i8

Last updated: April 2026

Privacy Policy

i18n-os, Inc. ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you use the i18n-os platform.

1. Information We Collect

Account information

When you create an account we collect your name, email address, and hashed password. If you sign up via GitHub OAuth we receive your GitHub username and public email.

Project data

To provide the service we store the locale files, extracted string keys, and translation coverage metrics you upload or generate via the CLI. This data is associated with your account and project ID.

Usage metrics

We collect product analytics events (page views, feature interactions, CLI command invocations) to improve the platform. Events are associated with your account ID and do not include raw translation content.

Payment information

Payment card details are handled exclusively by Stripe. We store only your Stripe customer ID and subscription status β€” never raw card numbers.

2. How We Use Information

  • To provide, operate, and improve the i18n-os service
  • To authenticate your account and enforce plan limits
  • To process payments and send billing receipts
  • To send transactional emails (e.g. password reset, coverage alerts)
  • To respond to support requests
  • To detect and prevent abuse or security incidents
  • To analyze aggregate usage patterns and guide product development

We do not use your project data (locale files, source strings) to train AI models or for any purpose other than providing the features you have requested.

3. Data Storage

All account and project data is stored in Supabase (PostgreSQL), hosted on AWS in the US East (N. Virginia) region. Data is encrypted at rest using AES-256 and in transit using TLS 1.3.

Uploaded locale files are stored in Supabase Storage (S3-compatible object storage) with the same encryption standards. Access is restricted to your account and authorized i18n-os service processes.

4. Third-Party Services

Stripe

Used for subscription billing. Stripe processes payment card data under their own PCI-DSS compliance. See stripe.com/privacy.

GitHub OAuth

Optional sign-in method. We only request read access to your public profile and email. We do not access your repositories without explicit permission.

AI Providers (OpenAI / Anthropic)

Source strings are sent to the configured AI provider when you run the translate command. We use data processing agreements that prohibit these providers from training on your content. You can opt out of AI translation by not using this command.

Analytics

We use PostHog (self-hosted) for product analytics. No data is shared with third-party advertising networks.

5. Data Retention

We retain your account and project data for as long as your account is active. When you delete your account, all associated data is permanently removed within 30 days.

Billing records (invoices, transaction history) are retained for 7 years to comply with financial regulations, but are not used for any product purpose after account deletion.

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you. Export your project data at any time from the project Settings page.

Correction

Update your account information (name, email) from the Account Settings page.

Deletion

Delete your account and all associated data from Settings, or by emailing us. Data is removed within 30 days.

Portability

Export all your locale files and project configuration in standard JSON format from the dashboard at any time.

Objection

Opt out of product analytics by emailing us or toggling the setting in your account preferences.

EU/EEA residents may also lodge a complaint with their local supervisory authority.

7. Contact

For privacy inquiries, data requests, or to exercise your rights, contact us at:

i18n-os, Inc.

[email protected]

We aim to respond to all privacy requests within 30 days.