Privacy policy
Effective 1 October 2026.
SyncLocale is operated by Altix Code Ltd, a company incorporated in and governed by the law of the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data we collect when you use our website, dashboard and command-line tool (the “Service”), what we collect on your behalf when you submit content for translation, why, how long we keep it, who we share it with, and the rights you have over it. It applies to synclocale.com and the dashboard, CDN and API it links to.
Two different roles are in play throughout this policy, and they matter: for data about you and your account, Altix is the data controller. For the source text and context you submit for translation — which is content from your own application, chosen and written by you — you are the data controller and Altix (together with the sub-processors listed below) is a data processor acting only on your instructions. See “When we process content on your behalf” below.
1. Data we collect about you
When you sign up and use the Service, we collect:
- Account details — your email address, an optional name, your organisation name, and a salted, irreversibly hashed copy of your password. We never store or have access to your actual password.
- Team and permission data — if your account has more than one person on it, we store each member’s email, role (Owner, Admin or Member), who invited them, and when, so an account owner or admin can manage access.
- Billing information — your subscription plan, status, and renewal date. Card and payment details are collected and held by Stripe, our payment processor; we only ever receive a subscription and customer identifier from them, never your card number.
- API credentials — a name and a SHA-256 hash of each API key you issue for the CLI or your CI pipeline. The key itself is shown to you once, at creation, and is not recoverable from what we store.
- Support and account communications — anything you send us by email, including transactional email we send you (password resets, email verification, team invitations, billing receipts).
- Usage and security logs — sign-in timestamps, and a security audit log of membership actions on your account (invitations, role changes, removals, and account deletion requests), each tagged with the actor’s email and the time it happened.
- Technical data — standard web server and request logs (IP address, user agent, timestamps) generated when you use the dashboard, CLI or API, kept briefly for security and abuse prevention.
2. When we process content on your behalf
The reason SyncLocale exists is to store and translate text extracted from your application: the string itself, the namespace and key name you gave it, any developer context notes you wrote to guide the translation, the interpolation tokens it contains (such as {{userName}}), and, optionally, where in your source code it was found. We process this content on your behalf and under your instructions; you remain its controller and are responsible for having the right to submit it, including if it happens to contain personal data of your own users or employees (for example, a default value that embeds someone’s name).
This content is used to:
- Store it as your project’s translation memory, and compile it into the published dictionaries your application fetches at runtime.
- When you trigger AI translation, send the source text and its context notes to a language model so it can produce a translation in your target locale. A translation produced this way is marked as AI-generated and unreviewed until a human on your team marks it reviewed; it is never silently treated as final.
OpenRouter and international transfer
AI translation is performed through OpenRouter, a United States-based routing service. We do not hold a direct contract with an underlying model provider; instead, OpenRouter receives your source text and context notes from us over an encrypted connection and routes the request to whichever underlying model powers the model slug configured for this deployment (currently an Anthropic Claude model), then returns the generated translation to us. This means that when AI translation is used, your submitted content leaves the European Union and Cyprus and is transferred to, and processed in, the United States by OpenRouter and by the model provider it routes to. We rely on OpenRouter’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover this transfer. If you do not want your content to leave the EU for this purpose, do not use the AI-translation feature — entering translations manually through the dashboard or CLI never calls OpenRouter or any model provider.
We deliberately do not send your account credentials, billing information, or team data to OpenRouter — only the specific string content and context you ask to have translated.
Published dictionaries (the compiled, final-text output you explicitly publish) are served from a public, unauthenticated endpoint, because they are meant to be fetched directly by your running application in your users’ browsers — the same way any static asset is public. Only locales and namespaces you have published are served; your unpublished editor content and translation memory are never exposed this way.
3. Why we process it
- To provide, maintain, and secure the Service — operating your dashboard, enforcing plan limits, and preventing abuse.
- To bill you, via Stripe, for a paid subscription you chose.
- To communicate with you about your account, including emails necessary to operate it (verification, password resets, invites, billing receipts) and, if you have not opted out, occasional product updates.
- To maintain a security audit trail of who did what on your account, so account owners and admins can review activity and we can investigate suspected compromise.
- To produce AI-generated translations when you request them, by sending the relevant source text to OpenRouter as described above.
- To comply with our legal and accounting obligations, including tax law.
4. Who we share it with
We do not sell personal data. We share it only with the processors needed to run the Service, each bound by contract to use it solely to provide their service to us:
- OpenRouter, Inc. (United States) — receives source text and context notes to generate an AI translation, and routes the request to the underlying model provider powering the configured model. See section 2 above.
- Stripe, Inc. — payment processing and subscription billing.
- Resend (via its SMTP relay) — delivery of transactional email.
- Cloudflare, Inc. — bot and abuse protection (Turnstile) on our sign-up and password-reset forms.
- Hetzner Online GmbH — our infrastructure host, where our servers and database physically run (EU-located).
Issued invoices are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company.
Some of these processors — notably OpenRouter — are located outside the European Economic Area. Where that is the case, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.
We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Altix, our customers, or others.
5. How long we keep it
- Account data, projects, translation keys, translations and published dictionaries are kept for as long as your account is active.
- Content sent to OpenRouter for a single translation request is not retained by us beyond producing the result; OpenRouter’s own retention for abuse-monitoring purposes is governed by its own policy, published at openrouter.ai/privacy.
- If you delete your account, every project, translation key, translation, published dictionary, API key, and team member’s access is removed immediately and permanently — see “Deleting your account”.
- Invoices already issued remain in our invoicing system independently of your account, for as long as Cyprus tax and accounting law requires us to keep financial records (currently up to seven years).
- Security audit log entries are retained after an account is deleted, because the point of a security log is to survive the event it may need to explain; entries are kept for as long as needed for security, fraud-prevention, and legal purposes.
- Server and request logs are kept briefly (typically a few weeks) and then deleted or anonymised.
6. Deleting your account
Account owners can permanently delete their account from Settings at any time. Doing so:
- Cancels any active subscription immediately — you are not billed again, and lose access right away rather than at the end of the billing period.
- Permanently deletes every project, translation key, translation, and published dictionary on the account, and revokes every API key issued to it.
- Removes every team member’s access to the account immediately.
- Records that the deletion happened, in a log entry that is not deleted with the account (see above).
- Does not affect invoices already issued, which remain in our invoicing system under our legal retention obligations, independently of the deleted account.
This action cannot be undone. The dashboard asks you to type your account’s name to confirm before it proceeds.
7. Cookies
Our own website and dashboard use a single strictly necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies on synclocale.com.
8. Your rights
If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Correct inaccurate data.
- Erase your data, including by deleting your account yourself as described above.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent, where processing relies on it (for example, optional product-update emails).
- Lodge a complaint with your local data protection authority — for Cyprus, the Office of the Commissioner for Personal Data Protection.
To exercise any of these rights, email privacy@altixcode.com. If the data you are asking about is content you submitted for translation rather than your own account, we will direct the request to the account that submitted it, which is the controller for that content, unless they have instructed us otherwise.
9. Security
Passwords are hashed with bcrypt and never stored in plain text. API keys are stored only as a SHA-256 hash and cannot be recovered from the database. Invite and password-reset links use single-use, cryptographically random tokens that are hashed at rest. Traffic to the Service is encrypted in transit with TLS. Access to production infrastructure is restricted to the people who need it to operate the Service.
10. Children
The Service is intended for businesses and professionals and is not directed at, or knowingly used to collect data from, children under 16.
11. Changes to this policy
If we make a material change to this policy — including adding or changing a sub-processor that handles your content, such as OpenRouter — we will notify account owners by email and update the effective date above before the change takes effect.
12. Contact
Altix Code Ltd, incorporated in and governed by the law of the Republic of Cyprus. For any question about this policy or your data, email privacy@altixcode.com.