Spellbound is an extension which allows for more efficient and targeted learning. It monitors misspellings in Google Docs and creates flashcards out of them, using spaced repetition to determine exactly which cards should be shown to students to provide optimal retention.
Last updated: 26 February 2026
SpellBound ("we", "our", "us") is a Chrome extension that turns Google Docs spelling corrections into flashcards for students. This privacy policy explains what data we collect, how we use it, and how we protect it.
Summary: We collect only what is needed to run the service — email addresses for accounts and spelling words for flashcards. Flashcard data is end-to-end encrypted. We do not sell, share, or use your data for advertising.
1. Information We Collect
Account information:
Email address — used to create and authenticate your account via Firebase Authentication.
Password — handled entirely by Google Firebase Authentication. We never see, store, or have access to your password in plain text.
Account type — whether you are a school administrator, collaborator, or student.
Spelling and flashcard data:
Misspelled words detected from Google Docs spelling correction suggestions.
The corrected spelling of those words.
AI-generated context sentences to help students learn each word.
Review progress — interval, repetition count, and next review date for each flashcard.
School administration data (administrators only):
School name.
Student email addresses added by the administrator.
Collaborator email addresses.
Subscription and billing status (managed through Stripe).
Usage data:
Click interactions with spelling correction suggestions in Google Docs — solely to detect corrections and create flashcards. We do not track browsing history, keystrokes, mouse movements, or any activity outside of Google Docs spelling suggestions.
2. Information We Do Not Collect
We do not read or store the content of your Google Docs documents.
We do not track your browsing history or activity on any website other than Google Docs.
We do not collect location data.
We do not collect health, financial, or demographic information.
We do not use cookies or third-party tracking scripts.
3. How We Use Your Information
Account authentication: To verify your identity and grant access to your flashcards.
Flashcard creation and study: To build personalised spelling flashcards from your Google Docs corrections and schedule reviews using spaced repetition.
Cloud sync: To synchronise your flashcard data across devices so you can study anywhere.
Context sentences: Spelling words are sent to our server to generate a helpful example sentence using AI. Only the individual word is sent — no document content.
School administration: To allow school administrators to manage student accounts and billing.
Billing: To process subscription payments through Stripe. We do not store credit card numbers — all payment processing is handled by Stripe.
4. Data Encryption and Security
All flashcard data is encrypted on your device using AES-256-GCM encryption before it leaves your browser. The encryption key is derived from your password using PBKDF2 with 100,000 iterations. We cannot read your flashcard data on our servers.
Data is encrypted and decrypted entirely in your browser — our servers only store encrypted ciphertext.
All communication with our servers uses HTTPS/TLS encryption in transit.
Firebase Authentication tokens are refreshed automatically and stored securely.
A backup encryption key is stored (encrypted) to allow account recovery if you change your password.
5. Data Storage and Retention
Flashcard data is stored locally in your browser (via Chrome storage) and synced to Google Cloud Firestore in encrypted form.
Account data is stored in Firebase Authentication and Firestore, hosted by Google Cloud Platform in the United States.
Your data is retained for as long as your account is active.
When a school administrator deletes their school account, all associated student accounts and data are permanently deleted.
Students can delete individual flashcards at any time.
6. Data Sharing
We do not sell, rent, trade, or share your personal data with third parties for marketing or advertising purposes.
We use the following service providers to operate SpellBound:
Google Firebase — authentication, database, and cloud functions hosting.
Stripe — payment processing for school subscriptions.
Google Gemini AI — generation of context sentences from individual spelling words (only the single word is sent, not document content).
These providers process data solely to provide their services and are bound by their own privacy policies.
7. Children's Privacy
SpellBound is designed for use in schools. Student accounts are created and managed by school administrators. We do not knowingly collect personal information from children under 13 without the consent of their school or parent/guardian.
School administrators are responsible for obtaining any required parental consent before creating student accounts. Student accounts collect only an email address and encrypted spelling flashcard data.
8. Your Rights
You have the right to:
Access your data — all your flashcard data is visible within the extension.
Delete your data — students can remove up to one flashcard per day from within the extension. Administrators can delete their entire school account and all associated data.
Withdraw consent — you can uninstall the extension at any time. Contact your school administrator to request account deletion.
For users in New Zealand, this policy is consistent with the New Zealand Privacy Act 2020.
9. Changes to This Policy
We may update this privacy policy from time to time. The "Last updated" date at the top of this page will be revised accordingly. Continued use of SpellBound after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this privacy policy or your data, please contact us at:
Email: thisisatestemailforspellcast@gmail.com
© 2026 SpellBound. All rights reserved.