Privacy Policy

Effective / last updated: 12 September 2026
Plain-language summary: you can use Translator app without an account. We process your speech to translate it, using Google’s Gemini API. Data is stored in the European Union (Frankfurt, Germany). Voiceprints - both speaker labelling and the optional "use my voice" clone - are biometric data, created only with your explicit consent and deletable at any time. Voice cloning is OFF unless you opt in. In a call both cameras stay off until one of you asks and the other says yes, and the picture goes straight from phone to phone, encrypted end to end - we never see or keep it. In a call without translation, which either of you can choose during a call, whatever languages the phones are set to, your voice travels the same way and is never sent to a translation provider at all. In a web browser the call works the same way with two differences worth saying plainly: the camera is on from the start and is your own switch to turn off whenever you like, and a message you type inside a call is translated for the other person and relayed to them without being stored by us. We do not sell your data and do not run ads.

1. Who we are

Translator app (https://lhtranslator.com) is operated by TK Digital Ltd. For any privacy request, contact tomziska@gmail.com.

2. What we collect and why

CategoryWhat & why
Device identityA per-install cryptographic key (a public key) generated on your device. This is a pseudonymous id - it does not contain your name, phone number, or email. You can use the app without creating an account or giving personal details.
Display name (optional)A name you choose for yourself, shown to the people you call and to the people who call you, once you are connected partners, and to nobody else; stored with your account; erased with it. It is entirely optional: you can leave it empty, change it, or clear it at any time in Settings, and everything in the app works the same way without one. When you set it, the people you are already connected partners with see it at the top of a call with you and on the screen when you ring them. It is never shown to a stranger, to someone who has only typed a room code, or to anyone either of you has blocked, and it is not used to identify you anywhere else.
Audio you speak / submitWhen you use a translation feature, your audio is sent to the translation provider (Google Gemini) to be transcribed and translated, then the result is returned to you. In normal use we do not keep that audio on our servers. In a call without translation - a call in which either of you has turned translation off, whatever languages the two phones are set to, so that you simply hear each other speak - your voice is NEVER SENT TO A TRANSLATION PROVIDER at all: it travels directly between the two phones, encrypted end to end, and when the two phones cannot reach each other directly the encrypted packets pass through a relay server of ours without being decrypted. There is nothing there for the quality-recording mode described below to capture either, because that mode records the audio of each translated utterance and a call without translation has none. Separately, we operate a quality-recording mode that is OFF by default and can be switched on only by us, the operator, for the service as a whole. There is no setting for it inside the app, so while it is on it applies to everyone who uses a translation feature. While it is on, the audio of each translated utterance is saved on our EU server together with its transcript and translation, and can be listened to only by the operator through a login-protected admin page. These recordings are not kept for a fixed period: they are held until automatic pruning deletes the oldest ones to stay within fixed limits on how many recordings and how much disk space they may use. You can ask us to erase your recordings at any time (see "Your rights").
Transcripts & translationsThe text produced from your speech and its translation. Saved on your device. It is kept on our EU server only while the quality-recording mode described above is on, in which case it is stored next to the recording (and copied to our EU database) so translation quality can be reviewed. Otherwise the text is produced, returned to you, and not retained by us. A call without translation produces neither a transcript nor a translation, anywhere, because nothing is transcribed: there is no text for us or for anyone else to hold.
Photos you translateWhen you use the "translate a photo" feature, the photo you choose is sent to the translation provider (Google Gemini) to read and translate the text in it, then the result is returned to you. The photo is processed only to perform that translation and is NOT stored on our servers; we do not use your photos for advertising or to identify you.
Family stories you saveIf you use Family Stories and choose to save a story, the recording you made, its transcript, the translations of it, and its summary are stored on our EU server so the people in your family group can play it back later. Unlike the quality recordings above this is something you deliberately save, and it is kept until it is removed. There is currently no delete button for a saved story inside the app: contact us and we will erase it.
Voiceprints (biometric)If you use the optional "who said what" feature, you record a short voice sample per person to create a voiceprint used to label who spoke. This is biometric data, collected ONLY with your explicit consent, used only for speaker labelling, and deletable at any time.
Voice clone (biometric)If you opt in to "use my voice", we create a synthetic copy of YOUR voice (via ElevenLabs) from a short sample you record with explicit consent, used only to read your own translations aloud in your voice. This is biometric data, collected only with your consent, never used to impersonate you elsewhere, and deletable at any time (deleting it also removes it from ElevenLabs).
Connected partnersWhen you and another person finish a paired call, we save one record so your two phones can reconnect later without anyone typing a code again. That record holds only the pair of pseudonymous account ids (see "Device identity" above), when the pairing was created, and when you last connected. That pairing record itself holds no names. The name you see on a partner card is the label YOU gave that person: it is stored only on your own phone, and they cannot set or change it. Separately, and only once the two of you are connected partners, each of you may set a display name for yourself (see "Display name (optional)" above): when the other person has set one, your phone shows THEIR chosen name at the top of a call with them and on the screen when they ring you, and in exactly the same way yours is shown to them. Either of you can clear your own name at any time, and neither of you can set or change the other’s. Tapping Forget on a partner removes the pairing for BOTH of you at once. When that happens we keep a permanent note that this pairing was removed (the two ids and the time), so that restoring one of our backups cannot bring a removed pairing back; pairing again with a fresh code always works. If you Block a partner, we also end any call in progress with them, remove the pairing, and keep a one-way record that you blocked them (the two ids and the time) so the two of you are not reconnected; only you can lift a block you made, and a block record is kept the same durable way a Forget note is. If you turn on Do Not Disturb, we store that choice (your account id and when it ends) so we can stop calls reaching you while it is on. Deleting your account in the app removes your pairings (for both sides), your own block records, and your Do Not Disturb setting. When you delete your account we also tell each person you were connected partners with, once, that the profile they were paired with was deleted, so the partner card left on their phone can say so and offer to pair again with a fresh code; that message carries no name and no reason beyond the fact of the deletion, and it goes only to the people you were connected partners with at that moment. A block record that someone else made to stop you reaching them is kept, so their protection is not undone by your deletion; you can still contact us with any erasure question.
Cameras and voice during a callA call always starts with both cameras OFF. A picture is added only if you tap "Turn on cameras", allow the camera when your phone asks, and the other person says yes; either of you can turn the cameras off at any moment, and the call and its translations carry on exactly as before. While the cameras are on, the picture travels DIRECTLY between the two phones and is encrypted end-to-end (DTLS-SRTP): our servers never see it, never store it, and never process it. If the two phones cannot reach each other directly, a relay server of ours passes the encrypted picture between them - it forwards packets it cannot read, keeps none of them, and runs on our own EU server, so no new outside company is involved in your picture. We do not record what your cameras show and we take no screenshots of it, so there is no picture of you for us to keep or to delete. To use the relay your phone is given a short-lived ticket (valid about an hour) tied to the pseudonymous account id described above and to that one call, so the ticket for one conversation is not a key to another, and the relay keeps only ordinary connection records of the kind covered by "Technical data" below. Connecting two phones directly means each one learns the other’s network address, so nothing about your connection is sent until the other person has said yes - and our server refuses to pass those messages on for an ask that nobody said yes to. THE SAME CHANNEL CARRIES YOUR VOICE in a call without translation: when either of you turns translation off, you hear each other speak, whatever languages your phones are set to, instead of hearing a translation read aloud, and that voice travels directly between the two phones, encrypted end to end, exactly as the picture does. It is never sent to a translation provider. When the two phones cannot reach each other directly the encrypted packets of the picture and the voice pass through the same relay server of ours, which forwards packets it cannot read, keeps none of them, and runs on our own EU server. We do not record your voice in such a call and there is no transcript of it, so there is nothing there for us to keep or to delete. Answering the call is what starts the voice: there is no separate question to answer, because there is nothing extra to agree to. THE SAME CALL CAN NOW BE JOINED IN A WEB BROWSER, from an invitation link, without installing anything, and every promise above is made there too. IN A BROWSER THE CAMERA WORKS DIFFERENTLY FROM THE PHONE AND THIS IS WHAT IT DOES: the camera is on from the start of the call and it is YOUR OWN SWITCH - you turn it off and back on whenever you like, nobody has to agree first, and the other person’s camera is theirs in the same way, so neither of you is ever waiting for the other to say yes. Your browser asks one question for the camera and the microphone, once, as the call starts, and it is the browser’s own question: nothing at all is captured until you allow it there. If you allow the microphone but refuse the camera, the call carries on with voice only and everything else works exactly as before; if you refuse both, nothing is captured at all. While the cameras are on, the picture travels DIRECTLY between the two browsers and is encrypted end-to-end (DTLS-SRTP): our servers never see it, never store it and never process it, and when the two browsers cannot reach each other directly the SAME relay server of ours passes the encrypted picture between them, forwarding packets it cannot read, keeping none of them, on our own EU server, with no new outside company involved. We do not record what your camera shows and we take no screenshots of it, so there is no picture of you for us to keep or to delete. Nothing about your connection - including your network address - is sent to the other person until you are both INSIDE the same meeting: the person who started it has to have sent you its link, and when they have asked to be asked about visitors they have to let you in as well; our server refuses to pass those messages on to anyone who is not in that meeting. What needs nobody’s yes is the CAMERA, which is your own switch as described above. What you SAY in a browser is handled exactly as "Audio you speak / submit" above describes it whenever you are speaking to be translated. AND THE CALL WITHOUT TRANSLATION IS NOW A BROWSER FEATURE TOO, not a phone one: when either of you turns translation off you hear each other’s direct voice in a web browser exactly as you would on a phone, over that same peer-to-peer channel, encrypted end to end, passing unread through our own relay when the two browsers cannot reach each other directly, and it is never sent to a translation provider. We do not record that voice and there is no transcript of it, so there is nothing there for us to keep or to delete.
Typed messages during a callInside a call you can type a message to the other person instead of speaking. What you type is sent to our server, translated into the language the other person is reading by Google Gemini (the same processor named below for speech), and passed to the people in that call and to nobody else; each of you sees your own line as you wrote it and the other person’s line in your own language. A message may be at most 2000 characters and a longer one is refused rather than cut. WE DO NOT STORE THESE MESSAGES: they are relayed as they are typed, no copy of the text is written to our database, our own log of the call records only how many characters a line had and which language it went to, and when the call ends nothing of the conversation remains on our side. What you can still see on your own screen is held by your browser alone and is gone when the call is closed.
Push tokenA Firebase token so we can send the app notifications.
Usage & cost meteringTimestamps, a connection id, and translation/token counts, used to run the service, measure load, and (in future) meter subscription usage.
Technical dataIP address and basic device/app info, used for delivering the service, security, and load balancing. We do NOT use advertising identifiers and we do NOT run advertising or attribution SDKs.

You do not need to provide your name, email, or phone number to use the core translation features.

3. Third parties that process data for us

We share only the data necessary, over encrypted connections, with these processors. We instruct them to process it only to provide the service and not to train their own models on your content. We do NOT sell your data.

ProcessorPurposeData
Google (Gemini API)Speech-to-text, text translation, and photo translation. Audio, text, and any photo you choose to translate are sent to Google’s Gemini API over an encrypted connection to produce the result, then returned.Audio, transcript text, photos you translate
Google Firebase Cloud MessagingPush notifications (e.g. waking the app to start/finish a session).A device push token
Google OAuthSign-in (used for the admin area today; for optional user sign-in when subscriptions launch).Account email / id when you choose to sign in
DigitalOceanHosting of the backend server and database, located in Frankfurt, Germany (EU). The relay used when two phones in a call cannot connect directly runs on this same server of ours, so neither turning on the cameras nor talking without translation adds any new outside company; the relay passes on a picture and voice that are already encrypted end-to-end and cannot read or keep either.All data processed by the service, at rest in the EU. For the camera picture and voice, only encrypted packets passing through, never decrypted and never stored
ElevenLabsOptional voice cloning. If you choose to create a copy of your own voice to read your translations aloud, a short voice sample you record (with consent) is sent to ElevenLabs to create the voice, and the text to be spoken is sent to synthesise speech in that voice.Your voice sample + the text to speak aloud
Sentry (error monitoring)Diagnosing crashes and errors. Enabled only when configured.Technical error/crash data
SlackInternal operational alerts to the operator (e.g. service health). Not used to share your content.Operational/system data

4. Biometric voiceprints

Two optional features use biometric voiceprints, each collected only after you give explicit, specific consent, stored in the European Union (Frankfurt, Germany), and deletable at any time in the app or by contacting us:

Speaker labelling ("who said what") creates a voiceprint from a short recording to label who is speaking. It is used only for speaker labelling.

Voice clone ("use my voice") is OFF by default. If you opt in, you record a short sample of YOUR OWN voice - after passing a liveness check that has you read a randomised phrase, so a covert or pre-existing recording cannot be used - and we create a synthetic copy of your voice via ElevenLabs, used ONLY to read your own translations aloud in your voice. Listeners are told when a voice they hear is AI-generated. You may only clone your own voice; it is never used to impersonate you elsewhere. Deleting it removes it from your phone and from ElevenLabs.

5. Where your data is stored

Your data is stored and processed in the European Union (Frankfurt, Germany). Some processors (e.g. Google) may process data in other regions under appropriate safeguards (such as EU Standard Contractual Clauses).

6. How long we keep it

We keep data only as long as needed to provide the service and meet legal obligations. While quality recording is on, stored recordings are capped and the oldest are pruned automatically; stories you save in Family Stories are kept until they are removed. A connected-partner pairing is kept until either side taps Forget, and the note recording that a pairing was forgotten is then kept permanently so a backup restore cannot undo the removal. We keep no picture from the cameras at all, for any length of time, so there is nothing there to delete. The same is true of your voice in a call without translation: it is never recorded, never transcribed and never sent to a translation provider, so no recording and no text of it exists to be kept or removed.

Deleting your account in the app erases your voice clones (including the copies held by ElevenLabs), your speaker-labelling voiceprints, your usage records, and your stored consent settings. It does not by itself remove quality recordings, saved family stories, or your connected-partner pairings: use Forget in the app to remove a pairing yourself, and contact us and we will erase the rest. Uninstalling the app removes locally stored data.

7. Your rights

Subject to applicable law (including the GDPR), you can: access a copy of your data; correct it; delete it; restrict or object to processing; withdraw consent (e.g. for voiceprints) at any time; and request portability. To exercise any right, contact tomziska@gmail.com. You also have the right to complain to your local data-protection authority.

8. Security

We use encryption in transit, access controls, and EU-based storage. No system is perfectly secure, but we take reasonable measures to protect your data.

9. Children

Translator app is intended for adults (18+). We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.

10. Changes

This policy is generated from our live data-practices configuration and updated whenever those practices change; the date above reflects the latest version. Material changes will be highlighted in the app or here.

Translator app - Terms of Use - Privacy Policy - contact tomziska@gmail.com