Summary
- Your PDF files stay on your device. They are never uploaded to our servers.
- Only the text you choose to translate is sent to our server and passed to a machine translation service. We do not store it.
- There is no registration and we do not ask for your name or email. With paid access you get a secret key. The server keeps a hash of the key, your orders, your balance and a log of balance changes. These records are linked to each other, so treat them as data about you, not as anonymous.
- To keep free translation to a fair amount a day and a month, the site puts one small cookie on your device the first time the reader is opened. The server counts the characters used against a one-way code made from it, never against your address or your name.
- Automatic deletion is not implemented yet. The retention table below says what is kept and how to have it deleted.
Status of paid access
Paid access is being introduced. Until it is switched on for everyone, the sections about keys, orders and payments describe how it will work and do not yet apply to you. They are published now so the rules are in place before the first purchase.
What stays on your device
Documents, reading position, extracted text, translations and saved terms are stored in your browser (IndexedDB). Interface settings are stored in the browser (localStorage). Nothing in this paragraph is sent to us. You can delete any document with everything related to it in the library, or clear the site data in your browser settings. If you save your library to a file, the file is created on your device and is not sent to us. It contains your documents, translations and terms, and no access key, so keep it as private as the documents themselves.
Free translation limits
Free translation is limited per day and per month. To count it without accounts, the site sets one cookie, pl_dev, the first time the reader is opened: a random number, kept for one year, sent only to this site and not readable by scripts. The server does not store the number itself, only one-way codes made from it and from your connection, together with how many characters were used today and this month. It does not store your IP address, and these records cannot be matched to a key, an order or a document. Records that nobody has used for 45 days are deleted automatically. The cookie is strictly necessary for this limit; the site has no advertising or tracking cookies.
Access keys and recovery codes
- The access key is a secret that lets a device use your paid quota. The recovery code replaces a lost key. Both are generated on our server and shown to you once, when you buy. We cannot show them again.
- The server stores only keyed hashes of them, never the key or the code themselves. A hash cannot be turned back into the secret, but it identifies the key when you present it.
- In your browser the key is kept in memory of the open tab and disappears when you reload. It is written to the browser storage (localStorage) only if you choose "Remember the key on this device". "Remove key" erases it from the device and does not touch your documents, translations or terms. It does not delete anything on the server.
- While you are on the payment page, the new key and the order number are kept in the tab (sessionStorage) so the app can activate the key when you come back. This record is removed when the payment is confirmed or when the tab is closed. The recovery code is never stored by the app.
- The key is sent to our server only in a request header, never in an address. Anyone who has your key can spend your quota: keep it private.
What the server stores
The table lists everything the server database keeps about paid access and the free allowance. It holds no names, emails or accounts.
| Record | What it holds and why |
|---|---|
Access keys | A one-way code of each key and of its recovery code, and when they were issued or replaced, to recognise a key when you present it. |
Orders | Which package, what price, whether it was paid, refunded or waits for a refund, until when it can be paid, and the payment provider's payment number. An unpaid order that passes its payment window is not deleted, because a payment may still arrive. |
Balance | The periods of each purchased package (how many characters, how many are left, when each starts and expires), holds on characters while a translation runs, and a log of every change of the balance with the time. A hold carries a one-way code of the translated text, used to recognise a repeated request; it is not the text, but it could be matched against a text someone already has. |
Deletion requests | A request to delete the records tied to a key, made from the account page: when it was made and whether it has been handled. |
Operator log | What the operator did to records (a manual package, a refund, a handled deletion request), with the written reason. It holds record numbers and the reason, not secrets. |
Free-allowance counters | One-way codes of a device and of a connection, and how many characters were used in the day and in the month. No address, no text, no key. Records unused for 45 days are deleted. |
These records are linked through the key. Together they show when a key was bought, how many characters were used and when. They do not contain your documents, the translated text, your name or your email.
Payments
Payment is handled by a payment provider (to be named here when chosen). You enter your card or bank details, and an email or phone number for the receipt, on the provider's page. We do not receive or store them. The provider tells us only that an order was paid or refunded, the amount and its payment number. The provider keeps your payment data under its own policy. Because the payment number links a payment in the provider's system to an order here, the provider or a support request could be used to tell whose order it is.
Text sent for translation
When you translate a selection, a page, or ask for a simple explanation, the selected text, a small amount of surrounding text from the same document, the chosen languages and your saved terms for that document are sent over HTTPS to our server, which passes them to a third-party machine translation service. The service may process the request outside your country, under its own terms. Our server does not store this text and does not write it to logs. Do not translate content that you are not allowed to share with a third-party service. With a paid key the request also carries the key so the balance can be charged, and the server keeps the hash described above.
Technical data and logs
To protect the service from abuse our server keeps short-lived request counters in memory, and counts the free allowance in its database as described above (not by IP address). Our server logs contain only technical information about requests: time, type, size and outcome. They never contain document text, keys, recovery codes or IP addresses. The hosting provider that runs the server may record IP addresses and request times in its own infrastructure logs under its own policy.
How long data is kept
| Data | Where | How long | How to delete it |
|---|---|---|---|
| Documents, text, translations, terms, reading position | Your device | Until you delete them or clear site data | You: library, or browser settings |
| Interface settings | Your device | Until you clear site data | You: browser settings |
| Access key, if you chose "Remember" | Your device | Until you remove the key or clear site data | You: "Remove key" in the access panel |
| Access key, if you did not choose "Remember" | Memory of the open tab | Until you reload or close the tab | Automatic (the browser) |
| New key and order number during payment | The tab (sessionStorage) | Until the payment is confirmed or the tab is closed | Automatic |
| Recovery code | Not stored by the app | Shown once at purchase | Not applicable |
| Key and recovery hashes, issue times | Server database | No automatic deletion yet. The period is not defined | On request to the contact below (manual) |
| Orders, balance packages, holds, balance log, deletion requests, operator action log | Server database | No automatic deletion yet. The period is not defined; unpaid orders will get an expiry first | On request to the contact below (manual) |
| Translated text | Not stored by our server | In transit only. The translation service handles it under its terms | Not applicable to our server |
| Technical logs (no text, keys or IP addresses) | Server logs | According to the hosting provider's log retention | Not individually |
| Free-allowance counters (one-way codes, characters used today and this month) | Server database | 45 days after last use, then deleted automatically | Automatic |
| Cookie pl_dev (a random number) for the free allowance | Your device | One year, or until you clear cookies | You: clear cookies in your browser settings |
| Card or bank details, receipt email or phone | Payment provider | According to the provider's policy | Ask the provider |
Where a period is marked as not defined, we will set it, together with the rules of the chosen payment provider and our accounting obligations, and update this page before any automatic deletion starts. We do not promise automatic deletion before it exists.
Deleting your data and your rights
- Everything on your device you can delete yourself, as described above.
- Server records tied to your key can be deleted or anonymised on request. You can make the request on your account page while your key is active, which shows that it comes from the holder of the key, or write to the contact below with the recovery code. Deletion is manual, so the request only puts it in our queue. When we carry it out, the key and the recovery code can no longer be used, any unused balance is withdrawn, and the technical fingerprints and operation numbers of your requests are wiped. Records of orders and of balance changes stay without any link to you, except the payment provider's payment number, because payment records may have to be kept.
- We may have to keep records of payments longer than other data, for example to meet accounting obligations. If we keep something, we will tell you what and why.
- Removing the key from the app does not delete anything on the server. Losing a key without its recovery code means we cannot connect the records to you.
Children
The app is intended for students aged 13 and older and does not knowingly collect personal information from children. Paid access is intended for adults.
Contact
To ask a question or to make a request about your data, write to itpampa@yandex.ru.
Changes
We will update this page, and its effective date, before the way the app handles data changes.