Privacy Policy

Effective date: July 1, 2026  ·  Previous version: May 28, 2026

The short version

1. Introduction

Unitra, Inc. ("Unitra," "we," "us," or "our") operates the Unitra desktop application and cloud services that provide real-time voice translation. This Privacy Policy explains how we collect, use, share, and protect your information when you use our services.

Our legal grounds for each kind of processing are summarised in Section 2. Where the law requires your consent — most importantly, before we can keep your translation text or audio for model improvement — we ask for an explicit, affirmative opt-in. Continuing to use the service is not treated as consent for optional processing. You can review, change, or withdraw your choices at any time in your account settings.

2. Why we are allowed to process your data

Most data protection laws require us to identify a legal ground for each kind of processing. In plain terms:

Why translation text and audio share a single switch

The text of a translation request and the audio behind it describe the same activity — what you said, and what we returned. They are useful for model improvement only together: a transcript without the matching audio teaches our speech recogniser nothing, and audio without the matching text teaches our translator nothing. We therefore treat them as one processing operation governed by one switch. If you want to allow text contributions but not audio (or vice versa) for your specific account, email info@unitra.ai and we will configure it for you.

Where consent is the legal ground for keeping data, it is the only ground we use; we do not fall back on "legitimate interest" to keep collecting from people who have not opted in or who have opted out.

3. What we collect

What's on by default — at a glance

Type of data Goes to our servers by default? Stored long-term by default?
Account info (email, display name)Yes — needed to log inYes — until you delete the account
Translation textYes — to return a translationNo — discarded after the request
AudioNo — speech recognition runs on your deviceNo
Translation text & audio (with Help Improve Unitra on)YesYes — see Section 7
Usage records (counts, language pairs, latency)YesUp to 90 days, then aggregated
Crash reportsYes — on by default (turn off in Settings › Privacy)Up to 90 days
Cross-site analytics, advertising, fingerprintingNo — not collected at allNo

Account information

When you create an account we collect your email address and display name. Your password is stored using one-way encryption that is intentionally slow to compute, so even in the worst case where our database were compromised, your original password could not be recovered.

Translation data

When you use our cloud translation service, the text content of your translation request is transmitted to our servers and forwarded to the translation model providers listed in Section 6, solely to return a translation. By default — without your explicit opt-in — translation text is processed in real time and is not written to long-term storage. Brief copies may exist for a few seconds (occasionally up to a few minutes) in the components that move the request through the system, and are discarded as soon as the request completes.

If you turn on Help Improve Unitra in Settings › Privacy, translation text you submit after that point is stored in our database under a random reference number rather than your email or name (this is what data-protection law calls "pseudonymisation" — see Section 7). You can review, export, or delete it at any time. Each stored sample also includes a small amount of operational information about how the request was processed — for example, recognition confidence, request timing, and your subscription tier at the time — used solely to evaluate and improve model quality.

Audio

By default, Unitra recognises speech entirely on your device; your audio is not transmitted to our servers. If you turn on Help Improve Unitra (the same single switch described above), short clips of your own microphone audio captured during normal use may be uploaded solely to evaluate and improve recognition accuracy. They stay linked to your account for up to 90 days (you can delete them at any time during that period), after which they are de-identified and retained for at most 2 years before permanent deletion (see Section 7). We never upload audio of other people on your device (for example, teammates on a call). Audio is not used for biometric identification or speaker recognition (see Section 8 for the Illinois-specific commitments).

Usage data

We collect operational information about requests to our cloud services, including:

This is used to operate, secure, and optimise the service, and to enforce subscription limits. It is not used to train translation models.

The country and data-centre fields above are used so we can monitor whether the service is healthy in each region (request volume, latency, error rate per region) and route traffic accordingly. They are kept linked to your account for 90 days, after which they are automatically cleared from individual request records; only aggregate per-region statistics survive past that point. We do not use them to build a profile of your movements or to personalise the product.

Device information

We collect basic device information sent with each request, such as your operating system and version (e.g., "Windows 11"), the application version, the type of processor (e.g., "x86" or "Apple silicon"), and a general description of your graphics processor (e.g., "NVIDIA RTX 4070"), when available. We use this to debug platform-specific issues and to understand how the service performs on different hardware.

We do not combine these fields into a stable device identifier; we do not use third-party analytics, tracking pixels, or browser/device fingerprinting. If you have opted in to Help Improve Unitra, a copy of these fields is kept next to each translation sample so we can group quality metrics by device after the sample is no longer linked to your account.

Crash reports

The Unitra desktop application can send a crash report to our servers when something goes wrong. A crash report contains:

Before sending, the crash reporter strips known parts of memory that may hold translation text, audio, or login credentials; we discard any such fields server-side as well. We do not use crash reports to recover translation content.

When it's on. Crash reporting is on by default so we can detect and fix problems across the user base — without it, the only crashes we'd ever see are the ones users take the time to report manually, and most never do. You can turn it off at any time in Settings › Privacy; the change takes effect the next time you start the application.

Why on by default. Crash reports are minimal (no translation text, no audio, no account-identifying data), kept for a short period, and used solely to improve reliability — the same legitimate-interest basis that any responsibly-built productivity application relies on for stability telemetry. If that doesn't sit well with you, the off switch is one click away.

How long we keep it. Up to 90 days. After that we strip the installation identifier and only keep aggregated counts grouped by the type of crash. Crash reports are used solely to fix bugs and measure how reliable each release is — never for marketing, never for training our models.

Payment information

Payments are processed entirely by Stripe. We never receive, store, or have access to your credit-card numbers or bank-account details. We only receive your subscription state and confirmation of payment from Stripe.

4. How we use it

We use the information we collect to:

5. Cookies and local storage

Our website (unitra.ai) does not set any first-party cookies and does not use third-party tracking scripts. We do not use analytics services such as Google Analytics.

Our infrastructure provider, Cloudflare, may set a small number of strictly-necessary cookies for security purposes such as bot detection and protection against denial-of-service attacks. These cookies are essential for the service to operate and cannot be disabled.

Technical detail (cookie names)
Cloudflare's strictly-necessary cookies are typically named __cfruid and cf_clearance. See Cloudflare's cookie policy for details.

The Unitra desktop application does not set or read website cookies. It does store a login token locally on your device, the same way websites store sign-in cookies, so you don't have to log in every time you open the app. You can clear it by signing out of the desktop application or by deleting your account.

Do Not Track and Global Privacy Control (GPC): because we don't sell or share data for cross-site advertising and don't track you across other sites, DNT and GPC signals don't change anything about how we handle your data — we already treat it as if those signals were on.

6. Who we share it with

We share data with a limited set of third-party service providers ("sub-processors") solely to provide our core functionality. Each one is bound by a written data-processing agreement that restricts their use of your data to the purposes we specify and requires appropriate security and confidentiality measures.

Our current sub-processors are:

A current, itemised list of sub-processors — including each entity's name, purpose, and processing location — is maintained at unitra.ai/sub-processors. Customers on paid plans may subscribe to update notifications; we will give prior notice of material changes so you have an opportunity to object before the change takes effect.

We do not sell, rent, or share your personal data with advertisers or data brokers. We do not use third-party analytics services. We do not share your data with any parties beyond those described above, except where required by law or to protect the rights, safety, or property of Unitra or others.

7. How long we keep things

We keep personal data only for as long as necessary for the purpose it was collected for.

8. Your rights

Depending on where you live, you have most or all of the following rights regarding your personal data. You can use the controls in Settings › Privacy for the most common ones, or email info@unitra.ai for anything else.

We respond within one month of receiving a verifiable request. For complex requests we may extend this by up to two more months and will tell you within the first month if that applies.

If you believe your rights have been violated, you can complain to your local data protection authority — for example, your national Data Protection Authority in the EEA, the Information Commissioner's Office (ICO) in the UK, or the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland.

Your US state privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, or another US state with a comprehensive privacy law, you have additional rights including the right to know, delete, correct, port, and opt out of data collection for model training (use the Help Improve Unitra toggle). You also have the right to non-discrimination for exercising your privacy rights.

We do not "sell" or "share" your personal information as those terms are defined under California law, and we do not use your data for cross-context behavioural advertising. We recognise the Global Privacy Control (GPC) browser signal; because we don't sell or share data, receipt of a GPC signal needs no extra action from us.

To exercise these rights, use Settings › Privacy or email info@unitra.ai. We respond within 45 days as required by applicable state law, with one possible 45-day extension where permitted.

Virginia residents have additional rights to opt out of targeted advertising, sale, and certain forms of profiling — none of which we engage in. If we decline a request, you may appeal by replying to our decision; we will respond to the appeal within 60 days.

Voice samples and biometric law (Illinois BIPA and similar)

If you opt in to audio quality improvement, voice samples are collected solely for evaluating and improving speech-recognition accuracy. We commit that:

Illinois residents: if you would like to allow translation-text contributions but opt out of audio collection specifically, email info@unitra.ai and we will configure that for your account. (You can also turn off the unified Help Improve Unitra switch to stop both at once.)

9. Automated decisions

Unitra does not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects on you. Subscription limits and rate limits are applied uniformly based on your tier and are not based on profiling.

10. Security

We protect your data with industry-standard technical and organisational measures, including:

No security control is perfect. We continuously improve our program and welcome responsible disclosures at info@unitra.ai.

If something goes wrong

If we discover a personal data breach, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to your rights, we will also notify affected users without undue delay, within the timelines required by applicable law.

11. Children's privacy

Unitra is a general-audience service. It is not designed for, marketed to, or directed at children, and we do not knowingly collect personal information from anyone below the applicable minimum age — generally 13, or the higher minimum required where you live (for example, 16 in much of the European Economic Area and 14 in certain jurisdictions).

We rely on the assumption that adults are creating their own accounts and on parents and guardians to supervise their children's use of internet services. If we become aware that an account belongs to someone below the applicable minimum age, we promptly delete the account and any associated personal data; the data is also removed from our backups as those backups age out of their retention window (see Section 7). Parents, guardians, or anyone aware of such a case can contact us at info@unitra.ai and we will act on the report without delay.

12. International data transfers

Our services and sub-processors are primarily located in the United States. If you access Unitra from outside the United States — including the European Economic Area, the United Kingdom, or Switzerland — your data will be transferred to and processed in the United States.

Where required by law, we rely on one or more of the following safeguards:

You may request a copy of the relevant transfer mechanism for a specific sub-processor by emailing info@unitra.ai.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change we will make the updated policy available in the app and on this page, and update the version dates at the top. Where a change expands the scope of processing that relies on your consent — for example, keeping voice samples longer — that new processing does not begin for you until you have reviewed the change and given a fresh, affirmative opt-in in the app. Until you do, we continue to operate under the choices you last confirmed, and any optional collection that depends on the new consent stays paused for your account. You can review, change, or withdraw your choices at any time in Settings › Privacy.

14. Contact

If you have questions about this Privacy Policy or our data practices, or want to exercise any of the rights described above, contact us at:

Unitra, Inc.
Email: info@unitra.ai

We have appointed an internal Privacy Contact who oversees compliance with this policy and handles data-subject requests; the contact above reaches them.

EEA / UK / Swiss residents: if we are required by law to designate a representative in the European Economic Area, the United Kingdom, or Switzerland, we will appoint one and publish their contact details here. In the meantime, please use the privacy email above; we will respond within the same one-month timeframe required of EU-established controllers, and you retain the right to complain to your local data protection authority. We will also formally appoint a Data Protection Officer and publish their contact details here if and when that obligation applies to us.

For data protection professionals, regulators, and others who want the underlying statutory references, the table below maps the sections above to the laws they implement.

Section Reference
Section 2 — legal groundsGDPR Art. 6(1)(a)–(c) and (f); UK GDPR equivalents
Section 2 — consent withdrawalGDPR Art. 7(3)
Section 7 — pseudonymisation framingGDPR Art. 4(5); Recital 26
Section 7 — storage limitationGDPR Art. 5(1)(e)
Section 8 — data subject rightsGDPR Art. 12(3), 15–22
Section 8 — Virginia appeal rightVa. Code § 59.1-577
Section 8 — California sensitive PICPRA § 7027
Section 9 — automated decisionsGDPR Art. 22
Section 10 — breach notificationGDPR Art. 33–34
Section 12 — transfer mechanismsEU Commission Decision 2021/914 (SCCs); UK IDTA
Section 14 — DPO and representativeGDPR Art. 27, 37