中 ScanChinese Privacy Policy
Back to app

Privacy Policy

Last updated 6 August 2026

Scan Chinese (“we”, “the service”) is a tool for reading and learning Chinese, operated at scanchinese.com. This policy describes what we collect, why, who else sees it, and how to get rid of it. It describes what the software actually does.

The short version

  • You can use the service without an account, for a limited number of uses.
  • We do not run analytics, advertising or tracking pixels of any kind.
  • We do not sell or rent personal data, ever.
  • What you scan, draw or type is sent to Google for recognition and translation.
  • You can export everything we hold, and delete your account yourself.

What we collect

If you do not have an account

We count how many times each visitor has used the paid recognition and translation features, so we can offer a free trial. That counter is stored against a salted one-way hash of your IP address. The address itself is never written down, and the hash cannot be reversed into it. Counters older than 30 days are discarded.

Our web server (nginx) keeps ordinary access logs, which include IP addresses, for operational and security purposes.

If you create an account

  • Email address. To identify you and to send password resets.
  • Password. Stored only as a scrypt hash. We cannot read it.
  • Display name, if you give one.
  • Your library. The characters and phrases you save, the folders you file them in, your notes, and your progress markers.
  • The pictures behind your cards. When a card comes from a photograph or a drawing, that image is stored so you can look back at it. It is resized and re-compressed on arrival, kept on our own server, and never sent anywhere else or shown to anyone but you. Deleting your account deletes all of them. Each account has a storage allowance.
  • Activity history. A record of each recognition, translation and save, so the service can show you what you have studied.
  • Where you signed up from. The IP address and browser of the account's first request, and an approximate country worked out from that address. The country is looked up against a database on our own server, so your address is not sent anywhere to resolve it. This is used to review access requests.
  • Session records. For each sign-in, the IP address, browser user agent and timestamps, so you and we can tell whether an account is being misused. Sessions expire after 30 days.

Session cookies and password-reset links are stored only as hashes, so a copy of our database would not let anyone sign in as you.

If you dictate with the Speak button

The recording is sent to Google to be transcribed and is not kept by us. Only the resulting text, and only if you are signed in, as part of your activity history. Your microphone is released the moment recording stops. Transcripts are cached against a hash of the audio so that repeating a recording costs nothing; the audio itself is not stored.

Sharing a card

You can turn any saved card into a link that anybody can open. Nothing is shared unless you ask for it, one card at a time.

  • What a shared link shows. The Chinese, the Pinyin, the Cantonese Yale, the English, and the photo or drawing the card came from. Anyone with the link can also play the audio.
  • What it does not show. Your notes, your progress markers, your folders, your email address, or anything else identifying you. Sharing a translation does not share your account.
  • The link is the permission. There is no password on it, so treat it like any other address you hand out: whoever has it can open it, and can pass it on.
  • Turning it off. Press Shared again in your library and the link stops working immediately. Sharing the same card later creates a different link, so the one you already sent stays dead.
  • Search engines. Shared cards are excluded in robots.txt and marked noindex. That stops the engines that respect it; it cannot stop somebody you sent the link to from publishing it.
  • Deleting the card also ends the link.

Cookies and local storage

We use one cookie, sc_session, set only when you sign in. It is HttpOnly, SameSite=Lax and expires after 30 days. It exists solely to keep you signed in; it is not used for tracking, and there are no third-party cookies.

Your browser also keeps some things locally, which never leave your device: your light/dark theme choice, recent translations and character meanings (so the app is faster and works offline), and. If you install the app; the recognition models. Clearing your browser storage removes all of it.

Who else sees your data

To do its job, the service sends some content to other companies:

WhoWhat they receiveWhy
Google Cloud Images you scan or draw, text you translate or have read aloud, and audio you record with the Speak button Optical character recognition, translation, speech synthesis and speech recognition
Google Fonts Your IP address and browser, when a page loads Serving the interface font
jsDelivr (CDN) Your IP address and browser, when a page loads Serving one recognition library

We have no other processors. There is no analytics provider, no advertising network, and no third-party session recording. Handwriting recognition and the neural model run in your browser and send nothing anywhere.

How long we keep things

  • Your account and library. Until you delete them.
  • Items you delete. Hidden from your account straight away, but kept on our side. We use them to work out why a recognition or a translation went wrong, to test changes against real examples, and to improve the service. They are never shown to other users and are not sold or shared. If you want them gone for good rather than merely hidden, use /api/account/erase, or write to us. See Your choices below.
  • Free-trial counters. Kept for the life of the account, because the trial is a one-off allowance rather than a monthly one.
  • Sessions. 30 days, or until you sign out.
  • Password reset links. One hour, and one use.
  • Recognition and translation results. Cached indefinitely so the same lookup is not paid for twice. These caches are keyed by the text or by a hash of the image, and are not linked to any account.

Your choices

  • Export. Signed in, request /api/auth/export to download everything we hold about you as JSON.
  • Delete individual items. Remove anything from your library at any time. It disappears from your account immediately; we keep a copy for the reasons set out above.
  • Erase deleted items. Signed in, request /api/account/erase, or write to us and we will do it for you. This permanently removes everything you have already deleted, including the copies we kept, and cannot be undone.
  • Delete your account. This erases your account, library, folders, notes, activity history and sessions immediately and permanently. We keep no copy, though a routine backup may retain it for up to 30 days.
  • Use it signed out. Nothing is stored against you at all.

If you are in the UK or EU, the GDPR gives you rights of access, rectification, erasure, restriction, portability and objection. The export and delete features above cover most of these directly; for anything else, write to us.

Security

The site is served over HTTPS. Passwords are hashed with scrypt; session and reset tokens are stored as SHA-256 hashes. The database accepts connections only from the machine itself. No system is perfectly secure, and we do not claim otherwise; but if you find a problem, please tell us before telling anyone else.

Children

The service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

Changes

If this policy changes materially, the date at the top will change and, where the change affects you, we will say so in the app.

Contact

Questions, requests or complaints: privacy@scanchinese.com.

Home Pricing Terms Privacy Credits

© 2026 Scan Chinese. All rights reserved.