KoeDash
Privacy Policy
Last updated September 23, 2026
Introduction
KoeDash is operated by Dmytro Dyshlyuk ("KoeDash", "we", "us", or "our") and provides a browser extension and website for smart interactive subtitles: live tab audio, dictionary lookup, on-screen scan, translation, and short explanations of a word in a subtitle line.
This Privacy Policy explains what information we collect, how we use it, and when it is shared with service providers. It describes the product as it works today. Sections that are not finished yet say so instead of promising a control or a retention period that is not in place.
Information we collect
Account information
KoeDash lets you sign in with Google. There is no email-and-password registration, and KoeDash does not collect or store a Google password.
Google sign-in uses the openid, email, and profile scopes. When you sign in, we receive and store:
- Google account ID
- email address
- name
- Google profile picture URL
- account creation, update, and last-login timestamps
Authentication information
KoeDash uses a session token to keep you signed in. On the website, that token is stored in an HTTP-only cookie named koedash_session. The extension stores the same kind of session in Chrome extension storage on your device.
The session is used to recognize your KoeDash account and to show account features, including saved subtitle sessions when that feature is enabled.
User preferences
The extension stores these settings on your device:
- preferred speech-recognition language
- subtitle display preferences, including theme and font size
- reading and word-spacing preferences
- translation and explanation language
- AnkiConnect deck, model, and field names
Those settings stay on the device. A feature sends only the setting it needs: for example, the speech-recognition language when capture starts, or the explanation language when you scan a region or request an explanation.
Website and webpage content
KoeDash processes the content needed for the feature you start. It does not upload an entire webpage or the page HTML.
A dictionary lookup sends the word, the language, the dictionary key, and, when available, part of speech and reading. Results come from dictionary data hosted with the KoeDash backend: JMdict, CC-CEDICT, KENGDIC, WordNet, and CMUdict. That lookup is not sent to an AI service.
AI-powered features
Some features send a narrow piece of content to Google Gemini. What is sent depends on the feature.
Scan
When you draw a region on a page, the extension captures the visible tab, crops it to that region, and sends the cropped JPEG to the KoeDash backend. The backend sends that crop to Google Gemini to read the text and translate it.
The full screen, the rest of the webpage, and the page DOM are not sent. KoeDash does not save the crop in its database or as a file after the request finishes. The recognized text, word tokens, and translation stay in the card on the page until you close it.
Explain
Explain is a separate action from a dictionary click. When you request it for a subtitle word, KoeDash may send Google Gemini the selected word, one subtitle line of up to 800 characters, and dictionary meanings already returned for that word. The webpage and other subtitle lines are not sent.
Live subtitles
For a live subtitle, KoeDash may send one recognized phrase of up to 800 characters to Google Gemini to correct speech-recognition errors and, if you turn translation on, to translate that phrase. Audio is not sent to Gemini.
Speech recognition
Live subtitles use Deepgram. Audio from the tab you capture is streamed to the KoeDash backend and then to Deepgram for transcription. KoeDash does not save that audio as a file on its servers.
Third-party service providers
KoeDash uses these providers to run the product. Each provider also handles information under its own terms and privacy notices.
Google provides sign-in through Google OAuth, and the paid Gemini API for scan, explanation, speech-recognition correction, and translation. Under Google's paid-service terms, prompts, images, and responses are not used to improve Google products. Google may log prompts and responses for up to 55 days to detect and prevent prohibited use and to meet legal or regulatory requirements. Content flagged by safety systems may be reviewed by authorized Google personnel.
Deepgram
Deepgram transcribes live audio for subtitles. The current integration does not set Deepgram's per-request Model Improvement Program opt-out. If the KoeDash Deepgram account participates in that program, Deepgram may retain a fraction of submitted data and use it to improve its voice models under the account's agreement with Deepgram. Deepgram states that it does not use that data for advertising profiles or redistribute it without permission.
MongoDB Atlas
MongoDB Atlas stores KoeDash accounts and, when signed-in subtitle saving is enabled, saved subtitle sessions.
Google Cloud Run
The KoeDash API runs on Google Cloud Run.
AnkiConnect
If you connect Anki, the extension talks to AnkiConnect on your computer at 127.0.0.1. Cards are not sent to KoeDash servers.
Saved subtitle sessions
When you are signed in and subtitle saving is enabled, a capture can be stored with your account. A saved session can include the subtitle text, the original speech-recognition text, word tokens, a translation, the tab title, and the page URL. Audio and scan images are not part of a saved session.
Saving is tied to a signed-in session. While sign-in is not required for capture, those captures are not written to the account database.
Cookies
The website uses cookies for sign-in. The extension does not use website cookies. KoeDash does not use advertising cookies.
- koedash_session keeps you signed in and expires after 7 days
- koedash_oauth_state is used during Google sign-in and expires after 10 minutes
- koedash_oauth_next remembers where to return after Google sign-in and expires after 10 minutes
The two OAuth cookies are cleared when sign-in finishes.
Analytics and advertising
KoeDash does not use Google Analytics, PostHog, Umami, Vercel Analytics, Sentry, advertising trackers, or data brokers. It does not sell personal information or user content. It does not keep a separate counter of users, uses, or hours.
Server logs
The API writes operational metadata and error information to Google Cloud Logging. Current application logs do not intentionally include account email addresses, selected words, or subtitle text. Earlier application versions could log recognized subtitle lines and account email addresses.
The Google Cloud Logging bucket used by KoeDash has a 30-day retention period. Earlier content-bearing log entries can therefore remain until that period expires. Logs are used to run and debug the service, not to build advertising profiles.
Data retention
Account information and saved subtitle sessions stay while the account exists. Deleting the account through the account page removes the account record and its saved subtitle sessions from KoeDash's database.
Scan images and other AI inputs are not saved by KoeDash after the request that used them. Paid Gemini API inputs and responses may be logged by Google for up to 55 days for abuse monitoring. Deepgram retention and model-improvement use depend on the KoeDash account's participation terms, and the current integration does not request per-call opt-out. KoeDash operational logs are retained for 30 days.
Account deletion
A signed-in user can permanently delete their KoeDash account from the account page. The action requires confirmation and deletes the account record and all saved subtitle sessions and subtitle lines associated with it. It does not delete the user's Google account.
Information already sent to a service provider remains subject to that provider's terms. Operational log entries may remain until the infrastructure retention period expires. You may also request help with deletion by emailing koiiimap225@gmail.com.
Security
KoeDash uses ordinary technical measures to protect information, including encrypted connections where the browser, API, and providers support them. No method of storage or transmission is completely secure.
Children's privacy
KoeDash does not set a minimum age and is not directed at children. It does not ask for a date of birth. If you believe a child provided personal information in circumstances where it should not have been collected, email koiiimap225@gmail.com.
Changes to this policy
We will update this policy when KoeDash features, data practices, or legal requirements change. The new version will be posted on this page with a new "Last updated" date.
Contact
KoeDash is operated by Dmytro Dyshlyuk. For privacy questions or deletion help, email koiiimap225@gmail.com. Website: https://koedash.com.