Privacy by design
Übersetz is designed so that supported speech recognition and translation workflows can be performed entirely on your device.
Standalone Übersetz does not require an account or send local transcripts to PT. Senja. Optional Classifier and Übercast transfers are separate, explicitly enabled features.
When you use a local processing option, your speech and translation content stays on your device unless you separately enable the optional Mac Classifier. Google ML Kit on Android may process the diagnostic metadata described below. This applies when Übercast is not enabled; its separate archive is described below.
Cloud AI providers are optional. Data is sent to a cloud AI provider only when you:
- intentionally select that provider;
- provide credentials for that provider where required; and
- explicitly give permission for Übersetz to send the disclosed data to that provider.
No speech or translation content is sent to a cloud AI provider before that permission is given.
Local processing
When you select a managed Whisper and Qwen model combination, speech recognition, translation and Advisor processing run locally on your Mac after the required models have been installed.
Compatible models used through a locally installed Ollama service also remain on your Mac.
Apple Translate uses Apple's on-device language detection and translation framework on compatible versions of macOS.
PT. Senja does not receive the audio, transcripts or translations produced through these local workflows. This applies when Übercast is not enabled; its separate archive is described below.
Übersetz does not create a permanent raw microphone or system-audio recording.
For local providers supporting Uncertainty Rescue, the app may temporarily retain up to approximately 90 seconds of captured PCM audio in memory. This temporary rolling buffer exists only so a recent phrase can be replayed or processed again. It is not written to the saved session, is not included in Markdown exports and is discarded when the session is cleared or restarted.
System audio is received using a macOS Core Audio tap. Übersetz does not capture, store or transmit screen pixels.
Android processing
On Android, Google On-device mode uses Google ML Kit speech recognition and translation. Microphone audio, transcript content and translated content remain on the Android device in this mode. ML Kit may contact Google to download or update models and may send device, application, configured-language, performance, usage and diagnostic metadata under Google's terms. Google states that ML Kit input and output content remains on-device.
When Ollama or OpenAI-compatible translation is selected on Android, Google ML Kit creates the transcript on-device and Übersetz sends stable transcript text, not microphone audio, to the endpoint configured by you.
When GPT or Gemini is selected on Android, live microphone audio is sent directly from the device to the selected provider. That provider creates the Heard transcript and translation.
Android can continue an active listening session while another app is open or the screen is locked. An ongoing Android notification identifies the session and provides a Stop action. Listening starts only after you tap Start listening. Force-stopping the app or the operating system terminating the foreground service ends capture.
The Android app does not create or retain a raw audio recording. Android 1.0.2 does not retain transcript or translation text after its app process is terminated.
Information stored locally on your device
To allow an interrupted session to be restored, Übersetz may locally store:
source transcript text; translated text; speaker labels; Advisor insights; application settings; selected provider information; and your cloud-provider consent choices.
This information is stored in the application's local support files on your Mac. The Android app currently stores provider, language, appearance and consent choices, but does not persist transcript or translation content across process termination.
Selecting Clear removes the retained current session from Übersetz. This applies when Übercast is not enabled; its separate archive is described below.
Selecting Save creates a Markdown export only at the location you choose using the macOS save panel. Because that exported file is under your control, you must delete it yourself if you no longer want to retain it.
Optional Übercast sharing and transcript archive
When you explicitly start Übercast, translated captions and generated speech are shared with attendees using direct delivery or the event’s assigned media server. Source transcript text and all produced event translations are also sent to PT. Senja’s event service for the private transcript archive. Raw microphone or system audio, Advisor output and Classifier scores are not part of that archive.
The Mac persists pending archive passages locally and retains recovery authorization in macOS Keychain. A passage is shown as server-saved only after acknowledgement of its committed record. Network or provider failures can still leave gaps; inspect archive status before clearing local data.
Organizer and Client Dashboard access use separate event credentials and account/contact information. Explicitly supplied event or correction-provider keys are server-side configuration; app-configured provider keys remain on the device. Review access before sharing event links or exports.
The active server database retains event transcript records for 90 days. Backups and downloaded exports have separate lifecycles; this is not a promise that every copy is deleted after 90 days. Local Clear does not delete server records. Contact support about server-held event records.
API keys and credentials
If you configure a cloud provider, your provider credentials are stored locally using macOS Keychain on Mac or Android Keystore-backed encryption on Android.
This can include:
OpenAI API credentials; Google Gemini API credentials; TypeSafe Classifier API credentials on Mac; and credentials for a custom endpoint.
Keys configured in the app remain on the device. Credentials explicitly supplied through the Übercast organizer or Client Dashboard are a separate server-side configuration.
Optional third-party AI processing
When a cloud AI translation provider is selected, or the optional Mac Classifier is enabled, information may leave your Mac. Before this occurs, Übersetz identifies the recipient and asks for your permission.
| Provider | Recipient | Data that may be sent | Purpose |
|---|---|---|---|
| GPT Realtime | OpenAI | On Android: live microphone audio. On Mac: live microphone and/or system audio. The provider may also receive text and current-session context required for the selected feature, plus ordinary network/request metadata such as your IP address. | Real-time speech recognition and translation; on supported desktop versions, Advisor processing and optional summaries |
| Gemini Live Translate | Google Gemini / Google | On Android: live microphone audio. On Mac: live microphone and/or system audio. The provider may also receive relevant transcript, translation or Advisor text required by the selected feature, plus ordinary network/request metadata such as your IP address. | Real-time speech processing and translation; on supported desktop versions, Advisor processing and optional summaries |
| Remote custom endpoint | The operator of the endpoint address entered by you | On Android 1.0.2, stable transcript text is sent and microphone audio is not. On other supported versions, the request content required by the selected feature may include transcript text, translation text, Advisor context and/or audio. Ordinary network/request metadata is also visible to the endpoint. | Processing explicitly requested by you through that endpoint |
| Optional Mac Classifier | TypeSafe AI / Jev | Recent Heard transcript text, prior text context, and a paired passage from the selected translation with source and target language codes. TypeSafe also sees ordinary network/request metadata such as your IP address. No raw audio is sent for classification. | Indicative live transcript and translation assessment after you enable the Classifier with your own TypeSafe API key |
PT. Senja does not receive a copy of these requests.
The connection is made from your device to the selected provider using the credentials or endpoint configuration you supplied.
Speech itself may contain personal information. For example, a conversation may include names, addresses, business information, health information or other information about you or another speaker. If this information is spoken while a cloud provider is active, it can form part of the audio or text sent to that provider.
Übersetz does not separately attach your name, email address, contacts, precise location, advertising identifier or similar profile information to these requests.
Permission before cloud AI processing
Selecting a cloud translation provider, or opening the Mac Classifier panel, does not by itself authorize Übersetz to send personal data.
Before Übersetz sends speech or text to that provider, the app presents a disclosure identifying:
the provider receiving the information; the categories of information that will be sent; the reason the information is being sent; and that the processing will occur under the provider's applicable terms and privacy practices.
You can either allow the transfer or cancel it. On Mac, the Classifier panel describes the TypeSafe text transfer and requires you to select Enable live classifier before any Classifier request. It is optional even when a local translation model is selected. Switching back to Advisor or Questions disables it.
If you do not give permission, Übersetz does not send your speech or translation content to that provider.
Consent is recorded locally on your device. On Android, permission for a custom endpoint is also tied to the endpoint destination; changing the destination requires permission again before transcript content is sent.
Permission granted for one provider does not automatically grant permission for another provider.
You can withdraw permission by disabling or deselecting that cloud provider, removing its credentials or revoking its provider permission in Übersetz. On Mac, switching away from the Classifier disables new TypeSafe requests. Once permission is withdrawn, Übersetz stops making new content requests to that provider.
Withdrawal does not automatically delete information that was previously transmitted to a provider. Previously transmitted data is subject to that provider's applicable retention and deletion rules.
The operating-system permission to access your microphone or system audio is separate from permission to send content to a third-party AI provider. Android also presents an in-app microphone and background-listening disclosure before requesting microphone permission.
Automatic summaries
If Automatic summaries is enabled while GPT or Gemini is selected, newly translated text is periodically sent to the same selected provider for Advisor processing.
No separate AI provider receives this information.
Turning Automatic summaries off stops these automatic requests.
Automatic summaries do not bypass cloud-provider permission. They operate only after permission has already been granted for the selected provider.
OpenAI
When GPT Realtime is selected, data is sent directly to OpenAI using the API credentials supplied by you.
PT. Senja does not operate an intermediary OpenAI account for your Übersetz sessions.
OpenAI states that data submitted through its API platform is not used to train its models by default. OpenAI also states that, except for certain endpoints and account configurations, API inputs and outputs may be retained for up to 30 days for service operation, security and abuse monitoring, after which they are deleted unless longer retention is legally required.
Your OpenAI account may have different or additional retention controls.
Your use of OpenAI through Übersetz remains subject to the OpenAI terms and privacy conditions applicable to your account.
Google Gemini
When Gemini Live Translate is selected, data is sent directly to Google's Gemini API using the Google credentials supplied by you.
PT. Senja does not operate an intermediary Google account for your Übersetz sessions.
Google's treatment of Gemini API content can depend on the type of Google project and service plan connected to your API key.
Google currently states that content processed under paid Gemini API services is not used to improve its products. Google also states that content submitted under certain free or unpaid Gemini API services may be used to improve Google products and machine-learning technologies.
You should therefore review the privacy and data-use conditions applicable to your own Google project before using Gemini for confidential or sensitive conversations.
Your use of Gemini through Übersetz remains subject to Google's terms and privacy conditions applicable to your account.
Custom endpoints
Übersetz can optionally connect to a remote Ollama or OpenAI-compatible endpoint that you manually configure.
PT. Senja does not select the operator of such an endpoint, does not receive the data sent to it and cannot control that operator's privacy, security, retention or deletion practices.
Before using a remote custom endpoint, Übersetz identifies the destination and requires you to acknowledge that information will be sent to the operator you selected.
You should use a remote custom endpoint only when you trust its operator and have confirmed that its privacy and security protections are appropriate for the information you intend to process.
A locally running endpoint such as Ollama on your own Mac does not constitute cloud transmission by Übersetz. On Android, remote custom endpoints must use HTTPS; cleartext HTTP is limited to the app's exact device-loopback destinations.
Protection by third-party providers
PT. Senja does not sell personal data and does not authorize supported AI providers to use Übersetz data for advertising, profiling or cross-service tracking on our behalf.
For built-in third-party integrations, PT. Senja selects services that publish privacy and security protections for API data and requires processing performed on our behalf to provide protection consistent with this Privacy Policy and applicable privacy requirements.
Where you connect a service using your own provider account, the specific contractual, retention and optional data-use settings associated with that account also apply.
For a custom endpoint independently selected by you, PT. Senja cannot guarantee the privacy practices of that operator. Übersetz therefore requires an explicit disclosure and user decision before information is transmitted to it.
Other speakers
Translation may involve speech belonging to people other than the person operating the device.
You are responsible for making sure that people whose speech is captured are aware of the recording or live processing where required and for obtaining any consent required by applicable law.
No advertising or tracking in the apps
The Übersetz app does not contain advertising.
PT. Senja does not use Übersetz speech, transcripts or translations to build advertising profiles.
The app does not use advertising identifiers to track you across apps or websites.
Retention and deletion
Standalone Übersetz does not require an account or send local transcripts to PT. Senja. Optional Classifier and Übercast transfers are separate, explicitly enabled features.
Local current-session information can be removed using Clear where session retention is available. On Android 1.0.2, transcript and translation content is held only for the current app process and is not restored after process termination.
Temporary rescue audio is discarded when the applicable session is cleared or restarted.
Saved Markdown exports remain wherever you saved them until you delete them.
Cloud data already transmitted to OpenAI, Google, TypeSafe or a custom provider is retained according to the terms and account configuration of that provider. Requests regarding information retained by those providers should be made through the provider account or privacy mechanisms applicable to you.
Revoking a provider's permission in Übersetz prevents future transmission but cannot retroactively delete information already transmitted to that provider.
Website
The Übersetz website is delivered using Cloudflare and the Übersetz website infrastructure.
When you visit the website, these systems necessarily process normal technical request information such as your IP address, browser information and HTTP request headers so the website can be delivered and protected.
Website analytics is separate from the Übersetz apps. We offer an optional Google Analytics choice to measure website visits and ad campaigns. The Google tag is not loaded and no analytics request is sent to Google until you select Allow analytics.
If you allow it, Google Analytics may receive the page address, referring page, campaign parameters, browser and device information, and technical connection data such as your IP address. It may set first-party analytics cookies to distinguish visits. No app audio, transcripts or translations are sent by this website tag.
We disable Google signals and ad-personalization signals in the website tag. We do not use this analytics choice to build cross-site behavioral advertising profiles.
You may decline or change your choice using Analytics settings on the website. Withdrawing consent stops new website analytics requests on this browser and removes the Google Analytics cookies accessible to this site; it cannot retract data already sent to Google. Your choice is stored in this browser. If browser storage is blocked, the choice lasts only for the current page.
Google processes information it receives under its own terms and privacy policy. Review Google's privacy information for its processing and retention practices.
Cloudflare may provide privacy-oriented website performance measurements according to Cloudflare's own privacy documentation.
Website activity is separate from the content processed by the Übersetz applications.
Privacy questions
Standalone Übersetz does not require an account or send local transcripts to PT. Senja. Optional Classifier and Übercast transfers are separate, explicitly enabled features.
For questions about this Privacy Policy, the website, or PT. Senja's handling of information, contact us using the privacy or support contact provided on ubersetz.app.
Changes to this policy
We may update this Privacy Policy if Übersetz functionality, supported providers or legal requirements change.
If a change materially expands the categories of personal data sent to a third party or introduces a new third-party AI provider, Übersetz will request the appropriate permission before transmitting data under that expanded use.