This Privacy Policy explains what data Polyglot collects, how we use it, and the choices you have across our command-line tools, website, dashboard, APIs, and GitHub integrations.
This Privacy Policy explains what information Polyglot collects, how we use and protect it, and the choices you have across our command-line tools, websites, dashboard, APIs, and GitHub Apps (together, the “Service”).
When you create an account, we collect your email address. If you authenticate via GitHub or install a Polyglot GitHub App, we receive the GitHub identity and installation metadata needed to connect the selected organization, repositories, and permissions. We store immutable GitHub identifiers, not installation access tokens.
We collect account- and project-linked usage data such as translations requested, API operations, Automation funnel transitions, bounded failure reasons, and service reliability metrics. Managed Check results include revisions, configuration and policy hashes, CLI version, conclusion, counts, paths and locations, categories, remediation, and keyed fingerprints; raw source excerpts are not uploaded with managed findings.
When you request translation, we receive the source strings and context you submit and store the resulting translation memory. After explicit catalog-sync consent, Polyglot Automation also receives catalog keys, source strings, existing translations, document paths, formats, languages, hashes, and related metadata. Publication stores the exact manifest, approved catalog values, verification summary, and approval records needed to create and audit a catalog-only pull request.
The CLI does not send analytics or detection telemetry. Local scan, wrap, check, validate, export, and preview operations stay in your repository. Authenticated translation, catalog synchronization, and managed GitHub workflows send only the data described in this policy for the operation you initiate or consent to.
We use PostHog to understand how our website and dashboard are used (pages visited, features used) and we record product events on our servers when you use the API — for example, a translation request completing or a plan change. We use this data to measure what is working and to improve the product; we do not sell it or share it for advertising. The CLI itself sends no analytics (see CLI telemetry above) — these events describe requests our API necessarily receives in order to serve them.
We use service providers including GitHub for authentication, App installation, webhooks, Actions, Checks, branches, and pull requests; PostHog for product analytics; Stripe for payment processing; Resend for transactional email; and an inference provider for translation generation. Their processing is limited to providing these functions. A current subprocessor list is available on request.
Service data is stored in encrypted PostgreSQL databases and communication between the CLI, API, dashboard, and GitHub uses TLS. GitHub App private keys, webhook secrets, OIDC signing material, and installation tokens are kept in secret storage or process memory and are not persisted in the product database.
Credentials stored by the CLI are saved locally at ~/.config/polyglot/credentials.json on your machine and are never transmitted except as authentication headers.
Polyglot i18n, LLC is based in the United States. We and our service providers process information in the United States and other countries, which may have different data protection laws from where you live.
When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses in our service providers' data processing terms. To request a copy of these safeguards, contact [email protected].
Account and translation-memory data are retained while the account uses the Service. Managed webhook metadata, OIDC exchanges, and credential digests are retained for 30 days; finding details and superseded unreferenced catalog or publication content for 90 days; and bounded run, audit, funnel, and service-level history for 400 days. Content is redacted before longer-lived audit records are removed. Uninstalling a GitHub App revokes future access but does not silently erase required audit history. Organization deletion removes tenant-linked data and analytics; you may request access, export, correction, or deletion through the dashboard or by contacting us.
You have the right to:
We may update this Privacy Policy from time to time. We will notify you of material changes via email. The “last updated” date at the top of this page indicates when the policy was last revised.
For privacy-related questions, contact us at [email protected] .
Start in your terminal
Install the CLI, run a scan, and see exactly what you're missing. Free, no account required.