Skip to content
legal / privacy

What we collect, and what we refuse to.

Written to be read. The plain language box at the top of the document says the same thing the clauses do, only faster.

  • effective september 8, 2026
  • fourteen documents, fourteen urls
privacy at transglot
Effective September 8, 2026

Privacy Policy

the human version

We collect your account details, the strings you send us to translate, and enough operational telemetry to debug a run. We do not train models on your content and we sell nothing to anyone. We do advertise: Google Analytics counts visits, and a Google Ads tag measures which ads bring people here. On this website that advertising data can build a remarketing audience and can follow you to another site that shows Google ads. Inside the product it cannot, because ad personalisation is switched off there and only the conversion is counted. Visitors in the European Economic Area, the United Kingdom and Switzerland are asked before either tag stores anything, and the Cookie Policy names all twelve cookies. You can get your data out or ask us to delete it, and the retention schedule below prints every window we actually enforce, including the ones that are longer than you might expect.

01

Who we are, and what this covers

This policy explains how the Transglot entity named on your order form or invoice ("Transglot", "we", "us") collects, uses, discloses and safeguards personal data when you visit the website or use the localization platform, including the editor, AI translation, the in-context editor, the REST API, the command line interface, webhooks, the delivery bundle and the marketplace connectors (together, the "Service"). It applies to visitors, to people who hold an account, to organization members and to anyone who writes to us. It does not apply to a third party site or system you reach through a connector, which has its own policy. Using the Service means this policy applies to you.

02

The two roles we act in

We are the controller of the personal data we decide the purposes for: your account record, your organization membership, billing records, support conversations, marketing contacts and the operational telemetry we need to run and secure the platform. We are a processor of the personal data that happens to sit inside Customer Content, because you decide what strings to send us and why. The Data Processing Addendum governs that second role, is incorporated into the Terms of Service, and applies without anything being signed. Where a right below is one you have against a controller, exercise it against us for the first category and against your own organization for the second.

03

What you give us directly

Account details: name, email address, a hashed password, and the organization name and role you are given. Profile details you choose to add, such as a display name, a locale preference and a notification preference. Billing details when you subscribe: the billing contact, the billing address and tax identifiers, plus a payment method token held by our payment processor. We never see or store a full card number. Support and sales correspondence: whatever you write to us, plus the address you write from. Program applications: what you submit on the open source application form or the Founding Partner enquiry. Content you post inside a workspace: comments, review notes, assignments and glossary entries, which carry your name inside that workspace.

04

What the Service records as you use it

Operational telemetry: IP address, user agent, referring page, the pages and screens you open, the API endpoints you call, request identifiers, timings, queue and run outcomes, quality gate results, error traces and rate limit decisions. Usage accounting: word counts, locale counts, run counts and token counts, which is what meters your allowance. Security records: sign-in attempts and their outcome, second-factor enrolment events, token creation and revocation, role and permission changes, and SSO or SCIM events. Audit events carry the actor, the action, the target, the time and the IP address. Metering records counts, never the body of a request.

05

Personal data inside your content

Customer Content is whatever you put into a project: translation keys, source strings, translations, glossaries, style guides, comments, screenshots captured by the in-context editor and the files you import. It may contain personal data, because a product string can. You decide what goes in, and the Acceptable Use Policy asks you not to submit payment card data, government identifiers, credentials or special category personal data as translatable content. We process what is in there on your instructions, under the Data Processing Addendum, and we do not go looking through it except where a report, a legal obligation or a security incident requires it.

06

What we get from somewhere else

If you sign in with a federated identity provider or with single sign-on, that provider sends us the identifiers and attributes needed to create or match your account, typically a subject identifier, an email address and a name. If you connect a repository, storage bucket, content platform or chat workspace, that system sends us the files, entries and identifiers the connector needs, using the access you granted. If you arrive through a Founding Partner link, we record the referral token, not who you are. If you arrive from a Google ad, we record the click identifier Google appended to the link, the campaign labels it carried and the page you landed on, and at that moment none of it names anybody; if you go on to create an account, it is attached to that account, which is how a signup is credited to the campaign that won it. Our payment processor sends us the status of a charge, the last four digits of a card and its expiry, and nothing more.

07

Cookies and similar technologies

We use a small number of first party cookies, a small number of browser storage keys, and one Google tag that serves both an analytics half and an advertising half. The Cookie Policy lists all twelve cookies by name, with the purpose, the lifetime, who sets it and whether it is encrypted. Visitors in the European Economic Area, the United Kingdom and Switzerland are shown a consent banner, and everything that is not strictly necessary is denied until they answer it: the tag still loads, but it writes no analytics or advertising cookie, and what reaches Google is a ping carrying no cookie and no click identifier. Everywhere else the default is granted, which is a decision we took rather than one the law took for us, and you can refuse afterwards by blocking cookies for this site or by running any content blocker. What the advertising half is allowed to do with the data differs by host on purpose. On this website ad personalisation is on, so the data can build a remarketing audience and can follow you to another site that shows Google ads. Inside the product it is off, so a conversion is counted and no advertising audience is built out of what you do in your own workspace. Every feature works without any of these cookies.

08

Why we use it, and on what legal basis

Where the GDPR or the UK GDPR applies, we rely on: performance of a contract, to create and run your account, provide the Service, meter usage, take payment and give support; legitimate interests, to secure the platform, prevent fraud and abuse, debug and improve the Service, keep records of what happened, measure aggregate demand and send service-related messages, balanced against your interests each time; legal obligation, to keep tax and accounting records, answer lawful requests and meet regulatory duties; and consent, where we ask for it, which covers the analytics and advertising cookies wherever the ePrivacy rules require it and optional marketing email, and which you can withdraw at any time without affecting what came before. Where we act as processor, the legal basis is the one your own organization relies on.

09

Special category and sensitive data

We do not ask for special category personal data (health, genetic, biometric identification, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation) and the Service is not designed to hold it. We do not knowingly collect it about you as a controller. If you place it inside Customer Content you do so as controller, on your own legal basis, and you should tell us first so we can tell you honestly whether the platform is appropriate for it. Under California law we do not collect sensitive personal information for the purpose of inferring characteristics about anyone.

10

How AI translation processes your strings

A translation run sends source strings and their surrounding context, in structured batches, to the AI subprocessors disclosed by category and region in our Trust Center and in the Subprocessors document, and named in the list we furnish on request under a non-disclosure agreement. That list is the authoritative record of who can process your content and in which region, and it is enforced rather than aspirational: an automated test fails our build if a translation engine becomes reachable without a disclosure row, so we cannot route your text to a vendor we have not told you about. An exact-match translation memory hit is resolved inside our own systems and is never sent to a subprocessor. A near-match hit is different, because finding one means embedding the source string first: that lookup sends the string to the embeddings subprocessor, and it runs only on a project that has turned semantic translation memory on, which is off by default. We do not use your content to train models, on any plan, and our AI subprocessors are called for inference only under commercial terms.

11

Automated decision-making

The Service is automated by design: it translates, it scores quality, it applies glossary and placeholder gates, and it blocks a row that fails them. Those are decisions about a string rather than about a person, and none of them produces a legal or similarly significant effect on an individual. We do not use profiling to make decisions about you, we do not credit-score you, and we do not use automated processing to decide whether to give you an account. Abuse and fraud signals can lead to a suspension, and the Acceptable Use Policy gives you a human appeal against one.

12

Who we share it with

Other members of your organization, according to their role and their project access, which is why a comment you write carries your name inside that workspace. The service providers that run the platform on our behalf, under written terms and confidentiality obligations, in the categories set out in the Subprocessors document: AI translation, cloud hosting and database, object storage, email delivery, payment processing and support messaging. The endpoints you yourself register: webhooks, connectors and storage destinations receive exactly the events and content you subscribe them to, and once delivered that data is in your hands. Professional advisers under duties of confidence. Anyone a valid legal obligation requires, where we will narrow the request and tell you unless we are legally barred from doing so. A successor, if the business is acquired or reorganised, subject to this policy continuing to apply. Google, which receives the website measurement and the conversion measurement described in clause 07 as an independent controller for its own advertising products, rather than as a provider acting on our instructions: which pages you opened, which ad brought you here, and, when you create an account or pay, a SHA-256 hash of your email address and, where a billing address gives us them, of your first and last name, alongside the postal code and the two letter country in the clear because Google will not accept those hashed. A SHA-256 hash is a one way digest, so what Google gets is a fixed string it can compare against a string of its own, and the address itself never leaves our servers. We do not sell personal data for money. The disclosure to Google is sharing for cross-context behavioural advertising under United States state law, and clause 24 sets out what you can do about it. Nothing you place in a project is part of any of this.

13

Subprocessors and how their list changes

The current subprocessor disclosure, with the purpose, the region and the condition under which each category is engaged, is published in the Trust Center and summarised in the Subprocessors document; the named vendors behind those categories are furnished on request under a non-disclosure agreement, by writing to privacy@transglot.ai. We give notice by email before a new subprocessor starts processing customer personal data, and the Data Processing Addendum gives you a right to object on reasonable data protection grounds. Several entries are conditional rather than always on: some are engaged only for paid plans, and some only when a project turns on an optional feature.

14

International transfers

We run the platform in one cloud region, fixed at deployment, and some of our subprocessors process data in the United States and, for one optional translation engine, in Singapore. There is no per-project region pinning today and we do not sell one. Where personal data leaves the United Kingdom, the European Economic Area or Switzerland, we rely on the safeguards recognised under applicable law, principally the European Commission Standard Contractual Clauses with the UK International Data Transfer Addendum where the UK GDPR applies and with the Swiss adaptations where Swiss law applies, together with the supplementary measures described in the Data Processing Addendum. A copy of the transfer mechanism relied on for a given subprocessor is available on request. The analytics and advertising data in clause 07 reaches Google in the United States, where Google is an independent controller of it and relies on its own transfer safeguards rather than on ours.

15

How long we keep it, in detail

Account and organization records: for as long as the account exists, then as clause 16 describes. Billing and tax records: as long as tax and accounting law requires, typically seven years. Support correspondence: while it is useful and then on our ordinary correspondence schedule. Project content: for as long as the project exists. Translation version history: 180 days, with a floor of the newest 20 versions per string, which survives any age, on every plan rather than as a paid tier. Notifications: 90 days. Comments: kept while a thread is unresolved, and 365 days after a thread is resolved. Activity feed: 180 days. Assistant conversations: 90 days, and deleted with the account that made them. In-context screenshots: 90 days. Connector sync run records: 90 days, keeping the most recent run per connection. Delivery bundle: the most recent 20 published versions per project and locale. Referral click records: 90 days. Ad click attribution: one row a person, holding the Google click identifier, the campaign labels it carried and the page it landed on, kept while the account exists and deleted with it. The conversion ledger, which records what we reported to Google, when, and the hashed identifiers sent with it: kept as the record of a report we made, and detached from your account when the account is deleted. Unreviewed translation memory entries that were never reused: 90 days. Audit events: append-only and kept until the organization is purged. Webhook delivery records: kept for the life of the endpoint, with no time-based prune today, so delete an endpoint to clear its history. Failed background jobs: 7 days. Expired API tokens: swept 24 hours after they lapse. Operational metrics: 30 days.

16

Deleting an account, and deleting a workspace

They are two different actions with two different clocks, and the difference matters. Deleting your own user account is immediate and irreversible: your sign-in methods, notifications, saved views, assignments, assistant conversations and the record of which ad click brought you are hard deleted at once, and there is no recovery window. What you contributed inside a workspace stays with that workspace, including the comments you wrote and the record of what you did, and those can still show your name, because deleting one member must not rewrite another organization’s history. Deleting a workspace starts a 30 day grace period during which it is read only and any owner can cancel; after that it is purged, the subscription is cancelled first, and projects, translations, versions, usage history, webhook deliveries, screenshots and audit events cascade out of the live database. That purge does not reach the encrypted backups behind it, which roll off on their own schedules described in clause 17.

17

How we protect it, and what we do not claim

Transport security with TLS 1.2 or better at the edge. Passwords hashed with bcrypt at cost factor 12. Optional two-factor authentication with time-based codes and recovery codes, plus passkeys, available on every plan including Free, and an organization-wide requirement an owner can switch on. API tokens and delivery keys stored as SHA-256 digests and shown once at creation. Third party credentials and webhook secrets stored in encrypted columns. Outbound webhooks signed HMAC-SHA256 over the timestamp and the body. Role-based access control at organization and project level on every plan, with per-language grants. Tenant scoping on every query, where a cross-tenant identifier answers 404 rather than 403 so existence never leaks. Rate limits on public endpoints. Append-only audit records. Encrypted database backups (retained as two full backups plus differentials with continuous write-ahead log archiving) and encrypted file backups (retained as 30 daily, 12 weekly and 12 monthly snapshots). What we do not claim: the live volumes are not disk-encrypted, there is no cryptographic hash chain over the audit log, and we hold no third party security certification today. The security page states those gaps in the same words.

18

If something goes wrong

We maintain an incident response process. If a personal data breach affects data we process on your behalf, we will notify your organization without undue delay after becoming aware of it, with the information the Data Processing Addendum requires, and we will assist you with your own notification duties. If a breach affects data we hold as controller and is likely to result in a high risk to you, we will tell you directly and notify the relevant supervisory authority within the time the law allows. We will not condition notification on your agreement to any restriction on what you may say about it.

19

Your rights

Depending on where you live, you may have the right to: know what personal data we hold and get a copy of it; correct data that is inaccurate or incomplete; delete it; restrict or object to processing, including profiling and direct marketing; receive it in a portable, machine readable form and have it transmitted to another controller where technically feasible; withdraw consent at any time without affecting what came before; and not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. Most account information is editable in your settings, and organization owners can manage members, roles, tokens and the workspace itself. We will not discriminate against you for exercising a right.

20

How to exercise a right

Write to privacy@transglot.ai and say what you want. We will verify that the request comes from you or from someone you have authorised, using the account email where we can and asking for reasonable additional information where we cannot; we ask for the minimum needed and we do not create a new identity record to answer a request. We respond within one month where the GDPR or UK GDPR applies, extendable by two further months for a complex request with an explanation, and within 45 days where United States state privacy law applies, extendable once by a further 45 days. There is no charge unless a request is manifestly unfounded or excessive. Where the personal data sits inside another organization’s project content we are the processor, so we will pass the request to that organization and support them in answering it rather than answering it ourselves.

21

Complaining to a regulator

If you are unhappy with how we have handled your personal data, tell us first and we will try to put it right. You also have the right to complain to a supervisory authority: in the European Economic Area, the authority in the country where you live, work or where the issue arose; in the United Kingdom, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner. Nothing in this policy takes away that right or requires you to come to us first.

22

Representatives and the data protection officer

Where we are required to appoint an Article 27 representative for the European Economic Area, that is our EU Article 27 representative, whose details are published here once appointed and are available on request in the meantime, and for the United Kingdom our UK Article 27 representative, on the same basis. As to a data protection officer, we have not appointed a Data Protection Officer, because we are not required to. Privacy questions are handled by the team behind the address below. You can always reach a person about privacy at the address at the foot of this document.

23

California: what we collect and why

This clause is the notice at collection required by the California Consumer Privacy Act as amended. In the last twelve months we have collected these categories of personal information: identifiers (name, email address, account identifier, IP address); customer records (billing contact and billing address); commercial information (plan, subscription and payment history); internet or network activity (pages and endpoints used, request logs, device and browser information); geolocation inferred only at the coarse level an IP address gives; professional information where you tell us your role or company; and content you place in a project, which may contain any category you choose to put there. We collect it for the business and commercial purposes in clause 08, retain it for the periods in clause 15, and disclose it to the categories of recipients in clause 12. Two of those categories are also shared for cross-context behavioural advertising, as clause 24 sets out: identifiers, meaning the hashed email address sent with a conversion and the click and cookie identifiers the Google tag uses, and internet or network activity, meaning which pages you opened and which ad you arrived on. We do not collect sensitive personal information for the purpose of inferring characteristics, and we make no use of it that would trigger a right to limit.

24

California: we do not sell, and what we do share

We do not sell personal information for money and we have not sold any in the preceding twelve months. We do share personal information for cross-context behavioural advertising, in the sense the statute gives that word: the Google tag described in clause 07 discloses the identifiers and the browsing activity listed in clause 23 to Google, which uses them for its own advertising products as an independent controller and not as our service provider. Before the effective date at the top of this document that was not so, and this clause said we did neither, so the sharing in the preceding twelve months runs from that date forward. We do not knowingly sell or share the personal information of consumers under 16 years of age. There is no "Do Not Sell or Share My Personal Information" link on this site today. The controls that work are these: block cookies for this site in your browser, which the tag cannot get around; run any content blocker, which stops the tag loading at all; delete the advertising cookies named in the Cookie Policy, which removes the identifiers already held; or send an opt out request to the address in clause 20, which we handle as a rights request under that clause. The consent banner is a fourth control, and it is shown to visitors in the European Economic Area, the United Kingdom and Switzerland, so a California resident will not usually be offered one. Nothing you place in a project is ever shared for advertising.

25

California: your rights and how to use them

California residents may request to know the categories and specific pieces of personal information we collected, the sources, the business purpose and the categories of recipients; to delete personal information, subject to the exceptions the statute allows; to correct inaccurate personal information; and to opt out of sharing for cross-context behavioural advertising, by any of the routes in clause 24. Make a request at privacy@transglot.ai. We verify a request to the degree of certainty the statute requires for its type, and we will not treat you differently for making one: no price difference, no service difference, no denial. An authorised agent may act for you with written permission signed by you, and we may still ask you to verify your own identity directly.

26

Other United States state privacy laws

Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky and Rhode Island, have rights to confirm, access, correct, delete, obtain a copy of and opt out of targeted advertising, sale and certain profiling. We do run targeted advertising on this website, described in clause 07 and disclosed in clause 24, and the ways to opt out of it are the ones clause 24 lists. We sell nothing and we run no profiling that produces a legal or similarly significant effect, so the substance of those two opt-outs is already how we operate. Use the same address in clause 20 to exercise any of them, and to appeal a decision we make about a request: we will respond to an appeal within the period your state allows and, if we refuse, tell you how to contact your attorney general.

27

Do Not Track and Global Privacy Control

There is no consistent industry standard for how a site should answer a browser Do Not Track signal, so like most operators we do not respond to one. A Global Privacy Control signal is a different thing, because several United States state privacy laws treat it as an opt out of sale and sharing. We do not read that signal on our servers today, so on its own it does not switch off the analytics and advertising described in clause 07. The controls that do switch it off are the ones in clause 24: block cookies for this site, run a content blocker, delete the advertising cookies, or refuse the consent banner where you are shown one, which we keep for 180 days across both the website and the product. Blocking costs you nothing here, because every feature of the site and of the product works without any analytics or advertising cookie.

28

Children

The Service is a business tool, is not directed at children, and is not intended for anyone under 16. We do not knowingly collect personal data from a child. If you believe a child has given us personal data, write to the address below and we will delete it. If your own product is directed at children and you localize its strings with us, you remain the controller of whatever you place in a project and are responsible for the consents that requires.

29

Messages we send you

Service messages are part of the product and are not marketing: invitations, run and review notifications, quota and billing notices, security alerts, incident notices and changes to these documents. You can tune many of them in your notification settings, and you cannot switch off the security and billing ones while you hold an account, because those are the ones you most need. Marketing email is separate, is sent only where we have a lawful basis to send it, and every one carries a one-click unsubscribe that we honour promptly.

30

Changes to this policy

We update this policy from time to time. When we do we change the effective date at the top and, for a change that materially affects your rights, give additional notice by email or in the console before it takes effect. We keep the superseded version available on request so you can see what changed. Continuing to use the Service after a change takes effect means the updated policy applies to you.

31

Who to ask

Privacy questions, data subject requests and anything about this policy go to privacy@transglot.ai. Vulnerability reports go to security@transglot.ai. Anything else, including contract and billing questions, goes to hello@transglot.ai. A postal address for formal correspondence is on your invoice and is available on request.

privacy@transglot.ai
works with what you already run

41 connectors, already built.

procurement, unblocked

Legal should not be the slow part.

Fourteen documents, each on its own URL, with the subprocessor list, the data posture and the compliance status published exactly as they stand today.

An executed Data Processing Addendum is a mail to privacy@transglot.ai.