TRANSCREATE AI
Global Privacy Policy
Effective date: 2026-09-15 · Version 1.1 (2026-09-15) · Applies to transcreateai.com and the Transcreate AI API
DRAFT TEMPLATE — this document is being reviewed by qualified counsel and any updates will be promptly communicated to our clients.
1. Who We Are and Scope
Transcreate AI ("Transcreate," "we," "us") of Ready-to-Publish Translations, LLC, 902 Secor Rd, Toledo, Ohio, 43623, 347-771-8229, provides an enterprise B2B software-as-a-service platform for AI-assisted translation and transcreation, with optional professional human review (the "Services"). This Policy explains how we process personal data of (i) business users who hold accounts ("Users"), (ii) freelance linguists and project managers who perform human review through the platform ("Workers"), and (iii) individuals whose personal data may appear inside documents our customers submit for processing ("Content Data Subjects").
For Content submitted through the Services, our business customer is the data controller (or "business" under the CCPA) and Transcreate acts as a processor/service provider under the Data Processing Agreement (DPA). This Policy describes our processor practices for transparency; controller obligations toward Content Data Subjects rest with the customer. For User account data and Worker data, Transcreate acts as a controller.
2. Data We Collect
- Account data: name, business email, organization, role, authentication identifiers (via Supabase Auth, including — where an organization has enabled single sign-on — identifiers supplied by the organization's SAML identity provider), and security logs.
- Worker data (linguists and project managers): name, email, language pairs, per-word rates, daily capacity settings, assignment and delivery history, quality and timeliness records, and amounts payable for completed work. Workers are independent contractors; their engagement is governed by a separate contractor agreement.
- Customer Content: documents, text, subtitles, and spreadsheets submitted for translation/transcreation, human-review orders and the reviewed output (including tracked-change edits made by Workers), and the resulting outputs, Translation Memories, and brand glossaries. Content may incidentally contain personal data placed there by the customer.
- Billing data: subscription tier, word-usage metering, payment transactions processed by Stripe, Inc., and — for organizations using invoiced human-review services — the billing identity the organization provides (legal entity name, billing address, tax/VAT ID, invoice recipient emails, purchase-order references) and the invoices we issue against it. We never store full card or bank numbers on our systems.
- Waitlist data: if you ask to be told when a seat opens, we store the email address you gave us, which form on the site you gave it through, the date, and our own notes about where you are in the queue (waiting, invited, joined). There is no other field on the form. We use it to tell you when a seat or the public beta opens, and internally to keep track of who is waiting: a summary of the list is emailed weekly to the person who runs the pilot, and to nobody else. Legal basis: consent (GDPR Art. 6(1)(a)), given by submitting the form, which states at the point of submission exactly what we will send. Every message carries a one-click unsubscribe, and you do not need a message to use it: write to hello@transcreateai.com and we will do it for you. Unsubscribing stops the messages immediately and marks the entry as unsubscribed. We then keep the address, and nothing else about it, on a do-not-contact basis — so that a later form submission cannot quietly put you back on the list, which is what deleting the entry outright would allow. If you would rather it were erased altogether, say so in the same email and we will delete it. We keep an address until you unsubscribe, until you become a customer, or for 24 months from the date you gave it, whichever is soonest.
- Usage data: job telemetry (processing time, token estimates, quality scores), device and log data (IP address, browser type) used for security and service integrity.
- Activity and audit records: a tenant-visible activity log of significant account events (e.g., orders placed, plans approved, settings changed), and audit logs of any access by our support staff to a customer workspace (see §7).
3. How and Why We Use Data
- To provide the Services: running the multi-agent translation pipeline, building your tenant-isolated Translation Memory, enforcing your brand glossary, and operating the human-review workflow — including routing review assignments to ranked, qualified Workers, tracking deadlines, and delivering reviewed output. Legal bases (GDPR): performance of a contract, Art. 6(1)(b); legitimate interests in service security and quality, Art. 6(1)(f).
- To bill and meter usage, and to issue invoices for human-review services (contract performance; legal obligation for tax records).
- To send transactional service email — job offers and assignment notices to Workers, delivery and approval notices, routing alerts, and billing notices. These are part of the Services and are controlled by the notification settings in your account rather than by unsubscribing.
- To tell people on the waitlist that a seat has opened. This is the only marketing email we send, it goes only to addresses that asked for it, and every message carries a one-click unsubscribe that works without signing in to anything. We do not send any other marketing email without a separate lawful basis and an unsubscribe control, and we never add a customer, a User or a Worker to the waitlist list because of their account.
- To secure the platform: fraud prevention, rate limiting, abuse and prompt-injection detection (legitimate interests).
- We do NOT sell or "share" personal data, serve advertising, or use Customer Content for advertising or profiling of any kind.
4. AI Processing, Human Reviewers, and Subprocessors
(a0) Correspondence. Our own mailboxes at transcreateai.com are hosted by Microsoft 365. This is not part of the processing pipeline and no Customer Content is routed there by the Services — but email is storage, not a pipe: anything you send us by email, including an attached document, comes to rest in Microsoft's cloud under our tenancy and stays there subject to our own mailbox retention. Where the content of a job is concerned we ask you to use the platform rather than email, which is better for you as well: a file uploaded to your workspace is covered by your organization's retention setting, and a file emailed to us is not. Note also that this is unrelated to single sign-on — where your organization signs in through its own Microsoft identity provider, that provider is yours and not ours, and we never receive your credentials.
(a) Human reviewers. Where a customer orders human review, vetted freelance linguists and project managers access the specific Customer Content in that order solely to perform the requested review. Workers are bound by written confidentiality and data-protection obligations (contractor agreement and NDA) before receiving any assignment, see commercial terms on a need-to-know basis only (Workers do not see customer pricing), and access is limited to their assigned orders.
(b) AI subprocessors. Customer Content is processed by large language model and OCR subprocessors solely to generate the requested output, on API terms that prohibit retention for training. Current subprocessors: [Cohere Inc. — LLM inference and embeddings]; [Google LLC — LLM inference via Vertex AI (Gemini), global endpoint]; [LlamaIndex Inc. (LlamaCloud) — document OCR/parsing]; [Supabase Inc. — database, authentication, storage]; [Stripe, Inc. — payments]; [Postmark (AC PM International/ActiveCampaign) — transactional email]; [Render, Inc. — application hosting for the API and background workers]; [Vercel, Inc. — hosting for the web application]; [Upstash, Inc. — rate-limit counters keyed by user identifier or, for unauthenticated requests, a non-reversible token derived from the caller's address; these never receive Customer Content]; [Functional Software, Inc. d/b/a Sentry — application error monitoring, which receives stack traces and error metadata for failed requests; request bodies, headers, cookies, query-string values and stack-frame variables are removed before transmission, and direct contact identifiers in the remaining text are replaced with placeholders]; [Backblaze Inc. — off-site backup storage, which receives only the encrypted nightly database archive and an encrypted copy of your uploaded files, and holds no key to either; file and folder names are encrypted too, so it cannot read what a file is called]; [Microsoft Corporation — email hosting for Transcreate AI's own mailboxes (hello@, support@ and awada@ at transcreateai.com); receives whatever a customer or Worker chooses to send us by email, including attachments, and stores it in our tenancy]. The live subprocessor list, with processing locations, is maintained at https://transcreateai.com/legal/dpa and changes are notified per the DPA.
4A. Tenant Isolation of Language Assets; Prohibition on AI Model Training; Service Improvement
(a) Customer Language Assets. All Translation Memory entries, sentence alignments, brand glossaries, terminology databases, brand-voice profiles, linguistic rules, and any derivatives generated from Customer content within the Services (collectively, "Customer Language Assets") are and shall remain the exclusive property of the Customer organization to which they pertain.
(b) Strict Tenant Isolation. Customer Language Assets are stored and processed exclusively within logically isolated, tenant-scoped partitions keyed to the Customer's unique organization identifier and protected by row-level access controls. Customer Language Assets are never commingled with, made retrievable by, or used to generate output for, any other customer or tenant of the Services.
(c) No Foundation-Model Training. Transcreate AI shall not — and shall contractually ensure that its subprocessors (including any provider of large language models, embeddings, or optical character recognition) do not — use Customer Content or Customer Language Assets to train, fine-tune, retrain, calibrate, or otherwise improve any foundational, general-purpose, or third-party artificial intelligence or machine-learning model, whether during the term of the agreement or after its termination. Customer Content is submitted to model providers solely for real-time inference, and no Customer Content or Customer Language Asset is incorporated into model weights, training corpora, or evaluation datasets of any third-party model. Transcreate AI configures each model provider to the strictest data-handling terms that provider makes available to it, and discloses the resulting position: optical character recognition is performed on a zero-retention basis, with no provider-side caching of the submitted document; large language model inference is performed with provider-side training use disabled, and prompts and outputs may be retained by the provider for a limited period (not exceeding 30 days) solely for the provider's detection of abuse and policy violations, after which they are deleted. Transcreate AI does not authorise, and no provider is permitted, any other use of Customer Content. Where a provider offers a contractual zero-retention mode, Transcreate AI will enable it and update the subprocessor list in §4(b) accordingly.
(d) Internal Service Improvement (limited; opt-out after pilot program). Separately from (c), Transcreate AI may use the linguistic corrections its own engaged Workers make to AI output during paid human review — after removal of customer identifiers, names, and any customer-specific terminology — in aggregated, de-identified form, solely to improve the quality of the Services (for example, internal quality heuristics and review guidance). This program never includes Customer glossaries, Translation Memories, brand-voice profiles, or any Customer Language Asset; never discloses one customer's content to another; and never feeds any third-party or foundation model. Nor does it produce one: the outputs of this program are written guidance, checklists and rule-based heuristics used by our own people and our own pipeline, and nothing arising from it is used to train, fine-tune or otherwise fit the parameters of any machine-learning model, ours or anyone else's. Concretely, what this program produces is material that is READ WHEN A PROMPT IS ASSEMBLED or by a person doing a review — terminology entries, do-not-translate rules, style and tone guidance, and reviewer checklists. No weights are altered, no model is fitted, and no artefact of this program is submitted to any provider as training data. That is a commitment about the method and not only about the data, so that our public statement that your content never trains a model is true without qualification. Any organization may opt out of this program entirely once its pilot period has ended (participation during a pilot is part of the pilot terms), in which case nothing arising from that organization's orders is used; the opt-out is honored platform-wide and fails closed (if an organization's status cannot be read, its data is not used).
(e) Quality control sampling. We keep the model input and output for steps that failed, were retried, or needed a fallback, so we can work out what went wrong. We also keep a random sample of about 5% of ordinary steps so our own linguists and engineers can check quality. Before the sample is stored, we automatically replace direct contact details — email addresses, phone numbers, web addresses and long account or order numbers — with placeholders. That is pseudonymization, not anonymization: the text is still your content, it stays in your organization's tenant, only our authorized personnel can read it, it is never shown to another customer and never used to train any third-party model, and it is deleted on your retention schedule — 90 days unless your organization has set a different period, and in no case longer than that schedule. Tell us and we will exclude your organization from the 5% sample; the diagnostic retention for failed steps still applies, because without it we cannot fix what broke.
(f) Survival; Deletion. This Section survives termination. Upon termination or upon Customer's verified request, Customer Language Assets will be exported to Customer in a portable format (CSV/TMX) and permanently deleted from production systems within thirty (30) days and from backups within ninety (90) days.
5. Retention
Account data: life of the account plus 24 months. Worker data: engagement records retained as required for tax and contract-law purposes. Customer Content and job outputs: 90 days by default or as configured by your organization — any period from 7 days to 10 years, set in Settings — after which they are purged; Translation Memories and glossaries persist as Customer Language Assets until deleted by the customer. Invoices and billing records: as required by tax law (typically 7–10 years). Activity logs: 24 months. Backups: our encrypted database archives are kept for 90 days; the encrypted off-site copy of your uploaded files follows whatever retention you have configured above, and is erased within 7 days of a file being deleted from the Service — so shortening your retention period shortens the backup copy with it, rather than leaving a longer copy behind. Support-access audit logs — our record of every time our own staff opened your workspace: 24 months, the same window as the activity log, because both answer the question "who touched this account" and both are the evidence in a dispute that is rarely resolved inside a year.
6. International Transfers
We process data in the United States. Where personal data is transferred across borders we use recognized safeguards: EU/UK Standard Contractual Clauses (Modules 2 and 3) with transfer impact assessments; the ASEAN Model Contractual Clauses where applicable; and the mechanisms described per jurisdiction in Section 8. Enterprise customers may request regional pinning of Content storage where offered.
7. Security
TLS 1.2+ in transit; AES-256 at rest; tenant isolation enforced by organization-scoped access controls and database row-level security, restated on every read and write; JWT-based authentication with pinned signature algorithms; least-privilege service credentials; logging that excludes Content payloads; share links protected by high-entropy tokens stored only as hashes; support access to customer workspaces is scope-checked and written to an audit log before any data is served — if the audit record cannot be written, access is refused; documented incident response with notification without undue delay (and within 72 hours to controllers where GDPR applies).
8. Your Rights by Region
8.1 European Union / EEA / UK — GDPR & UK GDPR
- Rights: access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and withdrawal of consent; complaint to your supervisory authority.
- Right to be forgotten in an AI context: on a verified erasure request we delete account data and, on controller instruction, the relevant Content, Translation Memory segments, and embeddings derived from them — including from vector indexes — within 30 days (90 days for backups).
- LLM training opt-out: no opt-out is required for model training because Customer Content is never used to train AI models (Section 4A(c)). The internal service-improvement program described in Section 4A(d) uses only de-identified reviewer corrections and offers a full organization-level opt-out.
- No solely automated decisions with legal or similarly significant effects are made about individuals (Art. 22). Automated routing of review assignments to Workers is subject to human oversight (project managers can reassign at any time) and concerns commercial work allocation, not legal effects on data subjects. EU/UK representatives: not appointed. We will appoint representatives under GDPR Art. 27 and the UK GDPR, and name them here, before offering the Services to data subjects established in the EEA or the United Kingdom. Data protection contact: hello@transcreateai.com.
8.2 United States — CCPA/CPRA and State Laws
- We act as a "service provider": we process personal information only per our customer contracts and do not sell or share personal information, nor use it for cross-context behavioral advertising.
- California residents may exercise rights to know, delete, correct, and limit use of sensitive personal information via their employer/our customer, or directly at hello@transcreateai.com for account data. We do not discriminate for exercising rights. "Shine the Light": we do not disclose personal information to third parties for their direct marketing.
8.3 United States — HIPAA (Text PII/PHI Safeguards)
- The Services are not designed for Protected Health Information by default. Customers must not submit PHI unless a Business Associate Agreement (BAA) has been executed with us and with our relevant subprocessors.
- Where a BAA is in place: PHI in submitted text is protected by the Security Rule safeguards described in Section 7, access logging, minimum-necessary handling, breach notification per 45 CFR §§ 164.400–414, and configurable zero-retention of Content after job completion. De-identification per § 164.514 is recommended before submission wherever feasible.
8.4 Singapore — PDPA
- We process personal data as a data intermediary for customers; we honor the Protection and Retention Limitation obligations, notify our customer of data breaches that are notifiable to the PDPC without undue delay (and in any case within the timelines enabling the customer to meet its 3-day PDPC notification duty), and support access/correction requests. Data protection contact: hello@transcreateai.com.
8.5 China — PIPL (Cross-Border Transfer Limitations)
- Customers established in, or targeting individuals in, mainland China are responsible for a lawful cross-border transfer mechanism before submitting personal information to the Services hosted outside China: CAC security assessment (for CIIOs or large-volume handlers), CAC Standard Contract filing, or certification. On request we execute the CAC Standard Contract as overseas recipient and provide the processing details needed for the customer's Personal Information Protection Impact Assessment.
- Separate consent: the customer must obtain the individual's separate consent for cross-border provision where PIPL requires it. We provide data localization options for Enterprise plans where available and honor PIPL rights (access, copy, correction, deletion, portability) through the customer.
8.6 Japan — APPI
- For transfers of personal data of individuals in Japan to foreign third parties, we support the customer's APPI obligations by disclosing our processing locations and safeguards ("information on the foreign country's system") and by contractual measures equivalent to APPI standards. Retained personal data rights (disclosure, correction, cessation of use) are honored via the customer.
8.7 South Korea — PIPA
- We act as an outsourced processor under Art. 26 PIPA with a written outsourcing agreement (the DPA), publishable by the customer as required. Overseas transfer disclosures (items transferred, country, dates/methods, recipient, purposes, retention) are available on request. Breaches are notified to the customer without delay to enable its 72-hour notification duties.
8.8 Brazil — LGPD
- We act as "operador" for Customer Content. Legal bases mirror GDPR (Art. 7). Data subjects may exercise the Art. 18 rights (confirmation, access, correction, anonymization, deletion, portability, information on sharing) via the controller. International transfers rely on ANPD-recognized safeguards including standard contractual clauses. Encarregado: hello@transcreateai.com.
8.9 Mexico — LFPDPPP
- This Policy serves alongside the customer's own "aviso de privacidad". ARCO rights (Acceso, Rectificación, Cancelación, Oposición) may be exercised through the controller; we support them as encargado. Transfers are performed under contractual clauses consistent with Arts. 36–37.
8.10 Canada — PIPEDA
- We apply the ten fair information principles; individuals may request access and correction of personal information under our control via hello@transcreateai.com; we support customer accountability through the DPA and provide breach-of-safeguards records and notifications consistent with PIPEDA's "real risk of significant harm" standard. Quebec Law 25: we support privacy impact assessments for transfers outside Quebec.
8.11 GCC — UAE PDPL, Saudi PDPL, and Regional Frameworks
- UAE (Federal Decree-Law 45/2021), DIFC DP Law 2020, ADGM DPR 2021: processing under documented controller instructions; cross-border transfers to jurisdictions with adequate protection or under appropriate safeguards/contractual clauses.
- Saudi Arabia (PDPL, as amended): transfers outside the Kingdom only per SDAIA regulations (adequacy, standard contractual clauses, or exemptions); breach notification supported within SDAIA timelines (72 hours).
- Qatar, Bahrain, Oman, Kuwait: equivalent contractual safeguards applied; details available on request.
9. Cookies
The web application uses strictly necessary cookies and browser storage for authentication, session security, and user-selected preferences only. We do not use advertising or third-party analytics cookies. Full details — every cookie and storage key, its provider, purpose, and duration — are in our standalone Cookie Policy at https://transcreateai.com/legal/cookies, which forms part of this Policy.
10. Children
The Services are B2B and not directed to anyone under 18; we do not knowingly collect children's data.
11. Changes and Contact
Material changes will be notified to account owners at least 30 days in advance. Contact: hello@transcreateai.com · Data protection contact: hello@transcreateai.com · 902 Secor Rd, Toledo, Ohio, 43623.