Security

The safest place for your text is the machine it is already on.

Traxlate translates on your own device. That is not a policy we could change next quarter — it is where the software runs, and it is why the list of things we hold about you is short enough to print in full.

What never reaches us

Your documents, PDFs, images, video, audio, camera frames, translation memory, glossary and history. Translation happens in the app on your machine, so there is no upload step to opt out of — until you install a language pack, nothing translates at all, because there is nowhere else for the text to go.

The two deliberate exceptions are named on this page rather than buried: the hosted API (/api/v2/translate), which runs on our servers and says so in every response’s provenance field, and human translation, where your text is sent to the linguist who translates it. Both are things you choose, one request at a time.

What we do hold

  • Your account — email address, an optional name, and a password stored as a scrypt hash. Sessions are opaque tokens; the database keeps only their SHA-256, so a leaked table cannot be used to sign in as you.
  • Billing records — subscription status, payments and invoices. Card details never touch our servers; they go to the payment processor directly.
  • Encrypted blobs, if you turn on sync or share with a team — the database columns are the ciphertext, a random IV and a key-derivation salt. The decryption key is derived on your device and never sent. We can see how large a blob is and when it changed. We cannot see a single sentence inside it, and neither can anyone who compels us.
  • Content-free usage counters — a small set of fixed event names, no text of any kind, deleted after 90 days.
  • Human-translation orders, when you place one — the text you sent, for as long as the order is open.

There is no analytics tracker on this site: no Google Analytics, no pixel, no session recorder, no third-party script watching what you type. That is a fact about the code, not an intention.

Sub-processors

The complete list. It is short because most of the product does not involve us at all.

  • Stripe — card payments and subscriptions.
  • NOWPayments — cryptocurrency payments, if you choose that.
  • An SMTP relay — password resets, receipts and failed-payment notices. Plain messages: no tracking pixel and no wrapped links.
  • Our hosting provider — the servers that run this website, the hosted API and the encrypted-blob store.

Your translations are not sent to any of them, because they are not sent anywhere.

How it is built

  • Passwords hashed with scrypt; sessions and API keys stored as hashes, never in a reusable form.
  • Sync and team shares are end-to-end encrypted with AES-GCM-256. For a team share the key travels only inside the link’s URL fragment, which browsers never send to a server — so it cannot appear in our logs, a proxy’s, or a CDN’s.
  • An API key is shown once and stored as a hash. Revoking one keeps the record, so the history of who had access survives.
  • Language packs are downloaded once and run offline afterwards. A subscription lapsing never switches off a pack you have installed.

Certifications, honestly

We do not hold ISO 27001 or a SOC 2 report. We would rather say so plainly than imply otherwise: if your procurement process requires one, we do not meet that requirement today.

What we can offer instead is the thing a certificate is usually asked to prove. For on-device translation there is no data flow to audit, no retention period to argue about and no sub-processor to review, because the text never leaves the machine it was typed on. If that is the question behind the questionnaire, this page is the answer to it.

Data processing agreement

If your organisation needs a signed DPA covering the parts that do involve us — your account, billing, and any encrypted blobs you sync — write to support and say so. Under UK and EU data-protection law you are the controller and we are the processor for exactly those records, and the sub-processor list above is what an annex would name.

Getting your data, or getting rid of it

Ask, and we will send you a copy of everything we hold about you, correct it, or delete it and close your account. That is a right under UK and EU data-protection law and we do not make you argue for it. Write to support.

Two things worth knowing before you ask. Most of what you would want back was never ours — your documents, memory, glossary and history live on your device, so exporting them is a button in the app rather than a request to us. And anything you synced is stored as ciphertext we cannot read, so what we can hand over is the encrypted blob itself; the key is on your devices.

Reporting a vulnerability

Tell us through support with enough detail to reproduce it. We would rather hear about a problem than not, and we will not threaten anyone who reports one in good faith. Please do not run automated scans against the hosted API or test with other people’s accounts.

The rest

Privacy policy · Terms · How the privacy model works · Service status66 languages, all of them on-device.

Security — Traxlate