Privacy Policy
Privacy Policy
Last updated: June 2026
At LexaTranslate, we are committed to protecting your privacy and ensuring the security of your personal information and translation content. This Privacy Policy explains how we collect, use, store, and protect your data when you use our AI-powered cultural translation platform. By using LexaTranslate, you consent to the practices described in this policy.
1. Information We Collect
Personal Data
When you create an account, we collect the following personal information:
- Full name and email address
- Account credentials (passwords are hashed and never stored in plain text)
- Billing information for paid plans (processed securely through Stripe; we never store full credit card numbers)
- Preferred language and regional settings
- Organization name and role (for Enterprise accounts)
Translation Content
When you use our translation services, we temporarily process the following content:
- Source text submitted for translation
- Uploaded documents (PDF, DOCX, TXT, and other supported formats)
- Translation output generated by our AI agents
- Strategy selections (literal, cultural, poetic, legal) and agent preferences
Text translations are not stored on our servers unless you choose to save them to your translation history. Book Mode keeps your manuscript and its translation only while your book is being translated, then deletes them automatically 24 hours after emailing you the results. You can request earlier deletion at any time by contacting us.
Technical Data
We automatically collect certain technical information when you interact with our platform:
- IP address and approximate geographic location (country/city level)
- Browser type, version, and operating system
- Device identifiers and screen resolution
- Pages visited, features used, and interaction patterns
- Referral source and search terms used to find LexaTranslate
- API request metadata (for developer/Enterprise accounts)
Cookies & Local Storage
We use cookies and similar technologies to maintain your session, remember your preferences, and analyze platform usage. See Section 6 for detailed information about our cookie practices.
2. How We Use Your Information
Translation Service Delivery
Your personal data and translation content are used primarily to deliver our AI-powered cultural translation service. This includes processing your text through our 15 specialized translation agents, applying your selected translation strategy, and generating culturally-aware translations. Without processing this data, we cannot provide the core service you signed up for.
Service Improvement & Development
We use anonymized and aggregated usage data to improve our translation models, agent performance, and user experience. This includes:
- Analyzing translation quality metrics and error patterns
- Optimizing agent routing and strategy selection algorithms
- Improving cultural context recognition and domain-specific terminology
- A/B testing new features and interface improvements
We do not use your content to train our own models. Your content is used only to provide the translation service to you.
Security & Fraud Prevention
We monitor platform usage patterns and technical data to detect and prevent unauthorized access, abuse, spam, and fraudulent activity. This includes rate limiting, suspicious login detection, and automated threat analysis. Security monitoring is essential to protect all users of the platform.
Communication
We may use your contact information to send you:
- Service-related notifications (billing, account changes, security alerts)
- Responses to your support inquiries and feedback
- Product updates and feature announcements (you can opt out of marketing emails)
- Policy change notifications (mandatory, cannot be opted out)
3. Data Storage & Security
Encryption Standards
- TLS 1.3 — All data transmitted between your device and our servers is encrypted using Transport Layer Security 1.3, the latest industry standard for secure communications.
- AES-256 — All data at rest is encrypted using Advanced Encryption Standard with 256-bit keys, providing military-grade protection for stored information.
Where Your Data Is Stored
Your account and translation data are stored with Supabase on Amazon Web Services infrastructure in the Mumbai (ap-south-1) region. The application is hosted on Vercel, and translations are processed through the Google Gemini API. These providers may process data outside the UAE and the GCC. We use encryption in transit and at rest, and we work with providers that maintain recognised security practices.
Data Retention
Text translations are not stored on our servers unless you choose to save them to your translation history. Book Mode keeps your manuscript and its translation only while your book is being translated, then deletes them automatically 24 hours after emailing you the results. You can request earlier deletion at any time by contacting us. Organisations with strict confidentiality requirements can contact us to discuss custom data handling terms.
Access Controls & Audit Logs
We implement strict access controls based on the principle of least privilege:
- Employee access to user data is restricted to authorized personnel only and logged in audit trails
- All data access events are recorded and auditable by our security team
- Enterprise customers receive detailed audit logs of all data access events related to their account
- Regular third-party security assessments and penetration testing are conducted
4. Data Retention
Real-Time Processing
Translation content is processed in real-time and is not retained in our systems after processing, except as described below. Source text and translation output are held in memory only for the duration needed to complete the translation and deliver the result to you.
Translation History Deletion
If you choose to save translations to your history, they are stored on our servers until you explicitly delete them. You can delete individual translations or your entire history at any time through the dashboard. Deleted translations are permanently removed from our active systems within 24 hours and from backup systems within 30 days.
30-Day Account Deletion
When you request account deletion, we initiate a comprehensive data removal process:
- Your account and profile information are immediately deactivated
- All translation history and saved content are permanently deleted within 7 days
- All associated personal data is purged from active systems within 14 days
- Residual data in backup systems is removed within 30 days of the deletion request
- Anonymized, aggregated analytics data derived from your usage may be retained
5. Your Rights
We respect your data rights and provide the following controls over your personal information:
Right of Access
You can request a complete copy of all personal data we hold about you at any time through your account settings or by contacting us.
Right to Correction
You can update or correct your personal information directly through your account settings. For corrections to transaction records, contact our support team.
Right to Deletion
You can request complete deletion of your account and all associated data. Deletion is processed within 30 days as described in Section 4.
Right to Data Export
You can export all your personal data, translation history, and account information in a machine-readable format (JSON) at any time.
GDPR Compliance
For users in the European Economic Area, LexaTranslate complies with the General Data Protection Regulation (GDPR). You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data infringes GDPR requirements. Our Data Protection Officer can be reached at privacy@lexatranslate.com.
UAE Personal Data Protection Law (PDPL)
As a UAE-based service, LexaTranslate fully complies with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). We ensure that your data is processed lawfully, fairly, and transparently, and that your rights under the PDPL — including access, rectification, deletion, and data portability — are fully honored. Data is stored within the UAE and GCC region, and any cross-border transfers comply with PDPL requirements.
6. Cookies & Tracking
Essential Cookies
We use essential cookies that are strictly necessary for the operation of our platform:
- Session cookies — Maintain your authenticated session and prevent unauthorized access
- CSRF tokens — Protect against cross-site request forgery attacks
- Preference cookies — Remember your language, theme, and translation strategy preferences
- Load balancing cookies — Ensure consistent server routing for optimal performance
Essential cookies cannot be disabled as they are required for the platform to function properly.
Analytics via Umami
We use Umami, a privacy-focused, self-hosted analytics platform, to understand how users interact with LexaTranslate. Umami analytics:
- Do not use cookies that track you across websites
- Do not collect personally identifiable information
- Aggregate all data so individual users cannot be identified
- Are fully compliant with GDPR, CCPA, and PECR without requiring consent banners
You can opt out of Umami analytics by enabling "Do Not Track" in your browser settings, which we respect.
No Third-Party Tracking
LexaTranslate does not use third-party tracking cookies, advertising pixels, social media trackers, or fingerprinting technologies. We do not share your browsing behavior with advertising networks, data brokers, or analytics companies. Your activity on our platform stays between you and us.
7. Third-Party Services
LexaTranslate uses the following third-party services to operate and improve our platform. Each service has been vetted for security and privacy compliance:
Cloudflare CDN
We use Cloudflare as our content delivery network, DNS provider, and DDoS protection service. Cloudflare may process the following data:
- HTTP request headers and metadata for routing and caching
- IP addresses for threat detection and bot mitigation
- SSL/TLS termination for encrypted connections
Cloudflare is certified to ISO 27001, SOC 2 Type II, and PCI DSS. Their privacy policy is available at cloudflare.com/privacypolicy.
Stripe Payments
All payment processing is handled by Stripe. We never store your full credit card number, CVC, or bank account details on our servers. Stripe processes:
- Credit card and debit card information
- Bank account details for Enterprise invoicing
- Billing address and tax identification numbers
Stripe is PCI DSS Level 1 certified (the highest level of payment security). Their privacy policy is available at stripe.com/privacy.
We do not share your translation content, personal data, or usage information with any other third parties except as required by law or as described in this policy.
8. Children's Privacy
LexaTranslate is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@lexatranslate.com.
Upon receiving verifiable notice that we have collected personal data from a child under 13, we will take immediate steps to delete that information from our servers and terminate the associated account. If we discover that a child under 13 has created an account, we will delete the account and all associated data without delay.
For users between the ages of 13 and 18, we recommend parental guidance when using our service, particularly when submitting sensitive content for translation.
9. International Data Transfers
Your data is stored and processed by our service providers, including Supabase (AWS, Mumbai region), Vercel and Google. This means your data may be processed outside the UAE and the GCC.
When your data is transferred internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) — We use EU-approved Standard Contractual Clauses as the legal basis for international data transfers where required by applicable law
- Adequacy decisions — Where the receiving country has been deemed to provide adequate data protection by the relevant authority, transfers may proceed on that basis
- Binding corporate rules — For intra-group transfers, we maintain binding corporate rules approved by the relevant supervisory authority
All international transfers are documented and auditable. Enterprise customers can request a copy of our Data Transfer Impact Assessment for their records.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes to this policy, we will:
- Provide at least 30 days' advance notice before the changes take effect
- Notify you via email to the address associated with your account
- Display a prominent notice on our website and within the application
- Update the "Last updated" date at the top of this policy
Your continued use of LexaTranslate after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you may delete your account before the changes take effect, as described in Section 4.
For non-material changes (such as clarifications, formatting updates, or corrections of typographical errors), we may update this policy without advance notice, though we will always update the "Last updated" date.
11. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy Inquiries
Email: privacy@lexatranslate.com
Data Protection Officer
Our Data Protection Officer is available to address any concerns about how your personal data is processed, to facilitate the exercise of your data subject rights, and to cooperate with supervisory authorities. You can reach the DPO at dpo@lexatranslate.com.
Mailing Address
LexaTranslate by Arabian AI
Data Privacy Team
Dubai, United Arab Emirates
We aim to respond to all privacy-related inquiries within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.