Privacy Notice v1.7-2026-08-10
Version 1.7 — last updated 10 August 2026. Hablexo is operated by Hablexo Ltd, a company registered in England & Wales (company no. 17354416), registered office 167-169 Great Portland Street, 5th Floor, London W1W 5PF. Hablexo Ltd is the data controller for the account, eligibility, billing, and operational data described below. Contact: hello@hablexo.com.
Hablexo delivers real-time speech translation to attendees’ phones. We built it to hold as little personal data as possible: on our servers the live content is processed in memory and never stored. Outside that content plane, we retain only what we need to verify and run accounts, bill usage, secure and support the Service, and comply with law. Some event content can be stored — not by us, but on the event organiser’s own device: chat posts always, and transcripts or audio recordings only if the organiser turns those on. See below.
The short version
- Captions, translations and audio are never stored on Hablexo’s servers. They are fanned out to devices in memory and discarded — we keep no transcript or recording.
- An organiser can choose to relay the event’s live audio to listeners. This is off by default. When the organiser switches it on, anyone with the event’s QR link can listen live — including people who are not in the room — and the attendee page says so while the feed is on. The audio is relayed unprocessed, in real time, through our servers and is not recorded or stored by Hablexo. The organiser may separately choose to record their own event; any such recording happens on the organiser’s own equipment, outside Hablexo’s relay.
- Some content is stored on the event organiser’s own device — never on ours. If you post in an event’s chat forum, your message (and the chat name you chose, if any) is saved by the organiser’s Hablexo app so the forum survives a restart; it is kept for a limited period — 7 days by default — and the organiser can delete it at any time. And if the organiser switches on transcript logging or audio recording (both are off by default), the event’s captions or audio are stored on the organiser’s device too.
- Attendees do not have accounts. Scanning a QR code to read captions gives us no login and no identity. To deliver captions to your phone we necessarily handle its network (IP) address, and we store a few preferences on your own device — see If you are an attendee.
- Outside the live content plane, we retain limited operational data — the contact details of the people named on an account, the Customer’s identity and eligibility details, aggregate usage counts, payment records, minimal security logs, and support material you choose to send — never caption content.
- If you are named on an organisation’s account — as an Admin or a Member — you are our data subject in your own right, not just part of your organisation’s record. We hold your own email and sign-in details, your role, and a record of which events your devices ran. See If you are named on an organisation’s account.
- We never sell your data, we don’t use it for advertising, and we send product news only to people who have asked for it — which, as at this version, is nobody: we do not currently send marketing email at all.
Information we collect
- Account: the email address you sign up or sign in with, and either a password (stored only as a salted hash) or — if you use “Continue with Google” — your Google-verified email address.
- Customer identity and eligibility: the legal or organisational name, customer type, country, registration number (where applicable), and the business-purpose and authority declarations you provide when registering or verifying an account. We also record the version of the declaration and when it was accepted.
- Membership and role: which organisations’ accounts you are named on and whether you are an Admin or a Member, together with who invited you and when you joined or left. The same email address can hold a place on more than one organisation’s account; each is a separate membership.
- Invitations: when an Admin invites a colleague, we hold the email address they nominated, the role offered, who sent it, and whether it was accepted, declined, revoked or left to expire. We hold that address from the moment the invitation is sent — before the person has any account with us — so that we can deliver it and so the Admin can see what they sent. An unaccepted invitation expires and is not used for anything else.
- Usage & billing: aggregate counts of minutes and messages translated (numbers only, no content), your credit balance, and transaction records. Each record also carries which membership produced it — see below, because it means your own organisation’s Admins can see what you used.
- Communication preference: whether you have asked for product news, and the evidence of that choice — when you made it, on which screen, and which version of this notice you were shown. If you later opt out we record that too, and we keep a do-not-contact record so the choice cannot be undone by accident.
- Operational logs: minimal technical logs (e.g. connection and error events) to keep the service reliable and secure. These do not contain caption content.
- Support: if you contact support or send a problem report from the app, we receive what you choose to send — the report text, an optional reply-to email address, and a short technical log excerpt that is scrubbed of secrets before it leaves your machine.
We do not collect or store the audio, transcripts, translations, chat messages, or synthesized speech that pass through the service. Note the emphasis: a chat post — and, where the organiser has switched on transcript logging or audio recording, a transcript or recording — is stored by the organiser’s app, on the organiser’s own device, as described above and below.
If you are an attendee
You scanned a QR code to read captions in your language. You have no account with us and we do not ask who you are. For most attendees, this is everything that happens:
- Your phone’s IP address is handled by our server for as long as your device is connected, because a caption cannot be delivered to a device without one. We do not log it to build a profile, and we do not use it to identify you.
- The language you pick is sent to our server so it knows which caption stream to send you. It is not tied to any identity.
- A few preferences are stored on your own phone (language, theme, text size, and your chat name if you set one) so the page remembers them. They stay on your device; they are not transmitted to us as a profile, and clearing your browser data removes them.
- Captions and translations are not stored by us. The organiser’s app does not store them either, unless the organiser has switched on transcript logging or audio recording — both are off by default, and anything they capture is stored only on the organiser’s own device, under the organiser’s control (see Retention, below).
If you post in a chat forum, that is different, and it is worth reading twice: your message and your chosen chat name are saved on the event organiser’s device (not on Hablexo’s servers), kept for a limited period — 7 days by default — and deletable by the organiser at any time. The Hablexo app tells you this at the moment you open a chat forum, before you can post.
Who is responsible for your data. The organisation or professional behind the event decides why and how it runs — so for the event’s content that entity is normally the data controller. The visible organiser may instead be an AV supplier or other processor acting for that controller. Hablexo acts as processor or sub-processor, as applicable, on their instructions. If you want to exercise your rights over an event’s content or its chat history, contact the organiser first; they can identify the relevant controller. For Hablexo’s own account data, operational security logs, or support correspondence, contact us at hello@hablexo.com.
Hablexo accounts are for business and organisational use, not wholly or mainly personal, family, or household use. Attendees do not become Hablexo customers by following an event link. If you believe the Service is being operated for household use or the organiser cannot tell you who is responsible for your data, contact us.
If you send us feedback about an event
There is one place where the paragraph above does not apply, and it is worth being exact about. The attendee page has a Feedback control — a speech bubble — you can use to tell us how it went, report a problem, or ask for a feature. If you use it, you are writing to Hablexo, not to the organiser, and for that message Hablexo is the data controller: we decide why we collect it, how we triage it, and how long we keep it. This is outside the processing we perform on the organiser’s behalf. We are still processing your data — we are simply not doing it as their processor.
When you send a report we receive:
- Your message — the summary and any details you type, and which of the three kinds it is (feedback, a problem, or a feature request).
- An email address, only if you type one. It is optional, it exists solely so we can reply, and it is never given to the organiser.
- Technical details about your session, only if you leave the diagnostics box ticked. You can untick it before sending, and the form shows you exactly what is included first. It is a fixed, short list: the caption language you chose and the language being spoken (where the organiser’s app reports it); your interface language, theme and text size; whether the connection dropped and how often, with the connection’s numeric close code; which speech route played audio, the name of the voice, and whether it worked; the audio format in use; whether the screen was kept awake; your window size; and your browser’s user-agent string with whether it supports Opus audio and speech.
- A report identifier and a random session identifier generated by your browser for that visit, plus signals we use to stop automated abuse: your IP address, an invisible field a person never fills in, and a token showing how long the form was open. The session identifier lives in your browser tab and is gone when you close it.
- Which organisation’s event you were at, where your link carried a valid event key. The key itself is resolved on our server and never appears in the email, our logs, or anywhere else. You can send a report with no key at all — that is deliberate, because “the QR code doesn’t work” arrives precisely when there isn’t one.
What we never collect through this form, whatever you have ticked: caption or translation text, chat messages, your chat display name, anything you posted in a forum, screenshots, or the event key. The diagnostics list above is the whole list — the form cannot collect anything outside it, and our server independently rejects anything that is.
Lawful basis. Legitimate interests (Article 6(1)(f)) — understanding and fixing problems with a service people are using live, and improving it. We have assessed this: the purpose is limited and the data minimal; you choose to write to us and choose whether to include diagnostics; nothing is used to profile, target or advertise to you; and your message is not shown to the organiser. Where you give an email address so we can reply, that is your choice and we use it only to reply.
Who else sees it. Your report is delivered by Resend and lands in a mailbox we hold with Migadu, both listed under Service providers below. If a report describes a bug or a feature we intend to work on, we may record a de-identified summary in our issue tracker (Atlassian): never your raw message, your email address, the event key, your session identifier, your exact user-agent, or the full diagnostics. If we ever use an AI service to translate a report that arrives in another language, it will be named here before we do, and it happens only when we read the message — never automatically as you send it.
Retention. Reports stay in the feedback mailbox while they are useful and are reviewed regularly; we delete them when they no longer are. Counts used for abuse limits are numbers only and expire within hours. To have a report deleted, or to ask what we hold, write to hello@hablexo.com — quoting the report identifier the page showed you makes it much quicker, but it is not required.
Attendee feedback is not visible to the organiser, in any form. If your complaint is about the event rather than about Hablexo, tell the organiser directly — we cannot pass it on for you.
If you are a translator at an event
An organiser can invite a live human translator: someone who listens to the event and speaks a translation into their own device, for listeners who choose that language. If that is you: you have no account with us and we do not ask who you are. You open a link the organiser shows you, choose the language you will speak, and ask to join; the event’s operator admits you.
- Your voice is relayed through our servers, in memory only, to the listeners who chose your language — like all event content, it is never stored on Hablexo’s servers. Where your spoken language is supported for transcription, your speech is also transcribed transiently by the speech-to-text providers listed below to produce captions for your listeners.
- A reconnect credential is kept in your browser’s session storage so a brief signal drop does not eject you from the event; it is discarded when you close the tab. Your language choice is remembered on your own device.
- We meter the minutes of translator audio relayed, as numbers only — never the content — because the organiser’s organisation is billed for them.
As with all event content, the organisation or professional behind the event is normally the controller of your relayed speech, and Hablexo processes it as their processor or sub-processor. The organiser may separately choose to record their event on their own equipment, outside Hablexo’s processing — ask the organiser if you want to know whether they do.
If you are named on an organisation’s account
A Hablexo account belongs to an organisation — the customer we contract with and bill. The people who use it are named on it individually: an Admin can invite colleagues, buy credit and manage events; a Member can run events but not spend money or change who has access. For this — your own details, as distinct from your organisation’s — Hablexo is the controller. That is the opposite of the arrangement for event content described above, where the organiser is the controller and we are a processor, and it is why this notice comes to you directly rather than through your organisation.
- Your email address and how you sign in — a password (stored only as a salted hash) or your Google-verified email address.
- Your role, and how you got it — which organisations you belong to, whether you are an Admin or a Member, who invited you, and when you joined or left.
- The devices you sign in from — the name each Hablexo install reports, so you and your Admins can tell one machine from another and sign a lost one out.
- What you ran — the events your devices published, and the minutes and messages they used. Counts only: never the captions themselves.
Your organisation can see which Member used the credit. Usage records carry the membership that produced them, so an Admin can see how the organisation’s balance was spent and by whom. We think that is what an organisation paying the bill should be able to see, and you should know it rather than discover it. What an Admin cannot see through us is any caption, translation or chat message: we store none of those on our servers, and anything an organiser’s own machine keeps is described above and under Retention.
You can belong to several organisations with one email address. They stay separate: each has its own role, its own credit, and its own usage records, and signing in asks which one you are acting for. An Admin of one organisation sees nothing about your membership of another.
If you leave, or an Admin removes you. Your access ends immediately — your devices are signed out and your operator app stops publishing. Two things deliberately do not happen. Your membership record is retired rather than deleted, and the record of past usage stays attached to it: those are the organisation’s billing records, and rewriting them to tidy up would destroy the evidence of what was actually charged. If you ask us to erase your personal data we remove the person — your email address and sign-in details — and leave behind an opaque reference that identifies nobody. See Your rights.
Lawful basis. We rely on contract and our legitimate interests in running an organisation’s account securely and billing it accurately. We do not ask you to consent to any of this, and your access does not depend on agreeing to marketing — which is a separate, explicit choice described below.
Signing in with Google
If you choose “Continue with Google”, Google shares with us only your verified email address and basic profile (name) so we can create or identify your account. We do not receive or store Google access or refresh tokens, and we request no access to your Gmail, Drive, contacts, or any other Google data. You can sign in with a password instead at any time.
Hablexo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Payments
Card payments are processed by Stripe. Card details go directly to Stripe and never touch Hablexo’s servers. We receive only the confirmation and metadata needed to credit your account.
Email we send you
Account and service email — verifying your address, resetting your password, confirming a payment, telling you an invitation is waiting, warning you that credit has run out. We send these because they are part of running your account, and you receive them regardless of any marketing choice: opting out of product news never stops a password reset or a security notice reaching you. If you want these to stop, close the account.
Product news is separate, and is opt-in. We send it only to people who have explicitly asked for it, on the basis of consent, and you can withdraw at any time from your account settings or from a link in the message itself. As at this version we do not currently send marketing email at all — the preference exists so that we never have to guess later. If that changes, this notice will be updated to name the tool we use to send it before the first message goes out.
The do-not-contact record. When you opt out — or ask us never to contact you — we keep a record of that request, and we keep it as a one-way hash of your email address rather than the address itself. It stays even if you delete your account or we erase your details, and that is the point: a suppression list that disappears with the account would let an old contact list, a re-import or a fresh signup quietly start the email again. It holds nothing but the hash, the reason and the date; it cannot be read back into an address, and it is used for one thing only — recognising an address we must not email.
Why we process your data (lawful bases)
For a sole trader or professional who is personally the Customer, we rely on contract (including steps requested before entering the contract) to verify eligibility, run the account, meter usage, and bill. Where an individual creates or uses an account for an organisation, we rely on our legitimate interests in verifying representatives and administering the organisation’s account and contract. We also rely on legitimate interests for keeping the service secure and reliable (operational logs) and for handling support requests. The same two bases cover the people named on an organisation’s account — Admins and Members alike — for administering their access, attributing usage to the right membership, and securing the account; no consent is needed for any of it, and none is asked for. Consent is used for exactly one thing: product news. For retained financial records we rely on legal obligation (UK tax and accounting law). For event content we act as a processor or sub-processor on the relevant controller’s instructions; that controller is responsible for the lawful basis for the event.
Service providers (processors)
We use a small set of providers strictly to deliver the service; they process data on our instructions and only as needed:
- Speech-to-text: Soniox and ElevenLabs process live audio transiently to produce transcripts. The audio captured at the event is streamed to the speech provider directly from the organiser’s device using short-lived access tokens — it does not pass through Hablexo’s servers. (Optional synthesized spoken audio travels to phones via our servers in memory only, like captions.)
- Translation: Makora, DeepInfra, and Google Cloud process transcript text transiently to produce translations. (DeepInfra is a standby for Makora — it hosts the same translation model and receives content only while a failover from Makora is active.) This content is not retained by us.
- Payments: Stripe.
- Email: Migadu (correspondence, including the mailbox that receives attendee feedback) and Resend (account and verification emails, and delivery of feedback reports to that mailbox).
- Issue tracking: Atlassian (Jira), where we record a de-identified summary of a bug or feature request. Never raw messages, email addresses or full diagnostics.
- Hosting: our servers run on cloud infrastructure (Oracle Cloud) in the United Kingdom (London region). This is where your account and billing data actually lives and is used.
- Backup storage: so that a failure of that infrastructure cannot destroy your account, we keep copies of the account and billing database away from it. A continuous replica is held by Cloudflare (R2) in its European Union jurisdiction, and a monthly archival copy is held by Backblaze (B2) in the Netherlands. Keeping the monthly copy with a second, unrelated company is deliberate: it means losing our Cloudflare account cannot take every copy at once. Both copies contain account and billing data only — never captions, chat or event audio.
The archival copy sent to Backblaze is encrypted before it leaves our systems, using a key held offline that we do not give to either storage provider. Backblaze therefore cannot read what it stores for us. Cloudflare’s continuous replica is encrypted by Cloudflare in transit and at rest.
Where a provider processes personal data outside the UK or EEA, we put an appropriate transfer safeguard in place (such as the UK International Data Transfer Agreement or Addendum, or standard contractual clauses). The current list of content-plane sub-processors, with locations, is published in the Data Processing Addendum.
Retention
On Hablexo’s servers: content-plane data (captions, translations, chat, audio) is retained only in memory for the few seconds or minutes needed for live delivery, then discarded. Account identity, eligibility, and billing data is kept for as long as needed to operate and defend the account and contract and, after closure, only as long as required or justified for legal, accounting, tax, fraud-prevention, and dispute purposes. Where full details are no longer needed, we delete or aggregate them.
Memberships and their usage records. When someone leaves an organisation the membership is retired rather than deleted, and the usage records already attached to it are not rewritten — they are the organisation’s billing history. If we erase a person’s data, we remove the identifying part (email address, sign-in details) and keep the membership as an opaque reference, so the organisation’s records still add up while the person behind them is gone. We do not relabel those records as anonymous, because that would be indistinguishable from usage that never had a person attached. The do-not-contact record is the one thing we keep beyond this, as a hash, and for the reason given there.
Backups. The copies described above are deliberately protected against being changed or deleted early, because a backup an attacker can erase is not a backup. One consequence is worth stating plainly: when we delete or pseudonymise your data, the change applies to the live system immediately, but existing backups still contain the earlier state until they expire — up to 30 days for the daily copies and about 13 months for the monthly archival copies. Those backups are access-restricted and isolated — they are not used for ordinary day-to-day processing, and are read only to recover from a failure. They are deleted automatically once their retention period ends. If we ever restore from a backup, we do not use it to reinstate a deletion, a marketing objection, or another choice you made after that backup was taken.
On the organiser’s own device, the Hablexo operator app writes a small number of files. These are on the organiser’s machine, under their control, and never sent to us:
- Chat history — attendee posts and chat names, per forum. Newest 50 per forum, deleted after 7 days by default. A forum can be set to memory-only so nothing is written at all. Deletable from Settings › Diagnostics.
- Audio recordings — off by default. Only if the organiser turns on “Record audio input”; capped by a disk budget and deleted after 7 days by default.
- Transcripts — off by default. Only if the organiser turns on transcript logging.
- Unsent problem reports — only while a report cannot reach us (offline); deleted after 30 days by default.
- A technical diagnostics log — operational events and errors, size-capped by rotation. It is not a transcript, and it is scrubbed of secrets before any part of it is sent to us with a problem report.
An organiser who records audio or logs transcripts is processing that content on their own equipment. They are the controller where they decide why and how to process it, or a processor where they operate the equipment for a client controller.
Your rights
Depending on your location (including under UK/EU GDPR), you may request access to, correction of, or deletion of your account data, and you may object to or restrict certain processing. You can exercise these against us whether you are the person who set the account up or a colleague who was invited onto it. Two limits are worth stating plainly rather than leaving you to find them: erasing your details does not remove your organisation’s billing history, which we keep as records of what was charged, and it does not clear a do-not-contact record, which exists precisely to survive it. To make a request or ask a question, email hello@hablexo.com. If you are in the UK you also have the right to complain to the Information Commissioner’s Office (ico.org.uk); if you are in the EU/EEA, to your local supervisory authority. We would appreciate the chance to help first.
Cookies & storage on your device
We use only the storage necessary to run the app, and we do not use advertising or third-party tracking cookies. Specifically:
- Operator console: a session cookie to keep you signed in.
- Attendee page: your chosen language, theme, text size, chat name, and whether you have seen the chat privacy notice — all kept in your browser’s local storage, on your own device. Nothing here identifies you to us, and clearing your browser data removes it.
- Translator page: your language choice in local storage, and a reconnect credential in session storage that is discarded when the tab closes.
Changes
We may update this notice as the service evolves; material changes will be reflected here with a new version date.
Hablexo Ltd · Registered in England & Wales · Company No. 17354416 · Registered office: 167-169 Great Portland Street, 5th Floor, London W1W 5PF · hello@hablexo.com
Hablexo home · Terms of Service · Data Processing Addendum · EULA · Sign up