Privacy Policy
Last updated: July 8, 2026 · Effective date: July 8, 2026
The full text below is in English, the legally authoritative version.
KAERIS i18n (kaeris.dev) is operated by Viacheslav Fedoruk, an individual entrepreneur based in Ukraine. This policy explains what data we collect, why, and your rights over it. We keep things simple because we collect very little.
1. What data we collect and why
| Data | Why | Stored where | Retention |
|---|---|---|---|
| Uploaded file content | For translation, sent to the AI model (OpenRouter). Format conversion, pseudo-localization and file validation are processed only on our server and are never sent to any third party. | Temp files on server, deleted within 2 hours | Max 2 hours |
| Translation job data (source + output) | Tracking translation progress, letting you download the result | Temporary SQLite database on server, deleted within 2 hours | Max 2 hours |
| Email address | Sending your API key after purchase | orders.json on server | Until deletion request, or 12 months from purchase — then the address is erased and replaced by a one-way fingerprint, which is what still lets you recover your key with the email you paid with |
| Email address (optional sign-up) | Only if you type it into the optional “keep me posted” box after a translation: product news and launch announcements. Separate from a purchase — we never add buyers to this list automatically. | subscribers.jsonl on server | Until you ask us to remove it — email [email protected] and it's gone |
| IP address | Rate limiting and abuse prevention, plus debugging outages. Never linked to your file content and never used for advertising. | Live rate-limit counters are held in memory; your IP is also written to the server's nginx access log, which rotates automatically | In-memory counters until server restart; access log per standard rotation on our server |
| API key | Authentication | api_keys.txt / premium_keys.txt on server | Until you request removal |
| Chat messages | AI support responses (sent to OpenRouter) | Not stored — processed in real time | Not retained |
| Interface preferences | Remembering your UI language, the target languages you last picked, and tool options — plus, if you arrived from a campaign link, which source referred you, so we can tell which channel works | Your browser's localStorage only | Until you clear browser data |
| Aggregate usage counts | Knowing how many people visited, started a translation or bought — per day and per traffic source. Totals only: no profiles, no identifiers, nothing that points back to a person | Counter table on our server | Kept as historical totals |
| Payment data | Processing purchases | Handled by Creem — we never see card details | Creem's policy applies |
We use no cookies and load no third-party trackers. Your browser's localStorage holds only interface preferences — your language, the target languages you last selected, tool options, and the campaign source you arrived from. We do count our own totals (page views, translations started, purchases, split by traffic source) so we know which channels work, but they are day-stamped aggregate numbers: no accounts, no identifiers, no profiles, no cross-site tracking, and nothing that can be traced back to you. We run no advertising trackers; if that ever changes, this page changes first.
2. Third-party sub-processors
To deliver the service we share data with these providers:
| Provider | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| OpenRouter | AI translation & chat (routes to DeepSeek / OpenAI) | File content, chat messages | openrouter.ai/privacy |
| DeepSeek | AI model (free tier) | File content (via OpenRouter) | deepseek.com/privacy |
| OpenAI | AI model (Pro/Scale/Team-API — GPT-4o-mini). Lifetime is BYOK — routed via your own OpenRouter key. | File content (via OpenRouter) | openai.com/policies |
| Google (Gemini) | Read-back QA — the independent back-translation and distortion check that runs only when you enable “Verify meaning” (routed via OpenRouter) | Source strings + translated output (via OpenRouter) | policies.google.com/privacy |
| Creem | Payment processing | Email, order metadata | creem.io/privacy |
| Cloudflare | CDN, DDoS protection, DNS | IP address, HTTP headers | cloudflare.com/privacypolicy |
Important: When you upload a file, its content is sent to OpenRouter for AI translation. Do not upload files containing personal data, passwords, or confidential information not related to UI strings.
3. Legal basis for processing (GDPR)
For users in the European Economic Area, our legal basis is:
- Contract performance — processing your translation request, delivering your API key after purchase
- Legitimate interest — IP-based rate limiting to prevent abuse
- Legal obligation — retaining order records as required by applicable law
4. Your rights
You have the right to:
- Access — request a copy of data we hold about you
- Erasure — request deletion of your email and API key from our records
- Rectification — correct inaccurate data
- Portability — receive your data in a structured format
- Object — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent
To exercise any right, email [email protected]. We respond within 30 days. Deletion requests are honored within 7 days for email and API keys.
5. Data retention
- Uploaded files — deleted from our server within 2 hours of the translation job completing
- Email & order record — retained until you request deletion, or 3 years from last purchase (whichever is sooner), for accounting purposes
- API keys — retained until you request removal; your key stops working immediately upon deletion
- IP addresses — written to our server's access log (to block abuse and debug problems) and rotated away automatically; not stored anywhere else, never linked to your files, never sold or used for advertising
- Optional sign-up email — kept until you ask us to remove it; one email to [email protected] and we delete it
6. Security
We use HTTPS everywhere (TLS 1.2+, enforced by Cloudflare). Data files on our server are permission-restricted. We do not store payment card data — Creem handles all payment processing under PCI-DSS compliance.
7. Children
KAERIS i18n is not directed at children under 13 (under 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has submitted data, contact us and we will delete it promptly.
8. International transfers
Your file content may be processed by OpenRouter, and through it DeepSeek, OpenAI and Google (Gemini, when you enable Verify meaning), on servers located in the United States. These transfers are covered by standard contractual clauses or the providers' own adequacy frameworks. By using the service you acknowledge this transfer.
9. California (CCPA)
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. California residents have the right to know, delete, and opt out of sale — contact us at [email protected].
10. Changes to this policy
We may update this policy. When we do, we update the "Last updated" date at the top. Continued use after changes constitutes acceptance. Material changes will be announced on kaeris.dev.
11. Contact
Email: [email protected]
Website: kaeris.dev
Country: Ukraine