Legal
Last updated September 13, 2026
Covers the Lichtung app for iOS and macOS, including its embedded Safari Web Extension (also named “Lichtung” within Safari; see “The Safari Extension” below), and this website, lichtung.xyz (see “This Website” below). If you use the Chrome or Firefox extension instead (“Web Reader for LingQ”), see its own Privacy Policy. See also Lichtung’s Terms of Use.
We (“we,” “our,” or “us”) are committed to protecting your privacy. This Privacy Policy explains how Lichtung (together with its embedded Safari Extension, “the App”) handles your information. The App is an unofficial companion to LingQ and is not affiliated with or endorsed by LingQ. LingQ is optional: languages you mark as local-only work entirely on-device with no LingQ account, API key, or LingQ network traffic at all. See “Local-Only Languages & Local Dictionaries” below.
The short version: reading and highlighting happen entirely on your device. Your LingQ API key and vocabulary go only to lingq.com, on your behalf, for languages you’ve connected to a LingQ account. We also use one privacy-first analytics service, TelemetryDeck, to see anonymous, aggregate feature usage: never who you are, never what you read. See “Product Analytics” below for the full detail.
For languages connected to LingQ, you provide your LingQ API key to the App. The key is stored in the Apple Keychain, shared only between the App and its Safari Extension’s native component: it is never exposed to the Safari Extension’s JavaScript at all. The key is sent only to lingq.com to authenticate your requests, is never logged, and is never sent anywhere else. Signing out removes it from your device.
For LingQ-connected languages, the App downloads your vocabulary (words, statuses, and translations) from your LingQ account and caches it locally on your device so that pages and books can be highlighted instantly and offline. When you tap a word to change its status or translation, that change is queued on your device and sent to lingq.com to update your LingQ account. Signing out deletes the local vocabulary cache for LingQ-connected languages.
A language you mark local-only never talks to LingQ: no sync, no card creation, no LingQ lookups, and no LingQ account or API key required for that language at all. Word definitions for a local-only language come from a StarDict-format dictionary you import (stored only in the App’s private storage on your device, never uploaded) or from definitions you type yourself. You can mix modes, a LingQ-connected language alongside a local-only one, and neither affects the other. A local-only language’s words are stored only on your device unless you explicitly export or back them up yourself (see “Backup Files” below).
To highlight words, the Safari Extension reads the text of the webpages you visit and matches it against your locally cached vocabulary. This happens entirely on your device. The content of the pages you read is never transmitted anywhere: not to us, not to LingQ, not to anyone.
The App includes a standalone ereader for EPUB, TXT, and MOBI files you import from your device. Imported books are stored only in the App’s private storage on your device, parsed and highlighted entirely locally the same way webpages are, and never uploaded anywhere. Word status changes you make while reading a book are queued and sent to lingq.com exactly as they are from the Safari Extension, for LingQ-connected languages; local-only languages behave the same way reading a book as they do on a webpage. Deleting a book from the in-app library removes it from your device.
The App can write a backup file covering every language you track (LingQ-connected and local-only alike), your local dictionaries reference, and your settings. A manual backup goes to a location you choose (for example, iCloud Drive, or anywhere the system’s file picker lets you save), created only when you explicitly ask for it. Pro also adds automatic backup: once daily, the App writes the same backup data on its own to your personal iCloud Drive, as one file per device, so multiple devices on the same iCloud account don’t overwrite each other. Either way, this stays entirely within services you already control, your own iCloud account, not ours, with nothing uploaded by the App itself to any server we operate.
Your preferences (selected language, translation language, sync interval, highlighting on/off, local-dictionary choices) and local diagnostic records (such as the offline write queue and a log of unexpected LingQ API responses) are stored on your device in the App’s private container and are never transmitted.
The App also keeps a more detailed, rolling log of the same kind of on-device diagnostic detail (sync, reader, and dictionary-lookup events) on by default, so that if you contact us about a problem we have real detail to work from right away instead of asking you to reproduce it a second time with logging turned on. This log is automatically capped and trimmed (oldest entries dropped first) so it never grows without bound, and it never includes your API key, vocabulary content, the word you looked up in a dictionary, or anything else beyond short event descriptions and counts. If the App crashes, it uses Apple’s MetricKit framework to record a one-line crash summary (the exception type, signal, and topmost frame symbol only, never arguments or other data) into this same log the next time the App launches, with no third-party crash-reporting service involved.
About → Contact Support’s “Export Diagnostic Log” action is the only way this data ever leaves your device: it opens the system share sheet with a plain-text summary for you to review and send yourself (for example, attaching it to a bug report), and nothing is sent anywhere automatically. That summary adds a short header (app version and build number, device model, OS version and locale, free disk space, your book and dictionary counts, reader appearance settings, and whether you’re on Free or Pro) and recent trace lines from the reader, sync, hint, and dictionary systems for your current session, on top of the log entries above. None of this adds your API key, vocabulary, or the content of any page or book to what’s exported.
The App uses TelemetryDeck, a privacy-first analytics service, to see anonymous, aggregate usage: which screens and features get opened, app version, OS version, and device model. Events carry no name, email, API key, vocabulary, or content from the pages and books you read. TelemetryDeck anonymizes its identifier on your device before anything is sent, uses no cookies, and keeps no persistent ID it could use to build a profile of you or link your usage back to a name, email, or LingQ account. TelemetryDeck is based and hosted in the EU; see TelemetryDeck’s own privacy policy for how they handle it on their end. The Safari Extension itself sends no analytics of its own; only the App does.
The Safari Extension embedded in this App appears in Safari’s own interface as “Lichtung”, the same name as the App, since a Safari user only ever sees one product. It shares the same code, the same on-device processing, and the same privacy behavior described throughout this policy (aside from Product Analytics, above); nothing about how it handles your data otherwise differs from the rest of the App. It is enabled and configured through the App’s own Settings, per the setup instructions there.
lichtung.xyz, the website you’re reading this on, is a separate, static site from the App. We run no analytics or tracking script on it, and it sets no cookies. It’s hosted on Cloudflare Workers, so Cloudflare sees the same request-level information (IP address, browser, timestamp) any host sees simply by serving pages; that’s ordinary web infrastructure, not something we collect or have access to ourselves. See Cloudflare’s privacy policy for how they handle it.
We do not:
For LingQ-connected languages, the App communicates exclusively with lingq.com: to validate your API key, download your vocabulary and language list, fetch community translations, and upload the word changes you make. These requests are made on your behalf using your API key, exactly as if you were using LingQ’s own website. Local-only languages generate no LingQ network traffic of any kind. Your use of LingQ is governed by LingQ’s own privacy policy and terms of service.
You can:
The App complies with applicable laws regarding children’s privacy. We do not knowingly collect any personal information from children, or from anyone else, since the App collects no personal information at all.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date.
If you have questions about this Privacy Policy, please contact us at josh@lichtung.xyz or through our contact page.