TranslateSimple

Legal

Privacy notice

Effective 14 August 2026

This notice explains how TranslateSimple processes information when operating the hosted service. It does not cover data that remains solely inside a customer’s WordPress installation.

Information processed

  • Account information such as the login email address and account status.
  • Connected-site information such as the WordPress site URL, installation identifier, selected languages, and token hashes.
  • Source segments deliberately submitted by a WordPress administrator and the resulting machine translations while a translation job is processed.
  • Operational metadata such as job identifiers, language pairs, character and segment counts, timestamps, states, bounded error codes, quota usage, and security audit events.
  • Stripe customer, subscription, invoice, and billing-status identifiers. TranslateSimple does not receive or store full payment-card details.
  • Information you submit through the support form, such as your name, reply email, topic, optional site URL, and message.
  • Limited technical logs needed for security and reliability. Application logs are designed not to contain source text, bearer tokens, cookies, or magic-login links.

Information not requested from WordPress

TranslateSimple scans supported published public content. Private drafts, form submissions, orders, users, cookies, nonces, passwords, hidden credentials, and full WordPress database contents are not submitted to the hosted translation service.

How information is used

Information is used to authenticate accounts and sites, provide machine translations, enforce plan quotas, process billing, prevent abuse, diagnose failures, answer support requests, and maintain service security. TranslateSimple does not sell customer content or use submitted segments for advertising.

Service providers

Selected source segments are sent to Microsoft Azure Translator or DeepL to produce translations. Stripe processes subscriptions and payments. Cloudflare Turnstile processes limited browser and network information to protect the support form from abuse. Hosting, email, DNS, proxy, and encrypted-backup providers process the minimum operational information needed for their role. Their processing is governed by their own terms and privacy notices.

Retention

  • Acknowledged source and result payloads are deleted from the hosted service within 24 hours.
  • Unclaimed, queued, failed, or provider-outcome-unknown payloads are deleted within 30 days.
  • Raw translation payloads are excluded from logical service backups.
  • Account, site, entitlement, usage, billing, and operational metadata is retained while needed to operate the account, meet security and accounting obligations, or resolve disputes.
  • Final translations and manual edits remain in the customer’s WordPress database and are controlled by that customer.

Cookies and account security

The customer portal uses an HttpOnly, SameSite session cookie after login. Magic-login links are single-use and expire. Site and session tokens are stored as hashes by the hosted service.

Your choices

The customer portal lets an authenticated user review connected sites, disconnect a site, export service-account metadata, cancel or manage billing, and request deletion. Other requests or privacy questions may be submitted through the support form. Some billing or security records may need to be retained where applicable law requires it.

Changes

This notice may change when the service or its providers change. The effective date above identifies the current version.

TranslateSimple

Terms Privacy Support