Privacy Policy
Last updated: 28 September 2026 · Version 2026-09-28
The short version:
- Microphone and meeting audio is not stored by us. It is processed as a live stream and discarded. Two exceptions are not under your control, so you should know about them: if you invite our bot into a Zoom, Google Meet or Microsoft Teams call, the provider that runs the bot may keep a copy of the call audio for up to 7 days before deleting it, and no setting in the app changes that; and synthesised voice-over audio is cached in the EU for up to 7 days. Recording is different and it is yours to decide: you start it, the file is saved on your device, and it reaches our EU storage only if you turn on “Cloud copy”.
- Transcripts created under your account are visible in the product only to that account. Our administrative tools work on counts, minutes and costs, not on the text of your meetings, and our staff do not open your transcripts except where required by law or to investigate abuse.
- By default, cloud transcripts are deleted automatically after 30 days. Where your plan allows it, you can choose to keep them until you delete them yourself; the app tells you whether yours does.
- You can start any meeting with “Don’t save this transcript”. Then we keep no transcript of it: no history, no cloud copy, and no cloud copy of a recording. Two things still happen, because the service cannot run without them: we keep the technical record of the session (room code, mode, languages, times and the minutes used, for billing and reliability), and, if voice-over is on, the synthesised audio of the spoken translation passes through our 7-day voice cache like any other meeting. The bot provider’s 7-day copy of call audio also sits outside this switch. The default for new meetings is set in Settings → Save transcripts.
- You can delete any transcript, export your data, or erase your whole account yourself, at any time.
- If you took part in a conversation that someone translated with Getix Translate and you are not our customer, section 8 is written for you.
1. Who we are
Getix Translate (“we”, “us”) is operated by Alexandru Kornienko, a sole trader (autónomo) established in Valencia, Spain, trading as Getix Translate. Tax number (NIF): Z3186423P. Postal address: Carrer de Colón 1 Bis, 46004 València, Spain. Contact for all privacy matters: office@getixtranslate.com.
We are the data controller for your account, billing, security and support data. For the content of meetings, our role depends on how you use the service:
- If you use Getix Translate for work, that is, in the course of a business, a profession or an organisation, you are the controller of the meeting content and we act as your processor. Section 5 of the Terms sets out that relationship. You decide what is translated and you are responsible for telling the other participants.
- If you use it for purely personal purposes, data protection law does not treat you as a controller at all, so there is no one above us to give instructions. In that case we are the controller of the meeting content. We process it only to deliver the translation, subtitles, voice-over and transcript you asked for, and for nothing else. Our legal basis is the contract with you (Article 6(1)(b) GDPR) for your own data, and legitimate interest (Article 6(1)(f) GDPR) for the other people in the conversation: letting a person follow a conversation in a language they do not speak, with the limited intrusion described in this policy. You can object to that at any time (section 5).
2. What we collect and why
- Account data: to create an account with an email address, we need your first name, your last name, your email address and a password. We keep only a salted one-way hash of the password, never the password itself. If you sign in with Google, or with Apple (where offered), instead, see “Sign-in with Google or Apple” below. Legal basis: contract (Article 6(1)(b) GDPR).
- Phone number and company (optional): the sign-up form offers these two fields and marks them as optional. If you leave them empty, nothing about the service changes. If you give us a phone number, we use it only to reach you about your own account, for example about a payment problem or a request you made to us; we do not use it for sales calls or marketing unless you separately agree to that. If you give us a company name, we use it only to know that the account is used for work and to help you with that account. Legal basis: our legitimate interest in reaching and supporting you in the way you chose to offer us (Article 6(1)(f) GDPR). You can ask us at any time to change or delete either of them, and we will do so without affecting your account.
- Confirming your email address: if you sign up with an email address, we may ask you to confirm it with a six-digit code that we send to that address, and in that case the account is created only after you enter the code. While we wait for it, the details you typed, with the password already hashed, are held only in an encrypted cookie in your browser, not in our database. Each code works for 15 minutes; for up to an hour after that you can ask for a new one, after which the request lapses and no account is created. To stop the form from being used to send codes to other people’s addresses, we count code requests per email address and per network, stored in pseudonymised form (a one-way hash, not the address itself). Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR), and our legitimate interest in preventing abuse of the sign-up form (Article 6(1)(f) GDPR).
- Sign-in with Google or Apple: if you choose “Continue with Google” or, where we offer it, “Continue with Apple”, that company confirms who you are, you do not create a password with us, and, because that company has already verified your email address, we do not send you a confirmation code. We check with Google or Apple that each sign-in is genuine. From Google we keep your first and last name, your email address and your Google account identifier; the sign-in token Google sends may also carry a link to your profile picture, which we do not store. From Apple we keep an account identifier that Apple issues for our service (other companies receive a different one for you), your email address and, the first time you sign in, the name you choose to share. Apple lets you hide your real email address: we then receive a random address ending in privaterelay.appleid.com, Apple forwards our emails from it to your inbox, and we do not learn your real address. If you later turn that forwarding off in your Apple settings, our emails, including the service emails described below, will no longer reach you. Stopping the use of Google or Apple sign-in for Getix Translate in your Google or Apple account does not delete your Getix Translate account: to delete it, use Settings → Privacy → Delete my account, or write to us. We use these details to create your account and sign you in. Legal basis: contract (Article 6(1)(b) GDPR). We also use your email address and, if you sign in with Apple, the identifier Apple issues for our service to give the free trial minutes only once per email address and per Apple account. Legal basis: our legitimate interest in preventing abuse of the free trial (Article 6(1)(f) GDPR).
- Promo and invitation codes (optional): if you enter a code, or arrive through a link that carries one, we record the code with your account so that the gift or discount, and any reward for the person whose code it is, can be applied. To stop people rewarding themselves, we compare the network you sign up from with the network the code’s owner signed up from, if that was within the last day, and do not link the two accounts if they match. Legal basis: contract (Article 6(1)(b) GDPR) for applying the code, and our legitimate interest in preventing abuse (Article 6(1)(f) GDPR) for the network check.
- Meeting content: audio is processed in real time to produce subtitles, translations and voice-over. Audio is streamed transiently and is not storedby us; it reaches our speech providers only as a live stream for processing (see section 3). How it reaches us depends on the mode you choose: your microphone (In-room, Pocket Translator, Transcribe), the browser tab whose sound you choose to share (Call on this screen), or a bot that joins your call as a visible participant (Invite a bot). Text transcripts are saved to your account so you can reread them: by default they are deleted automatically after 30 days; where your plan includes the storage option you may instead choose “keep until I delete” in Settings → Meeting storage, and the app tells you there whether your plan includes it. Transcripts created under your account are visible in the product only to your account. Our administrative tools work on counts, minutes and costs, not on the text of your meetings, and our staff do not open your transcripts except where required by law or to investigate abuse. Legal basis: where you use the service for work, we process on your instructions as your processor (Article 28 GDPR); where you use it privately, see section 1 for our own basis. We do not train AI models on your meetings.
- Speaker labels: when our bot is in a call, the meeting platform tells the bot who is speaking, so the display name people use in that call appears as the speaker label in the transcript. In every other mode we do not know who is speaking, and lines are labelled neutrally, for example “Speaker 1”, within that one session only. We do not try to recognise anyone by their voice and we do not build or keep a voice profile for anyone.
- Voice matching for voice-over: when the app reads a translation aloud, it has to pick a male or a female synthetic voice for each speaker. Where a participant name is available, the app goes by the name. Where it is not, the app estimates from about two seconds of speech, sampled up to a few times until the estimate is confident, whether it is a lower or a higher voice. In the modes that run in your browser that estimate is made on your own device and the sample is not sent anywhere for it; when our bot is in the call, the estimate is made on our server from the pitch of audio we are already processing. The result is used for one purpose only: choosing which prepared synthetic voice speaks that person’s lines. It is not written into the transcript, not stored in our database and not kept as information about the person. It is sent to the other people in that session, because their app has to speak the same lines in the same voice, and the voice chosen this way forms part of the name of the cached audio file, which is deleted within 7 days. You can override it at any time by setting a speaker to a male or a female voice yourself, and your choice wins. There is no way to switch the estimate itself off. Legal basis: the same as for the meeting content it belongs to.
- Recordings (optional): if you turn on recording, the video/audio file is saved locally on your device. If you additionally enable “Cloud copy”, the file is uploaded to our EU storage so you can re-watch it. Deleting a cloud copy is not self-service yet, and deleting your account does not remove it either. Each file is stored under a name that contains the date and the minute the recording was made, so write to us with that date and time and we will find it and delete it by hand. We are building an index and a delete button, and we will update this page when they work. Legal basis: contract (you initiate it).
- Support chat: messages you type in the support widget are answered first by an automated assistant run by a third-party AI model provider (United States, Standard Contractual Clauses) and, if you ask for a person, are delivered to our team through a third-party messaging service (outside the EU). We keep support messages on our servers for up to 7 days so the widget can show you the replies; they are not linked to your account. If you choose to continue the conversation in a messaging app, we store that app’s chat identifier with the thread for as long as the thread lives, so that replies reach you. Please do not include sensitive data in support chat; you can always email us instead. Legal basis: legitimate interest (answering your request, Article 6(1)(f) GDPR).
- Waiting list: if signups are full, we store the name, email, phone and company you submit. We remove the entry by hand when we invite you, or sooner if you ask us to; an automatic cut-off after 12 months is being added. Legal basis: steps taken at your request before a contract (Article 6(1)(b) GDPR).
- Balance, payments and billing records: minutes ledger, subscriptions, purchases, access-code activations, invoices. When you pay by card, the payment itself is handled by our payment provider (section 3): you enter your card details on the provider’s pages, not ours, and what we receive back is the confirmation that the payment went through, the last four digits of the card and the billing country. We never ask for, see or store your full card number. A plan can also be activated with a one-time access code after you arrange payment with us directly; the details you send us in that exchange, such as your name, your email address and your payment reference, reach us by email or through the messaging app you chose to write from. Either way we keep the invoice. Legal basis: contract (Article 6(1)(b) GDPR) and legal obligations (accounting and tax, Article 6(1)(c) GDPR).
- Service emails: when you sign up with an email address, we may send you the confirmation code described above; when your account has been created, we email you a confirmation of that, with the version of the Terms you accepted, as Spanish law on contracts made online requires (if one did not reach you, write to us and we will send it); when you buy something, we email you a confirmation of the purchase with the terms you accepted; before a subscription renews, we email you a renewal notice with the date and the amount; and if a package you bought has an end date, we email you a reminder before it arrives. These emails are part of the contract with you, and the sign-up confirmation, the purchase confirmation and the renewal notice are required by law. They are not marketing: they contain no advertising, and you cannot opt out of them while the contract runs. We keep a record of each purchase confirmation, renewal notice and package reminder we send (see section 4); for the sign-up emails, only the delivery logs of our email delivery service exist (see section 3). Legal basis: contract (Article 6(1)(b) GDPR) and legal obligation (Article 6(1)(c) GDPR).
- Consent journal: a record of every consent you give, with the policy version, the time, and the IP address and browser string at that moment, and of every withdrawal we register. Legal basis: legitimate interest (demonstrating compliance and defending legal claims, Article 6(1)(f) GDPR).
- Technical logs: connection and service-quality events, so that we can keep the service reliable and block abuse. Session events are deleted automatically after 30 days. Service-quality records, which include your account identifier, the room code and your browser and platform string, and anti-abuse records, which include an email address or an IP address used to rate-limit sign-in and other requests, are kept while they are useful for that purpose and cleared when we review them; an automatic cut-off is being added and we will state the period here once it runs. Legal basis: legitimate interest (running a stable and secure service). We do not use advertising or analytics trackers, and we do not make automated decisions about you that produce legal or similarly significant effects.
You are not legally required to give us any data. To create an account we need your first and last name, an email address and a password, or a Google sign-in (or an Apple sign-in, where offered); without them we cannot provide the service. The phone number, the company name and a promo or invitation code are optional: you can use the service without them.
3. Who receives data, and why
We use a small number of specialist providers to run the service. Most of them act only on our instructions, as our processors. A few of them, sign-in with Google or Apple (where offered) and the payment provider, act as their own controllers for part of what they do, and we say so below. With most of these providers we have a written data processing agreement in place. Where such an agreement is still being put in place, or where a provider does not offer one at all, which is the case for the messaging service that brings support messages to our team, we send only the minimum that the task needs. Where a provider is outside the EU/EEA, the safeguards in section 6 apply. By activity:
- Real-time speech recognition and machine translation (United States): receives the live audio stream only, processes it in memory and does not retain it; contractually barred from using it to train models.
- Speech synthesis (voice-over) (United States, Standard Contractual Clauses): receives translated text and returns audio; synthesised audio is cached in the EU for up to 7 days.
- Meeting-bot infrastructure, the participant that joins your Zoom, Google Meet or Microsoft Teams call (European Union; the provider also operates infrastructure outside the EEA, under the safeguards in section 6): call audio may be retained by this provider for up to 7 days for reliability, then deleted.
- Database, sign-in and real-time delivery of subtitles (European Union): accounts, transcripts and the subtitles shown to your guests.
- Application hosting and content delivery (European Union and United States, Standard Contractual Clauses).
- Object storage for optional cloud recordings and the voice cache (stored under EU jurisdiction).
- Server workers that run the meeting bot (European Union).
- Sign-in with Google or Apple(Google Ireland Ltd., Ireland; Apple Distribution International Ltd., Ireland), only if you choose “Continue with Google” or, where we offer it, “Continue with Apple”: the company you chose confirms your identity to us and gives us the details listed in section 2. Each acts as its own controller for what happens inside its own sign-in screens. If you hid your email address with Apple, our emails to you pass through Apple’s private email relay, which forwards them to your inbox; Apple provides that forwarding to you as its own service, under its own privacy policy.
- Payment provider (Ireland): handles card payments, refunds and the receipts and invoices it issues, and runs the page where you manage or cancel a subscription. It receives your name, email address, billing country and card details; we never see the full card number. For preventing fraud and for its own legal duties as a payment institution it acts as its own controller, under its own privacy policy. Its group processes some data in the United States under Standard Contractual Clauses.
- Email delivery service (United States; EU-US Data Privacy Framework and Standard Contractual Clauses): delivers our service emails, so it receives your email address and the content of each email; keeps delivery logs for about 30 days; we do not use open or click tracking.
- Mailbox provider for our support and sales inbox(data centre in the EU): holds the emails you send to us and our replies. The provider’s support staff may access the service from outside the EEA under Standard Contractual Clauses.
- AI assistant providers for support chat (United States): the widget answers with one provider and falls back to a second when the first is unavailable. Messages are kept for up to 7 days and are not linked to your account.
- Messaging service (outside the EU; no data processing agreement and no standard transfer safeguard is available for this service): delivers support-chat messages to our team and carries our internal operational notifications. Those notifications currently contain account email addresses, the plan and the balance left, meeting start and stop metadata such as mode, languages and room code, a link to the meeting room, and a monthly summary listing accounts and the minutes they used. They never contain meeting content. Because we cannot put this service under a processing agreement, we are cutting down what it receives: replacing email addresses with internal references and dropping the room link.
We may engage an additional real-time speech-recognition provider in the EU, UK or US under the same safeguards; hosts receive 14 days’ notice before it processes any meeting.
We describe our providers by category here. You can always ask for their names:
- If you host meetings, you are entitled to the full named list of our sub-processors, with their locations (Article 28 GDPR). We give 14 days’ notice before adding or replacing a sub-processor that handles meeting content; you may object by stopping use of the service.
- Whoever you are, if we process your personal data you may ask us which specific recipients have received it (Article 15 GDPR, as interpreted by the Court of Justice of the European Union in case C-154/21), together with a copy of the transfer safeguards in section 6. You do not need an account and you do not need to host meetings.
Write to the contact in section 1 from the email address linked to your account or request, so that we can confirm it is you. We reply within one month, usually within two business days.
4. Retention
- Cloud transcripts: deleted automatically after 30 days (default). If your plan includes the storage option and you switched it to “keep until I delete”, transcripts stay until you delete them, and we do not delete already-kept transcripts if your plan later lapses. Local copies stay on your device either way.
- Live meeting audio: not stored by us. Where the meeting bot is used, the bot provider may retain call audio for up to 7 days, then deletes it. That is the provider’s own retention: it is not switched off by “Don’t save this transcript” and there is no setting for it in the app.
- Voice-over audio cache: up to 7 days (EU storage), then deleted automatically. This applies to every meeting, including meetings you started with “Don’t save this transcript”.
- The male or female voice estimate described in section 2: held in memory for the length of the session only. It is never written to the transcript or to our database, and the only trace it leaves is inside the name of the cached voice-over file above.
- Optional cloud recording copies: EU storage, kept until we delete them by hand at your request, as described in section 2. There is no automatic cut-off for them yet.
- Support-chat messages: up to 7 days on our servers, then deleted automatically; not linked to your account. Messages that reached our team through the messaging service stay in that chat until we clear it.
- Waiting-list entries: removed by hand when we invite you or when you ask; an automatic cut-off after 12 months is being added.
- Invoices, payment records and access-code activations: 6 years from the end of the financial year, because Spanish commercial and tax law requires it (legal obligation, Article 6(1)(c) GDPR).
- Records of the purchase confirmations, renewal notices and package reminders we send (who, when, which text version): kept with the purchase record for 6 years for accounting and as proof of sending; your address and account id are removed from them when you delete your account.
- Unconfirmed email sign-ups: the details are held only in an encrypted cookie in your browser for up to 75 minutes (15 for the code, then up to an hour to ask for a new one); they reach our database only if you enter the code and the account is created.
- Account data, including the optional phone number and company name: while your account exists, or until you ask us to delete the optional ones.
- Consent journal: we keep each consent record (email address, consent type, timestamp, policy version) as evidence of compliance and to honour opt-outs, and we review it periodically; an automatic five-year cut-off is being added. When you delete your account we immediately unlink the record from your account and erase the IP address and device data stored with it.
- Minutes ledger and usage history: anonymised after account deletion. The invoices above are not anonymised, because the law requires us to keep them; after deletion they are kept for that purpose only and used for nothing else.
- Technical logs: as described in section 2.
5. Your rights
Under GDPR (and, for users in Ukraine, the Law of Ukraine “On Personal Data Protection”) you have the right of access, rectification, erasure, restriction, portability and objection. These rights belong to anyone whose data we process, not only to account holders. Where processing is based on consent, you may withdraw it at any time by emailing us, without affecting processing that already took place; we act on it and record the withdrawal, and a self-service switch in Settings is being added. You may object to direct marketing at any time. Self-service today: Settings → Privacy → Download my data / Delete my account. The download includes your account profile, your consent records, your minutes ledger and subscriptions, your cloud transcripts and the log of the service emails we sent you. You may also email us; we respond within one month (extendable by two months for complex requests, and we tell you within the first month if we need the extension). You can lodge a complaint with your supervisory authority (in Spain: AEPD, aepd.es; in the United Kingdom: the Information Commissioner’s Office, ico.org.uk; in Ukraine: the Parliament Commissioner for Human Rights).
6. International transfers
Some of the providers in section 3 are in the United States. Those transfers are made under the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), which form part of the data processing agreements we have with them, and, where a provider is certified under the EU-US Data Privacy Framework, under that certification. Our email delivery service is certified under that framework and is also bound by the Standard Contractual Clauses in its data processing agreement. Our support and sales mailbox is kept in a data centre in the EU; the provider’s support staff may access it from outside the EEA, and that access is covered by Standard Contractual Clauses within the provider’s group. Where such an agreement is still being put in place, we limit what that provider receives until it is done. You can obtain a copy of the relevant safeguards by emailing the contact in section 1. Meeting audio is processed transiently and is not retained by us. The messaging service named in section 3 is the one exception: no such safeguard is available for it, which is why meeting content never goes there and why we are cutting down what it does receive.
7. Security
We protect your data with industry-standard measures. All traffic is encrypted in transit. Passwords are stored only as salted one-way hashes, never in plain text. Sign-in sessions are signed so they cannot be forged. Our servers and databases are reachable only through access-controlled services, on a least-privilege basis. Live meeting audio is never stored by us, and access codes can be used only once. We do not sell personal data and we do not train AI models on your meetings. Report security issues to the contact in section 1.
8. If your words were translated and you are not our customer
Someone in your conversation may have used Getix Translate to translate or transcribe it. This section is for you.
What we do with your voice.We process it as a live audio stream and we keep the text of what was said. We do not store the audio. We do not try to recognise who you are from your voice and we do not build or keep a voice profile for anyone. We do not train AI models on your conversation, and nothing here is used for advertising; section 3 says what each category of provider may do with what it receives. Where speakers are told apart without a name, this happens within that one session and produces neutral labels such as “Speaker 1”, which are not linked to any identity. If our bot was a participant in a video call, the platform gave the bot the display name you were using there, and that name appears next to your lines.
One thing does look at the sound of your voice. When the app speaks the translation aloud, it has to choose a male or a female synthetic voice for each speaker. Where a name is available it goes by the name; where it is not, it estimates from about two seconds of speech whether the voice is lower or higher. That estimate chooses a voice and nothing else: it is not stored, not written into the transcript and not kept as information about you. It is passed to the other people in that session so that their app speaks your lines in the same voice. We do not identify anyone by their voice and we build no voice profile.
Who is responsible. If the person who used the service did so for work, that person or their organisation is the controller and we act as their processor; please contact them first, and we will help them answer you. If they used it privately, we are the controller and you can come straight to us. Our legal basis in that case is legitimate interest (Article 6(1)(f) GDPR): enabling a person to understand and take part in a conversation in another language, with the limited intrusion described above.
Why you are reading this instead of receiving a notice.Your data reached us through someone else’s device or call, and we have no way to contact you: we do not hold your email address or your name, and looking for them would create more data about you than the translation itself. That is the situation Article 14(5)(b) GDPR describes, and it requires us to publish this information instead. That is what this section is.
What happens to the text.It is visible only to the person who started the session. By default it is deleted after 30 days, and it is not saved at all if that person chose “Don’t save”. The categories of recipients, the international transfers and the retention periods are the ones set out in sections 3, 4 and 6.
How to reach us. You have the rights listed in section 5, including the right to object and the right to have your data erased, and the right to ask which specific recipients received it (section 3). Because we do not know who the speakers were, please tell us the date and the approximate time of the conversation and, if you know it, the room code or the email address of the person who used the service, so that we can find the data. If we cannot identify you in our records we will say so, and we will not collect extra data about you in order to try. Write to the contact in section 1. You can also complain to your supervisory authority (in Spain: AEPD, aepd.es).
9. Children
The service is not intended for anyone under 16, and we do not knowingly create accounts for children. If you believe a child has registered, write to the contact in section 1 and we will delete the account.
10. Changes
We will post updates here with a new version date. Material changes will be announced in the app before they take effect.