Privacy policy
reddit translate
Built-in models translate on your device. Cloud models send text to your chosen provider. For cloud models: You enable translation and choose the model. Text goes directly to the API you configure and authorize. The operator's advertising backend does not receive Reddit text, drafts, or model keys. The extension has no user registration, never publishes automatically, and sends no ad impression tracking events. Ad clicks are counted by the backend before redirecting to the destination.
01 Data processed
After you enable reading translation, the extension processes nearby visible posts, comments, feed titles, and formatting. If context is enabled, it also includes the post title, direct parent comment already on the page, and your additional background. It does not fetch entire discussions.
Drafts are processed only when you click the editor's translation button. Results are previewed; replacing, copying, undoing, and publishing are your actions. Passwords, verification codes, private messages, and chat are not read for translation. Text and model output are not executed as code.
The extension checks the current Reddit URL locally to identify supported pages and navigation. It does not read the browser's history database, build a browsing profile, or upload URLs as telemetry. Names, links, and other information within the text you translate may be sent with that text.
02 Model services and transmission
For cloud models: Text, model selection, target language, necessary context, and translation settings go directly to your configured and authorized model API. Your API key and required custom headers are sent to that endpoint for authentication, not to the operator's advertising backend or a translation proxy.
Remote services require HTTPS; a local service you configure may use HTTP on localhost, 127.0.0.1, or [::1]. Providers receive connection metadata such as your IP, may charge fees, and may retain inputs, outputs, or logs under their own policies. Read your provider's policy before use.
The official OpenAI adapter sends store: false. This does not control all provider logs or legal retention, and compatible services may not implement the same option. Test connection also sends a short translation request that may incur a fee.
RTF (RedditTranslateFicory) translates text and drafts on your device without sending them to a server or caching translations on disk. The model catalog comes from the official website and model files from Cloudflare R2. These services receive connection metadata such as IP addresses, request IDs and file paths. Models remain in extension storage until extension data is cleared or the extension is uninstalled. Automatic downloads are off by default. Clearing the translation cache does not delete models.
03 Local storage and retention
- Preferences and model settings stay in extension local storage, without browser sync. API keys and custom headers are restricted to trusted extension contexts and excluded from Reddit pages, page-facing configuration, diagnostics, and exports. They are not separately password-encrypted; someone with device or browser-profile access may read them.
- Reading translations use a local IndexedDB cache, up to 20 MB. Retention is 7 days by default or optionally 30 days, measured from creation; reading does not extend it. Older, less recently used entries are evicted when full. Matching uses a SHA-256 digest of text, language, model parameters, and effective context. Cached content includes translations.
- Tasks and short-lived drafts stay in extension session memory, are removed during maintenance after completion, and never enter the disk translation cache. Restarting the browser, disabling, or reloading the extension clears session storage.
- The ad catalog is cached locally for 1 minute. Images are cached briefly in background memory. Ad selection and dismissal are stored per tab for that session and removed when the tab closes; these records contain no page text, model credentials, or user identity.
- Exported settings omit API keys and custom headers but include text you enter in prompts and other ordinary settings. Review files before sharing and delete exported copies yourself.
04 Browser permissions
- storage saves preferences, model credentials, and session tasks. alarms supports periodic queue and cache maintenance.
- https://www.reddit.com/* allows reading supported posts, comments, and editor text and displaying translations and previews. https://reddittranslate.ficory.com/* allows fetching the ad catalog and images.
- Optional HTTPS and local HTTP host permissions support custom model APIs. Access is requested for the specific service host only when you save a configuration and authorize it. The extension does not request GPS location access.
05 Ads and network requests
The panel shows up to 5 active ads. With translation enabled, one may appear in a clearly labeled floating panel on Reddit. Dismissal survives reloads and navigation in the same tab; closing the tab, restarting the browser, or reloading the extension clears session state. No active ad or an unavailable service means no floating ad.
The catalog comes from https://reddittranslate.ficory.com/api/public/ads and images from the same domain. Requests omit cookies, referring page URLs, Reddit text, drafts, model credentials, and persistent device identifiers. Normal connection metadata, including source IP, and a random 16-character request ID for diagnostics still reach the service; the ID is not a persistent user or device ID.
There are no impression or targeting events or third-party ad scripts. Only clicking an ad opens its HTTPS destination, without appending page text or model credentials. That website follows its own privacy policy. Ads are not supplied by Reddit, and clicking them is not required to translate. Ad clicks are counted by the backend before redirecting to the destination. Click records contain the ad ID, count, time and a random request ID, without IP addresses or user identifiers. Counts remain until the ad is deleted; the latest 10,000 click audit records and backups may remain longer.
The operator's policy is not to retain HTTP access logs for the website or advertising API. Application launch commands and the Nginx example disable access logging; production proxy/CDN settings still need verification. Infrastructure providers may process security or operational metadata under their own policies; contact [email protected] for enquiries or deletion requests. Management audits and voluntarily submitted feedback are retained for their respective purposes.
The extension does not sell translation text, drafts, API keys, or browsing activity, or use them for personalized ads, credit assessment, or lending decisions. Necessary transmission to your chosen model service is used to fulfill your translation request, not additional telemetry.
06 Your choices and deletion
- You can pause translation, disable context, dismiss floating ads, revoke host permissions in your browser, or uninstall the extension.
- In Privacy → Local cache, disable caching, select retention, or clear the cache. Shortening retention prevents expired entries from matching and removes them during maintenance. Deleting a model profile removes its credentials; existing reading translations must be cleared separately.
- Uninstalling clears extension storage, not your exported files or data already received by a provider. Contact that provider under its policy for access, correction, or deletion of its stored data.
07 Website and administration
The product and privacy pages are public and use no analytics scripts or identifying cookies. The language you select is stored only as a local browser preference and in the page URL; it is not a user identifier. You can clear it by deleting this site's browser data. Pages request application version information; servers receive normal HTTP connection metadata.
/admin is for the operator's advertising and feedback management, not extension users. Admin sessions use HttpOnly, SameSite cookies, with Secure in production. The backend stores HMAC session digests and management audit records, not plaintext cookies or passwords in data files. There is no registration or add-user entry point.
08 Contact and policy updates
Public developer identifier: [email protected]. For support and privacy requests, contact [email protected].
The website’s optional contact form collects your email address, problem description, interface language, submission time and a random request ID. These are stored in private server JSON files for support and are visible only to the administrator. If enabled by the operator, Feishu bot notifications send the email and description to the configured group; Feishu and group members can then access that copy. Records remain until the administrator deletes them. Existing backups and Feishu messages require separate deletion. You can request deletion by email. Do not submit passwords, API keys or unnecessary private text.
Changes to data handling will be reflected in this page's date and content and in store disclosures. Where renewed authorization is required, affected features will be enabled only after that authorization.