Privacy policies tend to be the part of a service where companies say one thing and do another. We've tried to write ours so the things we promise here are actually the things we do, and so a normal person can read it without a law degree. If we ever break one of these commitments, please write to us — we'd rather hear about it from you than from a regulator.
If you only read one paragraph, make it this one: the books you upload are encrypted at rest, never used to train any AI model, and permanently deletable at any time. The rest of this page is the longer version.
1. What we collect
We collect three categories of data:
1a. Account information
- Email address and password (the password is stored hashed; we cannot read it).
- Optional: display name, preferred language.
- Email verification status and password-reset tokens.
- Account creation date and last login date.
1b. Books and reading data
- The PDF and EPUB files you upload.
- Derived content: translated text, vector embeddings used for chat, generated quizzes, your highlights and notes.
- Reading state (current page, progress, last-opened time).
1c. Usage and billing data
- Pages uploaded per month (for quota enforcement).
- API requests, errors, and rough timings (for service reliability).
- Billing details handled by Stripe — we never see your full card number; we only receive the last four digits and a token.
2. How we use it
- To run the service. Process your books, generate translations, power chat and quizzes, deliver the reading experience.
- To bill you. Charge subscription fees, calculate usage, prevent abuse.
- To support you. Respond to email when you write in.
- To improve the service. Aggregate, anonymized usage data tells us which features matter and which are broken.
We do not use your uploaded books to train AI models. We do not sell your data. We do not run ad-tech tracking. We do not share your reading history with third parties beyond what's needed to run the service.
3. Who we share data with
To run Translify, we send specific data to specific service providers. Each one is bound by their own privacy and security commitments.
- Anthropic (Claude API) — when you chat with a book or ask AI to explain a passage, we send the relevant book chunks plus your question. Anthropic processes the request and does not use it to train their models when called via their API. See Anthropic's privacy policy.
- DeepL — for European-language translation, we send the book text to DeepL. DeepL Pro (the tier we use) does not store or use customer data to train their models. See DeepL's privacy policy.
- Stripe — payment processing. Stripe receives your card details directly (we never see them) and your billing email. See Stripe's privacy policy.
- Resend — transactional email (verification, password reset, billing receipts). Resend receives your email address and the email content. See Resend's privacy policy.
- Hosting — our infrastructure (compute, database, file storage) is operated by reputable cloud providers in the EU. Data is encrypted in transit and at rest.
We do not share data with anyone else. We do not sell data to data brokers or advertisers. We do not run third-party advertising or marketing trackers on our website or in our app.
4. How long we keep your data
- Uploaded books and derivatives — until you delete them, or 90 days after you close your account.
- Account data — until you close your account, or 30 days after you request deletion.
- Billing records — retained for 7 years to comply with tax law, in anonymized form where possible.
- Server logs — automatically deleted after 30 days unless tied to an open support case.
5. Your rights
You have, at any time, the right to:
- Access your data — see what we have about you.
- Export your data — get a copy in a portable format.
- Correct inaccurate data — update your account information yourself, or write to us.
- Delete your account and all associated data.
- Object to any processing you believe is unjustified.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email [email protected]. We aim to respond within 5 working days; the legal maximum under GDPR is 30 days.
6. Cookies and tracking
We use minimal cookies — see our Cookie Policy for the full list. We do not use behavioral advertising trackers. We use a privacy-friendly, cookieless analytics tool (Plausible) when enabled, which gives us aggregate visitor counts without identifying individuals.
7. Children
Translify is not designed for children under 13. The Family plan includes a kid-safe mode, but accounts are always created and controlled by a parent or guardian. We do not knowingly collect data from children under 13. If you believe we have, email us and we'll delete it.
8. International users
Translify processes data on infrastructure located in the European Union. If you access Translify from outside the EU, you are consenting to the transfer of your data to the EU for processing, which is governed by GDPR — among the world's stricter data protection regimes.
9. Changes to this policy
We may update this policy. When we make material changes we email active users at least 14 days before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.
10. Contact
Privacy questions, data-access requests, complaints — email [email protected].