Data protection

Ponyglot processes your website content: pages, product descriptions, blog posts. This page explains where that content goes.

EU hosting

The hosted service runs in the EU. The application, its database, backups and background jobs are hosted in the European Union.

What is sent where

Recipient

What

When

Ponyglot Cloud

The source texts of the units your connector pushes, their structure and existing translations; results and review outcomes

Whenever the connector syncs

DeepL

Source texts to translate, the page title as context, glossary terms, formality

Only if DeepL is enabled for the site and chosen for the language

The LLM provider

Source texts to translate, the page title as context, glossary terms, brand voice, similar approved translations from your memory

Only if the LLM is enabled for the site and chosen for the language

Content is only sent to the translation engines you enable. Texts covered by the translation memory aren’t sent to any engine.

Ponyglot receives only what your connector sends: translatable texts, not your database. Ponyglot never connects to your site and needs no credentials for it.

Tenant isolation

Each organization’s content, translations, glossary, translation memory and brand voice are separate. An API key belongs to one site and can only read and change that site’s data. Dashboard pages only show organizations you’re a member of. Other organizations’ data is never used for your translations: the translation memory and glossary that help translate your content are your own.

Accounts and keys

  • API keys are shown once and stored only as hashes. Revoke a key in the dashboard at any time.

  • Sign-in uses your email address, with verification, and supports passkeys and second factors (see Sign in with a passkey).

  • Payments are handled by Paddle, our reseller. Ponyglot doesn’t store payment details.

Questions

For a data processing agreement or other questions about data protection, write to hello@ponyglot.app.