Privacy Policy

Effective date: August 10, 2026

This page describes what bullshittranslator.com ("the Service") processes, why, and who it is shared with. The Service is run by an independent individual; the contact channel for all privacy matters is the form at the bottom of this page.

What we process

Free (anonymous) users. Your IP address is never stored. A one-way salted hash of it is kept to enforce the daily free limit (3 translations) and to bind captcha solutions; the hash cannot be reversed into an IP address. We also log request metadata only — date, direction, language, character counts, latency. Never the text.

Pro users. We store a randomly generated account ID, a PBKDF2-hashed password, your plan, and the paid-until date. Your email never reaches us: payment happens entirely on Stripe's page, and whatever you enter there is seen by Stripe alone — we receive no copy in any form, not even hashed. Your credentials are shown on-screen exactly once, right after payment — nothing is ever emailed, and they cannot be recovered — store them somewhere safe. Every purchase creates a brand-new account: ten purchases from the same address are ten unlinkable strangers to us.

Submitted text is processed in memory, forwarded to the translation provider, and never written to any database or log. The forwarding is unattributed: requests leave our server under a single shared API key, so the provider receives the text but no account ID, no IP address, and no way to link it to you. The Service is the translation: opting out of this forwarding means not using the Service — if a text must not leave your device, do not paste it. Your on-screen history (last 20 translations, trimmed) lives only in your own browser's local storage — delete it anytime with the "clear history" button; we never see it.

Who receives anything

No data is sold, rented, or shared with advertisers or data brokers. No advertising or analytics trackers are used. Cookies: none; counters live in your browser's local storage.

Legal basis, retention, security

Processing is based on performance of a contract (GDPR Art. 6(1)(b)) and legitimate interest in rate limiting and abuse prevention (Art. 6(1)(f)), implemented via irreversible hashing. Account data is kept until the subscription lapses and deleted on request; usage counters are kept for the current day/month only and deleted within 60 days. Passwords are hashed with PBKDF2-HMAC-SHA256 (200,000 iterations); IPs are stored only as salted hashes, and email addresses never reach our servers at all. The processors above may operate outside the EU/EEA; where required, transfers are covered by their standard contractual clauses or equivalent data-processing agreements. Material changes to this policy will be announced on the main page at least 30 days before they take effect.

Your rights

Under GDPR you have the right to access, rectification, erasure, restriction, portability, and objection. In practice: the only record that can be linked to you is your account (random ID, password hash, paid-until date) — everything else is counters and one-way hashes. To exercise any right, send a message via the privacy form with your account ID; deletion requests are completed within 7 days. Without the account ID we cannot identify your record — that is deliberate, and it is also why a database leak would not expose you. You may also lodge a complaint with your local supervisory authority.


Contact

One message a day per person, human check required. If you want an answer, leave a way to reach you.

Sent with a human check, not with your IP — we store the message, not you.
← back to the translator