Privacy
Taliri swaps a few words on pages you read into the language you are learning. This policy is short because the architecture is the policy: what you read stays on your machine.
The short version. The pages you read, their addresses and your browsing history never leave your device. Your learning record and settings stay there too. No extension analytics, no telemetry, no sync. To use Taliri you buy a subscription and sign in with your email; Taliri's server keeps that email and the records needed to check your plan, listed under Your account.
If you press the speaker, your browser's own speech service pronounces that one word; some browsers use an online voice for it.
What Taliri reads. To choose which words to swap, Taliri reads the text of pages it runs on — the part on or near your screen, as you scroll — in the tab's memory, on your device. Page text is never stored and never sent. The only thing that crosses from a page to Taliri's local database is a lookup: which dictionary words appeared — no sentences, no order, no URLs. Editable fields and code are excluded. A built-in list keeps it off mail, banking, documents and payment pages, and it backs off any page that shows a password field. Copying text from a page keeps the original wording.
What Taliri stores on your device.
- Your settings: language, level, pacing, and the sites you have allowed or blocked.
- Your learning record: for each dictionary word, counts of encounters and your answers with their scheduling state. Words, not pages — nothing about where you met them.
- Daily counters that keep pacing honest.
- A courtesy list: to notice when it is being annoying, Taliri remembers at most 50 recent site addresses — the domain only, never the page or its contents — with whether you paused or blocked it there. The list rolls over continuously, stays on your machine, and is erased on reset.
- Your sign-in: your account email, a random identifier for this browser, a credential for checking your plan, and a signed note of what your plan allows, with its renewal date and whether it is monthly or yearly. While a sign-in is under way, its request number and a one-time secret for checking on it. If you bought Taliri in this browser, the checkout email taliri.app/welcome handed over, until you sign in or type another email.
- The dictionaries: the bundled ones, and any you downloaded from packs.taliri.app.
What Taliri sends. Never anything about what you read. The extension talks to two places, both run by Taliri:
- packs.taliri.app, for dictionary packs: plain requests for public files, sent without cookies, identifiers, or anything derived from your browsing. Every pack is cryptographically verified before use.
- taliri.app, to sign in and to check your plan. Signing in sends your email, the random identifier for this browser, the extension's version, and whether Taliri was already installed here before sign-in existed. That last flag is left over from a beta that has ended: the server keeps it with the sign-in request and does nothing with it. The server also notes the kind of browser the request came from, such as “Chrome on macOS”, and shows it on the confirmation page so you can recognise your own request. About once a week the extension checks your plan with its credential; that check carries no email and nothing about your browsing.
On first install, Taliri also opens taliri.app/welcome in a background tab. If you bought Taliri in this browser, that page hands your checkout email to the extension so you don't have to type it again. Otherwise it only tells the extension it can close the tab. There is no sync and no third-party service in the extension. Pronunciation uses your browser's own speech service, as above: usually a voice installed on your device, though some browsers use an online voice.
Where it runs. Nowhere, until you say so. At install Taliri can reach only its own dictionary server, packs.taliri.app, and none of the sites you read. You choose everywhere, selected sites, or only-when-you-click; Chrome's own permission prompt is the gate, and revoking access removes the script.
Your account
Taliri's server keeps your account email; for each browser you sign in on, its random identifier and credential (up to five browsers; a sixth sign-in replaces the oldest); and your subscription's state as Paddle reports it: customer and subscription identifiers, dates, payments and refunds. For each sign-in request it keeps the email, the browser's random identifier, the extension's version, the kind of browser and the times.
The server runs on Vercel, which keeps standard request logs such as IP address and browser. The database is hosted by Neon. Sign-in emails are sent by Resend, with open and click tracking off. To limit abuse, the server counts requests per IP address; the address is stored only as a hash in a short-lived counter, deleted within about two days.
How long we keep it. Sign-in requests: 30 days. Payment notifications from Paddle: 90 days after processing. Paddle customer records not linked to an account: 90 days. Your account, the browsers you have signed in on (including any a newer sign-in replaced) and your subscription records: until you ask us to delete them. After a deletion we keep, for 60 days, each deleted browser's random identifier and a hash of its credential, so a deleted sign-in cannot start working again; and, without an end date, the Paddle customer identifier with the deletion time, which has no email in it, so an old subscription cannot quietly bring a deleted account back.
Paying
Paddle is our merchant of record: it sells the subscription, takes the payment, sends receipts and handles tax. The checkout at taliri.app/checkout loads Paddle.js, Paddle's own script, on that page only. Your card and billing details go to Paddle, never to Taliri's server; Paddle tells Taliri which subscription is yours and whether it is active. Paddle's customer portal, linked from taliri.app/account, shows invoices and lets you change your payment method or cancel. What you give Paddle is covered by Paddle's privacy notice (opens in a new tab).
After you pay, this browser keeps your checkout email for 24 hours so the extension can fill it in when you sign in. It is never sent to Taliri's server: it is handed to the extension and deleted, or deleted after 24 hours.
Cancel, delete, erase
Three separate things:
- Cancel billing in Paddle's customer portal (taliri.app/account). This stops future charges; it does not delete your account.
- Delete your account on Taliri's server by writing to hello@taliri.app from your account email. Deleting does not cancel billing, so cancel first.
- Erase everything in Taliri's Settings erases your learning record and settings on that device. It cancels nothing and deletes nothing on the server. Uninstalling removes local data too.
Your data is yours. Export everything to a file, or erase it all, from the options page.
Feedback, refund requests and language requests
The language request form sends only what you type or choose in it. Feedback keeps what it is about, your message, whether you sent it from the website or from Taliri, your browser and system, the time, and a reply email if you give one. We include the extension version and language when you open the form from Taliri; you can switch that off before sending. The link from Taliri carries the version and language, and that it came from Taliri, so our hosting provider's request logs see them even if you switch them off.
With feedback we also keep your browser and system in short form — for example “Chrome 154 on macOS” — taken from what every browser sends with a request. Unlike the version and language, this can't be switched off. We never store your IP address or location with it.
A refund request is sent with the same form and kept the same way as feedback, except that it needs the email you paid with, so we can find your payment. The refund itself is made in Paddle.
A language request keeps the language, any note and the time, and an email only if you tick “Email me once when this language launches.” That email is used once, for that language's launch only, and for nothing else.
Each feedback message and refund request, with any reply address, your browser and system, and the extension details, is also emailed to the founder through Resend, our email provider. So is each language request: the language, any note, and whether you asked for a launch email, but never the email address itself. Those copies stay in the founder's mailbox and are deleted by hand. The per-IP counters described under Your account cover these forms too: the address is stored only as a hash in a short-lived counter, deleted within about two days.
How long we keep it. Feedback, including refund requests: until it is handled, then up to 24 months; any feedback at most 36 months. A reply email: removed 90 days after the feedback is handled. A launch email address: removed as soon as we send that one email, and in any case 24 months after the request if it is never sent. Language requests: at most 36 months. To have your feedback or requests deleted sooner, write to hello@taliri.app.
This website
Your light or dark mode preference is saved in this browser.
On this site, the example's speaker pronounces only its own sample word, using your browser's speech; some browsers use an online voice for it.
Website analytics are off. The extension counts nothing.
Website analytics, when enabled, use PostHog, which processes the data for us in the EU. For each page you view, they record:
- the page itself, such as /privacy — never the rest of its address, except the campaign tags below;
- the domain of the site whose link brought you here, such as news.ycombinator.com (never the page on it), and the campaign tags utm_source, utm_medium and utm_campaign if the link has them;
- your country. PostHog uses your IP address to look up your country, then discards it;
- how long the page was on screen and how far down you scrolled, in ranges such as “30 to 60 seconds” and “half to three quarters”;
- button clicks and demo use: the Add to Chrome buttons, the light and dark switch, the example at the top of the page (including its language and its on/off switch), the two-card example further down, which parts of the page came into view, the questions you open, and whether you open or send the language request form (never what you type in it).
There are no cookies and no session recordings. Each page load gets a new random ID that lasts only that page load and is not tied to your other visits, and nothing from analytics is kept in your browser after the page closes. Analytics never run on the checkout, welcome, account, feedback or sign-in pages. The site does not collect your extension learning record or the pages you read elsewhere.
PostHog keeps these events for at least a year under its own retention rules; because they carry no lasting identifier, they can't be traced back to you. Our legal basis is legitimate interests: knowing how many people visit, where they come from and whether the page helps them.
Because events carry no lasting identifier, we cannot single out your visits. To opt out, block analytics with your browser or a content blocker; it does not change how the site works. Questions go to hello@taliri.app.
Changes. A future version may add optional, clearly labeled features that use the network (such as sync across devices). They will be opt-in, this policy will be updated first, and one promise is permanent: the pages you read never leave your device.
Questions: hello@taliri.app.