Privacy Policy

Last updated: September 13, 2026

This translation is provided for convenience only. In case of inconsistency, ambiguity or dispute, the French version prevails.

1. Controller

The controller of the personal data collected through the BabelSpeech service (website babelspee.ch and desktop application) is Joel Rossier, 1963 Vetroz, Suisse, who can be reached at info@babelspee.ch (the “Operator”).

This policy supplements the terms of service. Processing is governed by the Swiss Federal Act on Data Protection (FADP) and, where it applies to persons located in the European Economic Area, by the General Data Protection Regulation (GDPR).

2. Principle: nothing that is said is recorded

The Operator does not record the captured audio, the transcriptions or the translations produced during a session. This content transits in real time, in volatile memory, between the organiser’s browser or application, the Operator’s servers, the artificial-intelligence provider and the viewers’ browsers. It is not written to any database or file on the Operator’s side and cannot be retrieved afterwards.

Concretely, the following data is not retained by the Operator:

  • the audio stream captured from the organiser’s microphone or computer;
  • the transcription in the source language;
  • the translated text in the target languages;
  • the synthesised audio in the target languages;
  • the identity of viewers: following a public link requires neither an account nor any identification.

The text displayed in a viewer’s or the organiser’s browser is kept only in the memory of the open page (a few hundred lines at most) and disappears when the page is closed or reloaded. Nothing, however, prevents a viewer from copying that text or taking a screenshot; the Operator has no control over this.

This absence of retention applies to the Operator. The artificial-intelligence provider (see art. 5) processes the audio to produce the translation and may, under its own terms, retain it temporarily (in particular for abuse-detection purposes). The Operator does not control that retention.

3. Data retained

To operate the service, the Operator retains the following data, limited to what is strictly necessary:

  • Account: name, e-mail address, password (hashed only, never in plain text), e-mail verification status, creation and update dates.
  • Login sessions: session token, expiry date, IP address and browser identifier (“user agent”) at login, device label for the desktop application. These sessions can be viewed and revoked from the “Account” page.
  • Events (translation sessions): title entered by the organiser, source language, target languages, audio option, creation, start and end dates, public-link identifier, status. The title is visible to anyone holding the public link.
  • Credits and usage: credit balance, history of movements (purchase, free credits, consumption, adjustment) and usage records indicating, per event, per minute and per target language, the number of credits consumed. These records contain no spoken or translated content.
  • Orders: Stripe transaction identifiers, amount, currency, credits granted, status and payment date. No payment-card data is received or stored by the Operator; payment takes place on pages hosted by Stripe.
  • Verification and device connection: temporary tokens for e-mail verification, password reset and desktop-application login, deleted or invalidated on expiry.
  • Technical logs: IP addresses, timestamps, URL or channel called, error codes and diagnostic messages generated by the web and realtime servers, including when a viewer opens a public link. These logs do not contain the translated content.
  • Correspondence: e-mails exchanged with the Operator (support, data-related requests).

4. Purposes and legal bases

  • Provision of the service (account creation, starting sessions, broadcasting to viewers, credit metering) — performance of the contract.
  • Billing and accounting (orders, credit history) — performance of the contract and legal retention obligations.
  • Security and abuse prevention (technical logs, login sessions, detection of multiple accounts) — legitimate interest of the Operator.
  • Communication (transactional e-mails: verification, password reset, information about the service or the Terms) — performance of the contract and legitimate interest. No newsletter or marketing e-mail is sent without consent.

The Operator does not carry out any profiling, does not make any automated decision producing legal effects on individuals, and does not sell or rent personal data.

5. Recipients and processors

Data is processed by the Operator and by the following providers, acting on its instructions, to the extent necessary for their task:

  • OpenAI (United States) — real-time speech recognition, translation and speech synthesis. The audio captured during a session is streamed to it continuously. This processing is the core of the service and cannot be disabled. OpenAI processes this data in accordance with its terms applicable to API services, which, as of the date of this policy, provide for time-limited retention and no use for training its models. The Operator does not guarantee these commitments, which are OpenAI’s.
  • Stripe (United States / Ireland) — payment processing. Stripe collects payment data directly and acts, for that data, as an independent controller under its own privacy policy.
  • Infomaniak (Switzerland) — hosting of the servers, database and technical logs. Delivery of transactional e-mails.

Data may also be disclosed to authorities where required by law, or to advisers (legal, accounting) bound by professional secrecy.

6. International transfers

Some providers, in particular OpenAI and Stripe, process data in the United States or in other countries that do not necessarily offer a level of protection equivalent to that of Switzerland or the EEA. These transfers rely on the standard contractual clauses recognised by the Federal Data Protection and Information Commissioner (FDPIC) and by the European Commission, and/or on the provider’s certification under the Swiss-U.S. / EU-U.S. Data Privacy Framework where available. By using the service, the organiser acknowledges that the audio of a session is transmitted outside Switzerland and undertakes to inform the persons concerned.

7. Persons whose voice is captured

An organiser who captures and broadcasts the speech of speakers or participants acts, for that content, as controller; the Operator acts as a technical processor and does not retain that content (art. 2). It is the organiser’s responsibility to inform the persons concerned of the automated processing of their voice by a third-party provider located abroad and, where applicable law so requires, to obtain their consent. The Operator cannot respond to requests from these persons regarding the content of a session, since it holds no copy of it.

8. Viewers

Following a public link requires no account. The Operator then collects only the indispensable technical logs (IP address, timestamp, requested session and language), used solely for security, diagnostic and capacity-planning purposes, and retained for the period stated in art. 10. No tracking cookie is placed on viewers’ browsers.

9. Cookies and local storage

The service uses only cookies strictly necessary for its operation:

  • babelspeech.session_token (and its associated cache) — keeps the user signed in; maximum duration of 30 days, renewed on use.
  • babelspeech.locale — remembers the chosen interface language; duration of one year. Set only if the user changes the language.

No advertising, audience-measurement or social-network cookie is used. Payment pages hosted by Stripe may set their own cookies, governed by Stripe’s policy. The desktop application stores the login token in the operating system’s secure credential manager; it is deleted on sign-out or on revocation from the “Account” page.

10. Retention periods

  • Audio, transcriptions, translations: never retained (art. 2).
  • Account data: for as long as the account exists, then deleted within 30 days of the deletion request, subject to data covered by a legal retention obligation.
  • Login sessions: until they expire (30 days after the last activity) or are revoked.
  • Events and usage records: for as long as the account exists; anonymised or deleted with it.
  • Orders and credit history: ten (10) years from the end of the relevant financial year, in accordance with Swiss accounting obligations (art. 958f CO), dissociated from the account identity once the account is deleted.
  • Technical logs: 90 days at most, unless longer retention is needed to analyse a security incident.
  • Temporary tokens (verification, reset, device login): until they expire, between 10 minutes and a few hours.

11. Security

The Operator implements reasonable technical and organisational measures: encryption of communications (TLS), password hashing, time-limited session tokens, server access control, no storage of session content. No system is entirely secure, however; the Operator cannot guarantee absolute security and will inform the persons concerned and, where applicable, the competent authority of any data breach presenting a high risk, in accordance with the law.

12. Your rights

Within the limits of applicable law, every data subject has the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interest, as well as the right to withdraw consent given. Requests should be sent to info@babelspee.ch; reasonable identity verification may be requested. The Operator responds within 30 days.

A complaint may be lodged with the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch) or, for persons located in the EEA, with the supervisory authority of their country of residence.

Reminder: since the Operator cannot return any spoken or translated content (it does not retain any), access requests concerning the content of a session cannot be fulfilled.

13. Minors

The service is not intended for persons under 18 as organisers. The Operator does not knowingly collect data from minors in that capacity; any account identified as such will be deleted.

14. Changes

This policy may be changed at any time, in particular to reflect changes to the service, its providers or legislation. The current version is published on this page with its update date; material changes are announced to users holding an account. This policy is drafted in French; this English version is a translation provided for convenience only. In case of inconsistency, ambiguity or dispute, the French version prevails.