Privacy policy

Effective 1 October 2026.

SyncLocale is operated by Altix Code Ltd, a company incorporated in and governed by the law of the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data we collect when you use our website, dashboard and command-line tool (the “Service”), what we collect on your behalf when you submit content for translation, why, how long we keep it, who we share it with, and the rights you have over it. It applies to synclocale.com and the dashboard, CDN and API it links to.

Two different roles are in play throughout this policy, and they matter: for data about you and your account, Altix is the data controller. For the source text and context you submit for translation — which is content from your own application, chosen and written by you — you are the data controller and Altix (together with the sub-processors listed below) is a data processor acting only on your instructions. See “When we process content on your behalf” below.

1. Data we collect about you

When you sign up and use the Service, we collect:

2. When we process content on your behalf

The reason SyncLocale exists is to store and translate text extracted from your application: the string itself, the namespace and key name you gave it, any developer context notes you wrote to guide the translation, the interpolation tokens it contains (such as {{userName}}), and, optionally, where in your source code it was found. We process this content on your behalf and under your instructions; you remain its controller and are responsible for having the right to submit it, including if it happens to contain personal data of your own users or employees (for example, a default value that embeds someone’s name).

This content is used to:

OpenRouter and international transfer

AI translation is performed through OpenRouter, a United States-based routing service. We do not hold a direct contract with an underlying model provider; instead, OpenRouter receives your source text and context notes from us over an encrypted connection and routes the request to whichever underlying model powers the model slug configured for this deployment (currently an Anthropic Claude model), then returns the generated translation to us. This means that when AI translation is used, your submitted content leaves the European Union and Cyprus and is transferred to, and processed in, the United States by OpenRouter and by the model provider it routes to. We rely on OpenRouter’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover this transfer. If you do not want your content to leave the EU for this purpose, do not use the AI-translation feature — entering translations manually through the dashboard or CLI never calls OpenRouter or any model provider.

We deliberately do not send your account credentials, billing information, or team data to OpenRouter — only the specific string content and context you ask to have translated.

Published dictionaries (the compiled, final-text output you explicitly publish) are served from a public, unauthenticated endpoint, because they are meant to be fetched directly by your running application in your users’ browsers — the same way any static asset is public. Only locales and namespaces you have published are served; your unpublished editor content and translation memory are never exposed this way.

3. Why we process it

4. Who we share it with

We do not sell personal data. We share it only with the processors needed to run the Service, each bound by contract to use it solely to provide their service to us:

Issued invoices are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company.

Some of these processors — notably OpenRouter — are located outside the European Economic Area. Where that is the case, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.

We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Altix, our customers, or others.

5. How long we keep it

6. Deleting your account

Account owners can permanently delete their account from Settings at any time. Doing so:

This action cannot be undone. The dashboard asks you to type your account’s name to confirm before it proceeds.

7. Cookies

Our own website and dashboard use a single strictly necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies on synclocale.com.

8. Your rights

If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to:

To exercise any of these rights, email privacy@altixcode.com. If the data you are asking about is content you submitted for translation rather than your own account, we will direct the request to the account that submitted it, which is the controller for that content, unless they have instructed us otherwise.

9. Security

Passwords are hashed with bcrypt and never stored in plain text. API keys are stored only as a SHA-256 hash and cannot be recovered from the database. Invite and password-reset links use single-use, cryptographically random tokens that are hashed at rest. Traffic to the Service is encrypted in transit with TLS. Access to production infrastructure is restricted to the people who need it to operate the Service.

10. Children

The Service is intended for businesses and professionals and is not directed at, or knowingly used to collect data from, children under 16.

11. Changes to this policy

If we make a material change to this policy — including adding or changing a sub-processor that handles your content, such as OpenRouter — we will notify account owners by email and update the effective date above before the change takes effect.

12. Contact

Altix Code Ltd, incorporated in and governed by the law of the Republic of Cyprus. For any question about this policy or your data, email privacy@altixcode.com.