LYSETATranslate← Back to home
Legal

Privacy Policy

Last updated: 5 June 2026

1. Who we are

For the purposes of UK GDPR and the Data Protection Act 2018, the data controller for Lyseta Translate is Lyseta Ltd, a company registered in England and Wales (company number 17167358).

Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Privacy enquiries: hello@lyseta.ai.

Where you upload content into the Service that itself contains personal data about your own end users (for example, screenshots of a logged-in user session), you are the controller of that personal data and we act as your processor in respect of it. The section “Your content as your data” below sets out how that works.

2. What data we collect

We collect and store only what is necessary to provide the Service:

  • Account information— your name and email address. Depending on how you signed in, this comes from a magic link (you supply the email), Google or GitHub OAuth (we receive the name and email from the provider), or your company's OIDC single sign-on provider (your company sends us the identifying claims it has agreed to release).
  • Organisation and membership data — the organisations you belong to, your role(s) in each, which languages a translator is assigned to, seat and admin slot counts, billing preferences, and audit metadata such as which admin promoted whom and when.
  • Project content — source strings, translations, glossary entries, screenshots, notes, and translator question-and-answer threads that you and your members add. This is content youcreate and place into our Service; see “Your content as your data” below.
  • Usage data — Lyseta token consumption ledger entries (which features were used, how much, by which member), used to operate the monthly token grant and any top-up balance. This is operational metering, not behavioural analytics.
  • Technical data — your IP address and basic request metadata, held transiently for rate-limiting, security, and abuse prevention. IP addresses are also derived briefly at signup to suggest the correct billing currency and are not retained beyond that.
  • Payment data — handled entirely by Stripe. We never see or store your card details. We do receive a Stripe-issued customer identifier so we can link your organisation to your invoices.
  • Email correspondence — if you email us at hello@lyseta.ai, we retain that correspondence to handle your query.

Your content as your data

Source strings, translations, screenshots, notes, and glossary entries are content you create within an organisation. We process it on your behalf to operate the Service. Where that content incidentally contains personal data of third parties (for example a customer's name visible in a screenshot of your logged-in application), you are the controller of that personal data; we act as your processor under these terms and the Data Processing Addendum implied by your use of the Service. You are responsible for ensuring you have a lawful basis for sharing such content with us, with the translators you invite, and with the AI provider we use (Anthropic), if you choose to enable AI features.

3. Legal bases for processing

We rely on the following legal bases under UK GDPR Article 6:

  • Performance of a contract — account, organisation, project, and subscription data are processed to provide the Service you signed up for. This includes AI-assisted translation and glossary generation where your organisation has enabled them, as these are features of the Service.
  • Legitimate interests— rate-limiting data, security telemetry, aggregate usage counts, and our consumption ledger are processed to keep the Service reliable, secure, and billable. Transactional and onboarding emails (member invites, billing notifications, important Service changes) are sent on the basis of legitimate interests and, where applicable, under the “soft opt-in” exemption in PECR.
  • Legal obligation — billing records are retained to comply with UK tax and accounting requirements.
  • Consent — we ask for explicit consent only where it is the appropriate legal basis under UK GDPR. We do not currently rely on consent for any standard feature of the Service.

4. How we use your data

We use your data only to:

  • Provide, operate, and maintain the Service
  • Process subscriptions, additional seats, and AI token top-ups
  • Meter and enforce AI usage against your monthly grant and top-up balance
  • Send transactional emails: member invites, billing notifications, security alerts, and notifications of important changes to the Service or these terms
  • Provide AI-drafted translations and glossary suggestions when an authorised member triggers them
  • Investigate and respond to suspected abuse, security incidents, or breaches of our terms

We do not send marketing newsletters. We do not sell, rent, or share your personal data with third parties for their own purposes. We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

5. Third-party processors

We use the following processors to operate Lyseta Translate. Each processes personal data only on our instructions, under a data processing agreement:

  • MongoDB Atlas (Ireland, eu-west-1) — primary database. Data is stored in the EU.
  • Vercel (US & global edge) — hosting and background-function execution. Vercel Blob is used to store screenshots as private blobs accessible only through our authorised proxy.
  • Stripe (US & global) — payment processing. Subject to Stripe's Privacy Policy.
  • Anthropic (US)— AI translation and glossary generation, via Anthropic's commercial API. Source strings, glossary entries, notes, and screenshots you submit for AI processing are sent under Anthropic's Privacy Policy and commercial API terms: inputs and outputs are not used to train Anthropic's models, and are retained only for a short period for safety and abuse monitoring before deletion. We do not train, fine-tune, or evaluate any model of our own on the content you submit. AI features are opt-in at the organisation level; if an admin disables AI, no project content is sent to Anthropic.
  • Inngest (US) — durable background job execution for longer-running AI tasks (bulk translation, glossary generation). Job payloads carry organisation, project, and version identifiers so the jobs can run; they do not carry source text directly.
  • Resend (EU region) — transactional email delivery (magic-link sign-in, member invites, billing notifications). Subject to Resend's Privacy Policy.
  • Google & GitHub (US/EU) — OAuth sign-in, if you choose to use them. We receive only the basic profile fields needed to identify you. Subject to Google's Privacy Policy and GitHub's Privacy Statement.
  • Your organisation's OIDC provider(only if your admin configured SSO) — the identifying claims it sends are processed by us under your organisation's direction, not ours.

6. International transfers

Some of our processors are based outside the UK and EEA, principally in the United States (Stripe, Anthropic, Inngest, and parts of Vercel and Google). When we transfer personal data outside the UK, we rely on one or more of the following safeguards under UK GDPR Chapter V:

  • The UK Extension to the EU–US Data Privacy Framework, where the receiving organisation is certified to it (the “UK–US Data Bridge”).
  • Standard Contractual Clauses approved by the UK Information Commissioner, together with the International Data Transfer Addendum, as a fallback.

You can request more information about our transfer mechanisms by emailing us.

7. Data retention

We retain your account and organisation data for as long as your organisation has an active subscription, and we do not automatically purge your data when you cancel — this is so you can resubscribe and resume work without losing translations, screenshots, glossary, or version history. If you want your data permanently deleted, request deletion in writing at hello@lyseta.ai and we will remove your personal data and organisation content within 30 days, except where we are required to retain it for legal or financial reasons (for example billing records retained for up to 6 years in line with HMRC requirements).

If you leave an organisation (without deleting it), your membership row is removed but content you contributed remains with the organisation so the remaining members are not disrupted. If you are the sole member of an organisation and choose to leave, the organisation and its content are deleted as part of that flow.

8. Security

We apply appropriate technical and organisational measures to protect your data, including:

  • Transport encryption (HTTPS) for all traffic to our servers
  • Encryption at rest on our database provider
  • AES-256-GCM encryption of stored OIDC client secrets, with the key held outside the database
  • Private-by-default storage of screenshots, served only through an authorisation-checked proxy
  • Server-enforced per-language and per-role access controls (a translator's scope cannot be bypassed by crafted API calls)
  • Restricted administrative access and audit logging of admin actions
  • Regular dependency updates and security review

No service can guarantee absolute security, but we take our obligations seriously and will notify you and the ICO of any personal data breach that meets the notification threshold under UK GDPR.

9. Your rights

Under UK GDPR you have the right to:

  • Access a copy of the personal data we hold about you
  • Correct data that is inaccurate or incomplete
  • Request deletion of your data (“right to be forgotten”)
  • Restrict or object to how we process your data
  • Port your data to another service
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at hello@lyseta.ai. We will respond within 30 days. Where the personal data in question is content you uploaded into an organisation (for example a translator's name appearing in a glossary entry), you may need to ask the relevant organisation admin first, since we act as a processor for that data rather than its controller.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe we are not handling your data in line with the law. You can contact the ICO at ico.org.ukor on 0303 123 1113. We'd appreciate the chance to address any concern first — please contact us before filing a complaint where possible.

10. Cookies and local storage

We use only strictly necessary cookies and limited browser storage to operate the Service. None of these require consent under PECR or UK GDPR, but we disclose them for transparency:

  • Authentication cookies — set when you sign in, to keep you signed in and to protect the sign-in process. These are essential to use the Service.
  • SSO organisation cookie — a short, signed cookie used during the OIDC sign-in flow to remember which organisation a sign-in attempt is for. Cleared after sign-in completes.
  • Stripe — when you proceed to payment or open the Stripe customer portal, Stripe operates its own checkout pages on its own domain. Stripe may set cookies on those pages for fraud prevention and payment processing, under Stripe's Privacy Policy. We do not set these cookies.

We do not use advertising cookies, third-party tracking cookies, or cross-site profiling. We do not load Google Fonts or other third-party stylesheets that would expose your IP address to a third party for non-essential purposes.

11. Children

The Service is intended for use by professional software teams. We do not knowingly collect personal data from anyone under 16. If you believe someone under 16 has created an account, please contact us and we will promptly delete the account and associated data.

12. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or by displaying a notice in the app. The date at the top of this page shows when the policy was last revised.

HomeTermsPrivacyDPA
© 2026 Lyseta Ltd. All rights reserved. Registered in England and Wales · Company no. 17167358 · 71-75 Shelton Street, London, WC2H 9JQ