Privacy Policy
Last updated: July 13, 2026
1. Information We Collect
We collect the following information when you use MultiSub:
- Account information: Email address and name from your OAuth provider (Google, GitHub, etc.)
- Language preferences: Your native language and configured language pairs
- Usage data: A record of each subtitle generation — the title (IMDb ID), season/episode, languages, and technical metrics like processing time and result status. We use this for quota tracking, service statistics, and cost monitoring. Records are unlinked from your account after 12 months.
- Activity and notification markers: When you last used the subtitle service, when Stremio last fetched your manifest, and when a quota notification email was last sent. These timestamps support account activity statistics, setup status, and notification deduplication.
- Shared translation cache: Subtitle text, translated cues, language codes, source-file identifiers, model name, and technical cost metrics may be cached and reused across users. Cache entries contain no user or account identifier, and display preferences are applied afterward.
- Payment information: Managed entirely by Stripe. We store your Stripe customer ID but never your card details.
- Server logs: Like most web services, our infrastructure logs requests (including IP address and user agent) for security, debugging, and abuse prevention. Logs are retained for up to 30 days and are not used to build user profiles.
2. How We Use Your Information
- To provide and improve the subtitle translation service
- To manage your account and subscription
- To enforce usage quotas and prevent abuse
- To communicate important service updates
3. Data Storage
Your data is stored in a PostgreSQL database hosted by Supabase (AWS infrastructure). Authentication tokens are managed by Supabase Auth. All data is encrypted in transit (TLS) and at rest.
4. Third-Party Services
MultiSub integrates with the following third-party services:
- Supabase: Authentication and database hosting
- Stripe: Payment processing and subscription management
- OpenSubtitles: Source subtitle data retrieval
- OpenAI: AI-powered subtitle translation (only subtitle text is sent, never your identity or account data)
- Vercel: Hosting, cookieless analytics, and performance monitoring
- Axiom: Server log storage for debugging and monitoring; logs are retained for up to 30 days
- Resend: Transactional email delivery (service emails, weekly digest)
- Upstash: Rate limiting (request counters only, no personal data)
Each service has its own privacy policy. We only share the minimum data required for each service to function.
5. Data Retention
- Account data: Retained until you delete your account
- Translated subtitles: Account-linked records and jobs are deleted with your account or when their operational cache expires. Shared translation-cache entries are not linked to an account and are retained until invalidated or no longer needed.
- Usage logs: Retained for billing period tracking and deleted after 13 months
- Generation history: Unlinked from your account (anonymized) after 12 months; anonymous statistics are kept
- Billing audit logs: Retained for seven years to meet tax, accounting, and dispute-resolution obligations; they are detached from your account when it is deleted
- Server logs: Retained for up to 30 days, then deleted
6. Your Rights
You have the right to:
- Access: View your data through the configure dashboard
- Delete: Permanently delete your account and all associated data from the account settings page
- Export: Download a structured JSON copy of your data from the account settings page. For a broader access request, contact support; we will respond within 30 days.
- Correct: Update your language preferences at any time
- Object: Object to processing based on our legitimate interests, including cookieless aggregate analytics, by contacting support. We will stop that processing unless we have compelling legitimate grounds or need it for legal claims.
When you delete your account, your Stripe subscription is canceled and account-linked operational data is removed. Billing audit records that we must retain are detached from your account and kept for the period stated above; shared cache entries are not associated with your identity.
7. Cookies
MultiSub uses essential cookies for authentication session management and a cookie that remembers your language preference. We do not use tracking or advertising cookies; our analytics (Vercel Analytics) works without cookies and does not track you across sites.
8. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes through the Service.
9. Contact
For privacy-related questions, contact us through our support page.