Privacy Policy
This explains what data we process, why, on what legal basis, and who else gets to see it. Without omissions — including where that is uncomfortable.
Data controller
The controller for data processing on this website within the meaning of the GDPR is:
Balane GmbH
Balanstraße 84
81541 Munich
Germany
Managing Director: Jonas David Höttler
Email: contact@balane.tech
We have not appointed a data protection officer; we are not legally required to do so.
What data we process
On registration
- Email address
- Password (stored only as a cryptographic hash, never in plain text)
- Time of registration
- Your consent to product emails, if you have given it
When using the service
- Your license record: license key, status, plan, number of seats, renewal dates, and the associated order and subscription IDs at Lemon Squeezy
- Usage data per translation run: token counts, model name, target-language code, a flag indicating whether your own model key was used, and the timestamp
That is all. The contents of your files, the translations and your translation memory never reach our servers — translation runs on your machine. A usage report never contains text, file names or project names.
Automatically, when you open the website
- IP address
- Browser type and version
- Operating system
- Time of access
- Referrer URL
Payment data — card numbers, bank details, PayPal accounts — never reaches our servers at any point. It is processed exclusively by Lemon Squeezy (see section 05).
Purposes and legal bases
- Account and license
- Performance of the contract with you (Art. 6(1)(b) GDPR). Without this data we cannot provide the subscription and license key.
- Usage data
- Performance of the contract and billing of the metered usage (Art. 6(1)(b) GDPR).
- Server logs and security
- Legitimate interest in secure, uninterrupted operation (Art. 6(1)(f) GDPR).
- Product emails
- Your consent (Art. 6(1)(a) GDPR). Revocable at any time with effect for the future.
- Analytics
- Legitimate interest in improving the website (Art. 6(1)(f) GDPR). The measurement is anonymous.
- Session replay
- Your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Nothing is loaded without consent.
- Retention of billing data
- Compliance with legal obligations under commercial and tax law (Art. 6(1)(c) GDPR).
Hosting and technical infrastructure
Application
The website is hosted with Vercel Inc. (USA) and served from data centres that include EU regions. Vercel is a US provider.
Database and authentication
Your account, license and usage data is held with Supabase on servers in Frankfurt, Germany; sign-in also runs through Supabase Auth. The operator is a US company. We store no files and no translations in the database.
License checks and usage metering
Our interface for license checks, usage reports and — when you translate with our model key — the forwarding of requests to the AI model runs on servers at Fly.io in Frankfurt, Germany. The same servers run the hosted engine behind the web app at app.shipglobal.dev: it receives the content of the files you select, translates it and returns it. Neither the source text nor the translations are stored there.
Email delivery
Transactional emails — registration confirmations, password resets, notices about your license and billing — are sent via Brevo, with servers in the EU.
Support
For support requests we use Zammad, an open-source ticketing system that we self-host on a server at Hetzner in Germany. Your enquiries therefore do not leave the EU.
Payment processing via Lemon Squeezy
You do not take out the subscription with us but with Lemon Squeezy, LLC (a Stripe, Inc. company, USA). Lemon Squeezy acts as Merchant of Record — it is the seller, not our processor.
This has a data protection consequence you should know about: Lemon Squeezy is an independent controller for the processing of your payment data. We have no influence over it and conclude no data processing agreement covering it. The Lemon Squeezy privacy policy applies. Lemon Squeezy Privacy Policy
What we receive from Lemon Squeezy
When a subscription is created or changed, Lemon Squeezy reports to us, via an interface, exactly the details we need to issue your license and keep it current:
- the order and subscription IDs,
- the chosen plan and the number of seats,
- your user ID in our system,
- the subscription status and the renewal dates.
We neither receive nor store card details, bank details or billing addresses. Your invoices are issued and kept by Lemon Squeezy.
AI translation
To translate your text, it has to be transmitted to an AI model. That is the core of the service and cannot be avoided.
We currently use models from OpenAI, L.L.C. (USA) exclusively, via their API. The request originates on your machine: with our model key it goes through our interface, with your own key it goes directly to OpenAI without touching our servers. What is transmitted is only the text to be translated — not your name, not your email address, not your payment data.
According to OpenAI, data submitted through the API is not used to train their models. We have concluded a data processing agreement with OpenAI pursuant to Art. 28 GDPR.
Do not translate files containing personal or confidential data that must not reach an AI service in the USA. A localization file normally contains interface strings — check that yours does too.
Your files and content
Where translation runs depends on which product you use. In data protection terms this is the most important point in this policy, so it comes first.
- Desktop app (macOS, Windows)
- Web app (app.shipglobal.dev)
- In the browser there is no program on your machine that could translate. The content of the files you select is therefore transmitted to our hosted engine (api.shipglobal.dev, servers in Frankfurt, Germany), processed there for the duration of the run and returned translated. Nothing is stored there — neither source text nor translations. Your translation memory travels along as JSON and lives between runs in your browser’s IndexedDB, not with us.
- In neither case do we transmit file names, folder structures or project names.
- Usage reports to our servers contain only token counts, model name, target-language code, a flag for your own key and the timestamp — never content.
- We do not use your content to train models and do not pass it on beyond the processors named below.
If your files must not leave your machine at all, use the desktop app. It is the path on which content goes to the AI model and nowhere else.
The desktop app
The desktop app for macOS and Windows talks to our servers at exactly five points. What it transmits there is set out here in full.
- License validation
- On start and before a run, the app asks whether the key is valid and whether metered translation is allowed. Transmitted are the license key and your IP address. Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
- Update check
- The app regularly asks whether a newer version exists. Transmitted are the operating system, processor architecture and installed version, plus your IP address — no license key, no device identifier. Legal basis: Art. 6(1)(b) GDPR and our legitimate interest in secure delivery, Art. 6(1)(f) GDPR.
- Usage report
- After a run using our model key, the app reports token counts, model name, target language code and timestamp — never content, file names or project names. Legal basis: Art. 6(1)(b) GDPR.
- Error report
- If the app crashes, it shows you the report and sends it only if you expressly agree. It contains the error message, app and engine version, operating system and architecture, the tail of the error output and — only if you supply them — your email address, display name and license key for attribution. The report becomes a ticket in our self-hosted Zammad. Legal basis: your consent, Art. 6(1)(a) GDPR.
- Support request
- If you send a ticket from the app, the subject, your message and your email address go to our self-hosted Zammad. Technical details (app and engine version, operating system, architecture, language, license key, last error, log tail) are attached only if you leave the checkbox ticked; the dialog shows exactly the object that is sent. Legal basis: Art. 6(1)(b) GDPR.
What never leaves your machine
- Your localisation files, your project paths and your translation memory.
- Your license key and your own OpenAI key (BYOK): both live in your operating system’s credential store — macOS Keychain, Windows Credential Manager — not in the app’s settings file. If that store is unreachable, they stay in the settings file on your machine; the app says so in its settings.
- Absolute file paths in error messages: the app replaces them with a placeholder before it even shows you the report.
In the desktop app your own OpenAI key is used by the engine on your machine, which talks to OpenAI directly — it never reaches us. In the web app this is necessarily different: there it travels as the x-openai-key header to our hosted engine, which uses it for the run only and neither stores nor logs it.
Obtaining the app from the Microsoft Store
If you obtain the Windows version from the Microsoft Store, Microsoft collects its own data when you download and update — for example your Microsoft account and device data. Microsoft is a separate controller for this; Microsoft’s privacy statement applies. Microsoft privacy statement
Downloading directly from our website avoids this: you download a signed file, and no account with the operating system vendor is required.
The desktop app contains no analytics and no session replay. The section “Cookies, analytics and session replay” concerns the website and the web app only.
Recipients and processors
We have concluded data processing agreements pursuant to Art. 28 GDPR with the following providers. They process data only on our instructions:
- Vercel Inc.
- Application hosting. USA, also served from the EU.
- Supabase
- Database and authentication. Servers in Frankfurt, provider based in the USA.
- Fly.io
- Our hosted engine: license checks, usage metering, forwarding of translation requests via our model key and — on the browser path — processing of the transmitted file content for the duration of the run. Servers in Frankfurt, Germany.
- OpenAI, L.L.C.
- Machine translation of the transmitted text. USA.
- Brevo
- Delivery of transactional email. Servers in the EU.
- Hetzner Online GmbH
- Infrastructure for our self-hosted services (Zammad, OpenReplay). Germany.
- Railway
- Infrastructure for our self-hosted analytics (Umami). EU.
Not a processor, but an independent controller
Lemon Squeezy, LLC processes your payment data as Merchant of Record on its own responsibility. There is therefore no data processing agreement, and one would not be legally correct. See section 05.
Beyond this, we do not pass your data to third parties. We do not sell data. Disclosure to authorities occurs only where we are legally obliged.
Transfers to third countries
Some of the services named are based in the USA. Personal data is therefore transferred to a third country whose level of data protection does not fully match that of the GDPR.
- USA
- Vercel, Supabase (servers however in Frankfurt), OpenAI, Fly.io, Lemon Squeezy (as an independent controller).
- EU and Germany
- Brevo, Hetzner, Railway, and the servers of Supabase and Fly.io.
We base these transfers on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Despite these safeguards a residual risk remains: under certain conditions, US authorities can access data without you having a remedy equivalent to the European one. We say this plainly rather than hiding it behind a formula.
Retention periods
- Account data
- For as long as your account exists.
- License data
- For as long as your account exists.
- Usage data
- As billing evidence, for as long as the statutory retention periods under commercial and tax law run (§ 147 AO, § 257 HGB). This data is blocked from deletion.
- Invoices
- Issued and kept by Lemon Squeezy as the seller, subject to the statutory retention periods.
- Server logs
- Seven days.
- Session replay recordings
- 30 days.
- Analytics
- Aggregated and anonymous, 24 months.
Deletion after inactivity
We delete accounts nobody uses any more. Data minimisation under Art. 5(1)(c) GDPR is not an end in itself — it is the best protection for data nobody needs.
- Accounts with no activity — no login and no active subscription — are marked inactive after 12 months.
- You receive an email 30 days before deletion.
- If there is no response, we delete the account together with its license and usage data, unless retention obligations require otherwise.
- Any login resets the period.
Your local projects and translation memories are not affected — they are with you, not with us.
Cookies, analytics and session replay
Strictly necessary cookies
These cookies are required for operation and are set without consent (§ 25(2) no. 2 TDDDG):
- Session cookie
- Login status and authentication.
- Locale cookie
- Stores your language choice (German or English).
- Theme cookie
- Stores your choice of light or dark appearance.
Umami — analytics without cookies
We self-host Umami on servers in the EU. Umami sets no cookies, stores no IP addresses and builds no cross-site profiles. It records pages visited, referrer, browser, operating system, device type and time on page — fully anonymised.
Because no personal data is processed, no consent is required for this. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
OpenReplay — session replay, only with consent
With your express consent we use OpenReplay to find bugs and usability problems in the application. We self-host it at Hetzner in Falkenstein, Germany. Without consent, OpenReplay is not loaded.
- Recorded
- Mouse movements, clicks, scrolling, navigation path, console and network errors, browser, operating system, screen size, truncated IP address, anonymous session ID.
- Not recorded
- Input in form fields. Passwords and payment data are masked by default.
- Retention
- 30 days, then deleted automatically.
- Legal basis
- Consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. Revocable at any time with effect for the future.
You can withdraw your consent at any time. An overview of all cookies and the settings are here: Cookie settings
Your rights
- Access (Art. 15)
- You can find out what data we process about you.
- Rectification (Art. 16)
- You can have inaccurate data corrected.
- Erasure (Art. 17)
- You can request deletion of your data. You can also delete your account yourself.
- Restriction (Art. 18)
- You can have processing restricted.
- Portability (Art. 20)
- You receive your account and usage data in a common, machine-readable format. Your files and your translation memory need no export — they are already with you.
- Objection (Art. 21)
- You can object to processing based on legitimate interests.
- Withdrawal (Art. 7(3))
- You can withdraw consent at any time with effect for the future.
To exercise your rights, an email is enough: contact@balane.tech
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Website: www.lda.bayern.de
Changes to this policy
We update this policy when the service or the law changes. For material changes — a new AI provider or a new processor, for instance — we notify you by email or in the service.
The current version is always on this page. The date is noted at the top.