Back to Home

Privacy Policy

Key Privacy Features

What We Store:

  • Email address (for OTP sign-in)
  • Credit balance and purchase receipts (for fraud prevention)
  • Usage summaries (token counts, costs - not raw audio)
  • Feedback messages (for support)

What We DON'T Store:

  • Passwords (OTP-only authentication)
  • Raw audio content (audio is relayed to OpenAI, not stored)
  • Audio recordings or transcripts

Data Usage:

  • No ads, no trackers, no data sales
  • Audio relayed to OpenAI for translation only
  • Temporary rate limiting data (expires in minutes to hours)

Your Control:

  • Delete your account anytime in Settings
  • All account data removed (email, credits, purchases, usage, feedback)
  • Only retained: non-reversible email hash (prevents welcome bonus abuse, cannot reconstruct email)

Last updated: 2025-11-04

This Privacy Policy explains how we collect, use, and protect your information when you use the XTranslate application and related services ("Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

  • Account: Email address used for one-time passcode (OTP) sign-in.
  • Credits and Purchases: Non-expiring credit top-ups and in-app purchase receipts (platform, product ID, receipt identifiers) for fraud prevention and accounting.
  • Usage Metrics: Session and usage summaries (e.g., token counts, cost) necessary to compute pricing and remaining credits. We store pricing and usage events in aggregate; we do not store your raw audio content.
  • Audio Relay: Your microphone audio is relayed to OpenAI's real-time model for transcription and translation. Audio may be processed by OpenAI per their policies.
  • Feedback/Support: User-submitted feedback messages and associated email address for support purposes.
  • Operational Data: IP addresses (temporarily logged for security/abuse prevention), account timestamps (creation, last login), and spending totals.
  • Temporary Rate Limiting Data: IP addresses and email addresses temporarily stored for rate limiting (60 second periods). Progressive backoff tracking data expires within 1 hour. Session count data expires within 2 hours.
  • Local Preferences: Model and language preferences stored locally on your device (not transmitted except as query parameters for service operation).

2. How We Use Information

  • Provide authentication via OTP and maintain your account.
  • Calculate pricing and update your credit balance.
  • Verify in-app purchases and prevent abuse.
  • Operate the real-time translation experience by proxying audio to the model provider.
  • Respond to user feedback and support requests.
  • Prevent abuse and enforce rate limits using temporary IP and email tracking.
  • Improve reliability, detect abuse, and comply with legal obligations.

3. Data Sharing

We do not sell your data. We share only what is necessary to operate the Service:

  • OpenAI (or future model providers) receive relayed audio and metadata necessary for transcription/translation.
  • App stores (Apple/Google) provide purchase validation data.
  • Email provider (e.g., Resend) sends OTP emails.

4. Data Retention

  • Account and credit ledger are retained while your account is active.
  • Usage event summaries and receipts are retained for accounting and fraud prevention.
  • We do not store raw audio content on our servers.
  • Temporary rate limiting data expires automatically (within minutes to hours).
  • Server logs may be retained for operational purposes.
  • Deletion: In-app deletion removes your account (email), credits, purchases, usage history, feedback messages, and operational metadata including timestamps and spending totals. We retain a one-way hash of your normalized email solely to prevent re-granting the one-time welcome bonus if you re-create an account. The hash cannot be used to reconstruct your email.

5. Security

We use industry-standard practices (e.g., TLS in transit, hashed OTP codes, JWT-based sessions). No password storage is used.

6. Your Rights

  • You may request access, correction, or deletion of your account data by contacting support.
  • If you are in a jurisdiction granting additional rights (e.g., GDPR/CCPA), you may exercise those rights by contacting us.

7. Children's Privacy

The Service is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect such data.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated in-app or via our website.

9. Contact

For privacy questions or data requests, xtranslate@nauman.im