Privacy policy
Last updated 11 September 2026
VTranslate is built around one idea: a transcript of unreleased work should reach as few parties as possible. This page lists what the service collects, why, who else receives it, and how long it stays. For the reasoning behind the model labels, read why privacy matters.
Your account
Signing up asks for a nickname, an email address and a password, never your real name. All three are handled by the sign-in service at auth.vtranslate.cc; the application itself never receives your password. The email address is used to identify your account and to send password-reset mail when you ask for it. It is not used for marketing.
Your videos and what is made from them
To run a job the service stores the video you upload or link, extracts its audio, transcribes it, and translates the transcript. The subtitles it produces are kept on the job so you can download them. A burned-in video is kept as a file for the same reason. The source video is deleted 7 days after the job that used it, which leaves time to re-run a failed job without uploading again. The transcript is cached for up to 30 days so that adding a language to the same video later does not transcribe it again.
Model providers
Translation, and sometimes transcription, is performed by the model provider you pick for each job, which necessarily receives the transcript. Every model in the app is labelled for what its provider promises: PRIVATE (not retained, not trained on), TEE (processed inside an attested hardware enclave), or E2EE (encrypted to that enclave end to end). Models with none of these labels are only available when you bring your own provider key, and then that provider's own policy applies to what you send it.
Payments
Credit is bought in Monero. The service records the invoice, the amount and the payment confirmation so it can credit your balance. It does not ask for or store a name, a postal address or card details.
API keys
An API key's secret is shown to you once. The service keeps only a peppered digest of it, which can verify a key but cannot reproduce it.
Operational data
Like any web service, VTranslate processes IP addresses and request logs to deliver pages, stop abuse and diagnose faults. It uses no advertising or analytics trackers. When a browser upload or download fails, it may send a coarse failure fingerprint containing only the operation, stage, artifact type, browser family, size bucket and error class. It contains no account or job identifier, path, URL, raw user-agent, exception text or persistent device identifier; the server retains only aggregate counters. The sign-in service sets the session cookies it needs to keep you logged in. Pages load their fonts from Google Fonts, which sees the request for the font files.
Who else receives data
- The model provider you select for a job, as described above.
- Cloudflare, which carries all traffic to vtranslate.cc.
- Resend, which delivers the password-reset mail you request.
Nothing is sold, and nothing is shared for advertising.
Your choices
You can download your results, revoke API keys, and choose which models see your transcripts. To get a copy of the data held about your account, to correct it, or to have the account and its data deleted, write to [email protected] from the address you signed up with.
Changes
A change to this policy is published on this page with a new date.