Privacy Policy
Updated: September 28, 2026
Account & login
We use your email to identify your account, send login codes, and link subscriptions. Google sign-in provides a verified email address; we do not read your Gmail. After each successful sign-in, we update the account’s latest sign-in IP address and time, plus the approximate country, region, and city supplied by Cloudflare when available, for account security and operational investigation. Only authorized administrators can view them. We retain them until account data is deleted, except where retention is required by law. An IP usually identifies a network exit and does not establish a home address. The website uses HttpOnly session cookies, and the browser extension stores its own login credentials separately. You can sign out of the current device or all devices from the account page.
The website also uses a non-HttpOnly functional cookie (wt.ui.locale) to remember the interface language you choose and keep it consistent across pages. A second cookie of the same kind (wt.ref) records an invitation code when you arrive through a friend’s invite link, so the referral reward can be issued, and is kept for 30 days. Neither carries account data, and you can clear both in your browser at any time.
Videos & subtitles
Local video files stay on your device. When no original subtitles are available, the service uploads audio segments as needed to generate subtitles; when subtitles exist, only the tracks that need translation are uploaded. Audio or subtitle data is sent to the recognition and translation providers configured for the service (OpenRouter, Alibaba Cloud Bailian). Bailian backup speech recognition processes uploaded audio segments in Singapore; Bailian translation processes subtitle text in Beijing. Please only use content you are authorized to access and process.
Temporary audio uploads are normally deleted after the task finishes, and cleaned up after service recovery if interrupted. Only when speech recognition has a structural anomaly, delivers a degraded result, or fails with both providers may we keep the already uploaded WAV window (at most 30 seconds) as a private diagnostic sample. A sample becomes inaccessible 24 hours after its first retention; while the service runs, expired files are cleaned up hourly, and samples may be deleted sooner when the storage cap is reached. Only operators use these samples to investigate failures. They are not used as subtitle cache and are not available to other users. Subtitle results are stored as task records and kept for reuse with no expiry. Subtitles for the same video, segment, and language pair can be reused free of charge at any time, including across accounts; the service never assigns subtitle ownership to a single account. Because subtitles are stored per video and language and shared with other accounts, subtitles already generated for a video cannot be deleted for one account alone; see Your choices for querying, correcting, or deleting your account data. We do not show your email, credits, or payment records to other accounts.
Payments & operational records
Payments are handled by Stripe; we never receive or store full card numbers. We keep the payment identifiers, order status, credit batches, and usage records linked to your account to provide subscriptions, reconciliation, and entitlement adjustments after refunds. Operational logs record request types, task status, and limited diagnostics, and should not contain login credentials or raw payment keys. Necessary translation-request diagnostics record the currently authenticated account, loaded code version, current extension version, package distribution channel, and its own installation method to investigate old-client and free-reuse issues. These client reports are not signed proof. Package channel is not first-touch acquisition, and normal CRX installation alone does not prove installation from the Store. Turning off extension usage statistics stops analytics events, but does not stop these necessary request diagnostics. These diagnostics add no device identifier, IP, raw user agent, audio, subtitle text, or login credentials.
Referrals, reliability & usage analytics
To understand which websites visitors come from, whether the product is stable, and whether the subtitle features are actually used, we record the referring domain, plus the external referrer URL actually supplied by the browser on public-page visits (which may include a path and selected content identifiers and campaign parameters, with credentials, fragments, search terms and other query parameters removed) and the visitor IP address, a randomly generated anonymous device identifier that you can reset, anonymous error diagnostics (error type and a deduplication fingerprint, with no page content), coarse media technical diagnostics (declared local file format and size bucket, duration and resolution category, plus audio codec category, sample-rate category and channel count when a local track is parsed; when MP4 audio configuration cannot be read, limited categories for the selected audio entry, configuration state and index layout; when MP4 audio index validation fails, limited categories for the index layout and failure reason), an aggregated estimate of caption-available playback time (forward playback seconds only, counted after a translated subtitle window is ready; excludes paused, background, and seek playback), and clicks on core controls as a fixed action enum (for example start/stop translation, changing language or subtitle source, changing display mode, export). This data is used only for referral, reliability, and product-usage analysis; when you are signed in, the server associates these statistics with your account so your own account page and operators can see usage. Referrer URL and visitor IP details are retained for 30 days and available only in the operator dashboard. Browsers may provide only the origin; removed paths cannot be recovered. Expired details are hidden immediately and deleted at the next cleanup; backups may retain prior copies under their lifecycle. We do not collect the currently playing video URL, titles, file names, media identifiers, or subtitle text; the referrer itself may point to an external video page. This data is not shown to other accounts and is not used for advertising, account authorization, or billing.
Viewing measurement retention
New versions also record a random identifier for each viewing attempt, host and subtitle-source categories, same-page time to the first subtitle, and aggregate seconds for foreground translated viewing, missing subtitles, confirmed no-content intervals, and media waiting. Presentation confirmation means a browser rendering opportunity, not proof of human attention or understanding. Viewing and click events, including first-subtitle events from the new protocol, are kept for at most 31 days; legacy first-subtitle and other analytics events are kept for at most 180 days.
Page traffic analytics
When you visit a public page, we also record a category from a fixed list of page routes to count page views and distinct devices. Language variants share one route; share links use a route template. We do not record the full page URL, query string, or dynamic share identifier for this purpose.
On public marketing pages only, you may choose to allow Google Analytics 4. If you allow it, Google receives a fixed page route, an optional referring website origin and safe campaign tags, plus the browser and cookie data needed for its visitor statistics. Google also uses your IP address at collection time to derive approximate location, then discards the IP before logging it in its data centers or servers. We do not send video, account, checkout, share-page, file or subtitle content to Google Analytics, and advertising features are disabled. The Google tag is not loaded before you allow it. Your choice is saved in this browser; you can change it here. Google processes this data under its privacy terms.
Your choices
You can stop translating, sign out, uninstall the extension, or cancel renewal from subscription management. To query, correct, or delete your account data, contact [email protected]; to verify your request we may need to confirm the account email. Records that must be retained by law or to process unresolved payment disputes may not be immediately deletable.