Privacy Policy
Last updated: 2026-09-11 Applies to: Turjuman for iOS, including its keyboard and share extensions.
1. In short
Turjuman translates messages between you and someone who does not share your language. To do that, the text you translate is sent to our servers and to an AI provider, and — unless you turn on Private Mode — stored so you can read the conversation later.
Three things are true and worth stating before the detail:
- We do not track you. No analytics, no advertising identifiers, no
crash reporting, no location, no contacts, no device identifiers. None.
- Your message text is encrypted where it is stored, with a key our
database does not hold. Some things around it are not — conversation titles and document file names are stored as plain text, and section 4 says so plainly rather than claiming otherwise.
- Your data leaves Korea. Our database is in Singapore and the AI
providers are elsewhere again. Section 6 sets out exactly who receives what, where, and for how long.
2. Who is responsible
| Service provider | Mostafa Essam |
| Address | Chungcheongnam-do Nonsan-si Eunjin-myeon Gyowa 1-gil 26, 202, Nonsan-si, Chungcheongnam 32998, South Korea |
| Privacy officer (개인정보 보호책임자) | Mostafa Essam |
| Contact for any privacy question or request | privacy@getturjuman.com |
Under Korea's Personal Information Protection Act (PIPA) we must name a privacy officer and a working contact address. Requests sent to the address above are answered within 30 days.
3. What we collect, and why
Account
| Data | Why | Lawful basis (PIPA Art. 15) |
|---|---|---|
| Email address | Sign-in identity, password reset | Necessary to perform the contract |
| Password | Sign-in. Stored only as a bcrypt hash; we never see or store the password itself | Necessary to perform the contract |
| Language, tone and formality preferences | To translate the way you asked | Necessary to perform the contract |
| Time zone | To resolve "tomorrow at 3" into a real date in appointment detection | Necessary to perform the contract |
What you translate
| Data | Why | Lawful basis |
|---|---|---|
| The message text you paste or type | To translate it | Necessary to perform the contract |
| The translation, and any suggested reply you choose | So the conversation is readable afterwards | Necessary to perform the contract |
| Conversation background you write yourself | To make translations fit the relationship | Consent — it is optional and you may clear it at any time |
| Conversation title | To label the conversation in your list | Necessary to perform the contract |
| Documents you upload for translation | To translate them | Necessary to perform the contract |
If Private Mode is on, no message content is stored at all. It is translated and returned to you, and nothing is written to the database.
Operational
| Data | Why |
|---|---|
| Request counts and timestamps | Rate limiting, to stop abuse and control cost |
| A request identifier | So a retried request cannot be charged or processed twice |
Payment
We never receive your payment details. Subscriptions are sold through Apple's In-App Purchase. Apple processes the payment and tells us only that a subscription is active. We do not see, store, or transmit your card number, billing address, or name.
4. How your messages are protected — and what is not encrypted
Your message text, its translation, any reply you selected, and the AI's analysis are encrypted before they are written to the database. The decryption key is not stored in the database and is not held by our database provider — it lives only in our processing service. Someone who obtained a copy of the database alone would hold unreadable data.
Being precise about what that does not cover. The following are stored as ordinary text, not encrypted:
- Conversation titles, which you or the app may set. A title can describe
a relationship.
- Document file names. A file name can be the sensitive part on its own.
- Your email address, language preferences and time zone.
- Timestamps and counts — when messages were sent and how many.
We would rather tell you this than write "all your data is encrypted", which would not be true.
Passwords are stored only as bcrypt hashes and are never visible to us, including during a password reset.
5. AI translation, and what the AI provider does with your text
Translation is not done by us. The text you translate — and the conversation background, if you wrote one — is sent to OpenRouter, which routes it to a model provider (currently Google and OpenAI models).
For those providers we have enabled:
- Zero Data Retention, so your text is not retained after the translation
is produced, and
- Training disabled, so your text is not used to train or improve any
model.
Both were verified on 2026-08-30 and are re-checked when providers change.
This is the part of the service where your message content travels furthest. If that is not acceptable for a particular conversation, do not translate it, or use Private Mode so that nothing is stored afterwards.
6. Where your data goes, including outside Korea
Our users are in Korea; our systems are not. Under PIPA Article 28-8, an overseas transfer must be disclosed specifically, so this section names each recipient, the country, what they receive, why, and for how long.
| Recipient | Country | What it receives | Why | Retention |
|---|---|---|---|---|
| Supabase | Singapore | Account data, encrypted message content, conversation titles, document jobs | Database, authentication, file storage | Until you delete it or close your account. Documents: 24 hours |
| Our processing service (n8n) | Singapore (DigitalOcean, SGP1) | Message text, conversation background, whole documents, and your session token — in plain text, because it holds the encryption key | Translation, encryption, orchestration | Successful runs store nothing. Failed runs retain their data for debugging, removed automatically within 7 days |
| OpenRouter, and the model provider it routes to | United States and elsewhere | The text being translated, and conversation background | The translation itself | Zero Data Retention enabled; no training |
| Resend | United States | Your email address and the contents of authentication emails, including reset links | Password reset and confirmation email | Email and log data 30 days; backups 7 days |
| Cloudflare | Global edge network | Connection metadata for requests to our service | Network delivery and protection | A limited period set by Cloudflare |
| Hostinger | European Union and elsewhere | Domain and email infrastructure records | Domain, website and email | Deleted 30 days after the service ends |
| Apple | United States | Subscription status | To know whether your subscription is active | Per Apple's own policy |
Transfers are made to perform the service you asked for, and each provider above is bound by a data processing agreement that requires comparable protection from anyone they use in turn.
You may refuse an overseas transfer — but because every part of this service runs outside Korea, refusing means the service cannot be provided. In that case you can delete your account at any time (section 8).
7. How long we keep things
| Account and preferences | Until you delete your account |
| Messages and conversations | Until you delete them, or delete your account |
| Uploaded and translated documents | 24 hours, then deleted automatically |
| Rate-limit and request records | A short operational period, then deleted |
| Abuse guard: a one-way hash of your email address, and a count | 7 days — and this one survives account deletion. See below. |
| Debugging records containing message content | Removed automatically within 7 days |
| Anything at all, in Private Mode | Not stored |
Deleting the app does not delete your data. Removing an app from your phone does not tell us anything. Your account and its messages remain until you delete the account itself, which you can do inside the app.
8. Your rights, and how to use them
Under PIPA you may access, correct, delete, and suspend the processing of your personal data, and withdraw consent. Two of these are built into the app and take effect immediately:
- Export everything — Settings → Export my data. Returns a single file
containing your profile, every conversation, every message in readable form, and the record of every document. It is produced on request, not from a stale copy.
- Delete your account — Settings → Delete account. Removes your
account, your messages, your conversations and your sign-in identity. This cannot be undone.
One thing survives deletion, and we would rather say so than let you find out. The free plan has a daily limit. Without a record that outlives the account, anyone could delete and re-register to reset it, and the cost of that falls on the people who pay. So when you use the service we store, separately:
- a one-way hash of your email address — not the address, and it cannot be
turned back into one;
- the number of requests you have made today;
- a one-way hash of the network address the request came from, paired
with the accounts seen using it. Also not reversible, and kept for the same reason: one address driving dozens of new accounts is a script, not a person.
Nothing else: no message, no name, no identifier that points back to you. These rows are deleted after 7 days, and the daily count resets every day regardless. If you come back after a week, you start fresh.
You can also correct your details in Settings at any time, and delete individual messages or whole conversations.
For anything else — including a complaint — write to privacy@getturjuman.com. We answer within 30 days.
These rights are never behind a paywall. Export and deletion work on a free account, on a paid one, and on a subscription that has lapsed.
You may also complain to Korea's Personal Information Protection Commission (privacy.go.kr, 국번없이 182).
9. Children
Turjuman is not intended for children under 14, and we do not knowingly collect their data. PIPA requires a legal guardian's consent below that age. If you believe a child has created an account, write to us and we will delete it.
10. Security
- Message content is encrypted at rest with a key held outside the database.
- All traffic uses HTTPS.
- Your sign-in session is stored in the iOS Keychain, protected by your
device passcode, and is never written into the app's ordinary storage.
- Access to production systems is limited to 1 administrator
account(s).
- Rate limits bound how much any one account can do.
If a breach affects your personal data, PIPA requires us to notify you and the Personal Information Protection Commission without delay, and within 72 hours of becoming aware. We will tell you what happened, what data was involved, and what you can do.
No system is perfectly secure, and we will not claim otherwise.
11. The keyboard
Turjuman's keyboard asks for Full Access. It needs it to reach the network, to read your saved sign-in, and to translate — without it the keyboard still types, but cannot translate.
While Full Access is on, the keyboard sends only the text you explicitly ask it to translate. It does not log your keystrokes, does not read what you type in other apps, and does not send anything anywhere unless you tap Translate.
12. Changes
If we change this policy in a way that affects you, we will tell you in the app before the change takes effect. The date at the top always reflects the current version.
13. Contact
privacy@getturjuman.com Chungcheongnam-do Nonsan-si Eunjin-myeon Gyowa 1-gil 26, 202, Nonsan-si, Chungcheongnam 32998, South Korea