PalTranslate
PalTranslate Privacy Policy
Last updated: 2026-06-16
Privacy Policy
Effective date: June 16, 2026
This Privacy Policy explains how PalTranslate ("PalTranslate," "we," "us," or "our") handles information when you use the PalTranslate: AI Voice Clone mobile application, its optional system keyboard, and any related services (together, the "Service"). PalTranslate is a real-time, two-way voice interpreter: two people can put one phone on the table, both speak freely, and the app shows live subtitles and speaks each person's words aloud in the other language — and, when you enable it, speaks your words in your own cloned voice. PalTranslate also translates text you type (in the app or with the PalTranslate keyboard) and text seen through your camera.
Because the Service captures speech and can create a personalized synthetic voice from a recording of you, this policy describes biometric data handling in detail (see Section 5). We try to collect as little personal data as we can while still making the Service work, and we explain everything we do collect below in plain English.
If you have questions about this policy, email us at support@inshort.io.
1. Who we are
PalTranslate is the data controller for the personal data described in this policy. For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the "data controller."
Our infrastructure and the third-party processors we use are located in the United States, so your data is processed in the US (see Sections 6 and 10).
2. No account required
PalTranslate does not require you to create a traditional account. You do not give us a name, email, or phone number to use the app.
- Anonymous identity. When you first open PalTranslate we create an anonymous account using Firebase Authentication and store an opaque, device-level user identifier for it. This lets us keep your settings, your subscription entitlement, and (if you create one) your voice clone associated with your device.
- We do not ask you to sign in with a name or email to interpret a conversation.
3. Information we collect
3.1 Microphone audio (live interpreting)
During a live two-person interpreting session, the app captures audio from your device's microphone and streams it in real time (over a LiveKit connection) to a speech-to-text provider (Soniox) and a translation step, so we can produce live subtitles and translated speech.
- Audio is processed in real time to perform the interpretation you requested, and is not retained by us after the session.
- Subtitles and transcripts are shown on your device and are transient — they are not stored as a permanent transcript by us.
3.2 Voice clone (optional — biometric data)
If you choose to enable it, you may record a short voice sample so the Service can create a personalized synthetic voice ("voice clone") via our voice vendor Cartesia. This is biometric data — see Section 5 for the full treatment of consent, purpose, retention, and deletion.
3.3 Camera and images (optional — point-at-text translation)
If you use the point-at-text translation feature, the app uses your camera to capture images of text so it can be recognized (OCR) and translated. These images are transient — captured to perform the translation and not retained by us as a photo library.
3.4 Information we collect automatically
- Device and app information. Device model, OS version, app version, language, time zone, and country (derived from IP).
- Usage events. Product events such as app opens, session starts, feature usage, paywall views, and purchases, collected via Firebase Analytics and PostHog (including sampled session replay of in-app screens). We use these to understand which features work and to improve the app.
- Crash and diagnostic data. Crash reports and basic performance metrics via Firebase Crashlytics.
- Identifiers for advertising. If you grant App Tracking Transparency (ATT) permission, we and our partners may receive your iOS Identifier for Advertisers (IDFA) for install attribution and ad measurement. If you decline ATT, we do not collect the IDFA. See Section 7.
3.5 Purchases
When you buy a subscription, Apple and our subscription manager (RevenueCat) tell us that the purchase happened, what was bought, and the status of your entitlement. We do not see or store your full payment card details.
3.6 Typed text (in-app translator and the PalTranslate keyboard)
Text you type to translate — either in the app's text translator or with the PalTranslate keyboard — is sent over an encrypted connection to our translation provider (Google Cloud Translation) to produce the translation, which is returned to your device. The camera images in Section 3.3 are sent to Google Cloud Vision for text detection and then translated the same way.
3.7 The PalTranslate keyboard and "Full Access"
PalTranslate includes an optional system keyboard you can enable in iOS Settings → General → Keyboard → Keyboards. Because keyboards are a sensitive category, please read this carefully:
- You can type normally without granting Full Access. The keyboard works as a standard keyboard with no network connection until you turn on "Allow Full Access."
- "Full Access" is required only to translate. Translating typed text requires a network connection, and iOS only lets a keyboard reach the network when you grant Full Access. When you enable it and tap Translate, only the snippet of text you chose is sent to our translation provider (Section 3.6), at the moment you tap.
- What the keyboard does NOT do. We do not log, store, or transmit your keystrokes in the background, and we do not collect what you type in password fields. Text leaves your device only for the specific snippet you ask us to translate.
- What we record about keyboard use. When the keyboard has network access we record anonymous, aggregated usage events (for example, that a translation happened, the languages used, and that the keyboard was opened) to measure and improve the feature. These events do not contain what you typed beyond the text needed to perform a translation you requested.
We do not knowingly collect any other categories of personal data, and we do not ask for sensitive information beyond the voice biometric data described in Section 5 (which is optional and only created with your consent).
4. How we use your information
We use the information described above to:
- Provide the Service: authenticate your device, capture and stream your microphone audio for the duration of a session, transcribe and translate speech, render subtitles, and speak translations aloud (in a generic voice, or in your cloned voice if you enabled one).
- Operate the voice clone you opted into, so the app can speak your translations in your own voice.
- Operate billing: verify purchases through Apple and RevenueCat and manage your subscription entitlement.
- Improve the Service: understand how features are used, diagnose crashes and bugs, and prioritize fixes.
- Measure marketing: attribute installs and conversions to advertising campaigns where you have granted ATT permission.
- Comply with legal obligations and protect the rights, safety, and property of users and the public.
5. Voice clone and biometric data
The PalTranslate voice clone is optional. You only create one if you choose to record a voice sample. We treat the voice sample and the resulting synthetic voice model ("voiceprint") as biometric data / biometric identifiers, including for the purposes of the Illinois Biometric Information Privacy Act (BIPA) and as "special category" data under the GDPR.
- Consent. We create a voice clone only after you affirmatively choose to enroll and record a sample. You may only clone a voice that is your own (or a voice you are otherwise authorized to use).
- Purpose. The voiceprint is used for one purpose: to synthesize speech in your own voice so the app can speak your translated words during interpreting sessions. We do not use it to identify you, to advertise to you, or to train general-purpose models, and we do not sell it.
- Where it's stored. The voice model is created and stored by our vendor Cartesia (United States). Cartesia processes it under its own terms and privacy policy.
- Retention. We keep the voiceprint only for as long as you keep the voice clone enabled on your account.
- Deletion / your control. You can delete your voice clone at any time — by unenrolling / deleting the voice clone in the app, or by deleting your account in the app. Either action deletes the voice model from Cartesia. You can also email support@inshort.io to request deletion.
If you are in Illinois, you have specific rights regarding biometric identifiers under BIPA, including the right to know what we collect and how long we keep it, and the right to have it deleted. The information in this Section 5 describes our biometric data retention and destruction practice.
6. Third parties we share data with
We share the minimum amount of data needed for each provider to do its job. We do not sell your personal data.
- Google Firebase (Authentication, Analytics, Crashlytics, and related backend) — anonymous auth, app analytics, and crash reporting. Receives: anonymous account ID, app and device metadata, crash logs, usage events. Policy: firebase.google.com/support/privacy and policies.google.com/privacy.
- Cartesia — voice cloning and text-to-speech. Receives: your voice sample and the resulting voiceprint (biometric data), and translated text to synthesize. Policy: cartesia.ai/legal/privacy.
- Soniox — speech-to-text and translation. Receives: streamed microphone audio during a session, processed in real time. Policy: soniox.com/privacy.
- Google Cloud Translation — translates typed text (in-app translator and the keyboard) and camera text. Receives: the text you ask to translate. Policy: cloud.google.com/terms/cloud-privacy-notice.
- Google Cloud Vision — detects text in camera images for the point-at-text feature. Receives: the image you capture. Policy: cloud.google.com/terms/cloud-privacy-notice.
- LiveKit — real-time audio transport between your device and the interpreting service. Receives: session audio in transit and connection metadata. Policy: livekit.io/privacy.
- PostHog — product analytics and sampled session replay. Receives: usage events, device metadata, and sampled recordings of in-app screens. Policy: posthog.com/privacy.
- Adjust — mobile attribution and analytics. Receives: device identifiers (incl. IDFA when allowed), install/event data, IP. Policy: adjust.com/terms/privacy-policy.
- Meta / Facebook SDK — ad attribution and conversion measurement. Receives: device identifiers (incl. IDFA when allowed), install/event data, IP. Policy: facebook.com/privacy/policy.
- RevenueCat — subscription and entitlement management. Receives: anonymous user ID, purchase events, subscription status, device/platform metadata. Policy: revenuecat.com/privacy.
- Apple (In-App Purchase, SKAdNetwork) — processes payments for subscriptions and provides privacy-preserving ad attribution via SKAdNetwork. Receives: Apple ID, payment, purchase receipt; SKAdNetwork conversion signals. Policy: apple.com/legal/privacy.
We may also share information with professional advisors, with successors in the event of a merger or acquisition, or with authorities where required by law.
7. App Tracking Transparency (ATT) and advertising
On iOS we present Apple's App Tracking Transparency prompt before any tracking that requires it. If you choose "Ask App Not to Track":
- We will not access your device's IDFA.
- Adjust and the Facebook SDK will run in a limited mode that does not link your activity to your identity across other apps and websites.
- Core analytics (crash reporting, product event counts) still operate using non-tracking identifiers, because they are necessary to run the Service.
- Apple's SKAdNetwork may still provide privacy-preserving, aggregate install-attribution that does not identify you.
You can change your choice at any time in iOS Settings → Privacy & Security → Tracking.
8. Data retention
- Live session audio, subtitles, and transcripts: processed in real time and not retained by us after the session ends.
- Typed text and camera images sent for translation: processed to return the translation and not retained by us as a stored history.
- Voice clone (voiceprint): retained only while you keep it enabled; deleted from Cartesia when you delete the voice clone or your account (see Section 5).
- Anonymous account and settings: kept for as long as your anonymous account exists. You can delete your account in-app.
- Logs and analytics events: typically kept for up to 14 months, then deleted or anonymized.
- Purchase and billing records: kept for as long as required by tax and accounting law.
When you delete your account, we delete or anonymize personal data (including your voice clone) within 30 days, except where we must keep it to comply with legal obligations.
9. Security
We use industry-standard measures to protect your data, including TLS in transit, encryption at rest with our cloud providers, scoped credentials for our third-party providers, and access controls for our team. No system is perfectly secure, however, and we cannot guarantee absolute security.
10. International data transfers
PalTranslate and its providers are based in the United States. If you use the Service from outside the US, your personal data will be transferred to and processed in the US. Where required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
11. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data ("right to be forgotten"), including your voice clone.
- Object to or restrict certain processing.
- Receive a copy of your data in a portable format.
- Withdraw consent (including withdrawing consent to biometric processing by deleting your voice clone).
- Lodge a complaint with your local data protection authority.
Biometric data (Illinois / BIPA): if you are an Illinois resident, you have rights regarding biometric identifiers, including the right to know what biometric data we collect, the purpose and retention period, and the right to have it deleted. You can delete your voiceprint at any time in-app (Section 5).
California residents have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right not to be discriminated against for exercising your rights. We do not "sell" or "share" personal information for cross-context behavioral advertising as defined by the CCPA, and we do not knowingly do so for consumers under 16.
To exercise any of these rights, use the in-app account-deletion and voice-clone-deletion options, or email support@inshort.io. We will respond within the time frames required by applicable law. To protect your account, we may need to verify your identity before acting on a request.
12. Children
PalTranslate is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The app is rated 4+ but is not a children's app. We require users to be at least 13 years old, or the minimum age required to consent to the processing of personal data in their country, whichever is higher. If you believe a child has provided us with personal information, contact support@inshort.io and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top and, for significant changes, notify you in-app. Continued use of the Service after a change means you accept the updated policy.
14. Contact us
For privacy questions, requests, or complaints, contact:
- Email: support@inshort.io