Picture Translate — Privacy Policy
Picture Translate is a Chrome extension that translates the text inside an image and gives you back a new, translated image. This policy explains what data the extension handles, where it goes, and why.
Summary
- When you install Picture Translate, it sends one install event (a random install ID) to our server. Beyond that, images are processed only when you start a translation.
- In Standard mode your image is sent from your browser to Google Translate. In High mode your image is sent to our server, which passes it to OpenAI to be translated.
- Our code does not store your images. Our server holds an image in memory only while it is being translated.
- We collect limited usage data tied to a random install ID, to keep the free service running, to prevent abuse and to count usage.
- We do not sell data, show ads, or use data for advertising, profiling or credit decisions.
1. Data the extension handles
1.1 Images you choose to translate
The image you pick — with Right-click → Translate Picture, with Select Area, or with Upload Image — is the content that gets translated. Images can contain any text or picture, including personal information if the image contains it. Please do not translate images you are not comfortable sending to the services named below.
- Right-click: the extension reads the image you clicked on the current web page.
- Select Area: the extension takes a screenshot of the visible part of the current tab, keeps only the rectangle you selected, and discards the rest of the screenshot immediately. The full screenshot never leaves your browser.
- Upload Image: the file you choose on the extension's own Upload page. Its file name is not sent anywhere.
The extension does not read or send the address of the page you are on, its title, your browsing history, or any other page content.
1.2 Settings stored on your device
Stored only in your browser's extension storage
(chrome.storage.local):
- your chosen target language;
- an install ID — a random identifier (UUID) created by the extension. It is a persistent pseudonymous identifier: it stays the same for as long as the extension is installed, and it is not linked to your name, email address, Google account or any account with us — we have no accounts.
The translation mode (Standard or High) is not stored. Removing the extension deletes this data from your browser.
1.3 Limited usage data sent to our server
- Install event — sent once, when the extension is first installed: the install ID.
- After each Standard translation finishes — the install ID,
the mode (
standard), how the translation was started (right-click, select area or upload), whether it succeeded, and the target language. Not the image and not the page. A translation you cancel is not reported. - With each High translation — the image, the target language, the install ID, a random request ID, and how the translation was started.
Like any web server, our server also receives your IP address when the extension contacts it (see section 4).
2. Standard mode — Google Translate
Standard is the default mode.
- Your image is sent directly from your browser to Google
Translate (
translate.google.com), inside a hidden frame the extension opens for that one translation. It does not pass through our server. - The source language is detected automatically; the chosen target language is sent with the request.
- The extension reads back only the translated image. It does not read your Google account information or cookies.
- Because the request comes from your own browser, Google receives what a browser normally sends to a Google website, such as your IP address, browser information and — depending on your browser settings — Google cookies.
- Google handles this data under its own terms and privacy policy: Google Privacy Policy and Google Terms of Service. Google's privacy policy states that Google collects "the content you create, upload, or receive from others when using our services".
Picture Translate has no agreement with Google about this processing and does not control what Google does with the data it receives.
3. High mode — our server and OpenAI
High is an optional mode you choose for one translation at a time.
- Your image, the target language, the install ID, a request ID and how the
translation was started are sent to our server,
picture-translate-api.up.railway.app, over HTTPS. - Our server sends the image and a translation instruction to
the OpenAI API (the image edits endpoint,
/v1/images/edits) and returns the translated image to you. The install ID, the request ID and your IP address are not sent to OpenAI. - Our server keeps the image and the result in memory only, for the duration of the request. Our code never writes them to disk or to a database and never logs them.
What OpenAI's API documentation states for the /v1/images/edits
endpoint (OpenAI
— Data controls):
- Training: data sent to the OpenAI API "is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)".
- Abuse-monitoring retention: 30 days. Abuse-monitoring logs "may contain certain customer content, such as prompts and responses", and are retained "for up to 30 days, unless longer retention is required by law".
- Application-state retention: none for this endpoint.
- Image inputs "are scanned for CSAM content upon submission", and an image flagged by that classifier is retained for manual review.
OpenAI's own handling is governed by OpenAI's terms and policies.
4. Our server, logs and retention
Our server runs on Railway (railway.com), a cloud hosting provider. There is no database: everything below lives only in the server's memory, and all of it is lost whenever the server restarts.
| Data | Purpose | How long our server keeps it |
|---|---|---|
| Image and translated result (High) | the translation | only while that request runs |
| Install ID, in the fair-use limiter | per-install limits on High | created only by a High translation; dropped 25 hours after that install's last High request |
| Request ID | preventing a High request from being charged twice | treated as a duplicate for 10 minutes; the ID itself stays with that install's limiter entry until it expires and is cleaned up, and at the latest when that entry is dropped (25 hours after the last High request) |
| IP-derived key, in the fair-use limiter | per-network limits | your IP address is turned in memory into a keyed hash (a random key that changes on every server restart). The hash and its counters are dropped 25 hours after the last request from that network. Our code does not store the IP address itself |
| Install ID, in daily usage counts | counting active and new installs per day | the current day and the previous day, then discarded — at most about 48 hours |
| Install ID, in weekly usage counts | counting active and new installs per week | the current calendar week and the previous one, then discarded — at most 14 days |
| IP-derived key, in daily / weekly usage counts (High only) | counting distinct networks, to check abuse protection works | same as the two rows above: at most about 48 hours / at most 14 days |
| Usage counts — numbers only (translations per mode, per workflow, per target language, errors, blocks) | operating the service | the current and previous day, and the current and previous calendar week |
Days and weeks are counted in the Europe/Moscow time zone.
Our server's own log lines contain timings, error types and truncated keyed hashes used to spot abuse — not images, IP addresses, full install IDs, or page addresses.
Our hosting provider's logs. Railway is the infrastructure provider for all requests to our server and keeps its own HTTP request metadata — which, according to Railway's documentation, includes the client IP address and user agent — under its own logging policy. Railway retains logs for a period that depends on the hosting plan; for our service that is 7 days. See Railway — Logs and the Railway Privacy Policy.
Operational reports. The operator receives daily and weekly summaries and alerts through a Telegram bot. They contain aggregate operational analytics only — totals, percentages, the most-used target languages, error and block counts. They contain no images, no IP addresses or IP-derived keys, and no install IDs. Messages remain in the operator's Telegram chat.
5. Why we use this data
- To translate your image — the single purpose of the extension.
- To keep the free service available — fair-use limits on High, which use the install ID and an IP-derived key, stop any single user or automated abuse from exhausting the service.
- To understand usage in aggregate — how many translations, in which mode, from which workflow, into which languages — so we can operate and improve Picture Translate.
6. Sharing
We share data only as described above:
| Recipient | What | Why |
|---|---|---|
| Google (Google Translate) | the image and target language, sent directly by your browser | Standard translation |
| OpenAI | the image and a translation instruction | High translation |
| Railway | infrastructure and hosting provider for all requests to our server; keeps its own HTTP request metadata under its logging policy | running our server |
| Telegram | aggregate operational analytics only — no images, no IP addresses, no install IDs | delivering reports to the operator |
We do not sell or rent data. We do not use or transfer data for advertising, personalised ads or profiling, or to determine creditworthiness or for lending purposes. We do not transfer data to advertising platforms, data brokers or other information resellers. We may disclose information if required by law.
The use of information received by Picture Translate adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
7. International processing
Google (Standard), OpenAI (High) and Railway (our hosting provider) may process data in countries other than yours. Railway states that its services "are largely operated in the U.S." Google and OpenAI process data in locations they determine under their own policies; we do not choose or confirm those locations.
8. Security
- Data the extension sends — to our server and to Google Translate — travels over HTTPS.
- The AI provider credentials exist only on our server. They are never part of the extension.
- Our code does not write translation images to disk or to a database.
- Our logs are kept to a minimum: no images, no IP addresses, no full install IDs.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. What we do not ask for or extract
Picture Translate does not ask for, and does not separately extract, your name, email address, account details, passwords or payment information. It has no accounts or sign-in. It does not collect your browsing history or the addresses of the pages you visit, and it does not record keystrokes, clicks or mouse movements.
An image you choose to translate may itself contain personal information — a name or an email address in a screenshot, for example. That image is handled exactly as described in sections 2–4: it is sent for translation, and our code does not store it or read anything out of it.
10. Your choices
- Use Standard if you prefer your image not to go through our server; use High only for images you are comfortable sending to our server and OpenAI.
- You can remove the extension at any time. This deletes the target language and the install ID from your browser.
- The install ID is not linked to your identity, so we cannot find your data without it. For questions or requests, write to andreneuroman@gmail.com.
11. Changes to this policy
If this policy changes, the updated version will be published at this address with a new effective date. If the extension's data practices change, we will also tell users about the change in the extension and in its Chrome Web Store listing.
12. Contact
Picture Translate — andreneuroman@gmail.com