01Overview
This policy explains how Linguana collects and uses personal data when you visit our website, use the dashboard, or connect an application to hosted translation. For account and workspace data, Linguana is the controller. For personal data that may appear inside text your applications send us, you are the controller and we process it on your behalf.
02What we collect
- Account data: name, email address, password hash or sign-in provider ID, organization name, and team roles.
- Billing data: plan, invoices, and usage totals. Card details are collected and stored by Polar, not by us.
- Project content: source strings, translations, glossaries, and build manifests uploaded by your builds or entered in the dashboard.
- Usage and security data: IP address, browser type, request timestamps, and audit events such as sign-ins, token creation, and publishing.
- Communications: messages you send to support or sales.
03How we use it
- To provide, secure, and support the Service (contract).
- To bill you and keep financial records (legal obligation).
- To detect abuse, debug problems, and improve reliability (legitimate interests).
- To send service emails such as invitations, receipts, and security alerts. We send product news only if you opt in (consent).
We do not sell personal data, and we do not use your project content to train AI models.
04Who processes it
We use these providers to run the Service. Each is bound by a data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting, content delivery, and file storage (R2) | Global |
| Neon | Managed Postgres database | United States / EU |
| OpenRouter | Routes translation requests to AI models | United States |
| Polar | Payments and invoicing (merchant of record) | United States |
| Resend | Transactional email | United States |
Translation requests contain only the text and context needed to translate it. Where data leaves the EEA or UK, we rely on Standard Contractual Clauses or an equivalent safeguard.
06How long we keep it
- Account and project data: for as long as your organization exists, then deleted within 30 days of closure.
- Billing records: as long as tax and accounting law requires, typically 7 years.
- Security and audit logs: up to 12 months.
- Backups: overwritten on a rolling basis within 35 days of deletion.
07Your rights
Depending on where you live, including under the GDPR, UK GDPR, and CCPA, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. We will not discriminate against you for using these rights.
Email privacy@linguana.dev and we will respond within 30 days. If your request concerns content your organization uploaded, we may refer you to that organization. You can also complain to your local data protection authority.
08Security
We protect data with encryption in transit and at rest, scoped access, and audit logging. See Security for details.
09Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
10Changes and contact
If we make material changes, we will update the effective date and notify account owners. Questions: privacy@linguana.dev.