Short version: We do not read your documents. We do not store your API keys on unencrypted servers. We do not sell your data. Your translations pass directly between your browser and the AI provider (OpenAI, Gemini, Claude, or Deepgram) using your own API key.
Transila Office is operated by Transila FZ-LLC, a company licensed in the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates, License No. 46000294.
Contact: privacy@transila.me · +971 56 953 4041
Files uploaded to the platform (DOCX, PDF, audio, video, etc.) are stored in a private Supabase Storage bucket scoped to your organisation. Files are used solely to enable the platform's features. We do not read, analyse, or share your file contents.
When you save API keys (OpenAI, Gemini, Claude, Deepgram, Mistral) in the Settings panel, they are stored encrypted on our server using AES-256-GCM encryption. The encryption key is held only on our server and is never transmitted to the browser or any third party. Keys are used solely to make requests on your behalf when you initiate an operation.
We log basic server-side events (file uploads, job creation, session start/end times) for billing, debugging, and security purposes. We do not use third-party analytics SDKs.
Payments are processed by Stripe, Inc. We never receive or store raw card numbers. Stripe provides us with subscription status, renewal dates, and invoice history. Stripe's privacy policy is available at stripe.com/privacy.
We do not use your data for advertising, profiling, or sale to third parties.
Transila Office operates on a Bring Your Own Key (BYOK) model. When you translate a document or transcribe audio, your content is sent directly from our server to the AI provider (OpenAI, Google, Anthropic, Deepgram, or Mistral) using your API key under your account. Each provider's data practices are governed by their own privacy policies and API terms:
Whether you are located in the EU, UK, or UAE, you have the right to:
To exercise any of these rights, email privacy@transila.me. We will respond within 30 days.
We use only technically necessary cookies for session management (Supabase authentication token). We do not use advertising or tracking cookies. For details, see our Cookie Policy.
We implement industry-standard security measures including:
Our infrastructure uses Supabase (hosted in AWS Frankfurt, EU) and Stripe (US). For EU users, data transfers to the US are covered by Stripe's Standard Contractual Clauses. If you require a Data Processing Agreement (DPA), please contact us.
We may update this policy from time to time. We will notify active subscribers by email at least 14 days before material changes take effect. The effective date above will always reflect the latest revision.
Also see: Terms of Service · Cookie Policy · Acceptable Use Policy