Privacy Policy
Nagashi LLC, a Nevada limited liability company, is the data controller for personal information collected through AllWord (allword.app). References to “we,” “us,” or “our” in this policy mean Nagashi LLC. AllWord is built so that there is very little to say here. We do not store what you write, and we set no tracking cookies. Two things are recorded by us: a short-lived counter that stops the service being abused, and anonymous page-view statistics. A third stays on your own device, where we cannot see it: the app itself, and anything you choose to keep. This page describes exactly what each one is.
Last updated: August 24, 2026
AllWord is owned and operated by Nagashi LLC, a Nevada limited liability company.
This page is translated for your convenience. If a translation and the English version disagree, the English version governs.
What we collect
Nothing that identifies you, unless you choose to sign in. Reading passages, browsing the canons and keeping a journal never ask who you are. Signing in is optional and exists only so a contribution can reach the right person: it gives us the email address you sign in with, held by our sign-in provider, and, if you contribute, a record that you did.
What you write in the message box is sent onward to choose your passages, as described below, and is not written to any database or log we control.
What happens to what you write
Before anything is sent, your own browser checks what you wrote for signs of crisis. If it finds them you are shown help instead of passages, and the message is not sent anywhere at all: not to us, and not to Google.
Otherwise your message is sent to Google's Gemini API, which reads it and returns references, for example a book, chapter and verse. Google processes it under its own terms as a provider to us.
The sources that supply the actual text (the Free Use Bible API, SuttaCentral and Wikisource) receive only the reference. They never receive your message.
Your message is not written to a log, an error report or an analytics event. This is enforced in the code rather than left to convention.
Rate limiting, and what it stores
To stop a single visitor exhausting the service, we count requests in a short window. What is stored is a SHA-256 hash of your IP address (never the address itself), together with a count and a timestamp. Nothing else: no message, no result, no locale.
Hashing is not the same as anonymity, and we would rather say so: the range of possible addresses is small enough that a determined party could work backwards from a hash. That is why these rows are deleted automatically by a scheduled job once their window has passed, rather than kept.
Cookies, analytics and tracking
We set one cookie for everyone and it does not track you: it remembers the language you chose, so coming back does not put you into English again. Signing in sets a few more, which are what keep you signed in; they come from our sign-in provider and go when you sign out. We embed no advertising or cross-site trackers. The typeface is served from this site rather than a font network, so loading a page does not tell a font network you were here.
We do count page views, using Vercel Web Analytics, run by the company that already hosts this site. It sets no cookies and identifies nobody: a visitor is a hash of the incoming request, discarded after 24 hours, and Vercel states the records are not tied to any individual or IP address. Recorded with each view are the page address, the site you arrived from, an approximate location, and your browser, operating system and device type. What you write is never part of it.
One more thing is counted, and only for visits that arrive from an AI search engine. When you reach this site from ChatGPT, Copilot, Bing, Perplexity or DuckDuckGo, we record which of them sent you and which page you landed on. Nothing else: no address, no device, nothing joining it to anything else you did, and never a word of what you write. Arriving any other way, or with a Global Privacy Control signal set, records nothing at all.
What stays on your device
Two things are kept by your browser, on your device, and never sent to us. The first is the app itself: pages you have opened, with the fonts, images and code needed to show them again, so it still opens when you have no connection. The second is your journal, if you use it: the passages you chose to keep, and, only when you tick the box as you save, what you wrote alongside them.
We never receive either one, which is the same reason we cannot restore either one. Clearing your browser data or uninstalling the app erases both. That is why the journal has a button to export everything and a button to erase everything.
When you send us a question or a correction
If you use the questions and corrections form, we keep what you wrote, which page you were on and in which language, so a correction can be acted on. If you give an email address it is stored only so we can reply to you, and it is never added to any list or used for anything else.
Before it is sent, your own browser checks what you wrote for signs of crisis, exactly as it does for a message. If it finds them you are shown help and nothing is sent to us. We store no IP address and no device information with your message.
Retention
The rate-limit counters described above are deleted automatically once their window has passed. Page-view statistics are held by Vercel in aggregate, and the 24-hour visitor hash is discarded on that schedule. From an anonymous visit we retain nothing else: there is no message and no result of yours on our side to keep, export or delete. If you have signed in, we keep your account and, if you have contributed, a record of that contribution, for as long as the account exists. Whatever your browser has kept on your device stays there until you clear it, and only you can do that.
Links to other sites
Passages link out to the edition they came from: Wikisource, SuttaCentral, eBible or Project Gutenberg. Those sites have their own privacy practices, and we do not control them.
Children
This service is not directed at children under 13, and we do not knowingly collect personal information from anyone. Reading needs no account, so nothing in the core experience is tied to anyone's identity. Signing in and contributing are for adults only.
Your rights
Rights of access, correction, deletion and portability apply to information a company holds about you. Without an account, the only things we hold are the hashed rate-limit counter described above, which deletes itself, and aggregate page-view statistics: neither is linked to a name, an email address or an account, and neither can be traced back to you in order to be shown or deleted. If you have signed in, we also hold your account and any record of a contribution, and these rights do apply to those: write to us and we will show or delete them. You can also delete your account yourself at any time, from the journal page. Your journal is not covered by these rights, because it is not ours to show or delete: it is on your device, and the journal page can export or erase it at any moment without asking us. If you believe otherwise, or want to ask how any of this works, write to us at the address below.
If this changes
Several additions are planned, and this policy will be updated to describe each one before it is switched on, not after.
Planned: a single two-button question asking whether a reading helped, recorded as a count with no text and nothing linking it to you; optional reminders, which would need your permission and an address held by your browser's push service; and an optional encrypted backup that could carry your journal between your own devices, encrypted on the device so that we could not read it.