听读ICU · TingduICU

听读ICU

隐私政策

生效日期:2026 年 10 月 4 日

本页先是中文版,后面是内容相同的英文版(English version)。

1. 我们是谁

听读ICU(英文名 TingduICU,网址 https://tingdu.icu)是一个网页版的英语听力练习工具。它由一位个人开发者运营(下称「听读ICU 运营者」或「我们」),没有成立公司,运营者在美国。

本政策说明你使用听读ICU 网站和服务时,我们收集哪些信息、怎么用、存在哪里、保存多久,以及你可以怎样查询和删除。

2. 要点

  • 你的视频文件只在你自己的电脑或手机上播放,不会上传到我们的服务器。
  • 为了翻译,网页会把视频里的英文字幕文字和从文件名整理出的片名发到我们的服务器,由服务器交给 OpenAI 翻译成中文。字幕和译文按内容全站共用(见 3.5)。
  • 跟读时,每读一遍的录音都会经我们的服务器发给 OpenAI 识别成文字;服务器不保存录音,只保存识别出的文字、分数和没读准的词。用来回放的录音和排对时剪下的几秒原声只存在你这台设备的浏览器里(见 3.8、3.9)。
  • 登录需要手机号和短信验证码。我们只发验证码短信,不发营销短信。
  • 我们不出售、不出租你的个人信息;你的手机号和短信同意(opt-in)信息不会提供给任何第三方用于营销。
  • 目前网页上没有「删除账号」按钮;要删除账号和数据,请发邮件到 80youth@gmail.com。

3. 我们收集哪些信息

3.1 手机号和登录信息

  • 手机号:你登录时填写的手机号。目前只支持中国大陆和美国 / 加拿大的手机号(美国含波多黎各等美国属地);同用 +1 国家码的加勒比等其他国家 / 地区的号码、免费 / 收费号码暂不支持。手机号就是你的账号。
  • 账号 ID:服务器为每个手机号生成的随机编号,学习记录按这个编号保存。
  • 账号时间:账号创建时间、最近一次登录时间。
  • 时区:第一次登录时从浏览器读取,用来决定你的「今天」从什么时候开始;可以在学习设置里修改。
  • 登录令牌:登录成功后发给浏览器的一串随机字符,用来保持登录。浏览器每次请求都会带上令牌,服务器据此认出你。服务器上保存令牌和它对应的手机号、创建时间、最近使用时间,以及这次登录是否经过短信验证。
  • 验证码发送记录:每次获取验证码时,我们记下手机号、请求来源的 IP 地址、时间、用途(登录 / 清除家长口令)和结果;输错验证码也会记一笔(这一笔不记 IP)。这些记录只用来防止滥用、限制发送次数。
  • 验证码:一次性使用,10 分钟内有效,用过或过期即作废,只用于这一次登录或清除口令。中国大陆号码和美国 / 加拿大号码的验证码可能由我们的服务器随机生成(中国大陆号码交给 Spug 推送助手发送,美国 / 加拿大号码用我们自己的美国号码经 Twilio 发送,见第 6、7 节):这时服务器只保存验证码经加密钥哈希(HMAC-SHA256)后的结果,不保存验证码本身;每个验证码最多核对 5 次,重新获取后旧的作废,这条哈希记录 2 天后删除。其他情况由 Twilio 的验证服务(Twilio Verify)生成和核对验证码,我们不保存。验证码不写进日志。
  • 短信同意记录:登录卡片的「获取验证码」按钮、学习设置里「忘记口令?」的「发验证码」按钮正下方都写着短信同意说明,点按钮即表示同意。每次成功给你发出验证码时,我们记下:手机号、用途(登录 / 清除家长口令)、当时页面上同意说明的版本号、在这一版下第一次和最近一次发码的时间、请求来源 IP 的网段(只保留截短后的部分:IPv4 只留前 3 段,例如 203.0.113.0/24;IPv6 只留前 48 位;不保存完整 IP)、一共发了几次。这份记录只用来证明你同意过接收验证码短信,保留到账号删除(见第 8 节)。

3.2 学习记录

在「排序」练习中每计一句分,服务器保存一条记录:时间和日期、字幕指纹和句子序号、句子原文、片名、片段起止时间、句子难度等级、得分、使用提示的次数、用时、循环次数等。此外还保存:每天的目标与达标情况(例如达标的时间);「最近在播」——你最近打开过哪份字幕、在什么时间,每人每份字幕一条,用来校验计分,也用来统计每份字幕有多少人打开过(运营者只看到人数)。

在「跟读」练习中,服务器保存:每天抽到的句子(从你排对过的句子里挑,含句子原文、字幕指纹和序号、片名);每读一遍的识别文字(最多 200 字)、分数、没读准的词、合格与否,和这一遍录音的时长、大小、音量(用来判断是不是没录到声音),以及这一遍的录音格式、录音窗口(这一遍最长能录多久)、识别用了多久、这台设备上有没有这句的原声、出错时的说明(例如识别超时);以及换句、系统跳过的记录。录音本身不保存(见 3.9)。在「每日单词」中,服务器保存:每天出的词和题目、每道题的作答(选的哪一项、对错、是否超时、用时、听了几遍)、每个词的熟练程度和下次复习的日期;题目里带的整句记有出处(字幕指纹、第几句、片名)。

3.3 学习设置

每日目标、未达标锁、循环时间、字幕显示偏好、难度筛选、难度档(小学 / 中学 / 高中 / 大学)、跟读的设置(每天几句、合格线、连着几次没过就给「换一句」、录音时长)、每日单词的设置(每天几个词、每题限时)、时区。每日目标、未达标锁,以及跟读、每日单词每天的量,按「从哪天起是多少」保存,历次修改都会留着,用来正确判断过去每一天有没有达标、那天该做多少。家长口令只保存经过加盐哈希(scrypt)处理后的结果,不保存口令原文;如果口令被清除过,会记下最近一次清除的时间和方式(短信验证码 / 运营者清除),这条记录留在设置里,界面上只显示 30 天。

3.4 生词本和查词记录

  • 生词本:你亲手加入的单词(原形和你点的词形)、加入日期、出处(字幕指纹、第几句、句子原文、片名、时间点)。把单词移出生词本时只做「已移出」标记,这一行仍会保留,以便以后认出「以前加过的词」。
  • 查词记录:登录状态下查过的单词都会记录(看视频时查的,以及在生词本页面点词查的),包括查询时间、在哪个页面查的和出处(字幕指纹、第几句)。没登录时查词不记录。查词记录保留 90 天。生词本页面能看到看视频时查过的词(按单词汇总,显示次数和最近一次查的日期);那里的「一键清空」会删掉你的全部查词记录。

3.5 字幕文字、片名和时长

打开视频时,网页在你的电脑或手机上读取视频里内嵌的字幕,先把按字幕内容算出的「指纹」发给服务器,问有没有现成的译文;服务器上还没有这份字幕时,再发送:整理成句子的字幕文字、每句的时长和片名。视频本身不会发送。

片名是网页从文件名(或视频文件里写的标题)整理出来的,例如剧名、年份、季、集、集名;认不出这些时,片名就是去掉扩展名、方括号和画质标记之后的文件名。如果文件名里有你不想让别人看到的内容,请先改名再打开。

服务器按指纹保存字幕原文、片名、每句时长、AI 生成的译文、注释、术语表和每句难度。同一份字幕全站只翻译一次、共用一份:其他用户打开内容相同的字幕时,会直接看到已有的译文,也可能在生词本的「出处」里看到第一位上传者那里整理出的片名。这份缓存里记有第一个上传它的账号的手机号(用于用量统计和费用控制),只有运营者能看到,不会展示给其他用户。我们还记录每份字幕被打开的次数和最后打开时间(只记数字;用来判断「同一个人同一天只算一次」的标记约 2 天后删除)。

3.6 使用量统计

按手机号记录每天的使用量:调用 AI 的次数和用量(token 数)、翻译的句数、直接从缓存拿到的句数、新上传的字幕数等,以及最近一次使用时间。用来控制成本、执行每日上限。

3.7 访问日志、运行日志和网站统计

  • 访问日志:服务器记录访问日志(IP 地址、访问时间、访问的网址、浏览器类型等),用于运维、排查故障和统计访问量。查词时,查的单词和字幕指纹写在网址里,所以也会出现在访问日志中。
  • 运行日志:后端程序记录运行情况和错误。日志里的手机号一律打码(例如 138****8000),不记录验证码和密钥;但可能包含账号 ID、字幕指纹、片名、句子开头的片段、加入生词本的单词、查词出错时的单词、学习设置改了哪几项和新的值、家长口令输错第几次等,用来排查问题。
  • 网站统计:我们用 Umami 统计网站访问情况。Umami 部署在我们自己的服务器上,不是第三方统计服务。按它的默认设置,它记录:访问的网址(含网址里的参数)和页面标题、来源网址、浏览器、操作系统、设备类型、屏幕尺寸、浏览器语言,以及由 IP 地址推算的大致位置(国家、省州、城市)。它不使用 Cookie,也不和你的账号关联。

3.8 存在你浏览器里的数据

下面这些存在你这台电脑或手机的这个浏览器里(localStorage、sessionStorage、IndexedDB):

  • 登录令牌和手机号:用来保持登录。浏览器每次请求都会把令牌发给服务器,服务器上也存着一份(见 3.1)。退出登录时清除本机的这份,并通知服务器作废。

下面这些只留在你的浏览器里,不会发给我们:

  • 界面和播放偏好(显示方式、布局、播放设置、字幕显示偏好、浮窗位置、登录时选的地区、今日进度的缓存、跟读识别暂时用不了的标记(带账号手机号和日期,只留在这个标签页里,关掉就没了)、是否来过本站);
  • 播放记录:最近打开过的视频(最多 40 个)的文件名、大小、修改时间、文件类型、最近打开的时间、播放进度、时长、缩略图、选用的字幕轨,以及浏览器提供的文件句柄(让你下次点一下就能重新打开同一个本地文件);
  • 跟读的原声片段:排对一句时,网页在你的设备上从你自己的视频里剪下这句的几秒声音,存进浏览器,给跟读的「原声」「慢速」用,不上传。换了设备、清了浏览器数据就没有了(跟读改用 AI 读)。

另外,你自己的跟读录音每句留最近读的那一遍在浏览器里,给「听我的」「对比听」回放用,第二天作废。这一份不上传;识别时发出去的那一份见 3.9。

你可以在浏览器设置里清除本网站的数据来删除它们。我们不使用 Cookie。

3.9 跟读录音和发音

  • 跟读录音:每读一遍,网页把这一遍录音发到我们的服务器,服务器交给 OpenAI 的语音识别,拿回识别出的文字后打分。服务器不保存录音,也不写进日志;只保存识别出的文字、分数和没读准的词(见 3.2)。
  • 单词和整句的发音(查词卡、生词本、每日单词里的发音,跟读的「AI 读」):由我们的服务器调用 OpenAI 的语音合成生成,按内容全站共用缓存——同一个词、同一句只生成一次,存在服务器上,谁听都是同一份。发给 OpenAI 的只有这个词或这句话的文字,不带你的手机号或账号。某个词的发音还没生成好时,查词卡和生词本会暂时用浏览器自带的朗读功能代替;部分浏览器的朗读会用到浏览器厂商的在线语音服务,这由浏览器厂商按它们自己的政策处理,我们不经手。

4. 我们不收集什么

  • 视频文件本身(画面和声音)不上传,只在你的电脑或手机上播放。
  • 不读取你电脑或手机里的其他文件,只读取你主动拖进来或选择的视频。
  • 不要求姓名、身份证件号码、住址、通讯录或精确位置;不收集支付信息(服务目前不收费)。
  • 不放广告,不使用第三方广告或跟踪工具。

5. 我们怎么使用这些信息

  • 登录和保持登录,确认账号属于持有这个手机号的人;
  • 保存和同步你的学习进度、设置和生词本:换一台电脑或手机,用同一个手机号登录,数据都在;
  • 翻译字幕、生成注释、判断句子难度、计分,识别跟读录音并打分,生成单词和整句的发音,执行每日目标和未达标锁;
  • 防止滥用:限制验证码的发送频率和次数、限制每天的翻译量、控制费用;
  • 记录短信同意,证明你同意过接收验证码短信;
  • 排查故障、维护安全、改进功能、了解网站访问量。

我们不出售你的个人信息,不把它用于广告,也不做营销用的用户画像。

6. 短信(SMS)

  • 我们只发两种短信:登录验证码,以及「忘记家长口令」时用来清除口令的验证码。两种都只在你(或你的家人)在网页上点「获取验证码」/「发验证码」后才发送。按需发送(Message frequency varies):每次请求发一条,不请求就不会收到。
  • 我们不发送营销或推广短信。
  • 发给美国 / 加拿大号码的短信由 Twilio 代我们发送(中国大陆号码见下一条)。我们用自己的美国号码发给美国 / 加拿大号码的验证码短信是英文的,开头写明 TingduICU,例如:「TingduICU: Your login code is 123456. It expires in 10 minutes. Reply STOP to opt out.」经 Twilio 验证服务发送的验证码短信用 Twilio 验证服务的标准短信模板。
  • 中国大陆号码的验证码短信由合作平台 Spug 推送助手(push.spug.cc,时巴克公司,中国)代我们发送,用平台的固定模板,例如:「您的验证码是123456,10分钟内有效,如非本人操作请忽略。」短信签名是平台的,内容里没有「听读ICU」字样;这类短信不能回复。
  • 可能产生短信和流量费用(Message and data rates may apply),具体以你的运营商为准。
  • 美国 / 加拿大号码:回复 STOP 可退订,回复 HELP 获取帮助。退订后,发验证码的那个号码就不能再给你发短信:你将收不到验证码,无法用短信登录,也无法用短信清除家长口令(网页上会提示这个号码已退订)。用这部手机给发验证码的号码回复 START(或 UNSTOP)即可恢复接收。
  • 中国大陆号码:短信由平台代发、不能回复,STOP / HELP 只适用于美国 / 加拿大号码。不想再收到短信,不再点「获取验证码」/「发验证码」即可(每条短信都是点了按钮才发的);需要帮助请发邮件到 80youth@gmail.com。
  • 运营商不对短信延迟或未送达负责。
  • 我们不会出售或分享你的短信同意(opt-in)数据或个人信息给第三方用于营销。你的手机号和短信同意数据不会出售、出租或分享给任何第三方、关联方或出售销售线索的中介(lead generators)用于营销或推广。

7. 我们与谁共享信息

我们只把完成服务所必需的信息交给以下服务商,它们按各自的条款和隐私政策处理这些数据:

  • Twilio Inc.(美国):发送短信验证码。Twilio 会收到你的手机号和短信内容(包括验证码本身);用 Twilio 验证服务时,验证码也由 Twilio 生成和核对。
  • Spug 推送助手(时巴克公司,中国):给中国大陆手机号发送验证码短信。Spug 会收到你的手机号和验证码(验证码由我们的服务器生成和核对,Spug 只负责发送)。
  • OpenAI(美国):翻译字幕、生成注释和术语表、判断句子难度、恢复全大写台词的大小写、解析句子、给每日单词标出句子里的词;识别跟读录音;合成单词和整句的发音。收到字幕句子文字和片名、你每一遍跟读的录音、要念的词或句子的文字。我们不向 OpenAI 发送你的手机号、账号 ID 或其他用来识别你身份的信息;但请注意,片名是从文件名整理出来的(见 3.5),录音里是你自己的声音(见 3.9)。
  • 腾讯云(Tencent Cloud):提供我们租用的服务器,位于日本东京。服务器端的所有数据——数据库、字幕缓存、日志、网站统计和备份——都存放在这台服务器上。

此外,只有在法律要求时(例如收到有效的法律文书),我们才可能提供相关信息。

以上各类共享都不包括短信发送方的 opt-in(同意接收短信)数据和同意信息;这些信息不会分享给任何第三方。

8. 保存多久

数据保存多久
账号(手机号、账号 ID、时区)、学习记录(含每日达标和「最近在播」)、学习设置(含修改历史)、生词本(含已移出的词)、使用量统计账号存在期间一直保存,直到你要求删除
登录令牌退出登录时通知服务器作废;超过 180 天没用的会被删除;每个手机号最多保留 10 个,超出时删掉最久没用的。如果退出时网络不通、服务器没收到通知,那个令牌要等 180 天没用后才删除
验证码发送记录(手机号、IP、时间)2 天后删除
由我们生成的验证码的哈希10 分钟后失效,2 天后删除
短信同意记录(手机号、用途、同意说明的版本、第一次和最近一次发码的时间、IP 网段、发送次数)账号存在期间一直保存,删除账号时一起删除
查词记录90 天后删除;可随时一键清空
字幕「今天是否打开过」的标记约 2 天后删除
字幕文字、片名、译文、注释、难度(全站共用缓存)长期保存,目前没有自动清理(运营者可以手动删除某一份);删除账号时去掉其中记录的你的手机号
跟读录音不保存:识别完就丢掉(服务器只留识别出的文字、分数和没读准的词,算在学习记录里)
单词和整句的发音(全站共用缓存,不记是谁要的)长期保存,目前没有自动清理
访问日志、运行日志按服务器的日志设置自动轮换删除;目前没有设定固定的保存天数
网站统计(Umami)不含账号信息,可能长期保存

表里的「X 天后删除」由服务器在运行中顺带清理(例如有人登录、获取验证码或查词时),不是到点立即删除;网站没人使用的时候,过期的数据可能会多留一些时间。

备份:服务器每天凌晨 4:30(东京时间)把数据库、登录和用量文件、字幕缓存备份到同一台服务器上。每份备份保留约 15 天后自动删除,所以已经删除的数据,最多还会在备份里保留约 15 天。

9. 儿童与家长

听读ICU 面向所有学英语的人,孩子也能用。孩子使用时:

  • 账号应当由家长(或其他监护人)持有,并用家长的手机号登录,验证码短信发到家长的手机上;孩子在家长同意下使用。登录卡片上也会提示用家长的手机号。
  • 跟读要录孩子的声音:每一遍录音只用来识别读得准不准,识别完不保存(见 3.9)。
  • 孩子用家长的账号练习时,练习记录、生词本、查词记录会保存在这个账号下。家长可以在网页上看到今日进度、生词本和看视频时查过的词;逐句的练习记录目前网页上看不到,可以发邮件索取。家长也可以随时发邮件要求删除。
  • 我们不要求孩子提供姓名、年龄、学校等信息。
  • 如果你发现孩子在没有家长同意的情况下用自己的手机号登录了,请联系我们,我们会删除这个账号的数据。

10. 你的权利

  • 查看:学习设置、今日进度、生词本和看视频时查过的词,可以在网页上直接看到。逐句的练习记录、账号信息、使用量等其他数据,目前网页上看不到,可以发邮件索取副本。
  • 更正:学习设置可以自己修改。更换手机号等其他更正,请发邮件联系我们。
  • 删除:查词记录可以随时一键清空,单词可以随时移出生词本。删除整个账号:目前网页上没有自助删除按钮,请发邮件到 80youth@gmail.com,写明要删除的手机号。核实你是这个号码的使用者后,我们会删除账号、登录令牌、学习记录(含每日达标和「最近在播」)、学习设置、生词本、查词记录、使用量统计、验证码发送记录和短信同意记录,并去掉字幕缓存里记录的你的手机号。备份里的副本会随备份轮换删除,最多约 15 天。
  • 撤回短信同意:不再请求验证码,就不会再收到短信;美国 / 加拿大号码也可以回复 STOP(退订后收不到验证码,回复 START 可恢复,见第 6 节)。中国大陆号码的短信由平台代发,不能回复 STOP。
  • 退出登录:头像菜单里的「退出登录」会清除本机的令牌,并通知服务器作废它(如果当时网络不通,服务器上的令牌会在 180 天没用后删除)。

我们会尽快答复,一般在 30 天内。

11. 安全措施

  • 浏览器和网站之间使用 HTTPS 加密连接。
  • 验证码限流。目前的规则是:同一号码 120 秒内只能获取一次;24 小时内同一号码最多 5 次、同一 IP 最多 20 次,全站每天也有上限;每个验证码最多核对 5 次;同一号码一小时内输错 10 次会暂停验证。
  • 由我们服务器生成的验证码只保存加密钥的哈希,不保存验证码本身。
  • 家长口令只保存加盐哈希;连续输错 5 次锁定 15 分钟。
  • 日志里的手机号打码,不记录验证码和密钥。
  • 服务器上的数据目录和密钥文件设置了访问权限,只有运行服务的系统账号和服务器管理员能读取。
  • 调用第三方服务用的密钥只保存在服务器上,不会发到浏览器。

没有任何系统能保证绝对安全。登录令牌保存在浏览器里,在共用的电脑或手机上用完请退出登录。如果发生可能影响你的数据的安全事件,我们会在网站上说明情况。

12. 数据存放地点与跨境传输

  • 我们的服务器位于日本东京(腾讯云)。无论你在中国大陆、美国还是其他地方使用,服务器端的数据都存放在日本。
  • 翻译、解析句子、给每日单词标出句子里的词、识别跟读录音、生成发音时,字幕文字、片名、跟读录音和要念的文字会传给美国的 OpenAI 处理;短信验证码经美国的 Twilio 发送,发给中国大陆号码的经中国的 Spug 推送助手(时巴克公司)发送——这时你的手机号和验证码会传到中国境内。
  • 运营者在美国,维护服务器时会从美国远程访问。

使用本服务,即表示你了解你的信息会在上述国家和地区之间传输和处理。如果你不同意,请不要使用本服务。

13. 本政策的变更

如果修改本政策,我们会更新本页顶部的生效日期;有重要变化时,会在网站上提示。

14. 联系我们

另见《服务条款》。

TINGDUICU

Privacy Policy

Effective date: October 4, 2026

This is the English version of the policy above (中文版). Both versions have the same content.

1. Who we are

TingduICU (Chinese name 听读ICU, website https://tingdu.icu) is a web-based English listening practice tool. It is operated by an individual developer (“the operator of TingduICU”, “we”, “us”) based in the United States. It is not a company.

This policy explains what information we collect when you use the TingduICU website and service, how we use it, where it is stored, how long we keep it, and how you can access or delete it.

2. Summary

  • Your video files play only on your own computer or phone. They are never uploaded to our server.
  • To translate, the website sends the English subtitle text from the video, and a title cleaned up from the file name, to our server, which uses OpenAI to translate it into Chinese. Subtitles and translations are shared site-wide by content (see 3.5).
  • In Read-aloud practice (跟读), every recording you make is sent through our server to OpenAI to be transcribed into text. Our server does not keep the recordings; it keeps only the transcribed text, the score, and the words you did not say clearly. The copy of your recording used for playback, and the few seconds of original audio cut when you sort a sentence correctly, stay only in the browser on your device (see 3.8 and 3.9).
  • Signing in requires a mobile phone number and an SMS verification code. We send verification codes only, never marketing messages.
  • We do not sell or rent your personal information. Your phone number and SMS opt-in information are never shared with third parties for marketing.
  • There is currently no “delete account” button on the website. To delete your account and data, email us at 80youth@gmail.com.

3. Information we collect

3.1 Phone number and sign-in data

  • Phone number: the number you enter to sign in. Currently only mobile numbers from mainland China, the US and Canada are supported (the US includes Puerto Rico and other US territories); numbers from other countries that share the +1 code, such as Caribbean nations, and toll-free or premium numbers are not supported. Your phone number is your account.
  • Account ID: a random identifier our server assigns to each phone number. Your learning records are stored under it.
  • Account dates: when the account was created and when you last signed in.
  • Time zone: read from your browser the first time you sign in and used to decide when your “day” starts. You can change it in Settings.
  • Sign-in tokens: a random string given to your browser after you sign in, so that you stay signed in. Your browser sends the token with every request so that the server knows it is you. The server stores each token with its phone number, creation time, last-used time, and whether that sign-in was verified by SMS.
  • Verification code records: each time a code is requested, we record the phone number, the requesting IP address, the time, the purpose (sign-in or parental PIN reset), and the result. Each wrong code entered is also recorded (without the IP address). These records are used only to prevent abuse and to limit how many codes are sent.
  • Verification codes: each code can be used once, is valid for 10 minutes, and stops working once it is used or expires. It is used only for that one sign-in or PIN reset. Codes for mainland China numbers and for US and Canadian numbers may be generated by our server (mainland China codes are then sent through Spug Push Assistant, and US and Canadian codes from our own US number through Twilio; see sections 6 and 7); in that case the server stores only a keyed hash (HMAC-SHA256) of the code, never the code itself, each code can be checked at most 5 times, requesting a new code cancels the previous one, and the hash record is deleted after 2 days. Otherwise, codes are generated and checked by Twilio’s verification service (Twilio Verify), and we do not store them. Codes are never written to our logs.
  • SMS consent records: an SMS consent notice is shown directly below the “获取验证码” (Get code) button on the sign-in card and below the “发验证码” (Send code) button under “忘记口令?” (Forgot PIN?) in Settings; tapping the button means you agree. Each time a code is successfully sent to you, we record the phone number, the purpose (sign-in or parental PIN reset), the version of the consent notice shown on the page, when the first and the most recent code were sent under that version, the network of the requesting IP address (truncated: only the first 3 parts of an IPv4 address, for example 203.0.113.0/24, or the first 48 bits of an IPv6 address; the full IP address is not kept), and how many codes were sent. These records are used only as proof that you agreed to receive verification code texts, and are kept until your account is deleted (see section 8).

3.2 Learning records

Each time you score a sentence in Sort practice, the server stores a record: the time and date, the subtitle fingerprint and sentence number, the sentence text, the title, the clip start and end time, the sentence difficulty level, points, the number of hints, time spent, the number of loops, and similar details. We also store your daily target and whether (and when) you reached it, and “recently playing”: which subtitles you opened recently and when, one entry per person per subtitle. It is used to validate scoring and to count how many people have opened each subtitle (the operator sees only the count).

In Read-aloud practice (跟读), the server stores: the sentences picked for each day (chosen from sentences you sorted correctly, with the sentence text, subtitle fingerprint and sentence number, and title); for each attempt, the transcribed text (up to 200 characters), the score, the words you did not say clearly, whether it passed, and the length, size, and loudness of that recording (used to tell whether any sound was recorded), as well as the recording format, the recording window (the longest that attempt could record), how long transcription took, whether this device had the original audio for that sentence, and a note on any error (for example, a transcription timeout); and records of swapped sentences and system skips. The recordings themselves are not stored (see 3.9). In Daily Words (每日单词), the server stores: the words and questions for each day, each answer (the option chosen, whether it was right, whether time ran out, time taken, how many times the audio was played), and each word's progress and next review date; when a question includes a whole sentence, its source (subtitle fingerprint, sentence number, title) is recorded.

3.3 Settings

Daily target, the lock-until-target setting, loop timing, subtitle display preferences, difficulty filter, difficulty grade (“小学 / 中学 / 高中 / 大学”: elementary, middle school, high school, college), Read-aloud settings (sentences per day, pass mark, after how many failed tries in a row “换一句” (Swap) is offered, recording length), Daily Words settings (words per day, time limit per question), and time zone. The daily target, the lock, and the daily amounts for Read-aloud and Daily Words are stored as “from this day on, the value is …”, so earlier changes are kept; this lets us judge correctly whether each past day reached its target and how much was due that day. The parental PIN is stored only as a salted hash (scrypt), never in plain text. If the PIN is cleared, we record when and how the most recent clearing happened (by SMS code or by the operator); this note stays in your settings and is shown in the interface for 30 days.

3.4 Word notebook and lookup history

  • Word notebook: words you add yourself (the base form and the form you clicked), the date added, and where the word came from (subtitle fingerprint, sentence number, sentence text, title, time point). Removing a word only marks it as removed; the row is kept so that we can recognize words you added before.
  • Lookup history: every word you look up while signed in is recorded (while watching, and also when you click a word on the Word Notebook page), with the time, the page, and where the word came from (subtitle fingerprint, sentence number). Lookups are not recorded when you are not signed in. Lookup history is kept for 90 days. The Word Notebook page shows the words you looked up while watching (one line per word, with a count and the last date); “Clear” there deletes all of your lookup history.

3.5 Subtitle text, title, and timing

When you open a video, the website reads the embedded subtitles on your computer or phone and first sends our server a fingerprint computed from the subtitle content, to ask whether a translation already exists. Only if the server does not have these subtitles yet does the website send the subtitle text merged into sentences, the duration of each sentence, and the title. The video itself is never sent.

The title is cleaned up by the website from the file name (or from a title stored inside the video file): for example the show name, year, season, episode, and episode title. If none of these can be recognized, the title is the file name with the extension, bracketed parts, and quality tags removed. If a file name contains something you would not want others to see, rename the file before opening it.

The server stores, by fingerprint, the original subtitle text, the title, sentence durations, the AI-generated translation, notes, glossary, and sentence difficulty levels. Each subtitle is translated only once and shared site-wide: when another user opens subtitles with identical content, they see the existing translation, and may see the title that came from the first uploader's file in the “source” of a notebook word. This shared cache records the phone number of the account that first uploaded it (for usage accounting and cost control); only the operator can see it, and it is not shown to other users. We also count how many times each subtitle is opened and when it was last opened (numbers only; the marker used to count “one person, once per day” is deleted after about 2 days).

3.6 Usage statistics

For each phone number, per day: the number of AI calls and tokens used, sentences translated, sentences served from the cache, new subtitles uploaded, and similar counts, plus the time of last use. We use these for cost control and daily limits.

3.7 Access logs, application logs, and site analytics

  • Access logs: the server keeps access logs (IP address, time, URL visited, browser type, and similar request details) for operations, troubleshooting, and traffic statistics. When you look up a word, the word and the subtitle fingerprint are part of the URL, so they also appear in the access logs.
  • Application logs: our backend logs its activity and errors. Phone numbers in these logs are always masked (for example 138****8000), and verification codes and secret keys are never logged. The logs may contain account IDs, subtitle fingerprints, titles, the beginning of a sentence, a word added to the notebook, a word whose lookup failed, which settings were changed and their new values, or how many wrong parental PINs were entered, to help us troubleshoot.
  • Site analytics: we use Umami to measure website traffic. Umami runs on our own server; it is not a third-party analytics service. With its default settings it records: the URL visited (including URL parameters) and page title, the referring URL, browser, operating system, device type, screen size, browser language, and an approximate location (country, state or province, city) derived from the IP address. It does not use cookies and is not linked to your account.

3.8 Data stored in your browser

The following is stored in this browser on this computer or phone (localStorage, sessionStorage, IndexedDB):

  • Your sign-in token and phone number, to keep you signed in. Your browser sends the token to our server with every request, and the server also keeps a copy (see 3.1). Signing out clears the copy in this browser and tells the server to revoke the token.

The following stays only in your browser and is not sent to us:

  • interface and playback preferences (view, layout, player settings, subtitle display, floating window position, the country code you chose at sign-in, a cache of today's progress, a marker that Read-aloud recognition is temporarily unavailable (with your account's phone number and the date; kept only in this tab and gone when you close it), whether you have visited before);
  • playback history: for up to 40 recently opened videos, the file name, size, modified time, file type, when it was last opened, playback position, duration, a thumbnail, the chosen subtitle track, and a file handle provided by the browser (so you can reopen the same local file with one click);
  • original audio clips for Read-aloud: when you sort a sentence correctly, the website cuts the few seconds of that sentence's audio from your own video, on your device, and stores it in the browser for the “原声” (Original) and “慢速” (Slow) buttons in Read-aloud (跟读). These clips are not uploaded. On another device, or after you clear the browser's data, they are gone (Read-aloud then uses AI reading instead).

In addition, your own Read-aloud recording of each sentence (only the latest attempt) is kept in the browser for playback (“听我的” (Play mine), “对比听” (Compare)) and discarded the next day. This copy is not uploaded; for the copy sent for transcription, see 3.9.

You can delete this data by clearing this site's data in your browser settings. We do not use cookies.

3.9 Read-aloud recordings and pronunciation audio

  • Read-aloud recordings: for each attempt, the website sends that recording to our server, which passes it to OpenAI's speech recognition and scores the transcribed text. Our server does not keep the recording and does not write it to logs; it keeps only the transcribed text, the score, and the words you did not say clearly (see 3.2).
  • Pronunciation of words and sentences (in the word card, the word notebook, Daily Words, and “AI 读” (AI reading) in Read-aloud): generated by our server with OpenAI's text-to-speech and cached site-wide by content, so each word or sentence is generated only once, stored on the server, and the same audio is served to everyone. OpenAI receives only the text of that word or sentence, never your phone number or account. If a word's audio is not ready yet, the word card and the notebook temporarily use your browser's built-in speech feature instead; some browsers use their vendor's online voices for this, which is handled by the browser vendor under its own policies, not by us.

4. What we do not collect

  • The video file itself (picture and sound) is never uploaded; it plays only on your computer or phone.
  • We do not read other files on your computer or phone, only the video you drag in or choose.
  • We do not ask for your name, government ID number, home address, contacts, or precise location, and we do not collect payment information (the service is currently free).
  • No ads, and no third-party advertising or tracking tools.

5. How we use information

  • To sign you in, keep you signed in, and confirm that the account belongs to the holder of the phone number;
  • To store and sync your progress, settings, and word notebook, so they are there when you sign in with the same number on another computer or phone;
  • To translate subtitles, generate notes, rate sentence difficulty, score practice, transcribe and score Read-aloud recordings, generate pronunciation audio for words and sentences, and apply your daily target and lock;
  • To prevent abuse: limiting how often and how many codes are sent, limiting daily translation volume, and controlling costs;
  • To keep a record that you agreed to receive verification code texts;
  • To troubleshoot, keep the service secure, improve features, and understand site traffic.

We do not sell your personal information, use it for advertising, or build marketing profiles.

6. Text messages (SMS)

  • We send only two kinds of text messages: a sign-in verification code, and a verification code used to clear a forgotten parental PIN. Both are sent only after you (or a family member) click “获取验证码” (Get code) or “发验证码” (Send code) on our website. Message frequency varies: one message per request. If you do not request a code, you will not receive messages.
  • We do not send marketing or promotional messages.
  • Texts to US and Canadian numbers are sent on our behalf by Twilio (for mainland China numbers, see the next item). Verification code texts that we send from our own US number to US and Canadian numbers are in English and start with TingduICU, for example: “TingduICU: Your login code is 123456. It expires in 10 minutes. Reply STOP to opt out.” Codes sent through Twilio’s verification service use that service’s standard message template.
  • Verification code texts to mainland China numbers are sent on our behalf by Spug Push Assistant (push.spug.cc, operated by the company 时巴克, China), using the platform’s fixed Chinese template, for example: “您的验证码是123456,10分钟内有效,如非本人操作请忽略。” (“Your verification code is 123456. It is valid for 10 minutes. If you did not request it, please ignore this message.”). The sender signature belongs to the platform, so these texts do not contain the name TingduICU, and they cannot be replied to.
  • Message and data rates may apply, depending on your carrier.
  • US and Canadian numbers: reply STOP to opt out, or HELP for help. After you opt out, the number that sends our codes can no longer text you: you will not receive codes, cannot sign in by SMS, and cannot clear the parental PIN by SMS (the website will tell you that the number has opted out). To receive messages again, reply START (or UNSTOP) from that phone to the number that sent the codes.
  • Mainland China numbers: texts are sent through the platform above and cannot be replied to, so STOP and HELP apply only to US and Canadian numbers. To stop receiving texts, simply stop clicking “获取验证码” (Get code) or “发验证码” (Send code) (every text is sent only after such a click); for help, email 80youth@gmail.com.
  • Wireless carriers are not liable for delayed or undelivered messages.
  • We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Your mobile phone number and SMS opt-in data are never sold, rented, or shared with any third parties, affiliates, or lead generators for marketing or promotional purposes.

7. Who we share information with

We give the service providers below only what they need to provide the service. Each processes the data under its own terms and privacy policy:

  • Twilio Inc. (United States): sends SMS verification codes. Twilio receives your phone number and the message text (including the code itself); when Twilio’s verification service is used, Twilio also generates and checks the code.
  • Spug Push Assistant (the company 时巴克, China): sends verification code texts to mainland China mobile numbers. Spug receives your phone number and the verification code (the code is generated and checked by our server; Spug only delivers it).
  • OpenAI (United States): translates subtitles, writes notes and glossaries, rates sentence difficulty, restores normal capitalization for all-caps lines, explains sentences, and picks out the words in each sentence for Daily Words; transcribes Read-aloud recordings; and generates pronunciation audio for words and sentences. Receives the subtitle sentences and the title, each of your Read-aloud recordings, and the text of the words or sentences to be spoken. We do not send OpenAI your phone number, account ID, or anything else used to identify you; note, however, that the title is cleaned up from your file name (see 3.5), and that the recordings contain your own voice (see 3.9).
  • Tencent Cloud: provides the server we rent, located in Tokyo, Japan. All server-side data (the database, subtitle cache, logs, site analytics, and backups) is stored on this server.

We may also disclose information when required by law (for example, in response to a valid legal order).

All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.

8. How long we keep information

DataHow long
Account (phone number, account ID, time zone), learning records (including daily results and “recently playing”), settings (including their change history), word notebook (including removed words), usage statisticsAs long as the account exists, until you ask us to delete it
Sign-in tokensSigning out tells the server to revoke the token; tokens unused for more than 180 days are deleted; at most 10 per phone number (the least recently used is removed). If the network is down when you sign out and the server is not told, that token is deleted after 180 days without use
Verification code records (phone number, IP, time)Deleted after 2 days
Hashes of codes generated by our serverInvalid after 10 minutes; deleted after 2 days
SMS consent records (phone number, purpose, consent notice version, first and most recent send time, IP network, number of codes sent)As long as the account exists; deleted together with the account
Lookup historyDeleted after 90 days; you can clear it at any time
“Opened today” markers for subtitlesDeleted after about 2 days
Subtitle text, titles, translations, notes, difficulty levels (shared cache)Kept long-term with no automatic cleanup at present (the operator can delete an entry by hand); your phone number is removed from it when your account is deleted
Read-aloud recordingsNot stored: discarded once transcribed (the server keeps only the transcribed text, score, and unclear words, as part of your learning records)
Pronunciation audio for words and sentences (shared cache; not linked to who requested it)Kept long-term with no automatic cleanup at present
Access logs and application logsRotated out automatically under the server's log settings; no fixed number of days is set at present
Site analytics (Umami)Contains no account information; may be kept long-term

“Deleted after N days” in this table means the server removes expired data during routine cleanup while it runs (for example when someone signs in, requests a code, or looks up a word), not at the exact moment it expires. When nobody is using the site, expired data may stay somewhat longer.

Backups: every day at 4:30 a.m. (Tokyo time) the server backs up the database, the sign-in and usage files, and the subtitle cache to the same server. Each backup is deleted automatically after about 15 days, so deleted data may remain in backups for up to about 15 days.

9. Children and parents

TingduICU is for anyone learning English, and children can use it too. When a child uses it:

  • The account should be held by a parent (or other guardian), who signs in with the parent's phone number, so verification codes go to the parent's phone; the child uses the service with the parent's permission. The sign-in card also recommends using a parent's phone number.
  • Read-aloud practice records the child's voice: each recording is used only to check how well the sentence was read and is not kept after transcription (see 3.9).
  • When a child practices under a parent's account, practice records, the word notebook, and lookup history are stored under that account. The parent can see today's progress, the word notebook, and the words looked up while watching on the website; sentence-by-sentence practice records are not shown on the website at present, but the parent can email us for them. The parent can also ask us by email to delete them at any time.
  • We do not ask children for their name, age, school, or similar information.
  • If you learn that a child signed in with their own phone number without a parent's permission, contact us and we will delete that account's data.

10. Your choices and rights

  • Access: settings, today's progress, the word notebook, and the words you looked up while watching are visible on the website. Sentence-by-sentence practice records, account details, usage, and other data are not shown on the website at present; email us for a copy.
  • Correction: you can change your settings yourself. For other corrections, such as changing the phone number, email us.
  • Deletion: you can clear your lookup history and remove words from the notebook at any time. To delete your whole account, there is currently no self-service button; email 80youth@gmail.com with the phone number. Once we confirm that you are the user of that number, we will delete the account, sign-in tokens, learning records (including daily results and “recently playing”), settings, word notebook, lookup history, usage statistics, verification code records, and SMS consent records, and remove your phone number from the shared subtitle cache. Copies in backups are deleted as the backups rotate, within about 15 days.
  • Withdrawing SMS consent: stop requesting codes and you will receive no further messages; US and Canadian numbers can also reply STOP (after that you will not receive codes; reply START to resume, see section 6). Texts to mainland China numbers are sent through a platform and cannot be replied to with STOP.
  • Signing out: “退出登录” (Sign out) in the avatar menu clears the token in this browser and tells the server to revoke it (if the network is down at that moment, the server deletes the token after 180 days without use).

We will respond as soon as we can, normally within 30 days.

11. Security

  • Connections between your browser and the website use HTTPS.
  • Verification codes are rate-limited. Current rules: one code per number every 120 seconds; at most 5 per number and 20 per IP address in 24 hours, plus a site-wide daily cap; each code can be checked at most 5 times; verification for a number is paused after 10 wrong codes in an hour.
  • For codes generated by our server, only a keyed hash is stored, never the code itself.
  • The parental PIN is stored only as a salted hash; 5 wrong PINs in a row lock PIN entry for 15 minutes.
  • Phone numbers are masked in logs; verification codes and secret keys are never logged.
  • On the server, the data directory and the key file have restricted permissions: only the system account that runs the service and the server administrator can read them.
  • Keys for third-party services are kept on the server and never sent to browsers.

No system is perfectly secure. Your sign-in token is stored in your browser, so sign out when you finish on a shared computer or phone. If a security incident may affect your data, we will post a notice on the website.

12. Where data is stored and international transfers

  • Our server is in Tokyo, Japan (Tencent Cloud). Wherever you use the service (mainland China, the United States, or elsewhere), server-side data is stored in Japan.
  • For translation, sentence explanations, picking out words for Daily Words, Read-aloud transcription, and pronunciation audio, subtitle text, titles, Read-aloud recordings, and the text to be spoken are sent to OpenAI in the United States; SMS codes are sent through Twilio in the United States, and codes for mainland China numbers through Spug Push Assistant (the company 时巴克) in China, in which case your phone number and the code are transferred to mainland China.
  • The operator is in the United States and accesses the server remotely from there for maintenance.

By using the service, you understand that your information is transferred to and processed in these countries. If you do not agree, please do not use the service.

13. Changes to this policy

If we change this policy, we will update the effective date at the top of this page, and we will show a notice on the website for important changes.

14. Contact us

See also our Terms of Service.