Privacy Policy
This policy describes what Lingivio does with personal data. It was written against the actual code and database schema, and where the system does something you would not expect, it is stated here rather than omitted.
Last reviewed — 2026-09-12
These documents were drafted by the operator and checked against the running system. They do not constitute legal advice and remain subject to review by a qualified practitioner.
Who you are dealing with
Lingivio is operated by Velniq Ltd, a private limited company registered in England and Wales (company no. 17454810, incorporated 11 September 2026). Velniq Ltd is not VAT-registered; purchases are sold by our merchant of record, who charges and remits any VAT or sales tax due.
- Company
- Velniq Ltd
- Company status
- Active — private limited company (Companies House)
- Jurisdiction of incorporation
- England and Wales, United Kingdom
- Company registration number
- 17454810
- Registered office
- 2nd Floor College House, 17 King Edwards Road, Ruislip, London, United Kingdom, HA4 7AE
- Date of incorporation
- 11 September 2026
- Effective date of these documents
- 2026-09-12
- Company website
- https://velniq.ai
- Service
- https://lingivio.com
- Support
- support@velniq.ai
- Privacy
- privacy@velniq.ai
- Data protection contact
- dpo@velniq.ai
- Abuse reports
- abuse@velniq.ai
- Legal and contracts
- legal@velniq.ai
1. Who is responsible
The controller for personal data described in this policy is Velniq Ltd, a private limited company registered in England and Wales (company no. 17454810), whose registered office is shown in the identity block.
Because the controller is established in the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO). For users in the EU, EU data protection law also applies to this processing. We have not appointed a statutory Data Protection Officer; the data protection contact address in the identity block reaches the person responsible.
2. Your document text leaves our infrastructure
This is the most important point in this policy. Translating a document means sending its text to a large language model that we do not operate ourselves.
When you translate a document, the translatable text of that document — including text recognised by OCR from scanned pages and images — is sent to OpenRouter, Inc., which routes it to the model provider that serves the model we run, currently OpenAI. Both are in the United States. If you attach a glossary, your glossary terms are sent with it. The target language, any source-language hint, the formality setting and a fixed structural label per segment such as spreadsheet cell or subtitle are also sent.
What is not sent: your name, email address, account id, filename, job id, or any other identifier of you, and never the file itself. The request carries the text and nothing that ties it to you. Cells, runs and lines that consist solely of a formula, a number, a code, a URL or an email address are excluded from the request entirely. A number or code embedded inside a sentence is sent with that sentence, because the sentence has to be translated as a whole.
If your document contains information you cannot lawfully or contractually send to a processor in the United States, do not upload it. We do not currently offer an on-premises, EU-only or self-hosted translation option.
3. What we collect and why
Account data: your email address, display name, password hash, and — if you sign in with Google — your Google account id, name and profile image, plus the tokens Google issues. We need these to create and secure your account and to let you sign back in.
Documents and their translations: the file you upload and the file we produce. These are stored in object storage, processed by our translation engine, and deleted on the schedule in section 5.
Job records: the original filename, the languages detected and requested, the options you chose, credit, page, segment, character and token counts, the model used, timing, status, and any error class. These are how the dashboard, billing and support work.
Billing data: your plan, subscription status and period, the customer and subscription identifiers issued by our merchant of record, and the full credit ledger of every grant, purchase, reservation, charge, release and refund on your account. Card details never reach us — the merchant of record handles payment.
Glossaries: the source and target term pairs you create. These are your content, and they are sent to the translation provider with any job that uses them.
Technical data: your IP address and browser user agent, recorded on each session by the authentication layer; abuse counters, which are keyed to your IP address before you sign in and to your account id or the identifier of the API key making the call once you are signed in; and server logs. Each counter is a number in a cache that expires by itself — within about two minutes for the ordinary per-minute limits, within two hours for the sign-in, sign-up and password-recovery limits, and within 48 hours for the limit on how often you can download a data export. We use these to keep accounts secure and to stop abuse.
Usage and cost telemetry: per-job counts of credits, segments, characters and tokens, the model tier used, and our own compute and model costs. We use these for spend limits, capacity planning and pricing.
Consent records: what you accepted, which version, when, and from where — the acceptance of these documents at sign-up, and any cookie choice you make while signed in. Your cookie choice is also kept in your own browser, and that copy is the one that decides what runs.
Safety records: if a scanner refuses an upload, we record that it happened — which check refused it, the scanner's own verdict label, the file name and size, your account id, the email address and name on the account at that moment, and the job it belonged to — and we move the file itself to a separate quarantine area instead of deleting it on the usual schedule. The record never contains the contents of your document.
Sales enquiries: if you use the contact form, the name, work email, company, role, what you need to translate, the volume and file types you describe, whether you need API access, and the message you write. We keep it to reply to you, and a copy is emailed to our sales mailbox.
4. Legal bases
Performance of a contract: creating and running your account, translating your documents, storing and delivering the output, glossaries, credit accounting and support.
Legitimate interests: keeping the service secure, preventing abuse and fraud, rate limiting, understanding our own compute and model costs, and defending legal claims. We have balanced these against your interests and use the least data that works.
Legal obligation: retaining the records of payments and credit entitlements that tax and accounting law requires us to keep, and preserving and reporting apparent child sexual abuse material, which the law requires of a provider that becomes aware of it and which we therefore cannot delete on request.
Consent: only for non-essential cookies and similar technologies — the analytics, diagnostics and marketing tools we may run in your browser, and the record of where you first arrived from. None of it starts until you allow it, and you can withdraw at any time as easily as you gave it. Section 15 sets out exactly what runs on consent and what does not, because the difference matters.
5. How long we keep things
Documents and translations: deleted 24 hours after the upload begins, by a cleanup job that runs every minute and removes the stored objects and the file record together. A file whose translation is still running is skipped until the job reaches a final state, so 24 hours is a floor rather than a hard ceiling; a separate sweep bounds how long a stuck job can hold a file open.
Job records outlive the file. The original filename, the language breakdown, the credit, page, segment, character and token counts, the model, the cost and the status are kept after the document itself is gone, so that your history and your invoice stay intelligible. They are kept until you delete your account.
Sessions and sign-in state: session records, including the IP address and user agent attached to them, are deleted once the session expires. Sessions last up to seven days. Short-lived sign-in verification records are deleted once they expire.
Failure diagnostics: the technical detail attached to a failed job is deleted from our database after 30 days. For a small number of unmapped errors that detail is the raw exception text from a document parser, which can contain a fragment of the document that caused it. Our database is not the only copy: the same unmapped exception is also written, with its traceback, to the log stream of the compute platform that runs the translation engine and to our hosting platform's logs. We do not redact those writes today, and those platforms' log retention is each provider's default rather than a period we set. A fragment of document content can therefore outlive the 24-hour file window in two places: our own copy, which we delete after 30 days, and the providers' logs. Redaction at the point of writing is an open item on our record of processing activities, and this section will state a retention period once it is closed.
Cached API responses: results of the segment translation API held for safe retries are deleted 24 hours after the call.
Financial records: the credit ledger, subscription records and usage telemetry are retained for as long as tax and accounting law requires, and are pseudonymised rather than deleted when you close your account, as described in section 8.
Safety records and quarantined files: an upload refused by the malware or content check, and the record of that refusal, are deliberately kept outside the 24-hour deletion above. Where the law obliges us to report the material we keep it for at least 90 days after the report, and longer if an authority asks us to; otherwise we keep it for 30 days to investigate the abuse and then delete it. Deleting it is an action taken by a named person, never a scheduled job.
Sales enquiries: kept until we have answered and you ask us to delete them, or until we remove closed enquiries ourselves. Deleting an account does not delete an enquiry sent before the account existed; write to us and we will remove it.
6. Training
We do not use your documents, translations or glossaries to train, fine-tune or evaluate any model, and we do not sell or share them for anyone else to do so.
Two things stand behind that statement. Nothing in our own systems is capable of training a model on your content: we operate no training pipeline and keep no durable store of your text. What our translation providers do with the text we send them is governed by the terms and account settings we hold with them, which is a contractual commitment rather than a technical one. If you need that commitment in writing, contact us.
7. Caching in the translation engine
To avoid translating and charging for the same text twice, the translation engine keeps recently translated fragments in the memory of the running process. This cache holds at most a few thousand fragments, is never written to disk or object storage, and disappears when the process restarts.
The cache is keyed on the text and the translation settings, not on the account, so two accounts translating an identical sentence with identical settings can be served the same cached result. It holds fragments of text with nothing identifying attached, it is not searchable, and because it is not durable it is not something a deletion request can address.
8. Who else processes your data
We use a small number of processors: a cloud platform for hosting, storage and the database; a compute platform that runs the translation engine and the OCR step; a model gateway and the model provider behind it; and a merchant of record for payments. Each one, what it receives, and where it processes it, is listed with a date on our Subprocessors page.
Our merchant of record is not only our processor. As the seller of record it is an independent controller for the tax, invoicing and fraud-prevention data it collects from you at checkout, under its own privacy policy.
9. International transfers
Processing outside the European Economic Area and the United Kingdom is the normal case for this service, not an exception. Our hosting runs at whichever edge location is nearest the visitor, worldwide. The translation engine runs in the United States. The model gateway and model provider are in the United States. The merchant of record processes in the United States, the United Kingdom and the European Union.
These transfers rely on the European Commission Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, in each case as set out in the data processing terms we have with each provider. We do not currently offer an EU-only processing region, and we do not pin storage or compute to the EU.
10. Your rights
You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent where consent is the basis. You will never be treated worse for exercising any of them.
Two of these are self-serve in Settings. Export downloads a machine-readable JSON file containing your account, sessions, job history, glossaries, credit ledger, usage records, subscription records, API key metadata and consent records. Delete account erases your account as described below. Everything else, and any request you would rather make in writing, goes to the privacy contact address; we answer within one month.
The export is capped at a few thousand rows per category and tells you plainly which categories, if any, were cut short. If yours is, write to us and we will supply the rest.
11. What deleting your account actually does
Deleting your account is irreversible and takes effect on the data itself, not on a status flag. Every session and API key is revoked immediately. Every stored object under your account in our storage, uploaded files and translated outputs alike, is deleted. Your identity record, password hash, linked sign-in accounts, sessions, files, job records, failure diagnostics, glossaries, API keys, cached API responses and consent records are deleted from the database.
If a translation is still running when you ask, deletion cannot complete instantly: cancelling a job in flight requires the compute backend to acknowledge it, and deleting a running job's storage underneath it would strand it. Your credentials are revoked straight away and the erasure completes automatically once the job reaches a final state, normally within minutes.
Three things are deliberately kept, pseudonymised rather than deleted, because accounting and tax law requires records of payments: the credit ledger, the subscription records, and the usage and cost telemetry. Your email address and name are removed from the billing profile, and the raw payment provider payload — which is the widest set of personal data we hold about a payment — is erased. What remains is an account identifier that no longer resolves to any person, attached to amounts and dates. The customer identifier issued by our merchant of record is kept so a later refund, chargeback or tax audit can be reconciled; the merchant of record retains its own records under its own obligations regardless.
One record is created rather than deleted: the fact that an erasure was requested and completed, and when. It contains no identity and exists so we can demonstrate that we did what you asked.
One further record survives an erasure and is not pseudonymised: a safety record and the quarantined file behind it, including the email address and name the account carried when the incident was detected. A report to the authority must still be able to identify the uploader after the rest of the account is gone. Where we have found apparent child sexual abuse material we are obliged to preserve it and to report it, and a deletion request cannot be used to destroy that evidence or to remove the record of a decision we took about an account. This is the exception the law makes for a legal obligation and for the defence of legal claims, and the periods in section 5 are its limit. For the same reason the export in section 10 does not include these records: the law restricts what we may tell a reported account. The refusal itself is not hidden from you: the upload is refused at the time, and a suspended account is told that it is suspended and how to reach us.
12. Security
Traffic is encrypted in transit. Passwords are stored as hashes, API keys are stored only as hashes and the plaintext is shown once and never again, and every storage key and database query is scoped to the owning account. Uploads go directly to storage under a server-derived key, so one account cannot address another account's objects.
Uploads are checked before they are translated: every file is scanned for malware by a virus scanner that runs inside our own processing container, and a file that carries images is also checked for sexual or abusive imagery by Amazon Web Services, which receives copies of those images in the European Union. Neither check is a guarantee. They classify apparent content and do not match against known-material hash databases, and where the image check is not available on a deployment we refuse an image-bearing upload rather than translate it unchecked. Two limits should be stated plainly: we do not yet operate a bug bounty programme, and our platform log retention is the default applied by our hosting provider. Report a suspected vulnerability or a security concern to the abuse contact address and we will respond.
13. Children
The service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe that a person under 18 has created an account, contact us and we will delete it.
14. Cookies
Most of what the app stores in your browser is strictly necessary or a functional preference. Two items are analytics and are stored only if you allow that category: an opaque random identifier so a visit is counted once rather than three times, and a note of the campaign or site you first arrived from. Neither is shared with anyone and neither is used to build a profile. Our Cookie Policy lists every cookie and browser-storage item with its purpose, lifetime and category.
15. How we measure the product, and on what basis
We measure two different things under two different legal bases, and we keep them apart deliberately.
On your consent, in your browser: privacy-preserving traffic measurement from Cloudflare, a count of which pages you reached, and a note of the campaign, search engine or site you first arrived from — including, when an advertising network appended one to the link you clicked, that network's opaque click identifier. If you decline analytics, none of this runs — the measurement script is never placed in the page in the first place, no identifier is stored, and nothing is sent. If you withdraw later, collection stops immediately, the identifiers in your browser are deleted, and the record of where you arrived from is deleted from our database too.
On contract and legitimate interests, on our servers: the record that an account was created, that a document was submitted, that a translation finished or failed and with which error, that a checkout was started, and that a subscription was created, renewed or topped up. These are records of things you asked us to do and of what they cost and earned us; we need them to run the service, bill correctly, understand our own margins and answer tax and accounting obligations. They are not analytics cookies and they do not depend on your cookie choice, so declining analytics does not remove them and is not meant to.
What is never in either of them: the content of your documents, any text extracted from or translated in them, filenames, storage keys, glossary terms or anything you typed. The set of details an event may carry is a fixed list of short technical values — a file format, a language code, a plan name, an error class, a page count — and anything outside that list is rejected rather than trimmed, so there is no path by which document content can arrive there.
The traffic measurement is Cloudflare Web Analytics, which is cookieless: it stores nothing in your browser and reads no identifier we hold. We verified that against Cloudflare's published description of the script. It is nonetheless placed behind your consent, so that the claim does not rest on our verification alone.
On your consent we also use Google Analytics, on deployments where it is configured. Its script loads with every permission switched off and stores nothing in your browser until you allow the matching category: allowing analytics lets it set its cookies and measure visits; allowing marketing additionally lets it connect a visit to the advertisement that led to it. If you are signed in and have allowed analytics, it receives a dedicated random identifier we mint for this purpose — never your account identifier or email — and withdrawing your consent discards that identifier on our side, so a later change of mind cannot be linked back. Google processes this data for us under the terms on our subprocessors page.
16. Changes and complaints
The current version and its effective date are always published here, and we will notify you in the app or by email before a material change takes effect. If you are dissatisfied with how we handle your data, please contact the privacy address first. You also have the right at any time to complain to the Information Commissioner's Office (ICO) in the United Kingdom, or to the supervisory authority where you live.