Privacy Policy
This Privacy Policy explains what personal data we process, for what purposes, on what legal bases, and what rights apply to people using SmartTranslate.ai (the "Service"). This document is prepared in line with transparency requirements under the GDPR (EU) and the UK GDPR, and includes additional disclosures used in selected jurisdictions (for example, the USA).
Last updated: 26/02/2026
1. Data controller and contact details
The controller of personal data is the entity operating the SmartTranslate.ai Service (the "Controller", "we").
Important: to meet the information requirements of many jurisdictions (including the EU/UK), please provide the Controller’s full legal name, registered office address, country of incorporation, and, where applicable, the registration number and details of the EU/UK representative here.
For matters relating to data protection and the exercise of data subject rights, you can contact us at: privacy@smarttranslate.ai.
2. Scope of the Policy and definitions
This Policy applies to the processing of personal data in connection with the use of the Service (website, dashboard, translation features, blog), including contact with us and marketing activities (for example, newsletters) — if they are carried out.
"Personal data" means information relating to an identified or identifiable natural person (for example, an email address, account identifier, IP address in certain situations).
"Processing" includes, among other things, collecting, recording, storing, using, sharing, and deleting data.
3. What data we process (data categories)
Data provided by the user: in particular an email address (for example, when joining the waitlist/newsletter), content sent for translation (text, files), and translation settings and preferences (for example, selected language variant, translation profile).
Waitlist/newsletter signup data: email, language/locale, consent information (for example, consent to the waitlist and optional marketing consent), as well as technical data connected with signup (IP address, user agent) and creation/update timestamps.
Account and authentication data: if you use sign-in, we process the data needed to create and maintain an account (for example, user ID, email address, session data). The Service uses the Clerk authentication provider.
Technical and operational data: IP address, cookie identifiers, device and browser information (for example, user agent), and events related to the use of the Service.
Analytical data: if you consent to analytics cookies, we may process statistical data about how the Service is used (for example, page views, basic session parameters) using analytics tools (for example, Google Analytics 4 and Cloudflare Web Analytics — depending on the configuration).
Communication data: the content of correspondence, if you contact us (for example, by email regarding privacy matters).
We do not intend to obtain, and we do not require, special categories of data (so-called sensitive data) or data relating to criminal convictions and offences. Please do not submit such data in translation content unless it is necessary and you have an appropriate legal basis.
4. Sources of data
We collect data directly from you (for example, when you join the waitlist, create an account, submit content for translation, or contact us).
Some technical data is collected automatically by IT systems and the browser (for example, IP address, cookies, device parameters).
If you use sign-in through an external authentication provider (Clerk), we may also receive account/session data from that system to the extent necessary for the sign-in to function.
5. Purposes of processing and legal bases (EU/UK)
If you are located in the EU/EEA or the United Kingdom, the legal bases for processing arise in particular from Article 6 of the GDPR / UK GDPR. Below we set out the typical purposes and legal bases — the actual scope depends on the features you use.
Performance of a contract or steps taken before entering into a contract (Article 6(1)(b) GDPR): providing the Service’s functions, including (where available) translation of content and documents, managing the user account, and handling tasks related to the service.
Consent (Article 6(1)(a) GDPR): newsletter signup (if offered), analytics cookies and similar technologies (for example, Google Analytics 4), and other activities for which we ask for your consent. You can withdraw consent at any time (without affecting the lawfulness of processing carried out before withdrawal).
Legitimate interests (Article 6(1)(f) GDPR): ensuring the security of the Service, preventing abuse (for example, limiting the number of signups from one IP within a short time), maintaining and developing the Service, and establishing or defending legal claims.
Legal obligation (Article 6(1)(c) GDPR): where the law requires us to process certain data (for example, in connection with handling reports, claims, or requests from authorities).
6. Whether providing data is mandatory
Providing some data is necessary to use certain features of the Service.
For example: to join the waitlist, you must provide an email address and give the required consent for waitlist management. Without this data, signup will not be possible.
For translations: providing the content to be translated and the selected settings is necessary in order to deliver the service.
7. Recipients of data and processors
We use trusted service providers (processors) that support the operation of the Service. These may include in particular: Cloudflare (hosting, CDN/infrastructure, Workers/D1/Images services), Clerk (authentication and account management), and providers of analytics tools (for example, Google Analytics 4, Cloudflare Web Analytics — depending on the configuration and your consent).
The providers process data under contracts and our documented instructions, to the extent necessary to provide the services.
We may also disclose data to: (a) authorised employees and contractors of the Controller, (b) advisers (for example, legal advisers) where necessary, and (c) public authorities where required by law.
8. Cookies, similar technologies, and analytics
The Service uses cookies and similar technologies for essential purposes (for example, maintaining sessions, security, remembering language preferences) and — with your consent — for analytics purposes.
The Service includes a consent banner that allows you to choose cookie categories. Analytics cookies are optional.
Depending on the configuration, we may use Google Analytics 4 (GA4) with Google Consent Mode v2 and Cloudflare Web Analytics. If you do not consent to the analytics category, we limit/disable mechanisms that require consent and clear the specified analytics cookies (for example, _ga, _gid).
Details about cookie categories and how to manage consent are set out in the Cookie Policy.
9. International transfers (outside the EU/EEA and UK)
Due to the global nature of cloud services, data may be processed in countries other than your country of residence, including outside the EU/EEA or the United Kingdom.
If we transfer data outside the EU/EEA or the UK, we use appropriate legal mechanisms, such as adequacy decisions or standard contractual clauses (SCCs) and — where necessary — additional safeguards.
You can ask for information about the transfer safeguards we use by contacting us.
10. Data retention periods
We keep data for as long as needed to achieve the purposes described in this Policy, and then delete or anonymise it — unless longer retention is required by law or is otherwise justified (for example, to establish, pursue, or defend claims).
Waitlist/newsletter signups: we keep data (for example, email, consents, technical signup parameters) until you unsubscribe/withdraw consent or until the data is no longer needed for the purpose for which it was collected.
Analytics data: retention periods depend on the configuration of the analytics tool and your cookie settings; details may also follow the providers’ policies.
Translation content (text/files): as a rule, we process it for as long as necessary to deliver the service and ensure its quality, and then delete or anonymise it — in line with account settings, plan settings, and security and legal requirements.
11. Data security
We use technical and organisational measures designed to protect data (for example, access control, privilege limitation, transmission encryption, infrastructure security mechanisms, monitoring, and event logging).
No system can guarantee 100% security. If we become aware of a personal data breach, we will take action in line with applicable laws (including notifications, where required).
12. Your rights (EU/EEA and United Kingdom)
If you are in the EU/EEA or the UK, you have — within the limits of the law — the rights to access, rectification, erasure (the "right to be forgotten"), restriction of processing, data portability, and objection to processing based on legitimate interests.
If processing is based on consent, you can withdraw your consent at any time (without affecting the lawfulness of processing carried out before withdrawal).
If you believe processing infringes the law, you have the right to lodge a complaint with a supervisory authority (for example, in Poland: the President of the Personal Data Protection Office) or the competent authority in your country.
13. Information for US residents (selected states) — disclosures and rights
Depending on where you live, you may have additional rights (for example, California — CCPA/CPRA; Colorado, Connecticut, and other states). As a rule, these include the right to know the categories of data collected and the purposes, access to data, deletion of data, correction of data, and in some states the right to opt out of the "sale"/"sharing" of data or processing for targeted advertising.
We do not sell personal data within the meaning of typical state privacy laws. If we ever start carrying out activities that qualify as a "sale" or "sharing" (for example, for targeted advertising), we will update the Policy and provide the required opt-out mechanisms.
To submit a privacy rights request (access/delete/correct/opt-out), contact us at: privacy@smarttranslate.ai. We may ask for information necessary to verify the request and protect against abuse.
We do not discriminate against users for exercising their rights.
14. Automated decision-making and profiling
The Service may involve automated processes (for example, automatic translation of text/documents using AI models, selection of settings based on the chosen translation profile).
As a rule, such operations do not produce legal effects concerning you or affect you in a similarly significant way. If we implement processes that meet the criteria of Article 22 GDPR (automated decisions with significant effects), we will provide separate information and the required safeguards.
15. Children's data
The Service is not intended for children. If you are a parent/guardian and suspect that a child has provided us with personal data without the required consent, please contact us — we will take appropriate action.
16. Changes to the Privacy Policy and contact
We may update this Privacy Policy to reflect changes in the Service, providers, or legal requirements. The current version is published on this page together with the date of last update.
For privacy matters and to exercise your rights, contact us at: privacy@smarttranslate.ai. For security reasons, we may ask for additional information to verify your identity or your authority to act on behalf of another person.
Privacy contact
privacy@smarttranslate.ai