Privacy Policy

Last updated: 2026-09-04

1. Who is responsible for your data

The data controller for i18n-keyless.com is Ambroselli.io, based in France. For any question about this policy or your data, write to .

This policy covers i18n-keyless.com, its dashboard, its API, and the account you create to manage a hosted project. It does not cover a self-hosted instance, which is operated by its own buyer — see section 4.

2. What we collect

Account data: your email address and a hashed password, or, for MCP agent access, an OAuth token bound to your account and one project.

Billing data: your Stripe customer identifier and billing email. Stripe holds your card details directly; we never see or store them.

Translation data: the source text your application sends us, the resulting translations, and a token count per string, kept so repeat requests are served from cache instead of billed again. If you enable the user-generated content feature, this also includes text written by your own end users.

Technical data: error reports sent to Sentry when the service fails, and basic site-traffic analytics collected on i18n-keyless.com. We do not collect this technical data from a self-hosted instance unless its administrator enables it.

3. Why we process it, and on what basis

To provide the account, the dashboard and the translation API you signed up for (performance of a contract). To bill a hosted subscription through Stripe (performance of a contract). To keep the service secure, diagnose errors and prevent abuse (our legitimate interest, balanced against your rights). To measure site traffic and improve the product (legitimate interest, or your consent where local law requires it). To comply with accounting and tax obligations (legal obligation).

4. The self-hosted edition

When you run the self-hosted Docker image, your accounts, projects, source texts and translations are stored in your own database, on your own server. We do not receive, see or process that data — the instance never sends it to us.

The one exception is error reporting: by default a self-hosted instance sends anonymous crash and error reports to Sentry, using our project, so that we learn about bugs affecting every instance including yours. An administrator can turn this off entirely by setting SENTRY_KEY=off. The self-hosted licence purchase itself (your email and payment) is processed by us and by Stripe exactly as described in this policy.

5. AI translation processing

To produce a translation, the source text you submit is sent to a third-party AI provider — Mistral by default on the hosted service, or the provider an administrator configures on a self-hosted instance (which may include OpenAI, Anthropic, Google, or another OpenAI-compatible provider). That provider processes the text to return a translation under its own terms and data-handling practices. Do not submit text you are not permitted to share with that provider.

6. Sub-processors

We use the following sub-processors to run the hosted service:

  • Stripe — payment processing and subscription billing
  • Sentry — error monitoring, for the hosted service and, by default, for every self-hosted instance
  • Mistral (or the AI provider you configure) — generating translations from the text you submit
  • OVH Cloud — hosting the servers the hosted edition runs on, in the EU
  • Datafast — web analytics on i18n-keyless.com

7. Retention

We keep your account data for as long as your account is active, and billing records for as long as accounting and tax law requires. Translation data is kept for as long as your project exists, so it can be served from cache; deleting a project deletes its translation data. Sentry error reports are kept for a limited period under Sentry's own retention settings before automatic deletion.

8. Your rights

If you are in the European Economic Area or a jurisdiction with equivalent law, you have the right to access, correct, delete or export your personal data, to restrict or object to its processing, and to withdraw consent where processing relies on it. To exercise any of these rights, write to .

You also have the right to lodge a complaint with your local data protection supervisory authority.

9. International transfers

Some of our sub-processors operate outside the European Economic Area. Where that is the case, we rely on the safeguards they provide — such as Standard Contractual Clauses — to protect your data during the transfer.

10. Security

Passwords are stored hashed, not in plain text. Traffic to the dashboard and the API is encrypted in transit. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable technical and organisational measures to protect your data.

11. Children

The service is intended for developers and businesses, not for children. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy from time to time. We will change the "Last updated" date above when we do.