Privacy notice

Applies to en.haozi.me and the Encounter browser extension. Updated October 8, 2026.

Account and learning records

Google or GitHub sign-in provides your name, email, avatar and account identifier to recognize your account and sync progress. Encounter does not receive your Google or GitHub password or request access to email content or repositories. The server stores sessions, provider credentials, devices, vocabulary, plans, answers and learning statistics. Provider access tokens are encrypted on the server; device refresh credentials are stored as hashes.

Word recognition on webpages

The extension scans page text on your device to find learned words. Full pages are never uploaded. By default it syncs word identifiers, hostnames, times, visible durations and interactions such as opening meanings or playing audio. Encountering a word does not count as a correct recall.

Optional page addresses and sentences

Page paths and context sentences are not saved by default. Sharing preferences sync across the website and extensions for the same account; enabling requires server confirmation. Addresses have query parameters and fragments removed. Disabling and saving a preference removes its stored details. The current default retention period is 90 days; account settings show the effective period. Expired details stop being displayed and are periodically removed. Vocabulary, encounter counts and learning records are retained.

Device storage and account controls

The website uses a sign-in cookie. The extension stores sessions, pending answers, vocabulary and audio caches in its own storage to support offline learning. You can sign out of the website or revoke one or all extension devices in account settings. Revoked devices cannot make further API requests or renew credentials. Unfinished local learning tasks are preserved.

Service providers

Google and GitHub handle sign-in authorization under their own policies. Cloudflare provides the website's network entry point. When audio is enabled, the pronunciation provider receives the requested word and accent; audio is cached in Cloudflare R2. Service infrastructure processes network information required for these functions, such as IP addresses and request logs.

Contact and data requests

To access, correct or delete account data, or report a privacy concern, contact [email protected]. We verify account ownership before handling account requests.