Listen Translate

Privacy policy

This policy explains how Listen Translate handles information when you use the app, cloud listening and translation, and these support pages. Cloud audio and text processing requires your separate, explicit consent in the app.

Effective date: 2026-09-24

Who provides the service

Listen Translate is provided by individual developer MA SHIQI. Privacy: williamvip777@protonmail.com. Usage, subscriptions and complaints: williamvip777@protonmail.com. The developer handles both.

Service availability and applicable regional information: The initial App Store launch is planned for mainland China. Download availability depends on the actual release status. This does not announce availability in other countries or regions. Processing locations and international transfer arrangements: Our backend, database and website use Alibaba Cloud in Shenzhen, China; speech and translation use mainland Chinese service endpoints. Apple and Google may use global infrastructure. Resend sends verification mail through Tokyo and stores mail data in the US. Proton Mail support servers are in Switzerland, Germany or Norway. These optional channels can involve overseas processing; see the provider notices below.

Audio and translated content

Floating captions use either compatible app audio or the microphone you select. System-audio mode does not capture screen images; microphone mode requires permission. Interpretation and transcription capture after you start and authorize the microphone. Text translation sends only explicitly submitted text. Cloud processing needs separate consent.

Audio passes through our server to Volcengine (ByteDance) for speech recognition or simultaneous interpretation. Auto-detect and language pairs unsupported by interpretation use Seed-ASR; recognized text, relevant terms and up to 3 confirmed preceding segments go to Qwen on Alibaba Cloud Model Studio (or DeepSeek on Volcengine Ark, according to service configuration) for translation. Supported fixed language pairs can receive source text and translations directly from Volcengine Simultaneous Interpretation 2.0. Transcription uses Seed-ASR only, without translation. Text translation sends your submitted source and languages to the configured Qwen or DeepSeek service. Spoken interpretation sends the translated text and target language through our server to Volcengine for speech synthesis. Audio streams back to your device for playback and is not stored by our server.

The providers' legal identities, applicable data-processing terms, protection commitments, retention, deletion and training treatment are: Recipients are Alibaba Cloud (hosting/Qwen), Beijing Volcano Engine Technology Co., Ltd. (speech and configured Ark translation), Apple (sign-in, device eligibility, purchases), Google (optional sign-in), Plus Five Five, Inc. / Resend (verification mail), and Proton AG (support mail). We send only data needed for each function and do not train models on your audio or text. Provider retention, security and deletion follow the linked official terms; we do not promise zero retention. Contact our privacy email for assistance. A setting that disables response storage is not, by itself, a promise of no provider retention or training.

Account, purchases and usage

Sign in with Apple supplies an Apple account identifier used to establish your app account. The app requests your verified email, but not your name, through Apple sign-in. Our backend keeps account and login records, encrypted Apple authorization credentials, consent choices, subscription status, purchase references and the audio usage needed to authorize service, prevent duplicate charges and handle account deletion. Apple handles payment details; we do not receive your card number. You may optionally choose a username and profile photo. They are linked to your account and stored on our backend to sync across devices. Only your selected photo is uploaded, after resizing and removing photo metadata. Updating or removing it replaces the current profile photo; account deletion removes the profile. When enabled, Google sign-in and email/password sign-in are also available. Google provides a verified account identifier. New sign-in methods with the same verified email use one account. For third-party Google email addresses, we request a fresh email code. Apple Hide My Email addresses cannot identify your real email; you can verify and link it in settings. Existing separate accounts are preserved when linking conflicts. Email authentication stores your email address and a password hash. The configured mail service processes recipients and verification messages for registration, password resets and email linking. Codes expire after ten minutes. Account deletion removes email credentials and associated verification records; Apple authorization is revoked only when an Apple identity is linked.

If you choose to claim the one-time allowance, Apple's DeviceCheck checks device eligibility. An ephemeral device token is sent through our backend to Apple; we do not store or log that raw token. We store the account's claim result. Apple's device eligibility bits do not reset when you delete an app account. Signing in again does not automatically create another allowance.

Diagnostics and contacting support

Our backend records bounded operational information such as request and session identifiers, outcomes, errors, service-request duration and model usage to operate the service, investigate failures and control abuse and cost. These records can be associated with an account or session; they are not described as anonymous. They are not intended to contain raw audio, subtitle text, credentials or device tokens.

Opening the app's help page does not upload diagnostics. If you choose to email support, we receive the address and content you send, and our email provider processes the message. Please do not send passwords, verification codes, private recordings or full subtitle histories. Support handling and retention: Email only, handled by the developer. No live chat, fixed support hours or guaranteed hourly response time. Necessary requests are handled promptly. Mail is kept only as needed to resolve issues, handle privacy requests and meet legal duties; unnecessary information is deleted when its purpose is complete. Support and privacy contact use Proton Mail. If you choose to email us, the mail provider processes the message, attachments and information such as sender, recipient, subject and timestamps. Ordinary incoming mail from an external provider should not be assumed to be end-to-end encrypted. Private audio or complete subtitles are not required to contact support.

These pages contain no forms, advertising scripts, analytics scripts or tracking cookies. Visiting a hosted page still sends ordinary connection information to its hosting provider. The actual hosting provider, connection logs, purposes and retention are: Hosted on Alibaba Cloud ECS, Shenzhen. Connections process IP addresses, requested URLs and ordinary network data for delivery and security. No website access-detail log, advertising or analytics is enabled. Infrastructure may retain error and security records for necessary purposes and applicable law. Following an Apple link or sending email uses the destination service's own processing practices.

How long information remains

Temporary audio and server subtitles support delivery and bounded reconnection while a broadcast remains active; the interruption window is 15 minutes. Stopping discards unconfirmed audio and preserves confirmed local history. Server audio becomes eligible for cleanup after durable completion. Completed server subtitles can be redelivered for 15 minutes; this is not a manual listening-resume feature. Local cleanup runs while the app runs; server cleanup is periodic and faults may delay deletion. Local subtitle history stays until you delete it. Each capture interval drains accepted audio and confirms server closure when stopped; remaining temporary audio is discarded during cleanup, which offline operation or faults may delay. Transcription also saves the original recording as a local WAV; pause and resume keep one recording. Deleting its record or clearing the account’s history deletes that WAV; signing out only suspends access. Interpretation does not archive original audio. Confirmed text and text-translation results remain locally until you delete them. Server text-translation results can be retrieved for 15 minutes after first admission, then become eligible for cleanup.

Final subtitle history stays on your device until you delete it or account deletion clears that account's history on the device. Exporting or copying creates a separate copy in the destination you choose; deleting the app's copy cannot remove those exports. We do not offer cloud history sync or recovery of deleted local history. Depending on your iOS backup settings, device backups may include local history. You manage those copies through your device settings or backup provider; deleting history or your app account does not itself remove existing device backups.

Audio and subtitle expiry does not delete every server record. Account, subscription, consent, usage and deletion-record retention: Account, entitlement, usage and consent records remain while serving the account. Deletion removes identity, profile and account-side records; minimal anti-duplication, refund and legally required receipts follow the separate rules below. Failed cleanup is retried, not immediate physical erasure. Completed-session receipt retention: Minimal delivery receipts enter periodic deletion 7 days after completion. Failed cleanup tasks remain until resolved. See this section for receipts and separate purchase records. Operational log retention: Operational and security logs rotate according to server storage limits; there is currently no uniform day-based automatic expiry. Necessary records serve troubleshooting, abuse prevention and legal duties, with periodic review and removal when no longer needed. Audio expiry does not imply log deletion. Database backup retention and handling of deleted data after restore: Access-restricted local database backups run daily. The daily job removes files older than 7 complete days; scan timing can make retention approach 9 days. Live audio directories are excluded. Deletion does not rewrite existing backups; recovery must reapply deletions and withdrawals before reopening service. Failures can delay cleanup. Purchased time does not expire. Minimal purchase and usage receipts are retained to preserve balances, prevent duplicate grants and handle refunds, with account links removed after deletion. They contain transaction IDs, opaque ownership digests, amounts and dates, but no audio or subtitles. Consumables are not automatically restored after deletion; use your remaining time or contact support for ownership verification first.

Provider cost-attempt records have a default 35-day retention and aggregate windows a 15-month retention. The cost tables do not contain audio, subtitle text or raw account/session identifiers. These limits do not specify the retention of separately associated operational logs or providers' own records.

Minimal paid-window receipts survive account deletion and contain opaque purchase identity, audio/character/call counters and dates, with no audio or text content. Periodic cleanup starts 35 days after the window, including verified grace; faults may delay it. Non-expiring audio/text packs retain minimal transaction, ownership digest, grant/use and refund receipts without expiry; deletion detaches the account. Restoring the same purchase never resets usage. Finished consumables do not restore automatically: original-transaction and ownership verification can restore only the remaining balance.

Once temporary audio and subtitles have been deleted, minimal completed-session receipts can move to the database at least 15 minutes after completion. They become eligible for deletion 7 days after completion. Failed cleanup remains pending and is retried. These receipts contain no audio or subtitles. A minimal session rejection record remains until account deletion to prevent expired sessions from restarting. Account deletion or withdrawal of processing consent also removes owned receipt archives.

Your choices and account deletion

Withdrawal stops cloud capture, text translation and translated speech, and requests cleanup of the account’s temporary audio and server text. Already-sent data and processing in progress cannot be recalled; offline operation or failures may delay cleanup. Withdrawal does not delete local history or transcription recordings, cancel subscriptions or refund used credits. History and recording playback remain available.

You can delete individual history entries in the app. To delete your account, use Settings and the account-deletion flow. The service first disables account access, stops its sessions, revokes the stored Apple authorization and removes account-owned data. Failed cleanup remains pending for retry; it is not shown as completed. Separately retained records and backups follow the retention terms above. Deleting the account does not cancel Apple's subscription: manage that separately with Apple.

Security and access

The app uses authenticated, encrypted network connections to our backend. Provider credentials remain on the backend; Apple authorization credentials are stored encrypted. Access is scoped to an account, and cleanup and recovery preserve account boundaries. No system can promise absolute security or uninterrupted availability. Regional disclosures about lawful requests, additional recipients and required safeguards are included in: Users in mainland China may, as provided by law, request access, copies, correction, completion or deletion of personal information, withdraw consent and ask for an explanation of processing rules. We use necessary, proportionate identity checks and handle requests promptly, explaining any lawful refusal. Legally retained or technically undeletable information is subject to applicable processing restrictions. You may also complain or report concerns to the competent personal-information protection authorities. This version is for adults aged 18 or older. Confirm your eligibility and read the privacy policy and terms before continuing. We do not collect your birth date or identity document. This version is not available to minors. You can still read the policies or email support to request deletion of an existing account and data..

Requests and changes

Depending on applicable law, you may have rights to access, correct, delete or receive your information, restrict or object to processing, withdraw consent or complain to a regulator. Contact williamvip777@protonmail.com; we may need proportionate verification of your request. Applicable legal bases, regional rights, representatives, response periods and age-related conditions: Users in mainland China may, as provided by law, request access, copies, correction, completion or deletion of personal information, withdraw consent and ask for an explanation of processing rules. We use necessary, proportionate identity checks and handle requests promptly, explaining any lawful refusal. Legally retained or technically undeletable information is subject to applicable processing restrictions. You may also complain or report concerns to the competent personal-information protection authorities. This version is for adults aged 18 or older. Confirm your eligibility and read the privacy policy and terms before continuing. We do not collect your birth date or identity document. This version is not available to minors. You can still read the policies or email support to request deletion of an existing account and data.. We do not ask you to email your password or login code.

We will date policy updates and make the current policy available here and in the app. A material change to the app's cloud-processing disclosure requires a new explicit consent before that processing is enabled. A policy update does not automatically accept cloud processing for you.