1. Information We Process
- Account details: email address, password hash, subscription plan and status.
- Session and device data: device identifiers, token identifiers, recent activity timestamps, IP address, and client version.
- Usage metadata: character count, request identifiers, model metadata, and service latency measurements.
- Billing references: Stripe customer/subscription identifiers and related payment references needed for subscription lifecycle management.
2. Translation Content and AI Processing
PowerBun processes only the text and request data needed for the requested translation or formatting job. The PowerBun API forwards the necessary content to service providers such as the OpenAI API to generate the requested output. Usage records and routine operational logs are designed to avoid storing raw translation content.
3. AI Providers and Customer Review
PowerBun uses the OpenAI API to help deliver translation services. According to OpenAI's business data policy, API data is not used to train OpenAI models by default unless a customer explicitly opts in. You can read more at OpenAI Business Data. Even with these controls, AI output can be imperfect, so users remain responsible for reviewing translated content before relying on it.
4. How We Use Information
- Authenticate users and enforce device/session rules.
- Apply plan quotas, monitor usage, and generate account dashboards.
- Create and manage checkout and billing workflows.
- Operate, secure, and improve service reliability.
5. Data Sharing
We share data only with necessary processors and providers, including the OpenAI API, Stripe, and infrastructure required to deliver PowerBun services. We do not sell personal data.
6. Payment Information and Card Data
English/global billing is handled through Stripe. PowerBun does not store raw card details in its own systems.
7. Security Measures
- Password hashing for account credentials.
- Refresh-token hashing and rotation with revocation controls.
- Production traffic between add-ins, the PowerBun API, and integrated providers is protected in transit with HTTPS/TLS.
- For stricter internal policies, additional redaction workflows may be configured to mask email addresses or selected keywords before translation.
8. Retention
Data is retained only as long as needed for service operation, legal compliance, dispute resolution, and security investigations. Expired token records are subject to automated expiration policies.
9. Your Choices
- Access and manage account/billing data through account and billing pages.
- Cancel subscriptions and manage payment methods through Stripe billing flows.
- Request account assistance or data inquiries via support contact.
10. Contact
Privacy questions and requests can be sent through the contact form.