1. What Duo processes
Duo by Tropfen helps two people translate conversations. Speech recognition runs on your device. No audio leaves your device or is stored. To translate, the recognised or typed text is sent encrypted to our EU translation proxy and then to the selected translation provider. Neither we nor the provider store the translation text; there is no server-side translation cache.
Conversation history and starred turns stay on your phone and are off unless you choose to save them. They are not synced to our servers.
2. Service providers and processors
We use these providers to operate Duo. Regions are stated where confirmed; a provider’s processing location can depend on its service configuration. The translation providers’ zero-retention terms must be verified before release.
- Supabase (EU, eu-west-1 / Ireland): anonymous authentication, quota and entitlement records, and service infrastructure. Anonymous server records are deleted after 12 months of inactivity.
- Our EU translation proxy: securely forwards translation text and the limited context needed for a translation; it does not store the text or cache translations.
- Anthropic (Claude Haiku; processing region to be confirmed): primary AI translation of text.
- DeepL (processing region to be confirmed): fallback machine translation of text.
- Apple and Google on-device speech and translation services: on-device speech recognition and, when an eligible offline pack is used, on-device translation. Audio and text for these operations stay on the device.
- Natural-voice provider (to be confirmed; region to be confirmed): cloud text-to-speech for Duo Plus. The provider name and zero-retention terms must be confirmed before release.
- Adapty (processing region to be confirmed): subscription status and entitlement management; Apple App Store and Google Play process payments.
- Google AdMob and Google UMP (Google services; processing region may vary): optional rewarded ads and the consent flow required before an ad in the EEA, UK and Switzerland. Without ad consent, only non-personalised ads are requested.
- Mixpanel (EU data residency): product analytics, only after your O7 analytics consent.
- Microsoft Clarity (processing region to be confirmed): consented, strictly masked session replay outside excluded screens; never conversation screens or text fields.
- Meta (Meta Platforms; processing region may vary): advertising attribution events only after analytics consent and, on iOS, App Tracking Transparency authorisation.
- Sentry (EU ingest): crash reports only after consent, with personally identifying information scrubbed.
3. Consent and your choices
Analytics and session replay are off by default. They run only if you allow them on the O7 consent screen. You can change or withdraw consent at any time in Settings → Privacy. If you do not consent, analytics and replay stay off. On iOS, Meta attribution also requires that you allow tracking in Apple’s App Tracking Transparency prompt. Google UMP is requested just before the first rewarded ad where required; without consent, ads are non-personalised.
Clarity replay is never recorded on chat, the conversation loop, face-to-face mode, typing or editing, history, starred turns, or other excluded screens. On other screens, text is strictly masked. Analytics and crash reports never include conversation text or audio.
4. Retention, deletion and age
We do not keep translation text or audio. History and stars are stored only on your device if you opt in. You can request erasure of your server-side data by writing to privacy@inovy.dev with the subject “Bize yaz”. Anonymous server records for quota and entitlement links are automatically deleted after 12 months of inactivity.
Duo is not directed at children under 13. Please do not use the service if you are under 13.
5. Contact
For privacy questions or an erasure request, contact privacy@inovy.dev.