Privacy Policy

1. Our role: controller and processor

For account, authentication, billing, and communications data, TrueIdiom acts as a data controller — we decide how and why that data is used.

For the documents, source text, terminology, and translations you submit through the Service (“Customer Content”), TrueIdiom acts as a data processor. We process Customer Content only to provide the Service on your instructions. If you are using TrueIdiom on behalf of an organization, that organization is the controller of the Customer Content, and this Policy is supplemented by any agreement between us.

2. Information we collect

2.1 Account and identity data

When you create a workspace or sign in, we collect your email address and your workspace (organization) name. If you sign in with Google, we receive basic profile and authentication information from that provider in accordance with the permissions you grant.

2.2 Authentication and security data

  • Passwords for email sign-up are stored only as salted, one-way hashes — never in plain text.
  • If you enable multi-factor authentication, we store the secret needed to verify codes from your authenticator app (TOTP).
  • We issue a session cookie after sign-in and keep records of security events (such as sign-ins, sign-in failures, multi-factor outcomes, and role changes), including your email address and, for single sign-on, technical claims from your identity provider describing how you authenticated. These records are kept for as long as your workspace exists.

2.3 Customer Content

This is the material you submit for translation: uploaded documents (such as DOCX, XLSX, and PDF files, or plain-text, HTML, and CSV files), source and target text, terminology entries, translation memories, review decisions, annotations, and the resulting translated (“golden”) files. Customer Content may itself contain personal data if you choose to include it — you control what you upload.

2.4 Usage and billing data

We record operational metrics needed to run and meter the Service, including translation job metadata, model selections, quality and verification scores, and token counts. Billing is a monthly subscription carrying an allowance of source characters, and what you consume of that allowance is measured solely by the volume of text you submit, counted in the characters of your source text; language pairs involving Chinese, Japanese, Korean, Thai, or Hindi are weighted at 3.5× that character count. Token counts are internal service and cost telemetry and never determine what you are charged. For workspaces on a free trial, we record the allowance granted — measured the same way — and the amount consumed. Payments are handled by our payment processor (see Section 5); we do not store your full card number.

2.5 Technical data

Like most online services, we automatically collect limited technical information such as IP address, timestamps, and request logs generated when you interact with the Service. We use this for security, debugging, and reliability. Server logs and operational telemetry are stored with our cloud provider (Microsoft Azure) and may include browser information and approximate location derived from your IP address.

3. How we use information

  • To provide, operate, and maintain the Service, including translating, refining, reviewing, and delivering your content.
  • To authenticate you, secure your account, and prevent fraud and abuse.
  • To meter usage and, where billing is enabled, process billing and payments.
  • To provide support and respond to your requests.
  • To contact you about important service matters — such as security incidents or material changes to the Service — at the email address associated with your account.
  • To monitor, debug, and improve the reliability and quality of the Service.
  • To comply with legal obligations and enforce our Terms of Use.

We do not use your Customer Content to train our own or third parties’ foundation models, and we do not sell personal data. We do, however, use your organization’s approved translations to improve later translations for your organization only: approved source and target pairs are stored in your workspace’s translation memory and may be included as reference examples in translation requests we send to our AI subprocessors on your behalf. They are never used for other customers and never used to train models.

4. Translation and AI processing

Delivering a translation requires sending your source content to large-language-model services. Customer Content is transmitted to and processed by Microsoft Azure OpenAI to produce the initial translation, run the reflective refinement pass, and generate quality assessments. We also generate vector embeddings of Customer Content — including terminology entries and translation-memory segments at the time you upload them, and source text at translation time — by sending that content to the same providers’ embedding services. Embeddings are stored with your workspace data and used to retrieve relevant terminology and examples for your translations.

These providers process the content to return a result to us and act as our subprocessors under their enterprise data-processing terms. Results that meet your workspace’s quality thresholds may be published automatically as golden files; results that do not are routed to a human reviewer in your workspace for inspection and sign-off before publication.

5. How we share information

We do not sell personal data. We share information only with the service providers (“subprocessors”) that make the Service work, and only as needed for the purposes below:

If your organization enables Bring-Your-Own-Storage, approved translation records and translated documents are written to a storage account your organization owns and controls. The approved translation records written there are redacted copies: they carry the approved source and translation, while the processing metadata behind them stays in TrueIdiom’s own systems. Whatever your storage configuration, TrueIdiom also retains the full job record in its own systems — including your source text and the final translation, along with translation-memory entries and document text segments — to operate the Service.

Where your organization uses TrueIdiom’s own storage instead, document artifacts are held in a container dedicated to your workspace inside a storage account TrueIdiom operates. That container is isolated from other workspaces and is not directly accessible to you; you reach its contents through the Service. A record of processing telemetry for each job is retained on TrueIdiom’s side only, and is never written to customer-owned storage.

We may also disclose information where required by law, to protect our rights, users, or the public, or in connection with a merger, acquisition, or sale of assets (with notice where required).

6. Cookies and local storage

We use a strictly necessary session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. We also use your browser’s local storage: while you are signed in, it holds values such as your session and refresh tokens, your email address, and your workspace name and identifier so you stay signed in across pages (removed when you sign out), along with preferences and convenience values such as your site language, interface preferences such as which panels you have collapsed, and the reviewer name you last entered. During sign-in, temporary state — such as the values needed to complete authentication — is kept in session storage and cleared when the tab closes.

Where analytics is enabled, we use PostHog product analytics, configured for EU data residency, without tracking cookies. Analytics events may be associated with your workspace but never include the content you submit for translation, and they are not used to build an advertising profile of you.

When you sign in with Google, or manage billing, your browser interacts directly with those providers’ pages, which collect data under their own privacy policies; payment details are entered on Stripe-hosted pages and never pass through our servers.

7. International data transfers

We and our subprocessors may process data in countries other than your own, including the United States and the European Union. Where personal data is transferred across borders, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an equivalent lawful transfer mechanism.

8. Data retention and deletion

We retain account, billing, usage, and security-log data for as long as your workspace exists and as needed to meet legal, tax, and accounting obligations. Customer Content is retained for as long as your workspace exists. Approved translations, together with the associated review decisions and reviewer identity, are additionally retained in your workspace’s translation memory and quality records so that future translations for your organization can reuse them.

You can delete translation-memory and terminology sets you have uploaded at any time from within the Service. Workspace administrators can also delete individual translation jobs and documents from within the Service; this permanently removes the content together with the approved translation pairs derived from it. Deletion is not always total: where the feature is enabled on a deployment, certain derived records kept to improve translation quality may survive, as do the usage, billing, and security-audit records described above. To request closure of your workspace or deletion we have not made self-service, contact us at privacy@trueidiom.com; we process these requests manually and will confirm when complete, except where we must retain data to comply with law.

9. Security

We use technical and organizational measures to protect your data, including encryption in transit, hashed passwords, optional multi-factor authentication, tenant isolation controls so customer organizations cannot access each other’s workspaces, and access controls. Our authorized personnel may access Customer Content only as necessary to operate, support, and secure the Service. Published translations can be retrieved by anyone who has the translation’s link, so share links to published results only with people you trust. No method of transmission or storage is completely secure, but we work to protect your information and to notify affected customers of material incidents as required by law.

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can export your translation memories directly from the Service. To exercise these or other rights, contact us using the details below; we handle such requests manually and will respond within the timeframe required by applicable law.

If TrueIdiom processes Customer Content on behalf of your organization, please direct rights requests to that organization, which we will support as its processor.

11. Children’s privacy

The Service is intended for use by businesses and adults. It is not directed to children, and we do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised Policy.

13. Contact us

For questions about this Policy or to exercise your privacy rights, contact us at privacy@trueidiom.com.

See also our Terms of Use.