Privacy
The short version: your camera feed and the skeleton derived from it never leave the device you are using. The only thing that can ever be transmitted is recognised gloss text, only if you switch on the optional polish tier, and the app shows you the exact request body before you do.
What runs locally
Everything that touches your image:
- Camera capture. The browser grants the page a media stream after you allow it. Frames are read by a Web Worker in the same tab and are released as soon as landmarks have been extracted from them. No frame is stored, buffered to disk, or copied anywhere else.
- Pose and hand tracking. MediaPipe landmark models, downloaded to your device and executed there, turn each frame into 85 coordinates. Those coordinates stay in memory shared between two workers inside your tab.
- Sign recognition. The classifier is a quantised model file your browser downloaded and cached. Inference runs on WebAssembly on your CPU. It has no network dependency once cached — which is why the app keeps working with the network switched off.
- Sentence assembly (default tier). Turning glosses into readable sentences is done by rules that ship with the app. Zero network egress. This is the default and most people never change it.
- Your settings and practice stats. Stored in your browser's local storage. They are not uploaded unless you sign in and turn on progress sync, which is an optional, separate choice.
What the optional cloud tier sends
Recognition produces glosses: bare dictionary words in sign order. A language model can rewrite those into more fluent English. That rewrite is the only feature that transmits anything, it is off by default, and it takes two deliberate actions to arm — selecting the tier does not enable egress; a separate confirmation does.
The entire request body
{
"glosses": ["YESTERDAY", "I", "SCHOOL", "GO"],
"locale": "en-IN"
}That is the whole payload. No image, no landmark array, no audio, no device identifier, no account identifier. The settings screen renders this preview using the same function that builds the real request, so what you are shown is by construction what is sent.
Turn the tier off and the recognition experience is unchanged apart from the phrasing of the assembled sentence. Nothing else in the product depends on it.
Accounts, telemetry and analytics
- Signing in is optional and never gates recognition, practice or the benchmark. It exists so practice progress can follow you between devices, and that is all it is used for.
- Telemetry and analytics are off unless you switch them on in settings. When enabled they carry technical metrics only — frame rate, inference latency, model version, error types. Recognised glosses, sentences and anything derived from your camera are never included, and there is no session recording.
- Problem reports are something you send deliberately. If you file one, it includes the page you were on, recent console messages and — only if you tick the box — a screenshot. Review it before sending; nothing is collected in the background.
How to check any of this yourself
- Open the studio, open your browser's network panel, and sign. You will see the model and runtime downloads on first load, and after that nothing.
- Load the app once, then disconnect from the network entirely and reload. Recognition keeps working.
- Open settings and select the cloud tier without confirming it. The payload preview shows you the request body, and the privacy badge stays on “local” until you confirm.
Changes and questions
If the data behaviour ever changes, this page changes with it in the same commit — it is part of the application source, not a separately managed document. Questions and corrections go through the in-app “report a problem” action.