PRIVACY POLICY

Last Updated: August 2, 2026

This Privacy Policy describes how 2705463 ONTARIO INC. (“ThePureLanguage,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information in connection with the website www.thepurelanguage.com (the “Website”) and the translation features and services (the “Service”). By accessing or using the Website or Service, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Website and Service.

This Website is not intended for children.

The Service is a general-audience reference and study tool for adults and learners aged 16 or over. It is not directed to children, we do not offer any children’s learning section, and we do not want or knowingly permit users under 16. If you are under 16, please do not use this Website. See Section 14 for the full position, including COPPA, the UK Age Appropriate Design Code, GDPR/GDPR-K and Québec Law 25.


1. Scope of this Policy

  • Visitors who browse the Website
  • Users who access translation tools
  • Users who submit text for translation
  • Users who contact us via email or forms

This Policy does not apply to third-party websites, platforms, or services that we do not control.


2. Information We Collect

2.1 Information You Provide Directly

  • Text you submit for translation (processed temporarily; see Section 8)
  • Email address and name (if you contact us)
  • A leaderboard nickname, if you choose to submit a score and a nickname field is offered. Where display names are generated automatically instead, no nickname is collected from you (see Section 17)
  • Any information you voluntarily provide in communications

2.2 Automatically Collected Data

  • IP address
  • Approximate location (country/region) derived from your IP address
  • Device type and operating system
  • Browser type and configuration
  • Pages viewed, request timing, and error/diagnostic data
  • Time zone and language settings
  • Referring URLs
  • An automated-client (“bot”) classification derived from your browser’s User-Agent string

We do not operate behavioral tracking, cross-site tracking, or advertising profiles of our own. The data above is limited to standard server and security logs (see Section 9), server-side operational analytics used to keep the site working and to detect automated abuse (see Section 19), and data collected by our advertising partner, Google, for ad delivery (see Section 7).

Our operational analytics are server-side and aggregate. They do not set cookies, do not use browser storage, do not follow you across websites, and are not used to build a profile of you or to personalize advertising.

2.3 Do Not Track (DNT)

We do not respond to browser “Do Not Track” (DNT) signals. Users may manage privacy preferences through our consent banner (CMP).

2.4 Cookies and Tracking Technologies

We set one essential first-party cookie:

  • .AspNetCore.Session — A server-side session cookie set automatically by ASP.NET Core. It is used solely for core site functions, including abuse prevention and as one secondary input to rate-limit enforcement (our request limits are applied primarily by IP address — see Section 20.1). It contains only an opaque session identifier (no personal data). It is HttpOnly, Secure (in production), SameSite=Lax, and expires after 30 minutes of inactivity. It is not used for advertising, tracking, or profiling.

We do not set any other cookies from thepurelanguage.com. However, because we display advertisements using Google AdSense/Ads, Google may set cookies or use device identifiers to enable ad delivery, measurement, and fraud prevention. We do not use Google Analytics or YouTube embeds on the Website.

Local Storage: We use browser localStorage (not cookies) to store your preferences and learning progress locally on your device. This includes:

  • Flashcard learning progress (cards viewed, quiz results, spaced repetition data)
  • User preferences (preferred HSK level, display settings including light/dark theme, learning mode)
  • Session continuity data to resume where you left off
  • Your daily study streak and the day's practice points
  • A random identifier your browser generates on your first visit (a random UUID, stored as tpl_anonId). It is created by your device, not assigned by us, and is not derived from anything about you or your hardware.

This data is stored on your device and is not shared with third parties. With one exception, it is never transmitted to our servers: if — and only if — you choose to submit a score to a public leaderboard, that submission sends the random identifier described above (together with your score and, where offered, a nickname). Nothing else in the list is ever sent, and simply playing a game sends nothing. See Section 17.

You can clear this data at any time by clearing your browser's local storage or site data for thepurelanguage.com. Because the identifier lives only in your browser's storage, clearing it, using a different browser, or switching devices makes you a new, unrelated visitor to us.

Certain regions (EU/EEA, UK, Switzerland, Québec) require user consent for non-essential cookies. When applicable, we present a consent banner (CMP). Non-essential cookies and personalized advertising are used only where a user has provided explicit consent.


3. Purposes for Collecting and Using Information

We process data for the following purposes:

  • Providing translation functionality
  • Improving accuracy through caching of translation outputs (output only)
  • Operating and maintaining the Website
  • Ensuring security and fraud prevention
  • Enforcing request limits and preventing automated bulk extraction of our data (see Section 20.1)
  • Service optimization
  • Complying with legal obligations
  • Running advertising (Google Ads / AdSense)

We do not sell personal data.


4. Legal Bases for Processing (GDPR / UK GDPR / ePrivacy)

For visitors in the European Economic Area (EEA), the United Kingdom (UK), Switzerland, and similar jurisdictions, we rely on the following legal bases:

  • Consent — for non-essential cookies, personalized advertising, and any processing requiring explicit opt-in.
  • Legitimate Interests — for basic ad delivery, fraud prevention, measurement, and service security where appropriate.
  • Performance of a Contract — to provide translation services requested by the user.
  • Legal Obligations — when required to retain records or respond to lawful requests.

Our CMP allows users in regulated regions to review and update their consent and Legitimate Interest preferences at any time.


5. Third-Party Microsoft AI Services (Azure Translator & Azure AI Speech)

5.1 Data Processing by Microsoft

To provide automated translation, we use Microsoft Azure Translator as a fallback when requested text is not available in our proprietary dictionary.

  • Your submitted text is transmitted securely to Microsoft’s servers for processing.
  • For text translation: Microsoft does not store customer text or use it to train AI models for most synchronous text translation operations.
  • For document or asynchronous operations: text may be temporarily stored for up to 48 hours for reliability and debugging.
  • All transmission is encrypted; temporary data is accessible only to authorized personnel under strict controls.

Microsoft Data Privacy

Refer to Microsoft’s documentation for current details on data handling:

5.2 Caching Policy

  • We cache only translation outputs returned by Microsoft for up to 60 days, to avoid repeating the same API calls.
  • We do not store your original input text. Cached outputs are keyed by a one-way hash of the input, which cannot be reversed to recover what you typed.
  • Translations sourced from Microsoft are marked with a cloud icon where shown in the UI.

5.3 Text-to-Speech (Microsoft Azure AI Speech)

When you use a “Listen” button to hear a word, phrase or pinyin syllable pronounced, the short text to be spoken is sent from our servers to Microsoft Azure AI Speech, which returns synthesised audio.

  • The request is made server-to-server. Your IP address, cookies and browser details are not sent to Microsoft by this feature.
  • Only the short text to be spoken is transmitted — capped at 100 characters, or 24 characters for a single pinyin syllable.
  • In normal use this is dictionary content (a word, phrase or syllable), not information about you.
  • Generated audio is cached so that the same text does not need to be sent repeatedly.
  • No microphone audio is involved. This feature only plays audio to you — it never captures anything. For microphone-based features see Section 18.
  • Processing region: South Central US. For visitors in the EEA, the UK or Switzerland this is a transfer to the United States, carried out under Microsoft's Standard Contractual Clauses and the Microsoft Products and Services Data Protection Addendum (DPA).
  • See Azure AI Speech — Data, Privacy and Security.

6. Third-Party Content Delivery Networks (CDNs)

To provide enhanced functionality and improve performance, we use third-party Content Delivery Networks (CDNs) to load certain libraries and resources. When you use the Website, your browser may connect to the following CDN providers to download these resources:

6.1 CDN Services Used

  • jsDelivr (cdn.jsdelivr.net) — Loads the HanziWriter software library used for Chinese character stroke order animations on our Stroke Order Animator, radical, beginner game, and certain article pages.
    The character stroke data HanziWriter animates is served from our own servers rather than from a CDN, so no record of which characters you look up is sent to any third party. For the authorship and license of both the library and that data, see our Open Source Licenses page.
  • Cloudflare CDN (cdnjs.cloudflare.com) — Loads jQuery, Bootstrap CSS/JavaScript, and Font Awesome for site functionality and styling.
    These are open-source libraries used for interactive features and responsive design; their authors and licenses are listed on our Open Source Licenses page.

6.2 Data Transmitted to CDNs

When your browser requests resources from these CDN providers, the following information may be transmitted:

  • Your IP address
  • Browser type and version
  • Referring website (thepurelanguage.com)
  • Request timestamp

These CDN providers may log this data for their own operational purposes (such as performance monitoring, security, and abuse prevention). We do not control the CDN providers' data practices. For details, please refer to:

Note: CDN usage is essential for Website functionality. If you block these connections, some features (such as the Stroke Order Animator or interactive elements) may not work correctly.


7. Google Services, Advertising & Cookies (GDPR / LI)

We use Google AdSense/Ads, including related-search ad units, to display advertisements. Google may collect cookies, device identifiers, usage data, IP address and browser metadata, and ad interaction and measurement data. Personalized ads are served only with users' explicit consent in regulated regions.

No advertising is directed to children. The Website is a general-audience service for users aged 16 or over and contains no child-directed content, so no page is designated as child-directed content in our advertising settings — because none is. We do not ask our advertising partner to target children, and we do not use advertising formats aimed at children. See Section 14.

Related search units: Some pages display a Google-operated “related searches” box. If you type a query into it or click one of its suggestions, that search term is sent to Google and is handled by Google as the controller, under the Google Privacy Policy — in the same way as a search you run on Google directly. We never receive your search term, we do not log it, and it is not connected to anything you type into our translation tools. If you do not interact with the box, no search term is generated.

How Google uses your data: For full details on how Google processes data — including IP addresses — when you use a site that displays Google ads, see How Google uses information from sites or apps that use our services, Google's Privacy & Terms / advertising data-use page, and Google's Advertising technologies policy.

  • Legitimate Interest purposes may be enabled for basic ad delivery, frequency capping, measurement, and fraud prevention where permitted by law.
  • Consent or Legitimate Interest status is communicated to Google and other advertising partners via our CMP.

Cross-Border Transfers:
Google and Microsoft may process data in the United States and other countries. Data transferred outside the EU/EEA, UK, or Switzerland is protected using Standard Contractual Clauses (SCCs) approved by the European Commission, alongside Google’s or Microsoft’s supplemental commitments and technical safeguards (encryption, access controls), to provide GDPR-level protection.

Controller / Processor Roles:

  • Google Ads / AdSense: independent data controller for its ad processing and targeting functions.
  • Microsoft Azure Translator: data processor acting on our behalf for translation processing.

Personalized ads are shown only when the user explicitly consents in regulated regions. Users may manage ad preferences via our CMP and at Google Ads Settings.

Our CMP follows the IAB Europe TCF guidelines for communicating consent and Legitimate Interest signals to advertising vendors.


8. Automated Decision-Making & Profiling

We use automated systems to generate translations, display contextual or (where consent is given) personalized ads, and detect/prevent fraud or invalid traffic.

  • We do not make automated decisions that produce legal or similarly significant effects on users.
  • In regulated regions (EU/EEA, UK, Switzerland, Québec), we do not profile or use personalized advertising or analytics unless the user has explicitly consented via the consent banner. If the user declines consent, ads are strictly contextual and profiling does not occur.

9. Data Retention

  • Translation input text: not stored — used only transiently in memory to produce your result. Our translation-output cache is keyed by a one-way hash of the input, so the original text is never persisted.
  • Microsoft temporary storage (when used): up to 48 hours.
  • Cached translation outputs: up to 60 days.
  • Log data (server and security logs): retained up to 12 months.
  • Operational analytics (Microsoft Azure Application Insights, see Section 19): retained up to 90 days, then deleted automatically by Microsoft. IP addresses are not retained in this data — see Section 19.
  • Emails: retained as needed for administration, then archived or deleted.
  • Essential session cookie (.AspNetCore.Session): expires after 30 minutes of inactivity or when the browser session ends.
  • Request-limit counters (see Section 20.1): held in server memory only, for at most one hour, then discarded. Never written to disk.
  • Advertising cookies and identifiers (Google): retained per Google's expiration policy.

Google may use data as an independent controller for its advertising optimization and measurement purposes.


10. Data Sharing and Disclosure

  • Microsoft Corporation — translation processing (processor). See Section 5.
  • Microsoft Corporation — text-to-speech audio generation via Azure AI Speech (processor). See Section 5.3.
  • Microsoft Corporation — website operational analytics and diagnostics via Azure Application Insights (processor). See Section 19.
  • Google — advertising (independent controller for ads).
  • Hosting and infrastructure partners (e.g., Azure or hosting provider).
  • Professional advisors (legal, accounting).
  • Regulators or authorities when required by law.

We do not sell personal information. Each vendor relationship is governed by a Data Processing Agreement (DPA) where required by law. Where applicable, DPAs with Microsoft and our hosting providers ensure GDPR-compliant processing and confidentiality obligations.


11. International Data Transfers

Data may be processed in the U.S., Canada, EU, or other regions. Transfers are protected by Standard Contractual Clauses (SCCs) and appropriate technical safeguards (for example, encryption in transit and at rest). We conduct Transfer Impact Assessments (TIAs) where required to evaluate risks and supplemental safeguards.

Specifically, the Website is hosted in, and the following Microsoft services process data in, the South Central US Azure region:

  • Website hosting and the translation-output cache;
  • Azure Translator, where a word or phrase is not in our dictionary (Section 5);
  • Azure AI Speech, used to generate “Listen” audio (Section 5.3);
  • Azure Application Insights operational analytics (Section 19).

If you access the Website from the EEA, the UK, or Switzerland, this constitutes a transfer to the United States, carried out under Microsoft's Standard Contractual Clauses and the Microsoft Products and Services Data Protection Addendum (DPA).


12. Cookie Policy (Summary)

ThePureLanguage.com sets one essential first-party cookie (.AspNetCore.Session) for core site functions, including abuse protection. This cookie contains only an opaque identifier — no personal data — and is not used for advertising or profiling. It expires after 30 minutes of inactivity. Our request limits are applied primarily by IP address rather than by this cookie — see Section 20.1. Because we display ads with Google AdSense/Ads, Google may also set cookies or use device identifiers for ad delivery, fraud prevention, and measurement. Those cookies and identifiers are controlled by Google.

Our website analytics (Section 19) set no cookies at all and use no browser storage — they run entirely on our server. Declining consent therefore has no effect on them, and they cannot be used to track you between visits or across other websites.

Consent:

  • In GDPR-regulated regions and Québec, our CMP displays a consent banner. Non-essential cookies (including personalized ads) are used only after explicit consent.
  • If you decline consent, ads will be non-personalized and profiling will not occur.

Manage ad preferences via our CMP or at Google Ads Settings.


13. Your Privacy Rights

Because we do not create user accounts, collect age information, or track users across the Website by default, we generally cannot identify who used the Service unless you provide additional information that allows us to verify your identity. Depending on your location, you may still have certain privacy rights that apply to the limited data we process (for example: temporary server logs or short fragments of cached translation output).

GDPR / UK GDPR / Switzerland

If you are located in the EEA, UK, or Switzerland, you have the right to:

  • Access, correct, or request deletion of any personal data we may hold.
  • Withdraw consent where processing is based on consent.
  • Restrict or object to processing (including processing based on legitimate interests).
  • Request data portability where applicable.
  • File a complaint with your local supervisory authority.

We will respond to verified requests within 30 days. Because we do not maintain long-term, account-linked records by default, we may require additional information to verify your identity and determine whether we hold any data tied to you.

Canada (PIPEDA & Québec Law 25)

Canadian residents have the right to:

  • Access any personal information we hold about you.
  • Request correction of inaccurate information.
  • Request a list of third parties to whom your data may have been disclosed (e.g., hosting providers).
  • Request cessation of dissemination where applicable under Québec Law 25.
  • File a complaint with the Office of the Privacy Commissioner of Canada.

Because we do not associate data with persistent user identities by default, some requests (for example, deletion of account-linked data) may not be applicable unless you provide details enabling us to locate relevant records.

California (CCPA / CPRA)

California residents have the right to:

  • Know the categories of personal information we collect and the categories of recipients with whom it is shared.
  • Request deletion of personal information that we maintain about you.
  • Request correction of inaccurate personal information.
  • Opt out of the sale or sharing of personal information for cross-context behavioral advertising.
  • Limit the use or disclosure of sensitive personal information.
  • Not be discriminated against for exercising privacy rights.

We do not sell personal information. Limited sharing for advertising purposes may occur when serving ads through Google. Because we do not maintain persistent consumer profiles or accounts, and because Google provides its own opt-out tools, we do not host a separate “Do Not Sell or Share” link on the Website.

How to submit a request: To exercise any of the rights above, please contact our Data Protection Officer at thepurelanguagecom@gmail.com. Include sufficient information for us to locate the data (for example, the approximate date and time you used the Service, any text you submitted, or the email address used when contacting us). We will verify your identity before responding to rights requests. Where identity cannot be reasonably verified or where no data associated with you can be located, we will explain why the request cannot be fulfilled.

If we deny your request, you may appeal the decision by replying to our response email with the word APPEAL in the subject line. We provide alternative accessible formats of this Privacy Policy upon request for individuals with disabilities.


14. Children’s Privacy — This Website Is Not for Children

14.1 Our position

The Website is a general-audience reference and study tool intended for adults and for learners aged 16 or over. It is not directed to children, it is not designed to appeal to children, and we do not want children as users.

Specifically, and as a matter of ongoing policy:

  • We operate no children’s section and offer no learning content directed to children.
  • We use no cartoon characters, mascots, animations, images of children, child actors, songs or other child-appealing features, and we state no age range below 16 anywhere on the Website.
  • We do not knowingly collect personal information from anyone under 16, and we do not knowingly allow anyone under 16 to submit anything to us.
  • We never request microphone access, voice recordings, photographs or video outside the two clearly-labelled optional Speaking Practice pages described in Section 18, which are likewise intended for users aged 16 or over.
  • We do not operate accounts, profiles, messaging, chat, uploads, friend lists or any other feature through which a user could publish personal details or be contacted by another user.
  • We do not knowingly build profiles of, target advertising at, or apply any form of behavioural profiling to children.

Because we collect no age data and operate no accounts, we cannot verify any individual visitor’s age. Our controls are therefore editorial and structural: we do not publish content aimed at children, and we have removed the content that was. Parents, guardians and teachers are responsible for supervising the internet use of anyone in their care.

14.2 COPPA (United States)

The US Children’s Online Privacy Protection Act applies to operators of websites or online services directed to children under 13, and to operators with actual knowledge that they are collecting personal information from a child under 13. Assessed against the factors the Federal Trade Commission applies — subject matter, visual and audio content, use of animated characters or child-oriented activities and incentives, the age of models, the presence of child celebrities, language, and whether advertising on the service is directed to children — this Website is a general-audience service and is not directed to children, and it contains no child-directed portion. We have no actual knowledge of collecting personal information from any child under 13. If we obtain such knowledge, we will delete the information promptly; see Section 14.6.

14.3 UK Age Appropriate Design Code (Children’s Code)

The UK Children’s Code applies to information society services likely to be accessed by children in the United Kingdom. We have assessed the Website against that standard. We do not target children, we publish no content of the kind that would appeal to a child rather than to an adult learner, and we removed the only section that plausibly would have. We have documented that assessment internally and keep it under review; where the Code’s data-protection expectations apply to us regardless of audience, we already meet them by design and by default:

  • Data minimisation: no accounts, no sign-up, no email address required to use any feature, and learning progress kept in your own browser rather than on our servers (Section 2.4).
  • High-privacy defaults: nothing is transmitted from your device unless you actively choose it. Submitting a leaderboard score is the only such action, it is off unless you tap the button, and no nickname is requested when display names are generated automatically (Section 17).
  • No profiling by default: personalized advertising is served only where a user has given explicit consent through our consent management platform in regulated regions (Sections 7 and 12). We apply no behavioural profiling of our own, and our analytics set no cookies, use no browser storage and retain no IP address (Section 19).
  • No nudge techniques: we use no streak pressure, loss-framing, countdowns or dark patterns to push any user toward sharing more data or spending more time than they intended.
  • Transparency: this Policy states plainly, at the top and here, that the Website is not for children.

14.4 GDPR and GDPR-K (EU/EEA and UK)

Under the UK and EU GDPR, the age of consent for information society services offered directly to a child ranges from 13 to 16 depending on the member state. We set our threshold at the highest of those, 16, and do not offer the Service directly to anyone below it.

Where we rely on legitimate interests (Article 6(1)(f)) — principally for security, abuse prevention and rate limiting, described in Section 20.1, and for server-side diagnostics described in Section 19 — we have taken account of Recital 38, which provides that children merit specific protection and that legitimate interests are a weaker basis where a child’s data may be involved. The processing in question is limited to IP address, User-Agent and request metadata; it is held in memory for no more than one hour (with the sole exception described in Section 20.1), is never used to build a profile of any individual, is never used for advertising or personalisation, and is necessary to keep a free service available against automated abuse. We consider that balance to hold even on the assumption that a child’s data could occasionally be involved — and we have reduced the likelihood of that by removing all child-directed content.

14.5 Canada — PIPEDA and Québec Law 25

We are an Ontario corporation and are subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA). The Office of the Privacy Commissioner of Canada treats the personal information of minors as inherently sensitive, and consent obtained directly from a young child is generally not considered meaningful.

Québec’s Law 25 likewise treats the personal information of a minor as sensitive: information concerning a minor under 14 may generally only be collected with the consent of a person having parental authority, and privacy settings must default to the highest level of confidentiality. We do not seek to rely on consent from a minor: we do not direct the Service to minors, we offer no accounts, and the confidentiality-affecting settings we do have — chiefly whether anything at all leaves your device — are already at their most protective by default and change only if you actively choose otherwise.

14.6 If a child has used this Website

If you are a parent, guardian or teacher and you believe a child has provided personal information to us — in practice this could only be a leaderboard entry or an email to us — please contact thepurelanguagecom@gmail.com and we will delete it promptly and without requiring you to create an account or prove anything beyond enough detail for us to find the entry.

Please note the practical limit set out in Section 17: a leaderboard entry is linked only to a random identifier held in the submitting browser. If that browser’s data has been cleared, we hold nothing that connects the entry to any person and may be unable to locate it. Where we cannot identify an entry, we cannot delete it selectively — but no leaderboard entry contains a name, an email address or an IP address in the first place, and where display names are generated automatically no user-entered text is stored at all.


15. Security

We implement reasonable technical and organizational safeguards to protect personal information, including encryption in transit, secure hosting, access controls, and monitoring. While we strive to protect your data, no security measure is perfect or impenetrable.


16. Changes to this Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last Updated” date. Material changes affecting your rights will be communicated to you where feasible.


17. Games & Leaderboards

Your streak and progress are stored only in your browser (localStorage) and are not sent to us. If you choose to submit a score, we store a display name, your score, the date, and a random identifier your browser generated. We do not collect your name, email address, or IP address with leaderboard entries. Entries are kept for the current period plus 35 days. You can remove your entries at any time with the “Remove my scores” button, or by contacting us.

How the leaderboard recognises you. We do not use a cookie or an account for this. Recognition relies entirely on the random identifier your browser created and keeps in its own local storage (see Section 2.4). It is sent only when you submit or remove a score. We treat it as pseudonymous personal data: on its own it identifies no one and we hold nothing that links it to your name, email address or IP address, but it is persistent, so we describe it here rather than calling it anonymous.

The identifier is never published. The public leaderboard data returned to browsers contains only a short one-way hash of it, which your own browser recreates locally to highlight your row as “(you)”. The hash cannot be reversed to recover the identifier.

Please note: that identifier is also the only credential proving a leaderboard entry is yours, and it exists nowhere but your browser. If you clear your site data, switch browsers, or move to another device, you become a new visitor to us and the “Remove my scores” button can no longer reach entries submitted from the old browser. We are then unable to locate those entries on request, because nothing connects them to you. If you want an entry removed, please use the button before clearing your browser data, or contact us with enough detail (the game, display name, score and approximate date) for us to find it.

How your display name is set. Depending on the game and our current configuration, the name shown next to your score is either:

  • Automatically generated by us — a random name such as “SwiftPanda42”, built from a fixed word list and derived from the random identifier your browser created. In this mode no nickname is collected from you at all: no nickname field is shown, and any name your device sends is ignored and discarded. The generated name contains no information about you; or
  • A nickname you enter — where a nickname field is offered, we store the text you type. Please enter a nickname only — never your real name or contact details.

In both cases the display name is shown publicly on the leaderboard, where it may be seen by anyone, including minors. A nickname you enter is user-generated content and is your responsibility — please do not enter offensive text or your real name. We apply automated profanity filtering that rejects or replaces nicknames we detect as inappropriate (substituting an automatically generated name), but no filter is perfect and we cannot guarantee every inappropriate nickname is caught. By submitting a nickname you agree to our nickname rules and acknowledge these points; see Section 4.1 of our Terms of Service for details.


18. Microphone & Speech Recognition

Two optional practice pages — Chinese Speaking Practice and its English counterpart — can listen to you say a word so the page can score your pronunciation. The microphone is used only on those pages, and only after you tap the microphone button and grant your browser's permission prompt. Every other page on the Website is blocked from requesting microphone access at the browser level (via a Permissions-Policy header), including advertisements, which can never request it.

18.1 What we do not do

  • We do not record your voice.
  • We do not store, upload or transmit any audio to our servers. No recording of your voice is ever created or sent to us — there is nothing for us to keep.
  • We do not use your voice to identify you, and we do not perform voice-print, biometric or speaker-recognition processing of any kind.
  • We do not use your voice, or anything derived from it, to train artificial intelligence or machine-learning models — ours or anyone else's.
  • We do not share or sell voice data, because we never receive any.
  • The microphone is never activated in the background, on page load, or while you are on any other page.

18.2 Your browser's speech recognition (important)

The speech recognition itself is performed by your web browser, using the built-in Web Speech API — not by us and not on our servers. This distinction matters:

Most browsers do not recognise speech on your device. They typically send the captured audio to their own provider's servers for transcription — for example Google in Chrome, or Microsoft in Edge. That transfer happens between your browser and its vendor. It is governed by that vendor's privacy policy, we have no visibility into it, we receive no copy of the audio, and we cannot control, limit or switch it off.

We reference the relevant vendor policies here so you can review them: Google Privacy Policy (Chrome) and Microsoft Privacy Statement (Edge). If you are not comfortable with your browser transmitting audio to its vendor, simply do not grant the microphone permission, or decline it in the prompt. Both speaking pages remain fully usable without it — you can still hear the model pronunciation and practise aloud; only the automatic scoring is unavailable.

18.3 What happens to the transcript

Your browser returns a text transcript of what it heard. That text is compared to the target word inside your browser to produce a score, and is then discarded — it is never sent to us. Words you missed can be saved to a review deck, which is stored in your browser's local storage on your device only (see Section 2.4). If you choose to submit your result to a leaderboard, only your numeric score is sent, exactly as described in Section 17 — never the transcript and never audio. The “Listen” button is unrelated to the microphone: it sends the target word (text only) from our servers to Microsoft Azure AI Speech to generate example audio, and involves no input from you. See Section 5.3 for details of that transfer.


19. Website Analytics & Diagnostics (Microsoft Azure Application Insights)

We use Microsoft Azure Application Insights, a server-side monitoring service, to keep the Website running correctly, to diagnose errors and slow pages, and to detect automated abuse. Microsoft acts as our processor for this data under the Microsoft Products and Services Data Protection Addendum.

19.1 What is collected

  • The URL requested, the HTTP method, the response status code, and how long the request took
  • Approximate location — country/region, and at most city level — derived from your IP address at the moment the data is received
  • Browser and operating system type (from the User-Agent string)
  • An automated-client classification (whether the request appears to come from a known crawler or bot, and which one)
  • Unhandled errors and exception diagnostics, including stack traces
  • A randomly generated, short-lived identifier used to group the requests of a single visit for troubleshooting

19.2 IP addresses are not stored

Application Insights is configured with IP masking enabled (the service default, which we have not disabled). Your IP address is used once, on receipt, to derive an approximate location, and is then discarded and stored as 0.0.0.0. We do not have access to the raw IP addresses of visitors in this analytics data, and we cannot re-identify you from it.

19.3 What is never collected

  • No text you submit for translation, and no translation results. Telemetry records only metadata such as input length and the options selected.
  • No microphone audio and no speech transcripts (see Section 18).
  • No names, email addresses, or account data — the Website has no user accounts.
  • No cookies and no browser storage. Application Insights is used server-side only; we do not load its browser-side JavaScript SDK, so it cannot track you across sites or sessions.

19.4 Legal basis and your choices

Where the GDPR or UK GDPR applies, we rely on our legitimate interests (Article 6(1)(f)) in operating a secure, functioning website and in preventing fraud and automated abuse. Because this processing is server-side, uses no cookies or similar technologies, and stores no IP address, it does not require consent under the ePrivacy Directive. You may still object to it under Article 21 — see Section 13 — and you can exercise all other rights described in Section 13 in respect of this data.

Retention is 90 days, after which Microsoft deletes the data automatically. Microsoft's privacy practices are described in the Microsoft Privacy Statement.


20. Geographic Availability & Access Restrictions

The Website is not available in every country. To protect the integrity of our advertising and to control infrastructure costs, we restrict access from certain regions and from certain automated crawlers. Requests from a restricted region or from a blocked automated client receive an HTTP 403 Forbidden response.

To apply this restriction we compare your IP address against a list of published country IP ranges at the moment of your request. This check happens in memory, during the request. We do not log, store, or share your IP address for this purpose, and no record of the blocked request is retained beyond ordinary short-lived server logs. Where the GDPR applies, the legal basis is our legitimate interests (Article 6(1)(f)) in protecting the service against abuse and in maintaining the commercial viability of a free service.

The list of restricted regions may change at any time. If you believe your region has been restricted in error, please contact us at the address in Section 21.

20.1 Request Limits and Automated-Access Protection

To keep this free service available and to prevent automated bulk extraction of our dictionary data, we limit how many requests a single visitor may make in a given period. Enforcing this requires us to count requests, and to do that we must be able to tell one visitor from another.

For that purpose we process, in memory and only for the duration of the counting period:

  • Your IP address;
  • Your browser's User-Agent string;
  • Whether your request carried the ordinary headers a web browser sends (such as Accept-Language and Sec-Fetch-*), which distinguishes a browser from an automated script;
  • In some cases, your Accept-Language header and the opaque session-cookie identifier described in Section 2.4, as a secondary check.

These counters are held only in our server's memory, are keyed to short fixed periods (at most one hour), and are discarded when the period ends. They are never written to disk, never attached to your translations or any other content, never used to build a profile, and never shared with anyone. Your IP address is not stored in our operational analytics either — see Section 19.2. If your request exceeds a limit, we return an HTTP 429 Too Many Requests response.

On the translation pages only, a request that exceeds a limit also starts a short waiting period before the next translation is accepted — a few seconds the first time, and longer if the limit keeps being exceeded. So that repeat and one-off events can be told apart, we hold a count of these events and the time of the most recent one, keyed to your IP address, in our server's memory for up to 24 hours; the record is erased after 24 hours without a further event, and is erased in any case when our server restarts. It is never written to disk, never linked to your translations or anything else you do on the site, and is used for nothing but deciding how long that waiting period should be. Ordinary use of the site — including flashcards, games, quizzes and audio playback, however rapidly you click — never creates such a record.

Where the GDPR or UK GDPR applies, the legal basis is our legitimate interests under Article 6(1)(f) in the security and availability of our network and information systems and in preventing abuse of a free service — a purpose expressly recognised as a legitimate interest in Recital 49 of the GDPR. This processing is strictly necessary to deliver the service you requested and to keep it running, so it does not depend on consent; it is not used for advertising or personalization. You may object to processing based on legitimate interests (see Section 13), though we may be unable to serve requests we cannot rate-limit.

Children. Recital 38 of the GDPR provides that children merit specific protection and weighs against legitimate interests where a child’s data may be involved. The Website is not directed to children and offers no children’s content (Section 14), so we do not expect this processing to concern children. We have nonetheless assessed the balance on the assumption that it might: the data is limited to IP address, User-Agent and request metadata, is held in memory only, is retained for no more than one hour except for the strike record described above, is never used to build a profile of any individual and never used for advertising, and without it the free service could not be kept available. See Section 14.4.


21. Contact Information

Data Protection Officer (DPO)
2705463 ONTARIO INC.
Email: thepurelanguagecom@gmail.com
Website: www.thepurelanguage.com

By using the Website and Service, you acknowledge that you have read and accept this Privacy Policy.