Privacy policy
Your pages are processed in your browser, a copy goes to an AI translation provider for a few seconds, and finished pages are kept for 30 days only if you’re signed in. We don’t sell data and we don’t train models on your uploads.
Last updated 12 September 2026
- Text detection and redrawing happen on your device. Only a copy of the page with numbered boxes is sent to the translation model, through a single-use link that expires in 10 minutes.
- Signed out: nothing about your page is stored. Signed in: the finished page is saved to your library for 30 days, and you can delete it any time.
- We keep: your Google account basics, a history of runs, and a credit ledger. We never see your card number.
- No advertising or analytics trackers. One session cookie.
- You can delete your account yourself; it’s erased after a 14-day grace period.
- 1. Who we are and what this covers
- 2. What we collect
- 3. What happens to the pages you upload
- 4. Why we use your data (legal bases)
- 5. Who we share data with
- 6. Cookies and browser storage
- 7. How long we keep things
- 8. Your rights
- 9. International transfers
- 10. Security
- 11. Children
- 12. Changes to this policy
- 13. Contact
1. Who we are and what this covers
TranslateMyManga is operated by [Operator legal name], [Country / region], who is the data controller for the processing described here. This policy covers the website at https://translatemymanga.com, the browser extension and the API. It doesn’t cover the sites you read comics on — the extension only touches the images you ask it to translate.
2. What we collect
| Category | What exactly | When |
|---|---|---|
| Account | Your Google account ID, email address, display name and profile picture, as provided by Google Sign-In. We store no password. | When you sign in |
| Usage history | For each run: when, which tool, target language, how many pages, how long it took, which model served it, whether it succeeded, the file name you uploaded, and the credits charged. | Every run while signed in |
| Your content | The pages you upload and the results (translated page, extracted text, or cleaned page). See section 3 for exactly where each copy lives and for how long. | Every run |
| Credit ledger | Every credit added or spent, with a reference to the run. | Sign-up, purchases, runs |
| Payments | Handled by our payment processor. We receive the amount, currency, what you bought, a transaction ID and a receipt link — never your full card number. | When you buy |
| Technical | For signed-out use, a one-way hash (SHA-256) of your IP address, used only to count free pages per day — the raw IP is not stored. Whether the request came from a datacenter network (to reduce abuse). Your browser’s user-agent string, attached to your session. | Every request |
| Support email | Whatever you send us when you write in. | When you contact us |
3. What happens to the pages you upload
- Detection runs in your browser. The page is opened locally; a small on-device model finds the speech balloons and text. Nothing has left your computer yet.
- A copy goes to the translation model. Your browser draws numbered boxes on a copy of the page and uploads it to a single-use address on our servers, valid for 10 minutes. Our server hands that address to the AI provider (section 5), receives the translated text, and deletes the temporary copy immediately after — it never waits for the 10 minutes. The providers process the image to produce the translation and, under their API terms, don’t use it to train their models.
- Rendering runs in your browser. The translation is drawn back into the artwork on your device.
- Saving is optional and only for signed-in users. If you’re signed in, the finished page (plus a small thumbnail, or the extracted text for OCR) is uploaded to your library so you can download it later. It is kept for 30 days and then deleted automatically. You can delete it earlier at any time; deleting it never removes the credit ledger entry. Signed-out results exist only in your browser tab.
- Resume after sign-in. If you pick a page and then sign in, the page waits in your browser’s local storage (IndexedDB) for up to 30 minutes so you don’t have to pick it again. It’s not sent to us until the run starts.
4. Why we use your data (legal bases)
- To provide the service you asked for (performance of a contract): processing pages, keeping your library, charging credits, showing your history.
- Our legitimate interests: preventing abuse of the free tier and of welcome credits, keeping the service secure, debugging failures, and keeping business records. We balance these against your interests and don’t use them for profiling.
- Legal obligations: keeping payment records for tax and accounting law, responding to valid legal requests, handling copyright notices.
- Consent: only where we ask for it, e.g. if we ever add optional analytics or marketing email. You can withdraw consent at any time.
We do not sell personal data, and we do not use your content or data to train AI models.
5. Who we share data with
Only the processors we need to run the service, each bound by a data-processing agreement or equivalent API terms:
| Provider | What they do | What they see |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, bot protection, network security | All traffic and stored data; IP addresses at the network edge |
| Google LLC | Sign-in (Google OAuth); backup translation model (Gemini via the Gemini API) | Your Google profile at sign-in; the numbered copy of a page when the backup model is used |
| kie.ai | Primary translation model gateway | The numbered copy of a page, for the seconds it takes to translate |
| Payment processor | Checkout, subscriptions, receipts, refunds | Your payment details and email; we get transaction metadata only |
We may switch or add AI providers to keep the service running; the list above is updated when we do. Beyond processors, we disclose data only if the law requires it, to enforce our terms, or — with notice to you where lawful — if the business is sold or merged. Rights holders who file a valid copyright notice may receive information about the account concerned as the law requires.
6. Cookies and browser storage
| Name / place | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you signed in. Strictly necessary; httpOnly, sent only to our domain. | 30 days, or until you sign out |
| Sign-in state cookie | Protects the Google sign-in handshake against forgery. | Minutes |
| IndexedDB / localStorage | Holds a page you picked while you sign in (30 min); remembers small interface choices. | Stays in your browser; never sent to us |
There are currently no advertising, analytics or social-media trackers on the site, so there is no cookie banner. If we add analytics later we’ll use a privacy-preserving tool or ask first, and update this table.
7. How long we keep things
| Data | Kept for |
|---|---|
| Temporary copy sent to the translation model | Deleted right after the run; hard limit 10 minutes |
| Finished pages / extracted text in your library | 30 days, or until you delete them |
| Run history and credit ledger | Until you delete your account |
| Account profile (Google ID, email, name, picture) | Until you delete your account |
| Sessions | 30 days, or until sign-out |
| Signed-out daily counter (hashed IP) | Per day; old rows are cleared |
| Payment records | As long as tax and accounting law requires (typically 7–10 years), anonymised after account deletion |
| Deleted-account marker | A one-way hash of the Google account ID, kept so that deleting and re-creating an account doesn’t grant welcome credits again. It can’t be turned back into your identity. |
Account deletion: request it from your library. You’re signed out immediately; after a 14-day grace period (sign in again to cancel) we erase your pages, history, ledger, sessions and profile. If you ever paid us, the payment records stay with your name and email removed.
8. Your rights
Wherever you live, you can ask us to access, correct, delete or export your data, to restrict or object to processing based on legitimate interests, and to withdraw consent where processing relies on it. If you’re in the EU/EEA, UK or Switzerland, these are your rights under the GDPR and you may also complain to your local data-protection authority. If you’re in California, you have equivalent rights under the CCPA/CPRA, and the right to know that we don’t sell or “share” personal information for advertising.
Most of this is self-service: your library shows and lets you delete every stored page, the Credits tab is your complete ledger, and account deletion is a button. For an export or anything else, email privacy@example.com from the address on your account; we answer within 30 days and never charge for it.
9. International transfers
Our providers run global networks, and the AI models are hosted in the United States and other countries. Where data leaves the EU/EEA or UK, we rely on the providers’ Standard Contractual Clauses or an adequacy decision. The temporary page copy is the only content that goes to the model providers, and it’s deleted after the run.
10. Security
Everything is served over HTTPS. Stored pages live in private storage that is only reachable through our servers after checking you own them. Sessions are random tokens in an httpOnly cookie. Uploads use single-use addresses. No system is perfectly secure; if we learn of a breach affecting you we’ll tell you and the relevant authority as the law requires.
11. Children
The service isn’t directed at children under 13 (or under 16 where that is the age of digital consent), and we don’t knowingly collect their data. If you believe a child has created an account, email us and we’ll delete it.
12. Changes to this policy
We’ll update this page when our practices change — in particular the provider and cookie tables. The date at the top tells you when. Material changes are announced on the site or by email at least 14 days in advance.
13. Contact
Privacy requests and questions: privacy@example.com. Everything else: hello@example.com. Postal address: [Operator legal name], [Country / region].