Privacy Policy
- Effective:
- 11 August 2026
- Last updated:
- 11 August 2026
- Version
- 1.0
This policy explains what personal information Localizethat handles, why we handle it, and the choices you have. It describes the service as it works today and will be updated as the product changes.
1. Who we are
Localizethat is a localization service operated by AJP Sweden AB (registration number 559516-6967, registered at Torbjörn Klockares gata 14, 113 30 Stockholm, Sweden).
We are the data controller for the personal information we handle to run the service itself: accounts, workspaces, sign-in, billing and credits, support, security and product operation. You can reach us at contact@localizethat.com.
For personal information that a customer chooses to include inside the content they submit for localization, we act on that customer's instructions. That distinction is explained in section 6.
2. Scope of this policy
This policy covers the Localizethat website at localizethat.com and the signed-in Localizethat application, including workspaces, the localization workflow, company context, review links and account settings.
It does not cover third-party sites or services you reach from Localizethat, such as Google, which have their own privacy terms.
3. Information we collect
We collect the following categories, and no others:
- Account information — your email address, the name you enter, the workspace or company name you provide at signup, your time zone and interface language, your notification preferences, and account status.
- Authentication data — your sign-in method (email and password, or Google), the identifier your provider returns, and the session tokens needed to keep you signed in. Passwords are handled by our authentication provider and are never stored by us in readable form.
- Workspace information — which workspaces you belong to, your role, who invited you, when you joined, and when you were last active.
- Invitation information — the email address, optional name and optional message used to invite someone to a workspace, plus the invitation's status and expiry.
- Review information — the email address and optional name of external reviewers you invite, their deadline and status, and the comments, suggested edits and approvals they submit.
- Usage information — localization runs, target languages, model calls, token counts, credits consumed and credit ledger entries, so we can meter usage and show you your activity history.
- Customer content — the material you submit for localization and the company context you build. See section 6.
- Integration information — if you connect Google Drive, we store an encrypted connection record for your user so the import can run.
- Email delivery information — a log of transactional emails we send you, including recipient address, template, delivery status and any error, plus unsubscribe records.
- Support and administrative information — messages you send us, and internal notes and audit entries our staff create when acting on an account.
- Cookie and device information — see section 15 and the Cookie Policy.
We do not run advertising or analytics tracking, and we do not buy or sell personal information.
4. How we use personal information
- To create and operate your account and workspaces, and to authenticate you.
- To deliver the localization service you request, including AI-assisted localization and retrieval of your company context.
- To enable collaboration: workspace membership, invitations, roles, external review links, comments and notifications.
- To meter credit consumption and show usage and activity history.
- To send transactional email: sign-in and account emails, invitations, review requests and reminders, and receipts where relevant.
- To provide support and to investigate and resolve problems.
- To keep the service secure, prevent abuse, and apply rate limits.
- To keep records of who accepted which version of our Terms of Service.
- To comply with legal obligations that apply to us.
5. Legal bases for processing
Where the GDPR applies, we rely on the following legal bases. This mapping is under legal review and may be refined.
- Performance of a contract — creating and operating your account and workspace, delivering localizations, collaboration features, credit metering and transactional email.
- Legitimate interests — securing the service and preventing abuse, debugging and improving reliability, internal administration and support, and keeping records of Terms acceptance. Our interest is operating a reliable and secure service; we balance it against your interests and keep the data involved limited.
- Legal obligation — retaining records we are legally required to keep and responding to lawful requests.
- Consent — only where we ask for it explicitly, for example optional cookies if we ever introduce them. We do not rely on consent for the core service.
6. Customer content
Localizethat lets you submit content for localization: source text you paste or import, uploaded or imported documents, translated segments, finalized output, and the company context you build (brand voice, terminology, approved claims, forbidden claims, market rules and approved language memory). Review comments and suggested edits are also customer content.
That content may itself contain personal information if you choose to include it. We do not require it and we ask you not to include sensitive personal information you do not need localized.
What happens to it, factually: it is stored in our database, scoped to your workspace, and is readable by the members of that workspace with an appropriate role, by external reviewers you invite for the specific language they are reviewing, and by our staff only where necessary to operate or support the service. Source text and the relevant compiled company context are sent to our AI provider to produce the localization and to generate the embeddings used to retrieve context. Finalized translations are written back into your workspace's translation memory so future localizations can reuse them.
Where we handle personal information contained in customer content, we do so on behalf of the customer, acting on their instructions — in GDPR terms, as a processor, with the customer as controller. Business customers who need this in writing will require a separate Data Processing Agreement. A Localizethat DPA is not yet available; contact us if you need one.
We do not sell customer content, and we do not use it to build products for other customers. Your approved language memory stays inside your own workspace.
7. AI and localization processing
Localizethat uses AI models to produce localizations, analyse source content before localizing, and create the embeddings that let us retrieve the right pieces of your company context.
Model calls are routed through the Lovable AI Gateway to Google Gemini models. What we send is: the source content you submitted, the compiled company context relevant to that request, your instructions and target languages, and technical parameters. We do not send your name, email address or account identifiers to the model provider as part of the prompt.
We record the token counts and costs of each call so we can meter credits and show you your usage. That record is stored by us, not by the model provider.
We are documenting model-provider retention, training and processing-location terms and will state them here once verified. Until then we make no claim in either direction about upstream provider retention or training, beyond this: Localizethat itself does not use your content to train models.
8. Workspaces and collaboration
Localizethat is built around shared workspaces. If you join a workspace, other members can see your name, email address, role, join date and activity within that workspace, and the content and context you create there belongs to that workspace rather than to you personally.
Workspace owners and administrators can invite and remove members, change roles, and see workspace-level usage and audit information.
External reviewers are invited by email and reach a specific localization through a private link. They see the content under review and the review history for their language, not the whole workspace.
9. Google and connected services
If you sign in with Google, we receive the basic profile information Google returns for sign-in — your email address, and the name and profile identifier associated with your Google account — and use it to create and authenticate your Localizethat account.
If you connect Google Drive to import a document, we request read-only access. We use it to read the file you select, at the moment you select it, and to import its text into your workspace. We do not write to your Drive, we do not synchronise, and we do not browse or store files you have not chosen to import. Your connection is stored in encrypted form and you can disconnect it.
10. Service providers and subprocessors
We use the following providers to run Localizethat:
- Lovable Cloud (built on Supabase) — application database, authentication and file storage. Handles account data, workspace data and customer content.
- Cloudflare — hosting and delivery of the application and its server endpoints.
- Lovable AI Gateway, routing to Google Gemini models — AI localization, analysis and embeddings. Receives source content and compiled company context.
- Lovable email delivery — transactional email sent from notify.localizethat.com. Receives recipient addresses and message content.
- Paddle — payment processing for credit purchases. Receives the billing details you enter at checkout; we do not receive or store your card details.
- Google — sign-in and, if you connect it, read-only Drive import.
A dedicated subprocessor page with regions and roles is planned. Until it is published, this list is the current and complete set.
11. International data transfers
Our providers are global services, so personal information may be processed outside the country where you are located, including outside the European Economic Area.
We are verifying the processing regions and transfer safeguards for each provider listed above and will describe them specifically here once confirmed. We are not, at this time, making a claim about which mechanism applies to which provider.
12. Data retention
Today, we keep account data, workspace data, customer content, translation memory, usage records and audit records for as long as the account and workspace exist, unless you delete individual items in the product.
Invitations and review links carry their own expiry, after which they can no longer be used, though the record of them remains for audit purposes.
We have not yet published fixed retention periods for each category. We are defining them and will state them here rather than promise a period we do not currently enforce. If you need specific deletion, contact us and we will action it manually.
13. Data security
We describe only controls that are actually implemented. Access to workspace data is enforced in the database itself through row-level security policies tied to workspace membership and role. Review and invitation links use hashed tokens with expiry. Third-party connection credentials are stored encrypted. Administrative actions by our staff are recorded in an internal audit log. Traffic to the service is served over HTTPS.
We hold no security certifications and make no certification claims. No service can be guaranteed to be completely secure.
14. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of your personal information, and to data portability.
In the product you can already: edit your name and time zone, change your notification preferences, leave a workspace, remove members from a workspace you administer, export your localized output, and unsubscribe from non-essential email.
Account deletion and a full personal-data export are not yet self-service. To request either, or to exercise any other right, email contact@localizethat.com and we will handle it manually.
Note that deleting your personal account does not automatically remove shared workspace records — localizations, approved context, translation memory and audit entries — that the workspace and its owner continue to rely on. Where we keep such records, we minimise the personal information attached to them.
16. Eligibility
Localizethat is intended for business and professional use and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
17. Changes to this policy
When we change this policy we publish a new version with a new version number and effective date. Significant changes will be communicated to account holders. Previous versions remain on record.
18. How to contact us
For any privacy question or request, email contact@localizethat.com. We are working on a dedicated privacy mailbox; until then this address reaches the right people.
