Zenyola

Privacy policy

Test-period version. Zenyola is being tested with a closed group of invited people. It is free and nothing is charged. This text says what Zenyola does today, without yet naming a territory or a legal entity: those are settled before Zenyola is offered publicly, and announced here.

Last updated: 19 September 2026

Zenyola is a language-learning tool. It shows two subtitle tracks, synchronized, over a video you are already watching on a video platform you already have access to, so that you can learn a language from shows you enjoy. This policy explains what Zenyola collects, why, where it is kept, and what you can do about it. It is written to be read, not skimmed: it names every kind of data we collect and what each is for. Zenyola is growing, and its study features — lessons from an episode, cards, reviews, practice — need to know more about what you have watched and learned than the first version did. When a new kind of data appears, this policy names it before it is collected, and your account page shows you what is held about you.

During the test period, Zenyola is run by the people who build it ("we"), and support@zenyola.com reaches them directly. When Zenyola is offered publicly, this line will name who operates it and from where.

1. The short version

2. Who this applies to

This policy applies to the Zenyola browser extension, the website at zenyola.com and the account portal on it, and the service behind them. It does not apply to the video platforms the extension works with: they have their own policies, and Zenyola has no access to what they hold about you.

3. What the extension does on the platform's pages

The extension runs only on the pages of the video platforms it supports. On those pages it:

It does not read your platform profile, your watch history, your search or browsing on the platform, your payment details, or any cookie of the platform. It does not record, download or store the video or the audio.

4. What we collect, and why

Read this section as kinds of data and the purposes they serve, not as a frozen inventory. Within the purposes named here — running the service, making it work, knowing whether it is useful, and building your study material — the detail of what we collect will grow as the features do. A purpose we have not named is a change to this policy, announced as section 12 says, and anything that needs your permission asks for it.

4.1 Your account

When you register we collect your email address. It is your identity in Zenyola and where sign-in links are sent. We do not ask for a name, a password or anything else.

When you choose them, we keep the language you are learning and the language you read in, so the subtitles come up in the right pair. Until you choose, they are empty.

We keep the date your account was created, your plan (during the test period every account is on the free plan) and your role (member, or operator for the people who run the service).

4.2 Sessions

When you sign in, the service issues a session token that the extension stores in the browser's extension storage, out of reach of any web page, and sends to our service with each request. We keep a one-way digest of that token, when it was issued, when it expires, and when it was last used, so that we can recognise your extension and let you sign out or revoke a session. The token itself is never stored on our side.

4.3 Usage events

The extension sends typed events so that we know whether Zenyola works, how much it is used, and which parts are worth building. Each event is one of a fixed list, never free text, and the list grows as the service does; what is on it today is:

In these events a title is identified only by a one-way hash, a code that we cannot turn back into a title name. Events never carry a page address or subtitle text. From the minutes and episodes we keep a usage count per month for your account.

We use these events to keep the service working, to measure whether it is useful, to decide what to build next and which titles to analyse first, and to protect the service from abuse. If your learning history is on (section 4.9), the same events also feed your study material, and then a title is named as well as hashed, because a lesson has to say which episode it is about.

4.4 The learning library

When you watch an episode with Zenyola, the two subtitle tracks the platform served to your browser are sent to our service and kept in a library: the text of each line and its timing, its language, the kind of track (subtitles or captions), the platform's identifier for the title, the name of the series and of the episode as the player shows them, the season and episode number when the platform gives them, and a code computed from the content itself. The name and the numbers are facts about the title, kept so that study material can say which episode it is about; they carry no reference to any person. Each track is stored once for everyone: if someone has already watched the same episode, nothing new is stored.

The library carries no reference to who watched what. A track is not linked to your account, and deleting your account leaves the library exactly as it was, because there is nothing of yours in it. We keep, per title and language, a count of how often it is watched, so that we can decide which titles to analyse first.

The library exists for one purpose: to align and, later, to analyse the language of the dialogue, so that the text a viewer sees is enriched with explanations. It contains text and timings, never video, audio or images, and it is served only to a viewer who is watching that very episode on the platform. See the terms of use for how rights holders can ask for a title to be withdrawn.

4.5 Problem reports

If you report a problem from the extension, the report is prefilled with the extension version, the build, the platform adapter in use, the last technical failure, and the title's hash. You see the whole report before sending it, and it goes to us by email. It never names what you were watching.

4.6 The website

The registration page uses Cloudflare Turnstile to tell people from automated scripts; Turnstile may set a cookie of its own for that purpose and is governed by Cloudflare's policy. Signing in to the portal sets a session cookie that lasts as long as your session. We use no analytics cookies and no advertising cookies.

4.7 What the extension keeps in your browser

In the browser's extension storage, on your device only, the extension keeps: your session; a cached copy of the remote configuration it reads from us; a cache of aligned subtitle pairs for the episodes you watched recently, so that they come up faster next time; and the position of the on/off switch. Removing the extension removes all of it.

4.8 The remote configuration

At start, and every few minutes, the extension reads a small configuration document from us that says which platform adapters are switched on and which extension version is the minimum supported. That read carries your session and nothing else; it is how we can switch the extension off for everyone within minutes if a platform changes its player.

4.9 Your learning history, only if you switch it on

Zenyola's study features — a short session after an episode, cards with the line where a word appeared, reviews that come back in the next episode of the same series, and later the practice of saying a line aloud — need to know what you have watched and learned. That knowledge is your learning history. It is off by default; nothing in this section is kept until you switch it on from your account page, and switching it off deletes it.

When it is on, we keep for your account what you do with the study features. Today that is:

As the study features grow — new kinds of exercise, new ways of reviewing — what they record grows with them, always inside this purpose: to build your study material, to know whether it is teaching you anything, and to make it better. A purpose beyond that is a change to this policy and asks for your permission first.

Models and your data. We do not train models on your personal data. Models are used to analyse the dialogue of a title once, for everyone, and to generate study material from that analysis; they never learn from a person. If we ever wanted to train on anything of yours, we would ask you first, in plain words, and you could say no and keep using Zenyola. Section 4.10 says what we do with data that no longer names anyone.

Your learning history is shown to you, exportable in a standard format, and deleted with your account or on its own from the account page.

4.10 Improving Zenyola, and data that no longer names you

To make the teaching better we look at what works across everyone: which explanations are read, which concepts most people get wrong, which episodes are too hard for the level they claim. That work is done on aggregated or de-identified data — counts and patterns with no account behind them, which we cannot turn back into a person. Data in that state is not personal data, we may keep and use it without the limits of this policy, including to build and improve the analysis, the lessons and the exercises, and to say publicly how the service is used.

Everything before that state — your account, your events, your learning history — stays under the rest of this policy, and the controls in section 9 apply to it in full.

5. What we do not collect

Some things we will not collect, whatever we build. We do not collect your platform credentials, the video or audio of anything you watch, the pages you visit outside the platform's pages, or precise location. We never read your watch history on the platform: the only titles we can know about are the ones you watch with Zenyola on. We do not use fingerprinting, and we carry no advertising or third-party tracking networks — what we measure, we measure ourselves, with the typed events of section 4.3.

And two promises that are not about collection at all, because they are the ones that matter: we do not sell your data, and we do not show you advertising. If a payment plan arrives, payment details will be handled by the payment provider and named here before it does.

6. What permission we process your data on

Everything rests on your permission, given in the knowledge of what this policy says and withdrawable whenever you like. That is deliberate: explicit permission is the most demanding thing any data-protection regime can ask for, so a text written on it holds wherever you live, without having to pick a country.

The learning library holds no personal data, and neither does aggregated or de-identified data (section 4.10).

If a data-protection regime applies where you live, you also have every right that regime gives you. This policy does not attempt to cut any of them down.

7. Who processes data for us

Our service runs on Cloudflare: the application, the database, the storage of the library, the sending of sign-in emails and the Turnstile challenge. Cloudflare processes data on our behalf and under its own privacy commitments. We may add a processor when a feature needs one — a payment provider, a speech or language model service for the study features — and each one is bound by a contract to use the data only for what we ask; the list here names them before they start. We do not share personal data with anyone else, we do not sell it, and we hand it over to an authority only when the law requires it.

Cloudflare operates a global network, so your data may be processed in a country other than yours. Every processor is bound by contract to use the data only for what we ask, and accepting this policy is your permission for that processing outside your own country.

8. How long we keep things

9. Your rights and how to use them

From your account page you can see what we hold about you, export it, sign out everywhere, and delete your account. Deleting your account removes your email, your languages, your sessions, your usage counts, your usage events and your learning history, at once and without asking why. What remains afterwards is nothing that refers to you.

You also have the right to know what we hold about you, to correct it, to ask us to delete it, to be told what use we make of it, and to withdraw your permission — none of which you have to justify.

How to use them. Write to support@zenyola.com from your account's email address, or from another one saying which account it is. That mailbox is attended by whoever builds Zenyola. We commit to answering you within fifteen days, and to telling you why if we ever need longer.

If there is a data-protection authority where you live, you can go to it, and you have whatever rights your regime recognises, including access, correction, deletion, restriction, portability and objection.

10. Security

Everything travels over HTTPS. Session tokens and sign-in codes are stored only as one-way digests. Secrets are kept outside the code and the repository. The extension sends your session to our service and to no other address.

11. Children

Zenyola is not directed at anyone under eighteen, nor at anyone below the age of majority where they live if it is higher there, and we do not knowingly hold an account for one. If you believe a child has registered, write to us and we will delete the account.

12. Changes

When this policy changes, the date at the top changes, and a change that affects what we collect or why is announced in the extension before it applies. Continuing to use Zenyola after that means you accept the new version.

13. Contact

support@zenyola.com. During the test period that mailbox is the only channel, and it is attended by whoever builds Zenyola.

When Zenyola is offered publicly, this section will name who operates it, with its address and whatever else the regime that applies by then requires.