Security & data handling

Last updated: August 12, 2026

Loclint is built to hold text from unannounced titles, so here is the whole picture up front: your strings live on Cloudflare, and unless you switch an AI feature on, they never reach any external AI. Below is exactly where they travel, where they're stored, and when they're gone — in enough detail to hand to your producer or client as-is.

Where your strings go

Your browser

Uploaded over TLS

Loclint, on Cloudflare

Stored in R2 + D1, encrypted at rest

OpenAI API

Only when AI review or AI translation is on. Never used for training; deleted within 30 days.

That is the whole map. Unless you turn an AI feature on, no external AI ever sees your text.

Checking without AI

The rule checks — missing placeholders, untranslated strings, length overflows, terminology — run entirely inside Loclint's infrastructure; your text never leaves it. Every run has a "Use AI review" toggle: switch it off and nothing is sent to any external AI. Under NDA? Run rules-only until the title is announced, then switch AI review on.

Shared report links

You can turn a completed check into a link that opens without a login, so an outside translator or client can read the report. Nothing is shared until you create that link. The link contains a 256-bit random token, stops working 30 days after you create it, can be deleted at any time, and is excluded from search engines. While it is live, anyone holding it can read that report — including the source and target text — so treat it like the file itself.

Storage & deletion

  • Uploaded files and extracted strings are kept until you delete them. Nothing expires silently, and past runs stay comparable for regression detection.
  • Deleting a project immediately removes the stored files, extracted strings, and check results.
  • Deleted data is also purged from disaster-recovery database backups within 30 days.
  • Your text is never used to train AI models — not by us, and not by the AI providers we call.

Who else touches your data

Exactly four providers process user data on Loclint's behalf:

  • CloudflareHosting, database, and file storage. All data lives here, encrypted in transit and at rest.
  • OpenAIReceives strings only while AI review or AI translation is enabled. API data isn't used for training and is deleted within 30 days.
  • StripePayments. Card numbers never touch Loclint's servers, and your text is never shared.
  • ResendInvitation and notification emails. Your text is never shared.

The legal treatment, including cross-border transfer, is set out in the privacy policy.

Access control

  • Every project belongs to an organization, and only that organization's members can access its data.
  • Auth tokens never reach browser JavaScript — the server exchanges your session for a short-lived token on every request.
  • We look at customer content only when a support request or an abuse investigation requires it.

What we don't have

Loclint holds no third-party certifications today — no SOC 2, no ISO 27001. What you get instead is this page: the complete data path, retention rules, and provider list, where every line describes the system as it actually runs. If your review needs more, email us — we'll answer your security questionnaire and discuss an NDA.

Questions & vulnerability reports

Security questions, vulnerability reports, and NDA inquiries: kota.m.sgr@gmail.com

Operator and business details are published on the legal page.

When you're cleared to try it, run your first check free — and leave AI review off until your title is announced. 500 strings a month, no credit card.

Run your first check — free