Privacy Policy
Privacy-First Translation Platform
1. Introduction & Data Controller
This Privacy Policy explains how Ravira (Ravira) collects, uses, and protects your personal data.
No Separate Contract
There is no separate contract. By registering and accepting theTerms of Useat sign-up, you authorize the data collection described in this Privacy Policy. Your registration and continued use of the service constitutes your acceptance.
Data Controller
Platform: Ravira
Business Structure: Sole Trader, United Kingdom
Privacy Contact: support@ravira.dev
Jurisdiction: England and Wales
Our Core Privacy Principle
Privacy-First Architecture: Your translation content is never stored on our servers. Translations are processed in temporary memory and deleted immediately after delivery on our end. We cannot access, review, or recover your translation content from our systems. Text is briefly processed by our AI infrastructure provider, which retains it for up to 7 days solely for abuse-prevention purposes, then automatically deletes it — never used for AI training.
2. Data We Collect
Important: There is no separate contract. By registering and accepting theTerms of Use, you authorize the collection of necessary data to provide the translation service.
| Data Type | Purpose | Legal Basis |
|---|---|---|
Email Address | Account creation, login, notifications | Terms Acceptance |
Name (optional) | Personalization | Your Consent |
Password (hashed) | Account security | Terms Acceptance |
Character Usage | Billing, usage tracking | Terms Acceptance |
Payment Reference | Transaction records (via Stripe) | Terms AcceptanceLegal Obligation |
Glossary Terms | Your saved terminology | Terms Acceptance |
Legal Basis Explanation
- Terms AcceptanceData necessary to provide the service you requested by accepting our Terms of Use
- Your ConsentOptional data you choose to provide (can be withdrawn anytime)
- Legal ObligationRequired by UK law (e.g., financial records retention)
Data We DO NOT Collect or Store
- • Translation content (source or translated text)
- • Document content submitted for translation
- • Translation history or logs
- • IP addresses in identifiable form
- • Cross-site tracking or ad-network profiling
- • Third-party advertising cookies
3. Privacy-First Architecture
How Your Data Flows (and Disappears)
- 1You submit text → Encrypted transmission to our servers
- 2PII Filter masks sensitive data (emails, phones, IDs) → Placeholders sent to AI
- 3Routed through our AI infrastructure provider, which retains data up to 7 days solely for abuse-prevention, then auto-deletes
- 4AI processes translation → Result returned
- 5PII restored → Translation delivered to you
- 6Immediate deletion → All content erased from memory
Total processing time: seconds. Storage on RAVIRA's systems: zero. Provider-side retention: up to 7 days (abuse-prevention only).
Technical Reality: Once delivered, your translation content no longer exists on RAVIRA's own systems — we have no database, backup, or log containing it, and cannot retrieve it under any circumstance. This is by design, not policy. Our AI infrastructure provider briefly retains processed text (up to 7 days) for automated abuse detection only, outside RAVIRA's control or access — see Section 4 for details.
Partial Translation Recovery
If a document translation is interrupted — due to a browser refresh, connection loss, or unexpected error — a temporary copy of the partial result is saved on our servers. This allows you to recover work already translated and paid for when you return to the page.
This data is automatically deleted after 60 minutes, or immediately when you retrieve and dismiss the partial result. This is the only exception on RAVIRA's own systems to this principle — a temporary safeguard to protect work you have already paid for.
4. Third-Party Services (Sub-Processors)
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| OpenRouter | AI Translation | PII-masked text; retained up to 7 days by provider for abuse prevention, then auto-deleted; never used for training | USA |
| Stripe | Payments | Email, payment details | USA (PCI-DSS) |
| Brevo | Email (2FA) | Email address only | EU |
| Google Analytics | Website traffic analytics | Aggregated, pseudonymous usage data (pages viewed, session duration, approximate region, device type); no translation content or account data shared | USA (Google, Standard Contractual Clauses) |
International Transfers
Some sub-processors operate in the USA. These transfers are protected by:
- • Standard Contractual Clauses (SCCs)
- • Data Processing Agreements
- • Technical safeguards (encryption, PII masking)
5. What We DON'T Do With Your Data
Your data is never sold, rented, or shared with third parties for marketing.
Your translations are never used to train AI models - ours or anyone else's.
No targeted advertising, no ad networks, no tracking pixels.
No behavioral profiling, no cross-site tracking, no user analytics beyond basic metrics.
6. Your Rights Under GDPR & UK Law
Right of Access
Request copies of your personal data
Right to Rectification
Correct inaccurate personal data
Right to Erasure ("Right to be Forgotten")
Delete your account and all data instantly via Settings
Right to Data Portability
Export your data in machine-readable format
Right to Object
Object to processing based on legitimate interests
Right to Withdraw Consent
Withdraw consent at any time (where applicable)
Exercise Your Rights: Email support@ravira.dev
Response Time: Within 30 days (extendable by 60 days for complex requests)
Self-Service: Delete your account instantly via Settings → Security → Delete Account
7. Data Security
Technical Measures
- • TLS 1.3 encryption in transit
- • Bcrypt password hashing
- • Two-Factor Authentication
- • Session timeout (24 hours)
- • PII masking before AI processing
Organizational Measures
- • Minimal data collection principle
- • No translation content storage
- • Regular security assessments
- • Vetted third-party providers
- • Data Processing Agreements
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Translation Content | Not stored by RAVIRA. Provider-side: up to 7 days (abuse prevention only) |
| Account Data | Until account deletion |
| Glossary Terms | Until account deletion |
| Session Data | 24 hours |
| Payment Records | 7 years (legal requirement - stored by Stripe) |
| Email Address (after account deletion) | Retained to prevent abuse of free-tier signup offers (legitimate interest, GDPR Art. 6(1)(f)) |
| Usage & Billing Logs | Retained for accounting and tax compliance purposes |
9. Cookies
We use essential first-party cookies required for the service to function, plus a limited analytics cookie to understand aggregate site traffic:
| Cookie | Purpose | Duration |
|---|---|---|
| session_token | Keeps you logged in | 24 hours |
| theme | Dark/light mode preference | 1 year |
Analytics Cookies (Google Analytics)
We use Google Analytics to understand aggregate website traffic (pages viewed, session duration, approximate region, device type). This data is pseudonymous and never includes your translation content or account details. These cookies are non-essential, so they are only set if you accept the cookie banner shown on your first visit:
| Cookie | Purpose | Duration |
|---|---|---|
| _ga | Distinguishes unique visitors for aggregate traffic stats | 2 years |
| _ga_[container ID] | Persists session state for Google Analytics | 2 years |
Cookie Consent: Essential cookies are exempt from consent requirements under GDPR/ePrivacy Directive and are always active. The Google Analytics cookie is non-essential, so it only runs if you accept our cookie banner; declining it keeps analytics off for your visit. We don't use any marketing, advertising, or cross-site tracking cookies.
10. Data Breach Response
In the unlikely event of a data breach:
Privacy-First Advantage: RAVIRA itself has no database or logs of translation content, so a breach of our systems carries no risk of exposing it. Content briefly held by our AI infrastructure provider is subject to their own security measures, detailed in Section 4.
11. Children's Privacy
Ravira is not intended for children under:
- UK/EU: 16 years (GDPR Article 8)
- USA: 13 years (COPPA)
If you believe a child has created an account, contact us immediately at support@ravira.dev. We will delete the account within 24 hours of verification.
12. Jurisdiction & Dispute Resolution
Governing law: England and Wales
This Privacy Policy is governed by the laws of England and Wales. Any legal proceedings must be brought in the courts of England and Wales.
Mandatory amicable resolution first
Before initiating any legal action regarding privacy matters, you MUST first contact Ravira:
- Email: support@ravira.dev with full details
- Response within 5 working days
- 30 days to attempt amicable resolution
- Only then: UK courts or ICO complaint
Supervisory Authority
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
ico.org.uk | 0303 123 1113
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements.
- Material changes: 30 days advance notice via email
- Minor changes: Posted on this page with updated date
- Your option: Delete account if you disagree before changes take effect
14. Contact Us
Privacy Queries:
privacy@ravira.dev
General Support:
support@ravira.dev
Response time: Within 30 days for GDPR requests | 5 working days for general queries
By creating an account or using Ravira, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your data as described.
Jurisdiction: England and Wales | GDPR Compliant | Last Updated: September 2026