Privacy Policy
Subtools is a small service and it stores very little. This page says what it does store, for how long, and what you can ask us to do about it.
Last updated: 15 September 2026
1. What we store
- Your account: email address, name, an avatar if you upload one, and your display preferences.
- Your files: the subtitle files you upload and the results we produce from them.
- Your activity: the jobs you run, your points balance and the transactions that changed it, and a record of significant account actions.
- Sign-in context: the IP address and country a login came from, used to notice a sign-in from somewhere new and ask you to confirm it.
We never see your card details. Payment is taken by the payment provider on their own pages. What comes back to us is a confirmation: which purchase succeeded, the amount, and an identifier for it.
2. Where translation happens
Translation runs on our servers, like every other tool. It used to run in your browser through a Google Translate widget; that is no longer how it works, and this section has been rewritten to match.
There are two ways to translate, and they differ in whose account the text passes through. You can connect a provider using your own API key — DeepL, Google Cloud Translation, Azure Translator, or an OpenAI-compatible endpoint — or, where we offer one, you can choose a Subtools-managed provider, which is the same kind of account held by us instead of by you. The provider is named in the picker before you start a job, and nothing is sent until you choose one: a translation job with no provider fails rather than picking for you.
Either way, the cue text is sent from our servers to the provider chosen for that job. What that provider does with it is governed by their terms, not this policy. With your own key you pick them and hold the account; with a managed provider we do, and you are relying on our choice — which is why the picker says which one it is.
Timing, cue numbering and styling are never sent — the provider receives text only, and the file is rebuilt here using your original timing. Your API key is encrypted before it is stored, is never shown again after you save it, and is never written to our logs. A managed provider's credential is ours and is never shown to you, for the same reason yours is never shown to us.
The file itself is stored and deleted on exactly the schedule in the next section, the same as for any other tool.
3. How long we keep it
Uploaded files and their results are deleted automatically at least 30 days after you last use them. For most files that is 30 days after upload; if you process the same file again, the 30 days run from that later job, so a file you are still working with is not removed from under you. That happens on a schedule; you do not have to ask. You can also delete any file yourself at any time from your dashboard, which removes both the original and the processed result from disk immediately.
Thirty days is the minimum, and it is what applies to every account today. A paid plan can keep files longer, never shorter, and where that applies the longer period takes effect automatically — you do not have to ask for it or turn it on.
Saved versions — the edited or translated copies you keep in the editor — live and die with the file they belong to. They count as using it, so a file you are still editing is not deleted out from under you, and deleting the file removes every version of it.
Visit records — the page, referrer and campaign information behind the traffic counts in our own dashboard — are deleted after 90 days.
Your account, your points balance and the record of purchases and refunds are kept while the account exists. Financial records are kept for as long as tax and accounting law requires, which is longer than the account itself.
4. Who can reach your files
Files are private to the account that uploaded them. Downloading one requires you to be signed in, and the server checks that the file belongs to you before it sends anything. They are not listed publicly, not indexed, and not reachable by guessing a URL.
Your connection to the site is encrypted. Files are stored as ordinary files on the server that runs the service — they are not separately encrypted at rest, and this page previously said otherwise, which was wrong. Passwords are stored only as salted hashes and are never recoverable, by us or by anyone else.
Sign-in uses HttpOnly cookies. The tokens that keep you signed in cannot be read by JavaScript running in your browser.
5. Who else is involved
- The payment provider handles the checkout and holds the payment details we never see.
- The translation provider used for a job receives cue text when — and only when — you run a translation job, sent from our servers. That is either a provider you connected and hold the account with, or a Subtools-managed one you picked from the same list; Section 2 explains the difference.
- Google Analytics receives page-view data. In the EU, EEA and UK that happens only after you accept; elsewhere it is on until you turn it off. Section 6 says exactly how, and Cookie Settings turns it off everywhere.
- Our email sender delivers account email such as verification codes and password resets.
We do not sell your data, and we do not share it with advertisers.
6. Cookies and analytics
The cookies that sign you in are strictly necessary — without them the site cannot know who you are — and they are always set.
Analytics is separate. If you are in the EU, EEA or UK you are asked before any analytics script loads, and nothing loads unless you accept. Elsewhere analytics is on by default and you can turn it off at any time through Cookie Settings in the footer. Advertising and personalisation signals are switched off for everyone, in every region, and we do not run advertising cookies at all.
Your choice is remembered on your device and can be changed whenever you like.
7. What you can ask for
You can ask us to:
- Send you a copy of the data we hold about you.
- Correct anything that is wrong.
- Delete your account and its data. We remove your uploaded files, their results and every saved version, and close the account so it can no longer be signed in to; we keep only the financial records the law requires. You do not have to wait for us to delete a particular file — deleting one from your dashboard removes the original, the result and every version of it straight away.
- Stop using your data for analytics, which you can also do yourself.
Ask through the contact form from the address on the account. We will confirm it is you before acting, and we aim to complete a request within 30 days.
If you are in the EU, EEA or UK you also have the right to complain to your national data protection authority.
8. Children
Subtools is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will remove it.
9. Who is responsible for your data
The data controller is [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS]. Data is stored on servers in [HOSTING JURISDICTION].
If this policy changes in a way that affects you, we will say so on this page and update the date at the top.
Contact
Questions about any of these documents, or about your own data, go through the contact form. It reaches us directly and we reply to the address you give.