KoeDash

KoeDash

Privacy Policy

Last updated September 23, 2026

Introduction

KoeDash is operated by Dmytro Dyshlyuk ("KoeDash", "we", "us", or "our") and provides a browser extension and website for smart interactive subtitles: live tab audio, dictionary lookup, on-screen scan, translation, and short explanations of a word in a subtitle line.

This Privacy Policy explains what information we collect, how we use it, and when it is shared with service providers. It describes the product as it works today. Sections that are not finished yet say so instead of promising a control or a retention period that is not in place.

Information we collect

Account information

KoeDash lets you sign in with Google. There is no email-and-password registration, and KoeDash does not collect or store a Google password.

Google sign-in uses the openid, email, and profile scopes. When you sign in, we receive and store:

  • Google account ID
  • email address
  • name
  • Google profile picture URL
  • account creation, update, and last-login timestamps

Authentication information

KoeDash uses a session token to keep you signed in. On the website, that token is stored in an HTTP-only cookie named koedash_session. The extension stores the same kind of session in Chrome extension storage on your device.

The session is used to recognize your KoeDash account and to show account features, including saved subtitle sessions when that feature is enabled.

User preferences

The extension stores these settings on your device:

  • preferred speech-recognition language
  • subtitle display preferences, including theme and font size
  • reading and word-spacing preferences
  • translation and explanation language
  • AnkiConnect deck, model, and field names

Those settings stay on the device. A feature sends only the setting it needs: for example, the speech-recognition language when capture starts, or the explanation language when you scan a region or request an explanation.

Website and webpage content

KoeDash processes the content needed for the feature you start. It does not upload an entire webpage or the page HTML.

A dictionary lookup sends the word, the language, the dictionary key, and, when available, part of speech and reading. Results come from dictionary data hosted with the KoeDash backend: JMdict, CC-CEDICT, KENGDIC, WordNet, and CMUdict. That lookup is not sent to an AI service.

AI-powered features

Some features send a narrow piece of content to Google Gemini. What is sent depends on the feature.

Scan

When you draw a region on a page, the extension captures the visible tab, crops it to that region, and sends the cropped JPEG to the KoeDash backend. The backend sends that crop to Google Gemini to read the text and translate it.

The full screen, the rest of the webpage, and the page DOM are not sent. KoeDash does not save the crop in its database or as a file after the request finishes. The recognized text, word tokens, and translation stay in the card on the page until you close it.

Explain

Explain is a separate action from a dictionary click. When you request it for a subtitle word, KoeDash may send Google Gemini the selected word, one subtitle line of up to 800 characters, and dictionary meanings already returned for that word. The webpage and other subtitle lines are not sent.

Live subtitles

For a live subtitle, KoeDash may send one recognized phrase of up to 800 characters to Google Gemini to correct speech-recognition errors and, if you turn translation on, to translate that phrase. Audio is not sent to Gemini.

Speech recognition

Live subtitles use Deepgram. Audio from the tab you capture is streamed to the KoeDash backend and then to Deepgram for transcription. KoeDash does not save that audio as a file on its servers.

Third-party service providers

KoeDash uses these providers to run the product. Each provider also handles information under its own terms and privacy notices.

Google

Google provides sign-in through Google OAuth, and the paid Gemini API for scan, explanation, speech-recognition correction, and translation. Under Google's paid-service terms, prompts, images, and responses are not used to improve Google products. Google may log prompts and responses for up to 55 days to detect and prevent prohibited use and to meet legal or regulatory requirements. Content flagged by safety systems may be reviewed by authorized Google personnel.

Deepgram

Deepgram transcribes live audio for subtitles. The current integration does not set Deepgram's per-request Model Improvement Program opt-out. If the KoeDash Deepgram account participates in that program, Deepgram may retain a fraction of submitted data and use it to improve its voice models under the account's agreement with Deepgram. Deepgram states that it does not use that data for advertising profiles or redistribute it without permission.

MongoDB Atlas

MongoDB Atlas stores KoeDash accounts and, when signed-in subtitle saving is enabled, saved subtitle sessions.

Google Cloud Run

The KoeDash API runs on Google Cloud Run.

AnkiConnect

If you connect Anki, the extension talks to AnkiConnect on your computer at 127.0.0.1. Cards are not sent to KoeDash servers.

Saved subtitle sessions

When you are signed in and subtitle saving is enabled, a capture can be stored with your account. A saved session can include the subtitle text, the original speech-recognition text, word tokens, a translation, the tab title, and the page URL. Audio and scan images are not part of a saved session.

Saving is tied to a signed-in session. While sign-in is not required for capture, those captures are not written to the account database.

Cookies

The website uses cookies for sign-in. The extension does not use website cookies. KoeDash does not use advertising cookies.

  • koedash_session keeps you signed in and expires after 7 days
  • koedash_oauth_state is used during Google sign-in and expires after 10 minutes
  • koedash_oauth_next remembers where to return after Google sign-in and expires after 10 minutes

The two OAuth cookies are cleared when sign-in finishes.

Analytics and advertising

KoeDash does not use Google Analytics, PostHog, Umami, Vercel Analytics, Sentry, advertising trackers, or data brokers. It does not sell personal information or user content. It does not keep a separate counter of users, uses, or hours.

Server logs

The API writes operational metadata and error information to Google Cloud Logging. Current application logs do not intentionally include account email addresses, selected words, or subtitle text. Earlier application versions could log recognized subtitle lines and account email addresses.

The Google Cloud Logging bucket used by KoeDash has a 30-day retention period. Earlier content-bearing log entries can therefore remain until that period expires. Logs are used to run and debug the service, not to build advertising profiles.

Data retention

Account information and saved subtitle sessions stay while the account exists. Deleting the account through the account page removes the account record and its saved subtitle sessions from KoeDash's database.

Scan images and other AI inputs are not saved by KoeDash after the request that used them. Paid Gemini API inputs and responses may be logged by Google for up to 55 days for abuse monitoring. Deepgram retention and model-improvement use depend on the KoeDash account's participation terms, and the current integration does not request per-call opt-out. KoeDash operational logs are retained for 30 days.

Account deletion

A signed-in user can permanently delete their KoeDash account from the account page. The action requires confirmation and deletes the account record and all saved subtitle sessions and subtitle lines associated with it. It does not delete the user's Google account.

Information already sent to a service provider remains subject to that provider's terms. Operational log entries may remain until the infrastructure retention period expires. You may also request help with deletion by emailing koiiimap225@gmail.com.

Security

KoeDash uses ordinary technical measures to protect information, including encrypted connections where the browser, API, and providers support them. No method of storage or transmission is completely secure.

Children's privacy

KoeDash does not set a minimum age and is not directed at children. It does not ask for a date of birth. If you believe a child provided personal information in circumstances where it should not have been collected, email koiiimap225@gmail.com.

Changes to this policy

We will update this policy when KoeDash features, data practices, or legal requirements change. The new version will be posted on this page with a new "Last updated" date.

Contact

KoeDash is operated by Dmytro Dyshlyuk. For privacy questions or deletion help, email koiiimap225@gmail.com. Website: https://koedash.com.