Skip to content
Legal & compliance

Privacy Policy

How TextSetu collects, uses, shares and protects personal data, and the rights you have over it.

Last updated 2026-07-28

1. Who we are

TextSetu is an independent project providing a translation management platform with an integrated AI translation engine, at textsetu.com and app.textsetu.com.

TextSetu is not an incorporated company. It is built and run by a small team acting in their own names, who are jointly the data controller for the personal data described here.

  • Contact: hello@textsetu.com
  • Data protection officer: none appointed. Given our scale and the nature of our processing we do not believe Article 37 GDPR requires one. We will appoint one if that changes.

We say plainly that we are unincorporated because it affects who you are contracting with and who is accountable for your data. If that matters to your procurement process, talk to us before relying on the service.

Identifying us formally. We do not publish the operators' names or a postal address on this page. If you are a data subject, a supervisory authority or a customer who needs our full legal identity and an address for service: for a data subject request, a regulatory enquiry or a formal notice, email hello@textsetu.com and we will provide them.

2. Two different roles

This distinction determines who is responsible for what.

We are a controller for data about the people who sign up for and administer a TextSetu account: name, email address, authentication details, any billing records and product usage. This policy governs that data.

We are a processor for the content you upload: translation keys, source strings, translated values, glossaries, screenshots and any personal data those happen to contain. You decide what goes in; we process it on your instructions. Where you need a data processing agreement covering that content, email hello@textsetu.com and we will provide one. We do not publish a standing one, because TextSetu is not incorporated and there is no legal entity able to execute it.

3. Personal data we collect

Data you give us

DataPurposeLegal basis (GDPR Art. 6)
Name, email, password hashCreate and secure your accountContract
SSO identifiers from Google, GitHub, GitLab or BitbucketSign-in without a passwordContract
Organisation and team membershipApply access controlContract
Support messagesAnswer your questionLegitimate interests
AI provider API keys, if you supply your ownSend your translation requests to that providerContract
Uploaded organisation and profile imagesDisplay them in the productContract
Billing details, if and when we start chargingTake payment, prevent abuseContract, legal obligation

Data we collect automatically

DataPurposeLegal basis
IP address, browser and device typeSecurity, abuse prevention, debuggingLegitimate interests
Product analytics via PostHog: page views, clicks and other interactions captured automatically, linked to your user ID, email and nameUnderstand and improve the productConsent where required. See the note in Cookies and Local Storage
Error diagnostics via Sentry, which can include your user ID and failing requestDiagnose and fix faultsLegitimate interests
Audit log entries (who changed or approved what, and when)Provide the audit trail the product promisesContract
Browser storageSee Cookies and Local StorageContract for the strictly necessary entries; consent where required for analytics

We do not knowingly collect special category data (health, biometrics, political opinions and the like), and the platform is not designed to hold it.

4. AI processing

This matters more than usual for an AI product, so we state it plainly.

  • When you run an AI translation, the source string and the context the engine assembles (matching glossary terms, translation memory segments, brand voice and per-language instructions) are transmitted to the AI provider you selected.
  • The providers we can route to are Anthropic (Claude), OpenAI, Google (Gemini) and DeepSeek. Which are used depends on the engine configuration your organisation sets. The current list is on our Sub-processors page.
  • If you bring your own provider key, the request is made against your own account with that provider and their terms govern it directly. This is the option we recommend if you have strict data requirements, because it removes us from the commercial relationship entirely.
  • If you use TextSetu platform keys, we make the request on your behalf under our own accounts with those providers. Each provider's own retention and training terms then apply to that request; we have not negotiated bespoke terms with them, so their standard API terms govern.
  • We do not use your content to train our own models, and we do not sell it.
  • AI-generated values are marked as AI-generated in the product and remain subject to whatever approval workflow you configure.

5. Why we use your data

Beyond the purposes in the tables above, we use personal data to operate and secure the service, provide support, comply with law, and, where we rely on legitimate interests, to understand how the product is used so we can improve it. Where we rely on legitimate interests we have assessed that our interest does not override your rights; ask us if you want detail on that assessment.

We will ask for your consent before doing anything materially different from what this policy describes.

6. Who we share it with

  • Sub-processors who run parts of the service for us: hosting, AI providers, email delivery and error monitoring. Each is listed with its purpose and location on our Sub-processors page, and each is bound by a written contract.
  • Other members of your organisation. Anyone with the relevant role can see your name, email and the actions attributed to you in the audit log.
  • Authorities, where we are legally required to disclose. We will tell you unless prevented from doing so.
  • A successor, if TextSetu is later incorporated, sold or transferred. We will notify you before your data becomes subject to a different privacy policy.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

7. International transfers

Personal data reaches processors outside your country. PostHog processes on its US Cloud region, and the AI providers we route to operate globally. Our own infrastructure region is set per deployment.

We are being straight with you here: we have not executed Standard Contractual Clauses with every sub-processor, and we are not in a position to claim a complete Article 46 transfer framework today. If you are transferring EEA, UK or Swiss personal data and need that framework in place before you can use the service, email hello@textsetu.com and let us tell you honestly where we are rather than putting your compliance at risk.

8. How long we keep it

We do not yet run automated retention or deletion schedules. In practice:

DataWhat happens today
Content you uploadKept until you delete it in the product
Account dataKept for as long as the account exists
Audit log entriesKept for the life of the project, because they are the audit trail the product provides
Analytics and error dataKept according to PostHog's and Sentry's own retention settings
Support correspondenceKept in our mailbox

There is currently no self-service account deletion in the product. If you want your account and content deleted, email hello@textsetu.com and we will do it manually. We would rather tell you that than publish a retention schedule we do not actually enforce.

9. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time. You can do most of this directly in the app; otherwise email hello@textsetu.com and we will respond within one month.

In the EEA, UK or Switzerland you may lodge a complaint with your local supervisory authority.

In California you have the right to know, delete, correct and opt out of "sale" or "sharing" of personal information, and not to be discriminated against for exercising those rights. We do not sell or share personal information as the CCPA/CPRA define those terms.

If your content is in TextSetu because your employer or a customer put it there, direct your request to them; as a processor we will refer it on.

10. Security

We maintain technical and organisational measures appropriate to the risk, described on our Security page. No system is perfectly secure. If we become aware of a personal data breach affecting you we will notify you and the relevant authority as required by law.

11. Children

TextSetu is a tool for product and localisation teams and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.

12. Changes

If we make a material change we will notify account holders by email or in the app before it takes effect. The date at the top of this page always reflects the current version.

13. Contact

hello@textsetu.com, or see our Contact page.