Tinta — Privacy Policy

Last updated: 26 September 2026

Tinta is a reading tool for language learners. This policy covers the macOS app and the web version at tintareader.com. Where the two differ, the section In a web browser says how.

The short version

What stays on your device

Your texts, the words you mark as known or learning, the dictionary entries you write, and your settings are stored on your Mac, in the app's own storage. They are not sent to us or to anyone else. Exports are written only where you choose to save them.

AI API keys are stored in the macOS Keychain. They are never written to the app's settings file or to a log, and the app has no way to show a saved key back to you.

Reading aloud uses the voices installed on your Mac. The text being read is not sent anywhere by the app.

What the app downloads

Dictionaries. The app checks for and downloads updated dictionaries ("language packs") from packs.tintareader.com, which is hosted by GitHub. These requests contain only which dictionary and version are being fetched. None of your text, vocabulary or settings is sent. As with any web request, GitHub can see your IP address; GitHub's privacy statement covers that: https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement

App updates — copies downloaded directly from us only. Those copies check github.com for a newer version of the app. The Mac App Store version gets its updates from the App Store and makes no such check.

The optional AI features

The app can ask an AI model to translate a sentence, gloss a word, pick which dictionary sense fits, or write a dictionary entry. This is off until you add an API key from one of these providers:

ProviderWhere your text goesTheir policy
Anthropic (Claude)api.anthropic.comhttps://www.anthropic.com/legal/privacy
OpenAIapi.openai.comhttps://openai.com/policies/privacy-policy/
Google (Gemini)generativelanguage.googleapis.comhttps://ai.google.dev/gemini-api/terms

Before the first request to a provider, the app asks you, says what will be sent, and links that provider's policy. If you decline, nothing is sent. You are asked once per provider, and you can withdraw your permission in Settings at any time. After that, nothing more is sent to that provider until you allow it again.

What is sent with each request is only what that question needs:

Nothing else from your texts, vocabulary or settings is sent.

How it is sent. Requests go directly from your Mac to the provider, using your API key. They do not pass through any server of ours, and we never see your text, your key or the provider's reply. Once the text reaches the provider, the provider's policy governs what happens to it, not this one. In particular, Google's free Gemini tier allows Google to use what is sent to improve its products, and people may read it. The app tells you this before you allow Gemini. Don't send anything private through a free-tier key.

Replies are stored on your Mac so the same question does not have to be asked twice.

In a web browser

The web version at tintareader.com works the same way, with these differences:

Children

The app does not knowingly collect information from anyone, including children. The AI features need an API key, which each provider issues under its own terms, including its own minimum age.

Changes

If this policy changes, the new version will be published at this address with a new date. A change that would send anything new off your device would also be asked for in the app before it happened.

Contact

Questions about this policy or your data: james.moult@gmail.com