Spellbound is an extension which allows for more efficient and targeted learning. It monitors misspellings in Google Docs and creates flashcards out of them, using spaced repetition to determine exactly which cards should be shown to students to provide optimal retention.
Last updated: 5 June 2026
SpellBound ("we", "our", "us") is a Chrome extension that turns Google Docs and Microsoft Word (for the web) spelling corrections into flashcards for students. This privacy policy explains what data we collect, how we use it, and how we protect it.
Summary: We collect only what is needed to run the service — email addresses for accounts and spelling words for flashcards. Flashcard content is end-to-end encrypted. We do not sell, share, or use your data for advertising.
1. Information We Collect
Account information:
Email address — used to create and authenticate your account via Firebase Authentication.
Password — handled entirely by Google Firebase Authentication. We never see, store, or have access to your password in plain text.
Account type — whether you are a school administrator, collaborator, or student.
Spelling and flashcard data:
Misspelled words detected from Google Docs and Microsoft Word spelling corrections.
The corrected spelling of those words.
AI-generated context sentences to help students learn each word.
Review progress — interval, repetition count, and next review date for each flashcard.
School administration data (administrators only):
School name.
Student email addresses added by the administrator.
Optional student class/group name and graduation year.
Collaborator email addresses.
Aggregate student progress statistics (such as words mastered, success rate, and study streaks) used for the administrator dashboard. These do not include the actual words a student has practised.
Subscription and billing status (managed through Stripe).
Usage data:
Click and text-change interactions with spelling corrections in Google Docs and Microsoft Word — solely to detect corrections and create flashcards. We do not track browsing history, the content of your keystrokes, mouse movements, or any activity outside of spelling corrections in those two editors.
2. Information We Do Not Collect
We do not store or transmit the content of your documents. To detect a correction in Microsoft Word, the extension briefly compares text changes locally in your browser; this text is never saved or sent to our servers. In Google Docs, only the single corrected word is read.
We do not track your browsing history or your activity on any website other than Google Docs and Microsoft Word for the web (including Office.com, OneDrive, and SharePoint, where Word documents are edited).
We do not collect location data.
We do not collect health, financial, or demographic information.
We do not use cookies or third-party tracking scripts.
3. How We Use Your Information
Account authentication: To verify your identity and grant access to your flashcards.
Flashcard creation and study: To build personalised spelling flashcards from your Google Docs and Microsoft Word corrections and schedule reviews using spaced repetition.
Cloud sync: To synchronise your flashcard data across devices so you can study anywhere.
Context sentences: Spelling words are sent to our server to generate a helpful example sentence using AI. Only the individual word is sent — no document content.
School administration: To allow school administrators to manage student accounts and billing.
Billing: To process subscription payments through Stripe. We do not store credit card numbers — all payment processing is handled by Stripe.
4. Data Encryption and Security
Your flashcard content is encrypted on your device using AES-256-GCM encryption before it leaves your browser. The encryption key is derived from your password using PBKDF2 with 100,000 iterations. We cannot read your flashcard content on our servers.
Flashcard content (your words and their context sentences) is encrypted and decrypted entirely in your browser — our servers only ever store it as encrypted ciphertext.
Account and administration data (such as email addresses, class names, graduation years, and aggregate progress statistics) is stored in standard form so the service and administrator dashboard can function. It is protected by access controls, encrypted in transit, and encrypted at rest by Google Cloud.
All communication with our servers uses HTTPS/TLS encryption in transit.
Firebase Authentication tokens are refreshed automatically and stored securely.
A backup encryption key is stored (encrypted) to allow account recovery if you change your password.
5. Data Storage and Retention
Flashcard data is stored locally in your browser (via Chrome storage) and synced to Google Cloud Firestore, with flashcard content stored in encrypted form.
Account data is stored in Firebase Authentication and Firestore, hosted by Google Cloud Platform in the United States.
Your data is retained for as long as your account is active.
When a school administrator deletes their school account, the associated student and collaborator accounts, encryption keys, and flashcard data are permanently deleted.
When a student is removed from a school, their access is deactivated immediately and their account data is permanently deleted after a 60-day recovery window.
Students can remove up to one flashcard per day from within the extension.
6. Data Sharing
We do not sell, rent, trade, or share your personal data with third parties for marketing or advertising purposes.
We use the following service providers to operate SpellBound:
Google Firebase — authentication, database, and cloud functions hosting.
Stripe — payment processing for school subscriptions.
Google Gemini AI — generation of context sentences from individual spelling words (only the single word is sent, not document content).
These providers process data solely to provide their services and are bound by their own privacy policies.
7. Children's Privacy
SpellBound is designed for use in schools. Student accounts are created and managed by school administrators. We do not knowingly collect personal information from children under 13 without the consent of their school or parent/guardian.
School administrators are responsible for obtaining any required parental consent before creating student accounts. Student accounts collect an email address, an optional class/group name and graduation year, encrypted spelling flashcard data, and aggregate progress statistics.
8. Your Rights
You have the right to:
Access your data — all your flashcard data is visible within the extension.
Delete your data — students can remove up to one flashcard per day from within the extension. Administrators can delete their entire school account and all associated data.
Withdraw consent — you can uninstall the extension at any time. Contact your school administrator to request account deletion.
For users in New Zealand, this policy is consistent with the New Zealand Privacy Act 2020.
9. Changes to This Policy
We may update this privacy policy from time to time. The "Last updated" date at the top of this page will be revised accordingly. Continued use of SpellBound after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this privacy policy or your data, please contact us at:
Email: spellboundapp@protonmail.com
© 2026 SpellBound. All rights reserved.