Privacy Policy
This explains what we hold about you, why we hold it and who else touches it. It is written to be read rather than to be complied with, and it describes what the software actually does.
The short version
We store the account you sign in with, the translation content you put into the service, and the minimum needed to keep it running and secure.
We do not sell anything to anybody, we run no advertising, and there is no analytics or tracking script anywhere in the product. The only cookies we set are the ones that keep you signed in.
Your translation content is yours. We do not use it to train any model.
What we hold
Your account: email address, and the name and profile picture your identity provider gives us if you sign in with Google or Microsoft. If you register with a password we store it hashed, never in a form we can read. We also keep your chosen interface language, so emails reach you in it.
Your content: projects, source strings, translations, comments, glossary entries, screenshots you upload, and the file imports and exports you run. This is the substance of the service and it is yours.
Credentials you give us: git access tokens and machine-translation API keys, encrypted at rest. Neither is ever shown again after you save it, and neither is returned by the API.
Records of activity: an audit log of who changed what in your team, with the actor, the action, the time and the IP address the request came from. This is what lets an owner answer the question 'who deleted that', and it is visible to the team's own admins.
Why we are allowed to
To perform the contract you entered into when you started using the service: your account, your content, the emails that make the product work, and the payment records if you are on a paid plan.
For our legitimate interest in a service that stays up and is not abused: the audit log, rate limiting, and the technical records described below.
To meet legal obligations: invoices and the accounting records that go with them.
Where we ever ask for consent, you will be asked, and you can withdraw it as easily as you gave it.
Cookies
Three, all strictly necessary, all first-party:
There is no analytics cookie, no advertising cookie and no third-party pixel, which is why the site does not ask you to accept anything.
| Cookie | What it does | How long |
|---|---|---|
| access_token | Keeps you signed in | 15 minutes |
| refresh_token | Renews the session so you are not signed out mid-sentence | 7 days |
| oauth_state | Proves a sign-in you started is the one that came back | 30 minutes |
Who else processes it
We use a small number of providers to run the service. Each of them processes data only on our instructions, and only for the purpose named.
| Who | What for | Where |
|---|---|---|
| Google Cloud (europe-west1, Belgium) | hosting, database, file storage | EU |
| Stripe | payments and invoicing | EU / US |
| Brevo | transactional email | EU |
Machine translation is on your own key
Linguiqo does not hold an account with OpenAI or DeepL on your behalf and never sends your content to one under our own credentials.
If you want machine translation you add your own API key, and from that point the relationship is between you and that provider: their terms, their data-retention policy, their invoice. Your strings are sent to them only when somebody in your team asks for a translation, and only the strings needed for it.
Without a key, the feature is offered and disabled, and no content leaves the service.
Where it lives
In the European Union. The service, the database and the file storage all run in Google Cloud's europe-west1 region in Belgium.
Payment processing involves a transfer to Stripe, which may process data outside the EU under the safeguards in its own data-processing terms.
How long we keep it
As long as your account exists, and then not much longer.
| What | How long |
|---|---|
| Account and content | Until you delete the team, then removed |
| Demo sandboxes | Two hours from the moment they are created, then deleted outright |
| Synchronization history | 30 days |
| Audit log | For the life of the team |
| Invoices and accounting records | As long as the law requires us to keep them |
What you can ask for
You can ask for a copy of what we hold about you, for it to be corrected, for it to be deleted, for us to stop or limit a particular use, and for your data in a portable form. Much of this you can do yourself: every language exports to a file at any time, and deleting a team removes its content.
Write to the address at the bottom of this page and we will answer within a month. If you think we have handled your data badly you can complain to your national data protection authority; in the Czech Republic that is the Úřad pro ochranu osobních údajů.
Keeping it safe
Everything travels over TLS. Passwords are hashed, and git tokens and API keys are encrypted with a key held separately from the database. Sessions are short-lived and can be invalidated everywhere at once by changing your password.
Access to production is limited to the people who operate the service. No system is perfect, and if a breach ever affects you we will tell you and the supervisory authority within the time the law allows.
Changes
If we change this policy in a way that matters, we will say so in the product rather than quietly changing the date at the top. The date at the top is when the current version took effect.
Who operates this service
Linguiqo