Skip to content

Privacy Policy

Last updated: May 7, 2026

LokAI is an AI-powered localization management platform for software teams. This Privacy Policy explains how LokAI collects, uses, shares, and protects personal data when you visit our websites, use LokAI Studio, use our API or CLI, interact with our documentation, or contact us.

For this policy, “LokAI”, “we”, “us”, and “our” means [LEGAL ENTITY NAME], located at [REGISTERED ADDRESS].

Contact us about privacy at [email protected].

LokAI acts as a controller for personal data we decide how to process, including website visitor data, account data, billing or commercial contacts, support messages, security logs, analytics, and product communications.

LokAI acts as a processor for customer workspace content that customers submit to the platform. This includes translation keys, source strings, target translations, uploaded files, glossaries, style guides, project metadata, comments, screenshots, context, translation memories, tenant rules, and tenant customizations.

Customers are responsible for deciding what customer content they submit to LokAI and for ensuring that they have the necessary rights and notices for that content.

We may collect the following categories of personal data.

CategoryExamples
Account dataName, email address, organization name, role, workspace membership, authentication identifiers, account preferences
Customer contentTranslation keys, source strings, target translations, glossaries, style guides, project files, comments, screenshots, tenant customization rules
Technical dataIP address, browser and device data, request logs, API logs, audit logs, security events, error reports
Usage dataPages visited, actions taken in the product, feature usage, workflow events, performance data
CommunicationsSupport requests, sales inquiries, feedback, survey answers, email preferences
Billing and commercial dataBilling contacts, invoice metadata, tax information, plan information, payment status

We do not intentionally collect special categories of personal data, such as health information, religious beliefs, biometric data, or government identification numbers. Customers should avoid submitting sensitive personal data to LokAI unless their own legal basis and security requirements allow it.

We use personal data to:

  • provide, maintain, and secure LokAI;
  • authenticate users and manage sessions, workspaces, roles, and permissions;
  • process localization workflows, imports, exports, translations, reviews, and tenant customizations;
  • provide API, CLI, and integration functionality;
  • deliver customer support and service communications;
  • monitor reliability, errors, abuse, fraud, and security risks;
  • understand product usage and improve the platform;
  • send product or marketing communications where permitted;
  • comply with legal obligations and enforce our agreements.

LokAI uses AI providers to support workflows such as translation, review, terminology application, style-guide enforcement, quality checks, and tenant customization.

When an AI job is requested, LokAI may send the minimum relevant customer content to the selected provider or model configuration. This may include source strings, existing translations, glossary entries, style-guide rules, tenant instructions, project context, file metadata, and prompt instructions needed to complete the job.

AI data handling depends on the selected provider and model configuration. Some AI paths may support zero-data-retention or equivalent enterprise controls. Others may apply standard provider retention for abuse monitoring, security, or service operation. LokAI will maintain provider-level disclosures so customers can understand whether a model path is zero-data-retention, no-training-by-default, or subject to standard provider retention before using it for AI jobs.

LokAI will not sell customer content. LokAI will not intentionally use customer content to train a shared LokAI model or authorize third-party model training unless the customer has selected or agreed to a provider, model, feature, or contract term that permits that processing.

Where the GDPR or similar laws apply, we process personal data under the following legal bases:

Legal basisExamples
ContractCreating accounts, providing Studio/API/CLI access, processing workspace content, support
Legitimate interestsSecurity, abuse prevention, service reliability, product analytics, internal administration
ConsentOptional marketing, non-essential cookies where required, optional feedback or research features
Legal obligationTax, accounting, compliance, lawful requests
Pre-contractual stepsResponding to sales inquiries, demos, procurement, and onboarding requests

We share personal data only when needed to provide LokAI, comply with law, protect rights or security, or complete a business transaction such as a merger, acquisition, financing, or sale of assets.

We use service providers and subprocessors to operate the platform. The list below reflects the current architecture and may change as the platform evolves.

SubprocessorPurposeData categories
SupabasePostgreSQL database, authentication, auth email hooksAccount data, authentication data, customer content, technical data
Deno DeployHosting for Deno services such as API and email serviceRequest data, technical data, customer content processed by API/email routes
Cloudflare PagesStatic hosting and delivery for documentation and marketing sitesWebsite visitor technical data
SentryError monitoring and diagnosticsError reports, technical data, limited request context after filtering
PostHogProduct analytics when enabledUsage data, device/browser data, account or workspace identifiers after identification
OpenAIOptional AI translation, review, and related AI jobsCustomer content and prompt context submitted for selected AI jobs
AnthropicOptional AI translation, review, and related AI jobsCustomer content and prompt context submitted for selected AI jobs
ResendTransactional email delivery when selectedEmail address, message metadata, transactional email content
MailjetTransactional email delivery when selectedEmail address, message metadata, transactional email content
LoopsTransactional or lifecycle email delivery when selectedEmail address, message metadata, template variables
GitHubSource hosting and repository integrationsRepository metadata, integration metadata, pull request or file data when connected
Web3FormsWebsite contact form processing when enabledContact details and message content submitted through the form

We do not sell personal data.

LokAI may process personal data in countries other than the country where you are located. Where personal data is transferred outside the European Economic Area, United Kingdom, or Switzerland, we will use appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses, Data Privacy Framework participation where applicable, or equivalent legal mechanisms.

We retain personal data only for as long as necessary for the purposes described in this policy.

Customer content is retained while the relevant workspace or account remains active. After workspace or account deletion, LokAI will delete or anonymize customer content within 90 days, unless retention is required for legal obligations, security, dispute resolution, backups, or another legitimate business need.

Backups may retain data for a limited period after deletion before they are overwritten according to our backup lifecycle. Billing, tax, audit, and security records may be kept for longer where required or permitted by law.

We use technical and organizational measures designed to protect personal data, including access controls, authentication, least-privilege permissions, encryption where appropriate, logging, monitoring, backups, dependency updates, and security review of critical workflows.

No online service can guarantee perfect security. If we become aware of a personal data breach, we will investigate and notify affected customers or authorities where required by law.

LokAI uses cookies and browser storage to operate the product, remember preferences, authenticate users, improve reliability, and understand usage. Some items are set only when the related product, site, or feature is enabled.

Name or patternTypePurposeDuration
sidebar_stateCookieRemembers whether the application sidebar is expanded or collapsed7 days
sb-*Local storage or session storageStores Supabase authentication session data, depending on the user’s remember-me choiceUntil sign-out, session end, or browser cleanup
lokai-auth-persistenceLocal storageRemembers whether the user chose persistent or session-only authenticationUntil changed, sign-out cleanup, or browser cleanup
lokai-theme-preferenceLocal storageRemembers light, dark, or system theme preferenceUntil changed or browser cleanup
lokai-user-cacheLocal storageCaches the authenticated user profile for faster loadingUntil sign-out, refresh, or browser cleanup
lokai-workspace-cacheLocal storageCaches workspace list and active workspace metadataUntil sign-out, refresh, or browser cleanup
lokai-active-workspace-idLocal storageRemembers the active workspaceUntil changed, sign-out, or browser cleanup
lokai-workspace-languages-*Local storageCaches workspace language metadataUntil workspace cache cleanup or browser cleanup
lokai-projects-cache-*Local storageCaches project lists per workspaceUntil workspace/project cache cleanup or browser cleanup
redirectUrlSession storageRemembers the page to return to after sign-inCurrent browser session
lokai.activation.tokenSession storageTemporarily stores account activation redirect stateCurrent browser session or until consumed
ph_* or PostHog-managed storageCookie, local storage, or session storageProduct and documentation analytics when PostHog is enabled in productionManaged by PostHog configuration and user opt-out state

The documentation and marketing sites load PostHog only in production when PUBLIC_POSTHOG_KEY is configured. The product analytics client is configured to respect the browser Do Not Track setting.

The documentation site may load fonts from Google Fonts. This does not set a LokAI cookie, but it does cause the browser to request font resources from Google-operated domains.

Depending on your location, you may have the right to access, correct, delete, export, restrict, or object to the processing of your personal data. You may also have the right to withdraw consent where processing is based on consent and to lodge a complaint with a data protection authority.

To exercise your rights, contact [email protected]. We may need to verify your identity before completing a request. If your request concerns customer content controlled by one of our customers, we may direct you to that customer or process the request according to that customer’s instructions.

LokAI is not intended for children. We do not knowingly collect personal data from children under 16, or a higher age where local law requires it. If you believe a child has provided personal data to LokAI, contact us so we can take appropriate action.

We may update this Privacy Policy from time to time. If changes materially affect your rights or how we process personal data, we will provide appropriate notice, such as by updating this page, emailing account contacts, or notifying users in the product.

Privacy contact: [email protected]

Legal entity: [LEGAL ENTITY NAME]

Registered address: [REGISTERED ADDRESS]