Privacy Policy
Effective date: July 1, 2026 · Previous version: May 28, 2026
The short version
- We don't sell or share your data with advertisers, and we don't use third-party analytics. No Google Analytics, no tracking pixels, no ad networks.
- By default, your translations are not stored. Audio is recognised on your device and — unless you opt in to Help Improve Unitra — is not sent to our servers; the text of a translation is processed on the fly and discarded as soon as the result comes back.
- Storing your translations is opt-in. If you turn on Help Improve Unitra in Settings › Privacy, we keep what you send for up to 90 days linked to your account so you can review, export, or delete it. After 90 days we permanently sever the link and keep the content de-identified for model improvement: text may be retained for ongoing training, and voice recordings are kept for at most 2 years and then permanently deleted.
- Stripe handles your card details — we never see them. We only receive subscription status.
- You can export or delete your data, or close your account, at any time. Use Settings › Privacy, or email info@unitra.ai. We respond within one month.
1. Introduction
Unitra, Inc. ("Unitra," "we," "us," or "our") operates the Unitra desktop application and cloud services that provide real-time voice translation. This Privacy Policy explains how we collect, use, share, and protect your information when you use our services.
Our legal grounds for each kind of processing are summarised in Section 2. Where the law requires your consent — most importantly, before we can keep your translation text or audio for model improvement — we ask for an explicit, affirmative opt-in. Continuing to use the service is not treated as consent for optional processing. You can review, change, or withdraw your choices at any time in your account settings.
2. Why we are allowed to process your data
Most data protection laws require us to identify a legal ground for each kind of processing. In plain terms:
- To deliver what you signed up for. We process the information needed to translate your requests, manage your account, enforce subscription limits, and bill you. Without this, we couldn't provide the service.
- To keep the service running and safe. We process a small amount of operational information for short-retention server logs, security and abuse prevention, rate-limit enforcement, debugging, and aggregate service-health metrics. The data is minimised, kept only as long as needed for the purpose, and access is restricted. You can object to this kind of processing at any time.
- With your consent, to improve our models. We collect translation text and audio samples for model improvement only when you turn on the single Help Improve Unitra opt-in (Settings › Privacy). It is off by default. You can withdraw it any time; new collection stops as soon as our systems propagate the change — typically within minutes. A request that was already in flight when you withdrew may finish and be stored, but no further samples will be taken after that. (Withdrawing doesn't make our prior collection unlawful, but you can request deletion of what we already collected — see Section 8.)
- To meet our legal obligations. For example, retaining payment records for tax purposes or responding to lawful requests.
Why translation text and audio share a single switch
The text of a translation request and the audio behind it describe the same activity — what you said, and what we returned. They are useful for model improvement only together: a transcript without the matching audio teaches our speech recogniser nothing, and audio without the matching text teaches our translator nothing. We therefore treat them as one processing operation governed by one switch. If you want to allow text contributions but not audio (or vice versa) for your specific account, email info@unitra.ai and we will configure it for you.
Where consent is the legal ground for keeping data, it is the only ground we use; we do not fall back on "legitimate interest" to keep collecting from people who have not opted in or who have opted out.
3. What we collect
What's on by default — at a glance
| Type of data | Goes to our servers by default? | Stored long-term by default? |
|---|---|---|
| Account info (email, display name) | Yes — needed to log in | Yes — until you delete the account |
| Translation text | Yes — to return a translation | No — discarded after the request |
| Audio | No — speech recognition runs on your device | No |
| Translation text & audio (with Help Improve Unitra on) | Yes | Yes — see Section 7 |
| Usage records (counts, language pairs, latency) | Yes | Up to 90 days, then aggregated |
| Crash reports | Yes — on by default (turn off in Settings › Privacy) | Up to 90 days |
| Cross-site analytics, advertising, fingerprinting | No — not collected at all | No |
Account information
When you create an account we collect your email address and display name. Your password is stored using one-way encryption that is intentionally slow to compute, so even in the worst case where our database were compromised, your original password could not be recovered.
Translation data
When you use our cloud translation service, the text content of your translation request is transmitted to our servers and forwarded to the translation model providers listed in Section 6, solely to return a translation. By default — without your explicit opt-in — translation text is processed in real time and is not written to long-term storage. Brief copies may exist for a few seconds (occasionally up to a few minutes) in the components that move the request through the system, and are discarded as soon as the request completes.
If you turn on Help Improve Unitra in Settings › Privacy, translation text you submit after that point is stored in our database under a random reference number rather than your email or name (this is what data-protection law calls "pseudonymisation" — see Section 7). You can review, export, or delete it at any time. Each stored sample also includes a small amount of operational information about how the request was processed — for example, recognition confidence, request timing, and your subscription tier at the time — used solely to evaluate and improve model quality.
Audio
By default, Unitra recognises speech entirely on your device; your audio is not transmitted to our servers. If you turn on Help Improve Unitra (the same single switch described above), short clips of your own microphone audio captured during normal use may be uploaded solely to evaluate and improve recognition accuracy. They stay linked to your account for up to 90 days (you can delete them at any time during that period), after which they are de-identified and retained for at most 2 years before permanent deletion (see Section 7). We never upload audio of other people on your device (for example, teammates on a call). Audio is not used for biometric identification or speaker recognition (see Section 8 for the Illinois-specific commitments).
Usage data
We collect operational information about requests to our cloud services, including:
- Number of translation requests and character counts
- Source and target language pairs
- Your subscription tier and usage against limits
- Timestamps and response latency
- The country your request originated from (2-letter country code only, provided by our edge provider Cloudflare — e.g. "JP", "US") and the identifier of the Cloudflare data centre that handled the request (3-letter code — e.g. "NRT" for Tokyo, "SJC" for San Jose). This is country-level coarse only; we do not collect city, latitude/longitude, or the raw IP address that resolved to this country.
This is used to operate, secure, and optimise the service, and to enforce subscription limits. It is not used to train translation models.
The country and data-centre fields above are used so we can monitor whether the service is healthy in each region (request volume, latency, error rate per region) and route traffic accordingly. They are kept linked to your account for 90 days, after which they are automatically cleared from individual request records; only aggregate per-region statistics survive past that point. We do not use them to build a profile of your movements or to personalise the product.
Device information
We collect basic device information sent with each request, such as your operating system and version (e.g., "Windows 11"), the application version, the type of processor (e.g., "x86" or "Apple silicon"), and a general description of your graphics processor (e.g., "NVIDIA RTX 4070"), when available. We use this to debug platform-specific issues and to understand how the service performs on different hardware.
We do not combine these fields into a stable device identifier; we do not use third-party analytics, tracking pixels, or browser/device fingerprinting. If you have opted in to Help Improve Unitra, a copy of these fields is kept next to each translation sample so we can group quality metrics by device after the sample is no longer linked to your account.
Crash reports
The Unitra desktop application can send a crash report to our servers when something goes wrong. A crash report contains:
- Technical details of the error (such as the error message and where in the application it happened);
- A short list of the actions you took just before the crash;
- A random number that identifies the installation (so we can tell two crashes came from the same copy of the app, without learning who you are);
- Basic device and version information; and
- For the most severe crashes, a small diagnostic snapshot of the application's state at the time it crashed.
Before sending, the crash reporter strips known parts of memory that may hold translation text, audio, or login credentials; we discard any such fields server-side as well. We do not use crash reports to recover translation content.
When it's on. Crash reporting is on by default so we can detect and fix problems across the user base — without it, the only crashes we'd ever see are the ones users take the time to report manually, and most never do. You can turn it off at any time in Settings › Privacy; the change takes effect the next time you start the application.
Why on by default. Crash reports are minimal (no translation text, no audio, no account-identifying data), kept for a short period, and used solely to improve reliability — the same legitimate-interest basis that any responsibly-built productivity application relies on for stability telemetry. If that doesn't sit well with you, the off switch is one click away.
How long we keep it. Up to 90 days. After that we strip the installation identifier and only keep aggregated counts grouped by the type of crash. Crash reports are used solely to fix bugs and measure how reliable each release is — never for marketing, never for training our models.
Payment information
Payments are processed entirely by Stripe. We never receive, store, or have access to your credit-card numbers or bank-account details. We only receive your subscription state and confirmation of payment from Stripe.
4. How we use it
We use the information we collect to:
- Provide the service — process your translation requests, manage your account, deliver subscription features.
- Enforce usage limits — track your usage against your subscription tier.
- Operate and protect the service — rate limiting, abuse prevention, fraud detection, debugging, and aggregate service-health analytics.
- Improve our translation and speech-recognition models — only using data from people who have explicitly turned on Help Improve Unitra.
- Communicate with you — essential account notifications such as password resets, security alerts, and material policy changes.
- Comply with law — respond to lawful requests, enforce our Terms, and meet tax / accounting obligations.
5. Cookies and local storage
Our website (unitra.ai) does not set any first-party cookies and does not use third-party tracking scripts. We do not use analytics services such as Google Analytics.
Our infrastructure provider, Cloudflare, may set a small number of strictly-necessary cookies for security purposes such as bot detection and protection against denial-of-service attacks. These cookies are essential for the service to operate and cannot be disabled.
Technical detail (cookie names)
__cfruid and cf_clearance. See Cloudflare's cookie policy for details.
The Unitra desktop application does not set or read website cookies. It does store a login token locally on your device, the same way websites store sign-in cookies, so you don't have to log in every time you open the app. You can clear it by signing out of the desktop application or by deleting your account.
Do Not Track and Global Privacy Control (GPC): because we don't sell or share data for cross-site advertising and don't track you across other sites, DNT and GPC signals don't change anything about how we handle your data — we already treat it as if those signals were on.
6. Who we share it with
We share data with a limited set of third-party service providers ("sub-processors") solely to provide our core functionality. Each one is bound by a written data-processing agreement that restricts their use of your data to the purposes we specify and requires appropriate security and confidentiality measures.
Our current sub-processors are:
- DigitalOcean, LLC (United States) — application hosting and managed databases. This is where account information, usage records, opted-in translation samples, and consent records are stored.
- Cloudflare, Inc. (United States) — edge network, security and bot protection, hosting for our websites and admin console, and storage for opted-in audio samples and crash diagnostics.
- Google Cloud (United States) — one of the cloud providers that runs our translation models.
- Modal Labs, Inc. (United States) — cloud inference for our speech-recognition and translation models.
- Microsoft Azure (United States) — one of our translation providers.
- OpenAI, L.L.C. (United States) — one of our translation providers; translation text is sent to its API solely to return a translation and is not used to train OpenAI's models. (OpenAI Privacy Policy)
- Stripe, Inc. (United States) — subscription billing and payment processing. (Stripe Privacy Policy)
- Resend (United States) — transactional email delivery for account verification, password resets, security alerts, and billing notifications.
A current, itemised list of sub-processors — including each entity's name, purpose, and processing location — is maintained at unitra.ai/sub-processors. Customers on paid plans may subscribe to update notifications; we will give prior notice of material changes so you have an opportunity to object before the change takes effect.
We do not sell, rent, or share your personal data with advertisers or data brokers. We do not use third-party analytics services. We do not share your data with any parties beyond those described above, except where required by law or to protect the rights, safety, or property of Unitra or others.
7. How long we keep things
We keep personal data only for as long as necessary for the purpose it was collected for.
- Translation text — opted-in users (0–90 days): stored encrypted, with the link to your account replaced by a random reference number ("pseudonymisation"). You can view, export, or delete it at any time in Settings › Privacy.
- Translation text — opted-in users (after 90 days): we permanently sever the link between the sample and your account so we no longer know who it came from. The text content itself, however, may still contain incidental personal information that you happen to have included (for example, a name in a sentence you translated). For that reason we treat the post-90-day dataset as pseudonymised — not "anonymous" — and continue to apply the same security and access controls. We may retain it for ongoing model training and evaluation. If you don't want any of your samples to reach this stage, delete them within 90 days using the controls in Settings › Privacy.
- Translation text — users who have not opted in: not stored beyond the brief processing needed to return a result (typically seconds; at most a few minutes inside the components moving the request through the system).
- Audio — opted-in users (0–90 days): stored encrypted, with the link to your account held as a random reference number ("pseudonymisation"). You can export or delete it at any time in Settings › Privacy.
- Audio — opted-in users (after 90 days): we permanently sever the link between the recording and your account. Because a voice recording is inherently harder to strip of identifying characteristics than text, we do not claim the result is fully "anonymous"; we treat it as de-identified — the account link and request metadata are removed, and the same encryption and access controls continue to apply. In this de-identified state we retain audio solely to train and evaluate our speech-recognition models, for a maximum of 2 years from the date of collection, after which it is permanently and irreversibly deleted. If you don't want any of your recordings to reach this stage, delete them within the first 90 days.
- Usage records: individual request records kept up to 90 days for billing, quota enforcement, and security; afterwards aggregated into anonymous statistics that don't identify you.
- Account data: kept while your account is active. On deletion, removed within 30 days, except a limited set of records we are legally required to keep — for example, payment and tax records for up to 7 years under tax law, and minimal security records to enforce our Terms or defend legal claims.
- Consent records (when you turn data collection on or off, accept Terms or this policy, etc.): retained for the lifetime of your account, and for up to 7 years after account deletion, so we can demonstrate the lawfulness of past data collection if asked by a regulator.
- Feedback you submit: kept up to 3 years for product-improvement analysis, then deleted. Contact details attached to feedback are deleted sooner on request.
- Server logs: our application logs and our hosting provider's request logs are kept on a short rolling schedule (typically two weeks or less) and then automatically deleted. Where feasible, we remove the last segment of any IP address that our application records in logs so it cannot be traced to a specific household; some logs at the infrastructure layer (for example, DDoS-mitigation logs at our edge provider) may retain the full IP for short periods because that is operationally necessary.
- Backups: encrypted database backups are kept on a rolling 30-day schedule. When you delete data from your account, the data is also removed from production immediately, but a copy may still exist in older backups for up to 30 days while those backups age out of the window. During that period the data in backups is locked: it is not accessible to anyone except for disaster-recovery operations (e.g., restoring service after a database failure), is not used for any other purpose, and is not restored to production unless a full system recovery is needed. Once a backup expires, the deleted data is permanently gone with it.
8. Your rights
Depending on where you live, you have most or all of the following rights regarding your personal data. You can use the controls in Settings › Privacy for the most common ones, or email info@unitra.ai for anything else.
- Access: get a copy of the personal data we hold about you.
- Correct it: have inaccurate personal data fixed.
- Delete it: ask us to delete your account and associated personal data, subject to the limited legal-retention exceptions described in Section 7.
- Take it with you: receive your data in a structured, machine-readable format (data portability).
- Restrict processing: ask us to limit how we use your data while a question is being resolved.
- Object: object to processing we do under "legitimate interest."
- Withdraw consent: for the optional Help Improve Unitra collection (which covers both text and audio), at any time. New collection stops as soon as our systems propagate the change — typically within minutes. A request already being processed when you withdraw may complete and be stored, but no further samples will be taken. You can separately ask us to delete what we already collected.
We respond within one month of receiving a verifiable request. For complex requests we may extend this by up to two more months and will tell you within the first month if that applies.
If you believe your rights have been violated, you can complain to your local data protection authority — for example, your national Data Protection Authority in the EEA, the Information Commissioner's Office (ICO) in the UK, or the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland.
Your US state privacy rights
If you are a resident of California, Virginia, Colorado, Connecticut, or another US state with a comprehensive privacy law, you have additional rights including the right to know, delete, correct, port, and opt out of data collection for model training (use the Help Improve Unitra toggle). You also have the right to non-discrimination for exercising your privacy rights.
We do not "sell" or "share" your personal information as those terms are defined under California law, and we do not use your data for cross-context behavioural advertising. We recognise the Global Privacy Control (GPC) browser signal; because we don't sell or share data, receipt of a GPC signal needs no extra action from us.
To exercise these rights, use Settings › Privacy or email info@unitra.ai. We respond within 45 days as required by applicable state law, with one possible 45-day extension where permitted.
Virginia residents have additional rights to opt out of targeted advertising, sale, and certain forms of profiling — none of which we engage in. If we decline a request, you may appeal by replying to our decision; we will respond to the appeal within 60 days.
Voice samples and biometric law (Illinois BIPA and similar)
If you opt in to audio quality improvement, voice samples are collected solely for evaluating and improving speech-recognition accuracy. We commit that:
- Voice samples are not used to identify individuals.
- We do not create or store voiceprints.
- We do not generate persistent voice embeddings (mathematical fingerprints of someone's voice) that could be used to recognise a speaker across recordings. Where intermediate numerical representations exist transiently inside the speech-recognition model, they are computed in memory only and are not persisted, exported, or used for identification.
- We do not share voice samples or any derived data with third parties for biometric-identification purposes.
- Audio samples are linked to your account for at most 90 days, after which we permanently sever that link. In de-identified form they are kept solely to improve speech-recognition accuracy and are permanently deleted no later than 2 years after collection — well within the destruction timeline required by biometric-privacy laws such as Illinois BIPA (which permit retention until the collection purpose is satisfied, and in any event no more than three years after your last interaction). You can delete your own samples at any time during the first 90 days.
Illinois residents: if you would like to allow translation-text contributions but opt out of audio collection specifically, email info@unitra.ai and we will configure that for your account. (You can also turn off the unified Help Improve Unitra switch to stop both at once.)
9. Automated decisions
Unitra does not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects on you. Subscription limits and rate limits are applied uniformly based on your tier and are not based on profiling.
10. Security
We protect your data with industry-standard technical and organisational measures, including:
- All data sent between your device and Unitra is encrypted in transit (the same "https://" lock you see in browsers).
- Translation text you opt in to share is encrypted before it is written to our database. The keys used to encrypt it are stored separately, and only a small set of authorised production systems can use them.
- Your password is stored using a one-way encryption method that is intentionally slow on purpose. Even in the worst case where our database were compromised, your original password could not be recovered.
- Login tokens expire after a short time and we can revoke them at any moment if needed.
- Database connections are encrypted; only internal services on private networks can connect to the database.
- Cloudflare protects our infrastructure from denial-of-service attacks and malicious traffic.
- We rate-limit suspicious activity, log administrative access, and follow the principle of giving each system only the access it strictly needs.
No security control is perfect. We continuously improve our program and welcome responsible disclosures at info@unitra.ai.
If something goes wrong
If we discover a personal data breach, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to your rights, we will also notify affected users without undue delay, within the timelines required by applicable law.
11. Children's privacy
Unitra is a general-audience service. It is not designed for, marketed to, or directed at children, and we do not knowingly collect personal information from anyone below the applicable minimum age — generally 13, or the higher minimum required where you live (for example, 16 in much of the European Economic Area and 14 in certain jurisdictions).
We rely on the assumption that adults are creating their own accounts and on parents and guardians to supervise their children's use of internet services. If we become aware that an account belongs to someone below the applicable minimum age, we promptly delete the account and any associated personal data; the data is also removed from our backups as those backups age out of their retention window (see Section 7). Parents, guardians, or anyone aware of such a case can contact us at info@unitra.ai and we will act on the report without delay.
12. International data transfers
Our services and sub-processors are primarily located in the United States. If you access Unitra from outside the United States — including the European Economic Area, the United Kingdom, or Switzerland — your data will be transferred to and processed in the United States.
Where required by law, we rely on one or more of the following safeguards:
- The EU–US Data Privacy Framework (DPF), its UK Extension, and Swiss–US DPF, where the recipient is certified.
- Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum, where applicable.
- Additional technical and organisational protections — encryption in transit and at rest, access controls, and data minimisation — where the assessment of a particular transfer indicates more is needed.
You may request a copy of the relevant transfer mechanism for a specific sub-processor by emailing info@unitra.ai.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change we will make the updated policy available in the app and on this page, and update the version dates at the top. Where a change expands the scope of processing that relies on your consent — for example, keeping voice samples longer — that new processing does not begin for you until you have reviewed the change and given a fresh, affirmative opt-in in the app. Until you do, we continue to operate under the choices you last confirmed, and any optional collection that depends on the new consent stays paused for your account. You can review, change, or withdraw your choices at any time in Settings › Privacy.
14. Contact
If you have questions about this Privacy Policy or our data practices, or want to exercise any of the rights described above, contact us at:
Unitra, Inc.
Email: info@unitra.ai
We have appointed an internal Privacy Contact who oversees compliance with this policy and handles data-subject requests; the contact above reaches them.
EEA / UK / Swiss residents: if we are required by law to designate a representative in the European Economic Area, the United Kingdom, or Switzerland, we will appoint one and publish their contact details here. In the meantime, please use the privacy email above; we will respond within the same one-month timeframe required of EU-established controllers, and you retain the right to complain to your local data protection authority. We will also formally appoint a Data Protection Officer and publish their contact details here if and when that obligation applies to us.
Legal references
For data protection professionals, regulators, and others who want the underlying statutory references, the table below maps the sections above to the laws they implement.
| Section | Reference |
|---|---|
| Section 2 — legal grounds | GDPR Art. 6(1)(a)–(c) and (f); UK GDPR equivalents |
| Section 2 — consent withdrawal | GDPR Art. 7(3) |
| Section 7 — pseudonymisation framing | GDPR Art. 4(5); Recital 26 |
| Section 7 — storage limitation | GDPR Art. 5(1)(e) |
| Section 8 — data subject rights | GDPR Art. 12(3), 15–22 |
| Section 8 — Virginia appeal right | Va. Code § 59.1-577 |
| Section 8 — California sensitive PI | CPRA § 7027 |
| Section 9 — automated decisions | GDPR Art. 22 |
| Section 10 — breach notification | GDPR Art. 33–34 |
| Section 12 — transfer mechanisms | EU Commission Decision 2021/914 (SCCs); UK IDTA |
| Section 14 — DPO and representative | GDPR Art. 27, 37 |