Privacy
duwen is a free reader you can use with no account at all. When you use it signed out, everything you save — your reading position, saved vocabulary, imported decks, and review schedules — lives only in your own browser and is never sent to us. This page describes the optional signed-in layer, which exists so that data survives across your devices and browser-storage limits.
What we store
- A nickname you choose. A passkey-only account stores your nickname but no email address, real name, or password. It stays email-free unless you choose optional Google recovery.
- Your named passkeys' public keys and details. You can have multiple named passkeys (public credentials) on your account. For each one, we store its public key, the name you supply, when it was added, and when it was last used. A passkey's private key never leaves your device and we never see it; its public key can verify that you signed in but cannot be used to sign in as you.
- Optional Google recovery data. If you link Google recovery, our server holds the verified email address and stable Google identity (Google's unique identifier for your account) that Google returns. We use them only to recognise your existing duwen account when you recover access; Google sign-in does not create a new duwen account.
- Your learner state. The same data the reader keeps in your browser — reading positions, saved vocabulary, imported study decks, and their spaced-repetition schedules — is synced to our server under your account so it is not lost.
How you sign in
Sign-in uses a passkey — the fingerprint, face, or screen lock your device already uses. There is no password to choose or forget. Passkey sign-in does not involve Google or another third party. Google participates only in the optional Google recovery flow: if you choose it, Google verifies your identity and email so duwen can link recovery to your existing account. Your session is kept in a secure, server-set cookie scoped to duwen.app; the reader never places an authentication token in browser storage.
Signed-in readers can manage recovery passkeys from the account page. Adding or removing a passkey requires confirmation with one of your existing passkeys, and duwen will not let you remove your final passkey. If you lose access to every usable passkey, your account is unrecoverable unless Google recovery was linked first, before the passkeys were lost. Recovery cannot be linked after you have lost the passkeys needed to prove that the account is yours.
Why we store it
We use this data only to recognise your account across devices and to keep your learner state durable and in sync. If you opt into Google recovery, we also use the linked identity and verified email only to restore access to that existing account. We do not sell this data, and we do not use it for advertising or profiling.
How long we keep it
We keep your account data for as long as your account exists. This includes the verified email and Google identity if you linked recovery. When you delete your account, it is removed.
Canceling or otherwise losing Pro does not delete your account. Ordinary synced learner state remains available under your account. Snapshots and private uploads remain stored while your account exists, but you cannot access them without Pro. Reading positions, saved vocabulary, decks, and review schedules already stored in that browser remain usable there.
Payments and subscription
duwen Pro is a recurring charge of $5.00 USD per month — the same terms the Pro page publishes. Helcim processes the payment and holds your card details: card numbers are entered on Helcim's own checkout form, embedded on duwen's account page but hosted by Helcim, and never reach duwen's server directly.
What duwen keeps about a subscription is one database row, and these are all of its fields:
- the account it belongs to;
- your Helcim customer code and a reusable card token — references to records that live at Helcim, used only to charge the next renewal;
- the plan you are on and its status;
- the current period end;
- a count of consecutive failed renewal charges, which is how duwen decides when to stop retrying and end a subscription that can no longer be charged.
No card number, expiry date, or billing address is among them; those stay with Helcim.
The subscription renews automatically each period until you cancel it. You can cancel at any time from the account page's cancel action, which opens with Cancel subscription on your account page. Cancelling stops the next charge, and paid access runs to the end of the current period.
For a refund, or any other question about a charge, email us — [email protected].
Deleting your account
Deleting your account cancels your subscription. Billing is safely resolved before any server-held data is removed: duwen marks the linked subscription canceled locally, stopping future renewal charges, and deletes server records only after that is confirmed, confirms billing had already ended, or there is no linked subscription.
If cancellation cannot be confirmed, deletion is blocked: your account and subscription mapping remain intact, you stay signed in, and you can retry the same confirmed deletion later. No server-held account data is removed during a blocked attempt.
You can delete your account at any time. Deletion permanently removes your server-held data — your nickname, your registered passkeys, your synced learner state, any sign-in sessions, and, if recovery was linked, your verified email and stable Google identity — from our database. This action cannot be undone.
Deleting your account removes the copy stored on our server. The copy held in your own browser (the duwen. data in this browser's local storage) stays on each device until you clear it yourself — you can do this from your browser's site-data settings.
Your browser-local data
Whether or not you sign in, duwen stores your reading position, saved vocabulary, decks, and review schedules in this browser's local storage under the duwen. prefix so the reader works offline and remembers where you were. This data never leaves your device unless you are signed in and it is synced to your account. You can export all of it, or remove it, from your browser at any time.
Contact
Questions about your data, or a deletion request you can't complete yourself? Email me — [email protected].