskify may disclose limited data if required by law, regulation, or valid legal process. Due to our privacy-first architecture, we typically hold no personal or identifying information that could be produced.

Children’s privacy

Danskify is not intended for or directed toward users under 13 years old. We do not knowingly collect data from minors. Parents or guardians who believe their child has used Danskify may contact us at privacy@danskify.com to request deletion.

Automated decision-making

Danskify does not engage in profiling or automated decision-making. Any future adaptive-learning features will operate locally within your browser, never on our servers.

Data portability and deletion

When account-based features become available, users will be able to export all stored account data in a machine-readable format (e.g., JSON or CSV) and request deletion at any time. Local-only users can delete all data by clearing Danskify’s storage or uninstalling the extension.

Subprocessors

ServicePurposeRegionPolicy
CloudflareAPI hosting, caching & audio storageEU/USPrivacy
DeepLDictionary translationsEUPrivacy
OpenAIContextual translationsUSPrivacy
Google CloudText-to-Speech generationUS/EUPrivacy
FreeWaitlistsBeta waitlist managementUSPrivacy

Data breach procedure

In the unlikely event of a data incident involving personal information (e.g., waitlist emails), we will notify affected users and the relevant supervisory authorities within 72 hours of discovery, in accordance with GDPR Articles 33–34.

Policy updates and version history

We may update this policy to reflect feature changes, new legal requirements, or infrastructure adjustments. Major updates will be announced on our site and include a changelog. Archived versions are available on request.

Marketing site analytics

The Danskify marketing website uses PostHog (EU-hosted) to collect anonymized usage analytics. This helps us understand how visitors discover and navigate our site, for example, which pages are viewed most often or where signups drop off.

  • No cookies or tracking pixels are placed in the extension itself.
  • IP addresses are anonymized before storage.
  • Data is processed and retained within the European Union.
  • We use PostHog’s privacy-focused configuration (no cross-site tracking).

These analytics help us improve the public website experience only and are never linked to Danskify extension users, waitlist submissions, or any personally identifying information.

11. Contact us

Have questions, concerns, or want your data removed? Email us anytime at privacy@danskify.com.

Ready to start
learning?

Join the beta and be among the first to experience effortless Danish learning while browsing your favorite websites.

No spam, just updates on the beta launch. Unsubscribe anytime.