Privacy Policy
This Privacy Policy explains how TrueIdiom (“TrueIdiom”, “we”, “us”) collects, uses, shares, and protects information when you use our human-in-the-loop translation service (the “Service”). It covers both the personal data we handle as a controller and the content you upload for translation, which we process on your behalf.
1. Our role: controller and processor
For account, authentication, billing, and communications data, TrueIdiom acts as a data controller — we decide how and why that data is used.
For the documents, source text, terminology, and translations you submit through the Service (“Customer Content”), TrueIdiom acts as a data processor. We process Customer Content only to provide the Service on your instructions. If you are using TrueIdiom on behalf of an organization, that organization is the controller of the Customer Content, and this Policy is supplemented by any agreement between us.
2. Information we collect
2.1 Account and identity data
When you create a workspace or sign in, we collect your email address and your workspace (organization) name. If you sign in with Google, we receive basic profile and authentication information from that provider in accordance with the permissions you grant.
2.2 Authentication and security data
- Passwords for email sign-up are stored only as salted, one-way hashes — never in plain text.
- If you enable multi-factor authentication, we store the secret needed to verify codes from your authenticator app (TOTP).
- We issue a session cookie after sign-in and keep records of security events (such as sign-ins, sign-in failures, multi-factor outcomes, and role changes), including your email address and, for single sign-on, technical claims from your identity provider describing how you authenticated. These records are kept for as long as your workspace exists.
2.3 Customer Content
This is the material you submit for translation: uploaded documents (such as DOCX, XLSX, and PDF files, or plain-text, HTML, and CSV files), source and target text, terminology entries, translation memories, review decisions, annotations, and the resulting translated (“golden”) files. Customer Content may itself contain personal data if you choose to include it — you control what you upload.
2.4 Usage and billing data
We record operational metrics needed to run and meter the Service, including translation job metadata, model selections, quality and verification scores, and token counts. Billing is a monthly subscription carrying an allowance of source characters, and what you consume of that allowance is measured solely by the volume of text you submit, counted in the characters of your source text; language pairs involving Chinese, Japanese, Korean, Thai, or Hindi are weighted at 3.5× that character count. Token counts are internal service and cost telemetry and never determine what you are charged. For workspaces on a free trial, we record the allowance granted — measured the same way — and the amount consumed. Payments are handled by our payment processor (see Section 5); we do not store your full card number.
2.5 Technical data
Like most online services, we automatically collect limited technical information such as IP address, timestamps, and request logs generated when you interact with the Service. We use this for security, debugging, and reliability. Server logs and operational telemetry are stored with our cloud provider (Microsoft Azure) and may include browser information and approximate location derived from your IP address.
3. How we use information
- To provide, operate, and maintain the Service, including translating, refining, reviewing, and delivering your content.
- To authenticate you, secure your account, and prevent fraud and abuse.
- To meter usage and, where billing is enabled, process billing and payments.
- To provide support and respond to your requests.
- To contact you about important service matters — such as security incidents or material changes to the Service — at the email address associated with your account.
- To monitor, debug, and improve the reliability and quality of the Service.
- To comply with legal obligations and enforce our Terms of Use.
We do not use your Customer Content to train our own or third parties’ foundation models, and we do not sell personal data. We do, however, use your organization’s approved translations to improve later translations for your organization only: approved source and target pairs are stored in your workspace’s translation memory and may be included as reference examples in translation requests we send to our AI subprocessors on your behalf. They are never used for other customers and never used to train models.
4. Translation and AI processing
Delivering a translation requires sending your source content to large-language-model services. Customer Content is transmitted to and processed by Microsoft Azure OpenAI to produce the initial translation, run the reflective refinement pass, and generate quality assessments. We also generate vector embeddings of Customer Content — including terminology entries and translation-memory segments at the time you upload them, and source text at translation time — by sending that content to the same providers’ embedding services. Embeddings are stored with your workspace data and used to retrieve relevant terminology and examples for your translations.
These providers process the content to return a result to us and act as our subprocessors under their enterprise data-processing terms. Results that meet your workspace’s quality thresholds may be published automatically as golden files; results that do not are routed to a human reviewer in your workspace for inspection and sign-off before publication.
7. International data transfers
We and our subprocessors may process data in countries other than your own, including the United States and the European Union. Where personal data is transferred across borders, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an equivalent lawful transfer mechanism.
8. Data retention and deletion
We retain account, billing, usage, and security-log data for as long as your workspace exists and as needed to meet legal, tax, and accounting obligations. Customer Content is retained for as long as your workspace exists. Approved translations, together with the associated review decisions and reviewer identity, are additionally retained in your workspace’s translation memory and quality records so that future translations for your organization can reuse them.
You can delete translation-memory and terminology sets you have uploaded at any time from within the Service. Workspace administrators can also delete individual translation jobs and documents from within the Service; this permanently removes the content together with the approved translation pairs derived from it. Deletion is not always total: where the feature is enabled on a deployment, certain derived records kept to improve translation quality may survive, as do the usage, billing, and security-audit records described above. To request closure of your workspace or deletion we have not made self-service, contact us at privacy@trueidiom.com; we process these requests manually and will confirm when complete, except where we must retain data to comply with law.
9. Security
We use technical and organizational measures to protect your data, including encryption in transit, hashed passwords, optional multi-factor authentication, tenant isolation controls so customer organizations cannot access each other’s workspaces, and access controls. Our authorized personnel may access Customer Content only as necessary to operate, support, and secure the Service. Published translations can be retrieved by anyone who has the translation’s link, so share links to published results only with people you trust. No method of transmission or storage is completely secure, but we work to protect your information and to notify affected customers of material incidents as required by law.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can export your translation memories directly from the Service. To exercise these or other rights, contact us using the details below; we handle such requests manually and will respond within the timeframe required by applicable law.
If TrueIdiom processes Customer Content on behalf of your organization, please direct rights requests to that organization, which we will support as its processor.
11. Children’s privacy
The Service is intended for use by businesses and adults. It is not directed to children, and we do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised Policy.
13. Contact us
For questions about this Policy or to exercise your privacy rights, contact us at privacy@trueidiom.com.
See also our Terms of Use.