Privacy policy
Last updated 21 September 2026. Applies to the Native Translate browser extension and the service at api.nativetranslate.app.
Native Translate reads the text of the web pages you choose to translate and sends that text to our servers so it can be translated. This page explains exactly what leaves your device, what we keep, and what we never do.
What the extension sends
- Text segments of the page you translate, with inline formatting replaced by placeholder tags, and the language pair. For the refinement pass of long articles: the page title, the site name and a short summary of the article.
- Hashes of text segments, to ask the shared cache whether a translation already exists before any text is sent.
- Text you choose to translate in an input field, only when you press the translate button or shortcut.
- Account and device data: a random device identifier, the extension version, and, if you sign in, your email address.
- Optional, off by default: content-free telemetry (timings, counts, error codes).
The extension never sends page URLs, cookies, form values, passwords, payment fields, one-time codes, or the full HTML of a page. Banking, health, government, webmail and password-manager sites are off by default until you enable them.
What we keep
- Translations, not source text. Successful translations are stored in an encrypted shared cache keyed by a hash of the source text. An entry becomes servable to other users only after three different devices have submitted the same text, so text unique to you never reaches anyone else and expires within 24 hours. Cache entries expire after 30 days (drafts) or 14 days (refinements). Text from sensitive sites and pages that look authenticated is never written to the shared cache. Privacy mode in the options turns the shared cache off entirely.
- Usage counters: characters translated per day per account or device, to enforce plan limits.
- Request logs with counts, timings, language pairs, model names and error codes, kept for 30 days. They contain no page text.
- Account records: your email address, plan and sign-in times. Session tokens are stored only as salted hashes.
Who processes the text
Translation is produced by third-party language models accessed through OpenRouter (Google, OpenAI, Anthropic, DeepSeek and others). Text segments are sent to them for the sole purpose of translation. We route requests with prompt-logging disabled where the provider offers it and do not allow providers to train on the text under our agreements. Sign-in emails are sent through Resend.
What stays on your device
Your settings, per-site rules, a local translation cache (up to 50 MB) and your session token are stored in the extension's local storage on this browser only. They are never synced to Google or to us. Local-only mode disables the network path of the extension completely; it then uses only the on-device translator built into Chrome, where available.
Your choices
- Use the free trial without an account.
- Sign out from the options page; sign out everywhere by emailing us.
- Turn on privacy mode (no shared cache) or local-only mode.
- Clear the local cache from the options page.
- Delete your account and its data by emailing privacy@nativetranslate.app from the signed-in address. We delete account records within 30 days; anonymised usage counters may be retained.
Legal basis and transfers
We process text to perform the service you request (contract) and account and log data for security and abuse prevention (legitimate interest). Servers are operated in the United States; providers may process text in other countries. Data-processing agreements are in place with our model provider and email provider.
Children
Native Translate is not directed at children under 13 and we do not knowingly collect their data.
Changes
We will post changes here and, for material changes, note them in the extension's release notes.