Legal
Privacy policy
Effective June 21, 2026
This policy explains how translate.lu handles personal data when you use the translator, tutor chat, account, history, audio, and password-reset features.
1. Who is responsible
MAVERICKA SARL-S is the data controller responsible for translate.lu. Contact us for privacy questions, requests, or complaints.
2. Data we process
Account data: email address, salted password hash, account role, verification status, and account timestamps.
Signed-in history: source text, translated text, languages, provider information, tutor conversations, messages, and timestamps.
Optional provider settings: provider name, model, endpoint, and encrypted API credentials supplied by the user.
Security and operational data: essential session identifiers, hashed IP information, bounded usage events, provider-health logs, and password-reset token hashes.
Audio data: Luxembourgish text submitted for server-generated speech and generated audio may be cached to avoid repeated generation.
3. Anonymous use
Anonymous translations and tutor chats are not added to account history or persisted as user records. They are processed transiently to provide the requested result.
The submitted text is still sent to the configured translation or AI provider when that provider is needed to perform the request.
4. Why we process data
We process account details, translation history, chats, audio, and reset emails to provide the service requested by the user.
We process limited security and operational information to protect accounts, prevent abuse, diagnose failures, and maintain the service.
The principal legal bases are performance of the service requested by you and our legitimate interests in security, reliability, and fraud prevention.
5. Service providers
Hosting is intended to be provided by Hetzner in the European Union.
Translation and tutor requests may be processed by Mistral AI or by another provider selected by the operator or the user, including OpenAI, DeepSeek, or a custom endpoint.
Password-reset emails are delivered through Resend, which receives the recipient address and the email content required for delivery.
Where a provider processes data outside the European Economic Area, we rely on the provider's applicable transfer safeguards and contractual terms.
6. Cookies
We use the essential lux_session cookie to keep signed-in users authenticated. It is HTTP-only, uses SameSite=Lax, and is marked Secure in production.
We do not currently use advertising cookies or third-party analytics cookies.
7. Retention
Account and signed-in history data are retained while the account remains active or until deletion is requested, unless a longer period is required for legal or security reasons.
Password-reset links expire after one hour and can be used only once. Expired and used reset records are removed from active storage.
Operational logs are bounded and replaced over time. Deleted information may remain in encrypted backups for a limited backup cycle before being overwritten.
8. Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, portability, or objection to processing. You may also complain to the Luxembourg National Commission for Data Protection (CNPD).
To exercise a right, contact the privacy address below. We may need to verify your identity before fulfilling the request.
9. Security
Passwords are stored as salted password hashes. Password-reset tokens are random, stored only as hashes, expire after one hour, and are invalidated after use.
Provider API keys are encrypted at rest. HTTPS, restricted administrative access, backups, and server security controls are used in production.
No internet service can guarantee absolute security. Contact us promptly if you believe your account has been compromised.
10. Changes
We may update this policy when the service, providers, or legal requirements change. The effective date shown on this page will be updated when material changes are made.
Controller and contact
MAVERICKA SARL-S
team@maverickans.com