Privacy Policy

Newey AI (“we”, “us”) complies with the privacy laws that apply to us. This policy explains what data we process, why we process it, how long we keep it, and what you can ask us to do with it.

1. Overview

This policy applies to Newey AI (newey.ai, the “Service”), our real-time interpretation caption service. We collect only the minimum personal data necessary to provide the Service, and we do not use it for any purpose other than those disclosed in this policy.

The Service has a free plan and, from August 2, 2026, paid plans as well. We never receive or store your payment card details: paid plans are sold through a merchant of record, which takes your payment directly and tells us only what your subscription is — see Processors and Third Parties. Before that date no payment information is collected at all. We do not use advertising tools. Our visit and usage analytics tools (Google Analytics, PostHog) collect data that can be linked to you only where you have consented; if you decline or make no choice, Google Analytics is not loaded at all and all that is left is an anonymous count of page views, which stores nothing on your device, assigns you no identifier, and cannot tell whether you have been here before — see Cookies and Analytics.

2. Audio, Caption, and Page Text

Live audio is not stored on or routed through our servers

The audio your microphone or a browser tab captures is sent directly from your browser to a specialized speech-processing provider in the United States. Our servers only issue a temporary authentication key; they do not receive, store, or route that audio. The real-time transcription and translation stream (live captions) does not pass through our servers either, unless you turn on Audience sharing or Voice interpretation (both off by default — see below). If you choose to save an ended session, its summary, transcript, and translation text are kept in your account (Sections 3 and 5). Private sessions and sessions you do not save are never stored on our servers.

This applies to live capture. An audio file you upload yourself is handled differently, and is described immediately below.

Audio files you upload for transcription. When you choose a recording and ask us to transcribe it or turn it into an AI note, that file is uploaded from your browser straight to our storage provider’s network in the European Union — it does not pass through our application servers. We then give the speech-processing provider a short-lived, unguessable link so it can fetch the file once. The file is deleted as soon as the transcription finishes — whether it succeeded or failed — and anything left behind is removed within 24 hours. We also delete the transcription held at the speech-processing provider as soon as we have the result. The resulting transcript, translation, and note are kept in your account under the same rules as a saved session (Sections 3 and 5), and you can delete them at any time.

If you turn on the Audience sharing feature yourself (off by default), that session’s caption text is (1) displayed in real time to audience members (third parties) who hold the share link, and (2) temporarily routed through our servers to deliver it. Our servers only relay it from memory without storing the caption text, and it is immediately discarded when you turn sharing off or the session ends. You can turn sharing on and off at any time during a session.

If you turn on Voice interpretation yourself (off by default, Business plan), each confirmed sentence of the translated caption text is sent through our servers to a voice synthesis provider in the United States, and the spoken audio comes back the same way to play on your device. Your microphone audio is not part of this — it still goes directly from your browser to the speech provider. We do not store the sentence text or the audio; both are discarded as soon as the request finishes, and the copy held by the provider is deleted immediately after synthesis. You can turn it off at any time during a session.

That spoken audio is generated by AI. It is synthesized from the translated text using a preset voice from the provider’s catalogue — it is not a recording of a person, and it is not built from your voice or from the voice of anyone speaking in the session: we do not create voice copies, and your microphone audio is never sent to the voice synthesis provider. The audio plays out loud on your device, so people around you hear an AI-generated voice without ever using the Service themselves. The app tells you this while the feature is on and asks you to tell them, because they cannot see your screen. Nothing about the audio is recorded or kept: it is played once and discarded, we do not offer a download or a recording of it, and it is not sent to anyone holding an audience share link — they receive caption text only.

Your display settings are kept only in your browser’s storage (localStorage) and never leave your device. Your glossary is stored in your browser as well, and a copy is also mirrored to your account so the browser extension and your other devices can read it — this account copy is stored like other account data (not end-to-end encrypted), is replaced whenever you save, and is deleted together with your account. Only you can access it, unless you publish a glossary (below). Session caption records, where you choose to save them, are retained in your account and can be accessed from multiple devices (Sections 3 and 5), with an encrypted copy also kept in the browser for immediate display.

Shared glossaries (from August 21, 2026 — off unless you publish one). The Service lets you publish one of your glossaries so that other people can install a copy of it. If you choose to publish one — and only then — we store a snapshot of that glossary on our servers, together with the listing details you provide, and make it available to anyone browsing the shared-glossary marketplace within the Service (an unlimited and unidentified group of third parties). We publish it under your account display name — the name on your account, which may be your real name if that is what your account uses (for example, the name provided by Google or Microsoft when you signed in). We show you the exact name before you publish, and you can change your display name in the Service settings; your email address is never shown. We also show listing statistics such as the number of installations. Editing your own glossary afterwards does not change the snapshot, and unpublishing it — or deleting your account — deletes the snapshot from our servers and stops further installations. It does not delete copies that other people have already installed: those copies become part of their data and cannot be recalled, by you or by us (Section 5). Nothing in your glossary is published unless you publish it.

In addition, portions of the transcript text may be sent to the API of a large language model (LLM) provider in the United States in three cases: (1) only where you have turned on the Smart Context (AI suggestions) feature yourself — this feature is off by default; (2) where a session record is saved to your account, a short excerpt of the transcript is sent once to generate an automatic session title; and (3) where you ask the Service to generate an AI session note (a structured summary document) from a saved session record — on your request, or at the end of a saved session if you have turned on automatic generation in the settings (off by default) — the transcript of that record is sent to generate the note. In each case the text is transmitted transiently for that processing only and is not stored by our servers; the generated note itself is kept with the session record it was made from (Sections 3 and 5). Where the record is end-to-end encrypted, we hold no readable transcript: your device sends the transcript with your request, it is processed transiently in the same way, and the note is stored only in an encrypted form we cannot read. The processing is performed by one of two LLM providers (both in the United States), depending on our configuration at the time.

Page translation in the browser extension. Our browser extension can translate the page you are reading, and which engine it uses decides whether that page text leaves your device. With Basic translation the text never leaves your browser: your browser’s own built-in translator runs on your device and we receive nothing at all. With Pro translation the visible text segments of the page are sent to our server, which passes them to one of the two AI providers named in Section 6 and returns the translated text. Pro is used only when all of the following are true: your account is on a paid plan, you are signed in, the extension’s translation engine is set to Pro, the extension’s private toggle is off, and the site is not one the extension treats as sensitive (webmail, banking, health). If any of them is not met, the extension falls back to on-device translation. Paid accounts start on Pro, and you can switch to Basic at any time in the extension popup. On the free plan the extension translates on your device and the Pro option is not offered; if a request reaches our server anyway, the server refuses it before any of the text is translated, stored, or sent to an AI provider.

What is sent is the text segments themselves, the target language, the detected source language, and the glossary terms you have saved. The address of the page you are on is not sent. The text is processed in transit only: neither the original nor the translation is stored on our servers or written to our logs. What remains of a request is an internal accounting entry — how much text it was and what it cost us to process, with none of the text in it. Translated text is cached on your device in the extension’s own storage, which the page you are reading cannot access, and is cleared when you sign out, turn on the private toggle, or turn translation off.

Using your own AI provider key. The extension also offers a third engine, My API key, in which you supply your own key for an AI provider you choose — one of the providers the extension lists, or any OpenAI-compatible endpoint whose address you enter yourself — and the extension sends the page text from your browser directly to that provider, on your own account. It does not pass through our servers, so we never see that text, and there is nothing for us to meter or store. This engine is available on every plan, including the free plan.

Because the request is made on your account, what the provider does with the text is governed by your agreement with that provider, not ours — worth checking, because some providers may use input sent on a free tier to improve their models. Your key is stored only in the extension’s storage on that device; it is never sent to us, and after you save it the extension shows only its last four characters. You can register more than one key and switch between them, and remove any of them at any time, on the extension’s key page. The two limits described above still apply: this engine is not used on a site the extension treats as sensitive, or while the private toggle is on. In both cases translation falls back to your browser’s on-device translator.

3. Data We Collect

What we collect and process on our servers:

Personal data we process
CategoryItemsCollection method
Account informationEmail address, name, profile pictureProvided by Google when you sign in with your Google account (OAuth); provided by Microsoft (email address and name only — we do not collect your profile picture from Microsoft) when you sign in with your Microsoft account; or entered by you when you sign in with an email one-time code (email address only)
Language and region preferenceYour preferred interface language and your country or regionSet from the language settings your browser sends (Accept-Language) when you first sign up — we do not use IP-based geolocation — and editable by you at any time in the Service settings; kept as account data and deleted together with your account
Where you first came fromA single short label for the source that first brought you to our site (for example, the audience caption page), taken from the utm_source value in the link you followedRecorded once when you first arrive, from the link you clicked — kept in your browser and attached to your account when you sign up, then never changed. Only a short label from a fixed format is stored: the rest of the web address, the campaign, and the page you landed on are not. It tells us which channels bring people to the Service; it is deleted together with your account
Session metadataCaption session start and end times, selected languages, usage time (seconds)Generated automatically while you use the Service
Usage recordsPer-account ledger of caption usage time (monthly and daily aggregates)Generated automatically while you use the Service
Subscription information (paid plans — from August 2, 2026)The plan you bought, the billing period, the status of the subscription, its renewal and end dates, any plan change you have scheduled, and the identifiers the merchant of record assigns to your subscription, your customer record, and each invoice — together with the plan each invoice was paid onCreated when you subscribe to a paid plan and updated by the merchant of record as the subscription changes. We never receive or store your card number, expiry date, or security code — you enter those on the merchant of record’s checkout and it collects them as the seller (Section 6). The card brand and last four digits shown to you in the Service are read from it each time and not stored by us
Saved session records (optional)Summary, transcript, and translation text of ended sessions you choose to save, session titles, and technical quality measurements for that session (caption display delay and how often displayed text was revised, plus word counts)Only where you choose to save a session — private and unsaved sessions are excluded. The quality measurements are numbers only, contain no part of what was said, and are kept and deleted with the record; where the record is end-to-end encrypted they are stored alongside it because they are not derived from readable content
AI session notes (optional)Notes generated from a saved session record (note title and body), and any edits you make to themOnly where you request note generation for a saved session record, or turn on automatic generation in the settings (off by default — Section 2). Kept with the session record and deleted together with it and with your account; where the record is end-to-end encrypted, the note is stored as ciphertext we cannot read
Glossary (optional)Terms and background context you add to your glossaryMirrored to your account when you save it, so the browser extension and your other devices can read it — stored like other account data (not end-to-end encrypted), replaced on every save, and deleted together with your account
Scheduled sessions (optional)Settings you save for an upcoming session: a title, language and usage settings, background context text, your glossary selection, and — if you reserve one — the share code of the audience linkOnly where you schedule a session — kept until you delete the reservation, deleted together with your account, and included in your data export. No caption content is involved: a reservation stores settings, not what is said
Shared glossary (optional — from August 21, 2026)A snapshot of the glossary you publish (terms, translation pairs, background context), the listing details you provide (listing name, description, preset icon and color choice, categories, language tags), your account display name (shown publicly as the publisher), the share code, when it was published or updated, whether it is still published, and how many times it has been installedOnly where you yourself publish a glossary — the snapshot and listing are then available to anyone browsing the marketplace (Section 2). Published under your account display name, which may be your real name unless you change it in the Service settings; we show you the name before you publish. Your email address is not shown
Content reports (optional)The report category and description you submit about a shared glossary, a contact email address if you choose to give one, and the IP address the report was sent fromOnly where you submit a report about shared content — no account is needed to report. Reports are kept as a record of what was reported and of what we did about it
Inquiries and attachments (optional — from August 2, 2026)What you write to us through a contact or feedback form (your message, the topic you pick, and — for business inquiries — the company, contact name, job title, and work email you enter), your email address and name, your country, the IP address the message was sent from, and any files you choose to attach (images, PDF, or text and log files, up to 3 files of 10 MB each)Only where you write to us. Attachments are stored separately from your account data and deleted 90 days after the inquiry; the message itself is kept as a record of what was asked and how we answered
Extension removal feedback (optional)The reason you pick and anything you write in the short survey shown when you remove the browser extension, and the IP address it was sent fromOnly where you fill that survey in — it is not attached to your account, and no account is needed to send it
Access logsIP address, browser information (User-Agent)Collected automatically while managing your login session — destroyed together with the session information when the session expires or you log out
Passkey information (optional)Public key, credential identifier, device typeOnly where you register passkey sign-in yourself — passwords and biometric data are not stored
Behavioral information (optional)Cookie and browser-storage identifiers, pages visited and usage history, your approximate location worked out from your IP address on the analytics provider’s servers (country and city level — not a precise position), error reports from your browser (error type and message, stack trace, page address), and, when you are logged in, linkage to an internal user identifier (a pseudonymized ID — not your email or name)Google Analytics and PostHog — only where you consent to analytics tracking (Section 8). Error reports go to PostHog only
Anonymous page view countThe path of the page you opened (without any query string), the domain that referred you (not the full address), whether you are using the website or the desktop app, and — read from the User-Agent and Accept-Language information your browser attaches to every request — your operating system and its version, your browser, whether the device is a desktop, a mobile, or a tablet, and your browser language. The request also carries your IP address, which the analytics provider uses on its own servers only to compute a value that changes daily, so that two page views on the same day can be counted as one visitor. The address is not stored on the event and your location is not worked out from itPostHog only — sent whether or not you consent, including where you decline or make no choice. Google Analytics is not loaded at all until you consent, so it receives nothing. No cookie, browser-storage entry, or identifier is created on or read from your device; your screen or window size and your time zone are not collected; nothing else about what you do is recorded; and the counts are never linked to your account. Because the daily value changes every day, a visitor returning on a later day cannot be recognized. The Audience viewer page is excluded entirely

We do not collect original audio, payment card details, or government-issued identifiers. Transcription and translation text is not stored on our servers during real-time processing; it is processed only for session records you choose to save (the table above) and for the AI and Audience sharing features described in Section 2. Page text sent for translation by the browser extension is not stored either — it is passed through for translation and discarded (Section 2).

4. How We Use Your Data

  • Identifying you and maintaining your login state (account information, session cookies)
  • Managing free usage limits and preventing abuse (session metadata, usage records)
  • Selling and running paid plans — matching the subscription you bought to your account, applying what it entitles you to, and handling renewals, plan changes, refunds, and cancellations (subscription information)
  • Keeping the records of contracts and payments that commercial law requires us to keep (subscription information — see Data Retention)
  • Translating a web page when you ask the extension to (the page text — on paid plans only, passed through for translation and not stored)
  • Answering what you write to us and keeping a record of it (inquiries and attachments), and finding out why people remove the extension so we can fix it (extension removal feedback)
  • Operating the Service, responding to incidents, and improving quality (statistical use of session metadata)
  • Personalizing your experience and understanding, in aggregate, which languages and regions our users come from (language and region preference)
  • Understanding, in aggregate, which channels bring people to the Service, so we know where to keep investing (where you first came from)
  • Improving the Service through visit and usage analytics (behavioral information — only where you consent)
  • Knowing how much the Service is used at all, and which countries, languages, operating systems, browsers, and device types to support, so that we can run and size it (anonymous page view count — no consent is needed for this because nothing is stored on or read from your device and no one is identified)
  • Fulfilling legal obligations and responding to disputes

5. Data Retention

  • When you delete your account or your agreement with us ends, we destroy the personal data we have collected without delay — except for the security records described below and anything we must keep by law. You can delete your account directly in the Service settings (“My data”) or request deletion at support@newey.ai.
  • Information we are required to retain under applicable law is kept for the period prescribed by that law — see Country-Specific Privacy Terms for examples.
  • Subscription records, from August 2, 2026. Where you buy a paid plan, the record of that contract — what you bought, when, for which period, and what happened to it afterwards (renewal, plan change, refund, cancellation) — is kept for 5 years from the transaction, including after you delete your account. The tax and commercial law that applies to us requires us to keep the books and supporting records of our own transactions for that period, and we rely on Article 17(3)(b) of the GDPR — retention necessary to comply with a legal obligation. These records contain no captions, transcripts, glossaries, or card details. Deleting your account still cancels the subscription and deletes everything else described here; what remains is the record that the purchase happened. The merchant of record keeps its own copy of the transaction under its own policy.
  • Files you attach to an inquiry, from August 2, 2026. Attachments are deleted 90 days after the inquiry they belong to, and a file you upload without ever sending the form is deleted within 24 hours. They are stored separately from your account data, and only we can open them — the storage address is not a public link. The text of your inquiry is kept as described below.
  • Inquiries and extension removal feedback. The IP address a contact or feedback form — or the short survey some people fill in when they remove the browser extension — was sent from is deleted 1 year after we receive it. It is there to limit abuse of a form anyone can send, and after that it has no further use to us. What you actually wrote to us is kept for 3 years and then deleted, so that we keep a record of what was asked and how we answered for as long as it can matter. The removal survey carries no account and no email address at any point; once its IP address is gone, what is left is a reason and a comment we cannot trace back to anyone. Files attached to an inquiry are deleted earlier, on the schedule above.
  • Security records, and the encrypted off-site copy of them. We keep an internal record of security-relevant actions on the Service — such as signing in, deleting an account, exporting your data, and administrative access — noting what was done, when, the account email address, and the IP address. It contains no captions, transcripts, glossaries, or anything else you created. We keep these records for 2 years, including after an account is deleted: their purpose is to show what happened, which they cannot do if what they record can be made to disappear. If you ask us to erase your data, we remove your email address and IP address from these records, leaving only an internal account reference, the kind of action, and when it happened — and once your account is deleted, that reference no longer resolves to anyone.
  • From August 3, 2026 we also store an encrypted copy of those security records off-site (Sections 6 and 7), so that our record of a security incident does not sit only in the system such an incident would affect. From August 26, 2026 that copy is write-once: once written it cannot be changed or deleted by anyone, including us and including in response to an erasure request, until it expires and is destroyed automatically 3 years after it was written. That is longer than the 2 years above, because the copy exists to prove the records were not tampered with, and it has to outlast the originals to do that. We rely on Article 17(3)(e) of the GDPR — retention necessary for the establishment, exercise, or defence of legal claims — together with our obligation to keep our own security records; a record that can be edited on request is not a record. The copy is encrypted before it leaves our servers with a key we keep offline and never give to the provider, and we use it only to investigate a security incident, to answer an audit, or to deal with a legal claim. Until August 26, 2026 no such write-once protection is in place.
  • Data stored only in your browser (display settings and the local cache of session records) is not held by us and can be deleted by you directly in your browser. The glossary’s account copy (Section 3) is replaced whenever you save and is destroyed together with your account. If you delete your account from within the Service, we also clear the local caches of session records and of the glossary, and the on-device encryption key, in the browser you used at that time. Copies cached in other browsers or devices stay on those devices — they are yours, are never sent back to us, and can be removed directly in that browser.
  • Session records you choose to save are retained in your account, and you can delete them individually or all at once, or export them, within the Service. AI session notes generated from a record (Section 3) are kept with it: you can delete each note individually, and deleting the record deletes its notes. When you delete your account, saved session records and their notes are destroyed together without delay.
  • Shared glossaries: a limit on erasure you should know about before you publish. A glossary snapshot you publish is retained until you unpublish it or delete your account; either destroys the snapshot on our servers without delay and stops further installations. Copies that other users have already installed are not deleted. An installed copy becomes part of that user’s own glossary — their data, on their devices and in their account — and neither you nor we can recall it. This is an inherent consequence of letting other people keep what they installed, and it is a practical limit on your right to erasure. We tell you this before you publish so that you can decide accordingly: publish nothing you may later need to withdraw from the people who already have it. Content reports (Section 3) are retained as a record of moderation even after the reported content is removed.

6. Processors and Third Parties

We use service providers (processors) to operate the Service. They process personal data only for the tasks we assign to them, and are not permitted to use it for any other purpose.

Processing overview
ProcessorTaskData processedNotes
Anthropic PBC (United States)AI featuresText sent by the feature — transcript excerpts, page text for translation
Cloudflare, Inc. (United States)DNS, network delivery, inbound email routingConnection data (IP address, requested address); email you send usYour email passes through on its way to our mailbox
Cloudflare, Inc. — audit record archive (European Union)Off-site copy of our security audit recordsSecurity audit records (account email address, IP address)From August 3, 2026. Encrypted before upload — the provider holds ciphertext only
Cloudflare, Inc. — inquiry attachments (European Union)Storage of files you attach to a contact or feedback formThe files you attachFrom August 2, 2026. Stored under addresses that are not publicly reachable, and deleted 90 days after the inquiry
Cloudflare, Inc. — uploaded audio (European Union)Temporary storage of an audio file you upload for transcriptionThe audio file you choose and uploadFrom August 7, 2026. Held only until the transcription finishes, then deleted; anything left behind is removed within 24 hours
Deep Infra, Inc. (United States)AI featuresText sent by the feature — page text for translationFrom August 15, 2026
Fireworks AI, Inc. (United States)AI featuresText sent by the feature — page text for translationNot in use — the change it was added for is paused, and nothing is sent to it
Google LLC — AI features (United States)AI featuresText sent by the feature — transcript excerpts, page text for translation
Google LLC — Google Analytics (United States)Visit analyticsCookie identifiers, pages visited, usage historyOnly with your consent to analytics cookies — without it the tool is not loaded and receives nothing at all (Section 8)
Google LLC — sign-in (United States)Sign in with GoogleEmail address, name, profile pictureOnly if you use this sign-in method
Inworld AI (Theai, Inc. — United States)Voice synthesis for spoken interpretationThe translated text of a confirmed sentence, and the audio generated from itNot in use — added ahead of a voice model option that has not shipped; nothing is sent to it
Lemon Squeezy (Sold through Link, LLC — United States)Selling and billing paid plansEmail address, name, an internal reference to your account; the payment and billing details you enter go to it directlyFrom August 2, 2026. Merchant of record — the seller of your subscription, not only a provider acting for us
Microsoft Corporation (United States)Sign in with MicrosoftEmail address, nameOnly if you use this sign-in method
PostHog Inc. (European Union — Frankfurt)Product usage analytics and error diagnosticsBrowser-storage identifiers, pages visited, usage history, pseudonymized user ID, and error reports from your browser (error type and message, stack trace, page address) — or, where you have not consented, only the anonymous page view count described in Section 8 (page path, referring domain, website or desktop app, operating system and version, browser, device type, browser language, and the IP address the request carries)Identifying data only with your consent to analytics tracking; the anonymous count regardless (Section 8)
Railway Corp. (United States)Server and database hostingThe server-stored items listed in Section 3Our hosting infrastructure
Resend (Plus Five Five, Inc., United States)Sign-in, subscription, and enquiry-reply email deliveryRecipient email address; the one-time code, or the plan, billing period, and the date a change takes effect shown in a subscription notice, or the content of our reply to an enquiry including the message you sent us quoted in itOnly when you request a sign-in code, when your subscription starts, changes, or ends, or when we reply to an enquiry you sent to one of our contact addresses
Soniox Inc. (United States)Audio processing for live captions, and transcription of audio files you uploadAudio streamed during a caption session; an audio file you upload, which the provider fetches from our temporary storageSession-scoped and transient; not retained by us. For an uploaded file we delete the transcription at the provider as soon as we have the result
ElevenLabs Inc. (United States)Voice synthesis for spoken interpretation (Voice interpretation, off by default)The translated text of a confirmed sentence, and the audio generated from itTransient; discarded when the request finishes and deleted at the provider immediately after
Wise (Wise Payments Limited, United Kingdom / EEA)Sending referral commission payoutsThe partner's payout email address and the payout amount — never bank account details, which Wise collects from the recipient directlyOnly for partners who join the referral programme and request a withdrawal

Payments: the merchant of record. From August 2, 2026, paid plans are sold through Lemon Squeezy, which acts as the merchant of record — the seller you buy from, the name on your receipt, and the party that charges your card — rather than only a provider processing data for us. When you start a purchase we pass it your email address, your name if your account has one, and an internal reference to your account, so that the subscription it sells can be matched to the right account. You then enter your card and billing details on its checkout and it collects them as the seller: they do not reach us at any point. It tells us back what your subscription is (Section 3). Your contract for the purchase is with it, its handling of the data you give it is governed by its own privacy policy, and what this means for you is set out in our Terms of Service.

Apart from the processing described above, we do not provide personal data to third parties and we do not sell personal data. Lawful requests from authorities based on applicable law are an exception.

7. International Data Transfers

To provide the Service, personal data is transferred internationally as set out below. If you do not want your personal data transferred abroad, you may stop using the Service and request account deletion; in that case, however, the Service cannot be provided.

These transfers are necessary to perform our contract with you — to provide the Service you have asked for — and that necessity, together with the disclosure in this section, is the basis on which they are made.

Where a provider processes personal data on our behalf, we rely on a data processing agreement with that provider which incorporates the European Commission’s Standard Contractual Clauses, together with the United Kingdom addendum where the provider offers one. Ask us at the address in Section 14 which of the Clauses applies to a particular transfer. Three recipients sit outside that pattern, and we name them rather than let the sentence above be read as covering all of them. Where you sign in with an account you hold with another company, your sign-in reaches that company under the terms you have with it. And the merchant of record that sells our paid plans receives your data as the seller under its own terms as well as under a data processing agreement with us; that agreement commits both parties to rely on the Standard Contractual Clauses for transfers out of the European Economic Area, but it does not annex them and it carries no United Kingdom addendum. And when we pay a referral partner who has asked to be paid, the regulated payment institution that moves the money receives that partner’s payout email address and the amount as an independent controller: the anti-money-laundering and identity checks it runs are its own legal duties, not instructions from us, and it handles that data under its own terms with the partner.

International transfer overview
RecipientCountryContactData transferredPurpose and methodRetention period
Anthropic PBCUnited Statesanthropic.comText sent by an AI feature — transcript excerpts, page text for translationAI features — sent when the feature is usedUntil the purpose of processing is fulfilled
Cloudflare, Inc.United States (globally distributed network)cloudflare.com/privacypolicyConnection data (IP address, requested address); email you send usDNS, network delivery, inbound email routing — as the request or email passes throughFor the time needed to route the request or deliver the email
Cloudflare, Inc. (audit record archive)European Union (storage) — recipient established in the United Statescloudflare.com/privacypolicySecurity audit records (account email address, IP address), encrypted by us before uploadOff-site copy — sent monthly, from August 3, 20263 years from each copy, then destroyed automatically (see Section 5)
Cloudflare, Inc. (inquiry attachments)European Union (storage) — recipient established in the United Statescloudflare.com/privacypolicyThe files you attach to a contact or feedback formAttachment storage — uploaded when you attach a file, from August 2, 202690 days after the inquiry, then destroyed automatically (see Section 5)
Cloudflare, Inc. (uploaded audio)European Union (storage) — recipient established in the United Statescloudflare.com/privacypolicyThe audio file you upload for transcriptionTemporary storage — uploaded when you choose a file, from August 7, 2026Deleted as soon as the transcription finishes; anything left behind within 24 hours
Deep Infra, Inc.United Statesdeepinfra.com/privacyText sent by an AI feature — page text for translationAI features — page translation in the browser extension, from August 15, 2026Held only for the request and deleted when it completes. The provider records operational debugging metadata (request identifier, cost, sampling parameters) — never the request or response content — and deletes it after three weeks
Fireworks AI, Inc.United Statesfireworks.ai/privacy-policyText sent by an AI feature — page text for translationAI features — not in use; the change it was added for is pausedNot kept after the request is answered
Google LLC (AI features)United Statespolicies.google.com/privacyText sent by an AI feature — transcript excerpts, page text for translationAI features — sent when the feature is usedUntil the purpose of processing is fulfilled
Google LLC (Google Analytics)United Statespolicies.google.com/privacyCookie identifiers, pages visited, usage history — only with analytics consent; without it the tool is not loaded and nothing is sent (Section 8)Visit analytics — sent while you use the Service, after you consentUp to 14 months after collection
Google LLC (sign-in)United Statespolicies.google.com/privacyEmail address, name, profile pictureSign in with Google — sent at sign-inIn accordance with Google account policy
Inworld AI (Theai, Inc.)United Statesinworld.ai/privacyThe translated text of a confirmed sentence, and the audio generated from itVoice synthesis for spoken interpretation — not in use; the voice model option it was added for has not shippedNot kept by us; nothing is sent to the provider yet
Lemon Squeezy (Sold through Link, LLC)United Stateslemonsqueezy.com/privacyEmail address, name, an internal reference to your account; and the payment and billing details you enter on its checkout, which it collects directly as the sellerSelling and billing paid plans — sent when you subscribe and while the subscription lasts, from August 2, 2026Kept by the recipient under its own policy; our own record of the contract for 5 years (Section 5)
Microsoft CorporationUnited Statesprivacy.microsoft.comEmail address, nameSign in with Microsoft — sent at sign-inIn accordance with Microsoft account policy
PostHog Inc.Germany (EU Frankfurt region)posthog.comBrowser-storage identifiers, pages visited, usage history, pseudonymized user ID, browser error reports (with analytics consent); without consent, only the anonymous page view count of Section 8 — page path, referring domain, website or desktop app, operating system and version, browser, device type, browser language, and the IP address the request carriesProduct usage analytics and error diagnostics — sent while you use the ServiceUp to 1 year after collection
Railway Corp.United Statesrailway.comThe server-stored items listed in Section 3 — account, session metadata, usage records, saved contentServer and database hosting — stored while the Service operatesUntil account deletion
Resend (Plus Five Five, Inc.)United Statesresend.com/legal/privacy-policyRecipient email address; the one-time code, or the plan, billing period, and effective date shown in a subscription notice, or the content of our reply to an enquiry including the message you sent us quoted in itSign-in, subscription, and enquiry-reply email delivery — sent when you request a code, when your subscription starts, changes, or ends, or when we reply to an enquiryCodes expire within minutes; the processor retains delivery records and the content of sent messages for up to 30 days
Soniox Inc.United Statessoniox.comAudio streamed during a caption session; an audio file you upload for transcriptionAudio processing — streamed live during a session, or fetched once from our temporary storage when you upload a fileUntil the purpose of processing is fulfilled; for an uploaded file we delete the transcription at the provider as soon as we have the result
ElevenLabs Inc.United Stateselevenlabs.ioThe translated text of a confirmed sentence, and the audio generated from itVoice synthesis for spoken interpretation — only while you have Voice interpretation onUntil the purpose of processing is fulfilled
Wise (Wise Payments Limited)United Kingdom / EEAwise.com/gb/legal/privacy-notice-business-enThe partner's payout email address and the payout amountSending referral commission payouts — only when a partner requests a withdrawalUnder the payment institution's own rules, as it holds the data as an independent controller

8. Cookies and Analytics

We distinguish between strictly necessary cookies required to provide the Service (such as login) and optional analytics cookies used only with your consent. We do not use cookies for advertising or personalized tracking.

Cookies in use
CookieCategoryPurposeDuration
better-auth.session_token (prefixed with __Secure- over HTTPS)NecessaryMaintaining your login session7 days (automatically extended with use)
Temporary authentication cookies such as better-auth.stateNecessaryPreventing forged requests (CSRF) during the sign-in process (Google or Microsoft OAuth)For the duration of the sign-in process (a few minutes)
newey:localeFunctionalRemembering your selected display language1 year
_ga, _ga_* (Google Analytics)Analytics (optional)Distinguishing visitors and visit/usage statisticsUp to 2 years — set only with consent, and the tool itself is not loaded until then
ph_* (PostHog — localStorage, not a cookie)Analytics (optional)Distinguishing visitors, product usage statistics, and error diagnostics — no cookie is setWritten only with consent, and deleted if you decline or withdraw — the anonymous page view count described below needs no storage at all
newey:first-touch (localStorage, not a cookie)FunctionalRemembering the single short source label from the link that first brought you here, so that it can be attached to your account if you later sign up (Section 2, “Where you first came from”) — it identifies a channel, not youUntil you clear your browser storage. No cookie is set, and nothing is sent anywhere until you sign in
  • Necessary and functional cookies are used without separate consent to the extent needed to provide the Service; if you block them in your browser settings, some features such as login will be unavailable.
  • Analytics cookies and browser storage are used only if you accept them in the consent banner shown on your first visit. If you decline or make no choice, no analytics cookie is set and no analytics entry is written to or read from your browser storage.
  • What still happens if you decline or do not answer. We count page views anonymously, because we need to know how much the Service is being used in order to run it. Only one of the two tools is involved: Google Analytics is not loaded at all before you consent, so it receives nothing; the count is done by PostHog alone. No cookie is set, nothing is written to or read from your browser’s storage, no identifier is assigned to your device, and nothing is linked to your account.
  • What that anonymous count contains, exactly. The path of the page you opened, with any query string removed; the domain that referred you, not the full address; whether you are using the website or the desktop app; and, read from the User-Agent and Accept-Language information your browser attaches to every request, your operating system and its version, your browser, whether the device is a desktop, a mobile, or a tablet, and your browser language. Your IP address reaches the provider because every web request carries it; the provider uses it on its own servers only to compute a value that changes daily, so that two page views on the same day can be counted as one visitor. The address is not stored on the event, and your location is not worked out from it. We deliberately do not collect your screen or window size, your time zone, the full page address, the page title, or the full referring address — these have to be read from your device or can carry personal data, and we do not need them. Nothing else you do in the Service is recorded — not the buttons you press, not your sessions, and not error reports. Because the daily value changes every day, we cannot recognize a visitor who comes back on a later day; anonymous counting tells us how many visits and visitors there were on a given day and nothing more. The Audience viewer page is excluded from this too.
  • Your consent choice is stored only in your browser (localStorage), and you can change (withdraw) it at any time below. Withdrawing takes effect immediately, without reloading the page: Google Analytics stops receiving anything, and PostHog falls back to the anonymous page view count described above. Everything PostHog had stored in your browser is deleted at that moment; a Google Analytics cookie that was already set stops being used, but remains until it expires or you clear it in your browser settings.

Manage analytics consent

Current setting: Checking…

Switching to Decline stops analytics that can identify you, straight away. Google Analytics receives nothing at all, nothing is stored on your device, and all that remains is an anonymous page view count sent to PostHog — the page path, the domain that referred you, and what your browser sends with every request (your operating system, browser, device type, and language). Your location is not worked out from your IP address. Cookies that were already stored can be removed in your browser settings.

9. Your Rights

  • You may request access to, correction of, deletion of, or restriction of the processing of your personal data at any time. Contact support@newey.ai, and we will act without delay (and no later than within the statutory deadline) and inform you of the outcome.
  • You can also exercise the most common rights yourself, at any time, in the Service settings (“My data”): delete your account and the data associated with it (subject to the one limit described below), or export your data as a downloadable file.
  • One limit on erasure you should know about. The internal security records described in Data Retention are kept even after an account is deleted, and from August 26, 2026 the encrypted off-site copy of them cannot be altered or deleted at all until it expires. When you ask us to erase your data we remove your email address and IP address from those records in our live systems, and we tell you plainly that the off-site copy remains until it is destroyed automatically at the end of its period, and when that will be. We will not tell you a copy has been deleted when it has not.
  • You may exercise your rights through a legal representative or an authorized agent; we may request documentation confirming the lawful representation.
  • Additional rights that apply in your country or region — and how to lodge a complaint with your local authority — are described in Country-Specific Privacy Terms.

10. Children's Privacy

The Service is not directed at children under the age of 14 — or under any higher minimum age that applies in your jurisdiction — and we do not knowingly collect children’s personal data. If we confirm that a child’s information has been collected, we will destroy it without delay.

11. Security

  • Encryption in transit: all of the Service’s communications (including audio transmission) are encrypted with TLS.
  • Data minimization by design: real-time audio and the live transcription stream are designed not to be stored on our servers, reducing the risk of exposure; only the session records you choose to save are retained in your account.
  • Local encryption: the local cache of the glossary and session caption records stored on your device is encrypted with AES-256-GCM. The encryption key is kept in the browser’s secure storage in a non-exportable (non-extractable) form and is not transmitted externally. Saved session records are stored on managed database infrastructure, scoped so that no other user can access them; with opt-in end-to-end encryption enabled, the server stores ciphertext only.
  • Access control: secret values, such as database connection credentials, are managed only in the server environment and are not exposed to the client.
  • Session security: HttpOnly and Secure attributes are applied to authentication cookies, and the origin of API requests is verified.

12. Country-Specific Privacy Terms

  • EEA and United Kingdom (GDPR / UK GDPR). In addition to the rights in Section 9, you have the right of access (Art. 15), the right to erasure (Art. 17), the right to data portability (Art. 20), and the right to object to processing (Art. 21), and you may lodge a complaint with the supervisory authority in your place of residence. Our legal bases are performance of a contract (Art. 6(1)(b)), your consent for optional analytics (Art. 6(1)(a)), and legitimate interests (Art. 6(1)(f), preventing abuse and counting page views anonymously as described in Section 8).
  • Japan (APPI). You may request disclosure, correction, or suspension of use of your retained personal data under the Act on the Protection of Personal Information — exercise these rights as described in Section 9. Personal data is handled by processors in the countries listed in Section 7; information about the personal-data protection systems of those countries is available on request (Section 14), and by agreeing to this policy and using the Service you consent to these transfers. Our business name, address, and representative are provided without delay on request. You may also contact the Personal Information Protection Commission (ppc.go.jp) with complaints.
  • Republic of Korea. You have the rights of access, correction and deletion, and suspension of processing under the Personal Information Protection Act; the statutory retention periods referred to in Section 5 include, from August 2, 2026, our books and the supporting records of subscription transactions (5 years, Framework Act on National Taxes and Commercial Act). Because the merchant of record is the seller of your subscription, the seller-side records required by the Act on Consumer Protection in Electronic Commerce are kept by it, not by us. You may seek redress through the Personal Information Infringement Report Center (privacy.kisa.or.kr, dial 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972). The entrusted processors and their assigned tasks are disclosed in Section 6.
  • United States (California — CCPA / CPRA). We do not sell personal information or share it for cross-context behavioral advertising. You may request disclosure of the categories collected, as well as deletion and correction, and you will not be discriminated against for exercising your rights.
  • Other jurisdictions. If the privacy law of your country of residence grants you additional rights, those rights are not limited by this policy — contact us to exercise them.

13. Changes to This Policy

How much notice you get depends on what changes.

  • If we change what we do with your data — a new category of data collected, a new third party receiving it, or a new purpose — we announce it in the Service at least 7 days before it takes effect. For material changes affecting your rights we announce it at least 30 days beforehand and, where required, ask for your consent again.
  • If it only applies when you buy something — a new recipient or a new category of data that exists only because you chose to purchase a paid plan, and that receives or records nothing about you otherwise — the revision takes effect when we publish it. Nothing reaches that recipient, and nothing is collected, unless and until you buy. Where the same change would also affect people who do not buy, the notice periods above apply instead.
  • If we are describing something that already exists — an optional feature you have to turn on yourself, a correction, or clearer wording — and what we collect, who receives it, why, and how long we keep it do not change, the revision takes effect when we publish it. We still record it in the revision history, marked as effective on publication.

This version was published on August 21, 2026. Every revision is listed in the revision history with its date and whether it took effect on publication or on a later date.

Some provisions take effect later, and none is in use before its date:

  • August 21, 2026 — shared glossaries (Sections 2, 3, 5, and 7). Glossary sharing does not open before that date, and nothing you have already stored is published as a result.
  • August 26, 2026 — the write-once protection on that off-site copy, which limits what we can erase (Sections 5, 7, and 9).

The dated list of all past revisions is available in the revision history.

For matters relating to the terms of use of the Service, please see the Terms of Service.

14. Contact

For inquiries, complaints, or remedies concerning the processing of personal data — including requests for the information described in Section 12 — contact our Information Security team, the unit responsible for personal-data protection and related grievances, at support@newey.ai. We will respond and act without delay.