Privacy Policy
Version 1.0 · Effective date 2026-07-30
1. Who we are, controller and privacy officer
Abo Labs is responsible for the personal data that we actually receive, store or control in the course of operating the Service. Our full business registration details are shown in the footer of our website.
Google, Paddle and the AI service providers we use each handle the data they hold in accordance with their own role, their own terms and their own privacy rules. This policy describes what we receive and what we do with it; it does not describe, and we do not control, the data those parties hold in their own systems (Section 9).
Privacy officer
- Name: Ji Cheol-guk (지철국)
- Position: General Manager
- E-mail: contact@abolabs.io
Requests to access, correct or delete your personal data, and complaints about how we handle it, may be addressed to the privacy officer at that address (Section 11).
2. Scope and service surfaces
This policy covers two surfaces.
2.1 Free tools. Publicly available file conversion and related utilities that can be used without an account. Section 3 applies.
2.2 abo Workspace. Our account-based localization workspace, including translation memory, terminology, style resources, project data and AI-assisted processing. Sections 4 to 7 apply.
2.3 Reading rule. Statements in this document about how content is processed apply only to the surface under which they appear. In particular, statements that content is processed locally in your browser and is not transmitted to us apply to the free tools surface only, and do not apply to abo Workspace. Where a statement is intended to apply to both surfaces, it says so expressly.
3. Free tools: local processing
The free tools run in your browser. Files and text you load into them are processed locally on your device. They are not transmitted to us, and we do not store them. No account is required and we do not create a user record for use of the free tools.
We do collect limited technical and analytics data about visits to the site, as described in Sections 7 and 8.
4. Account data
To provide abo Workspace we process:
4.1 Sign-in data. You sign in with a Google account. Your Google account is managed by Google, under Google's own terms and privacy policy; we do not administer it and we do not have general access to it.
We request only the scopes needed to identify you: openid, email and profile. We have not requested and do not receive access to Gmail, Drive, Calendar or Contacts. What Google shares with us is shown to you on Google's consent screen.
From that sign-in we receive only the limited information needed to authenticate you and to link your session to an abo Workspace account.
4.2 What we store. The account record we keep consists of: an account identifier, the e-mail address associated with the account, an optional display name, authentication identifiers, the date the account was created, and how it was created.
Information disclosed by Google at sign-in but not listed above is not kept by us as part of your account record.
4.3 Subscription and entitlement records. Your subscription status and subscription period, and the ledger of AI usage entitlements associated with your account — including, for each batch, the date it was acquired, its expiry date, its status, and the amount consumed and remaining.
4.4 Support correspondence. If you contact us, the content of that correspondence and the address you used.
We rely on third-party authentication and data-storage providers to operate the account directory and the underlying storage; see Section 9.
5. Project assets and user content
Content that you choose to save in abo Workspace — translation rows, terminology, translation memory, style resources, language files and project data — is stored on systems operated for us so that it persists across sessions and devices. This is a material difference from the free tools surface described in Section 3.
This Section covers that project content only. It does not cover data held by Google in your Google account, or content held by an AI service provider in its own systems (Sections 6 and 9).
We process this content in order to provide the workspace features you use, including the AI processing described in Section 6. We do not use it to train models, and we do not send it to any third party for the purpose of training models. Where content is sent to a provider to carry out a task you have requested, that provider's handling of it is governed by our contract with the provider and by any applicable data processing arrangement.
Section 5 of the Terms of Service governs rights in that content.
6. AI processing
6.1 What is sent. When you choose to run an AI-assisted task, we send to a third-party AI service provider the source text of the task together with the context you have selected for it, which may include related terminology, translation memory entries and style resources. We do not send your account credentials.
6.2 Where it is processed. The AI service provider carries out the processing in its own systems, which are not part of abo Workspace and are not administered by us. Content held there is held by that provider in its own environment.
6.3 Purpose and legal basis. Performance of the contract between you and us, so that we can carry out the task you requested (Section 8).
6.4 Provider handling. The handling of submitted content by an AI service provider — including whether it is retained, and for how long — is governed by our contract with the provider concerned and by any applicable data processing arrangement. We state the contractual position; we do not make claims about a provider's internal conduct beyond what our contracts and our actual processing support.
7. Cookies, sessions and local storage
7.1 Free tools. Tool preferences are kept in your browser's local storage so that your settings persist between visits. This data stays on your device.
7.2 Account sessions. If you have an account, we use a session cookie and equivalent browser storage for two purposes: to keep you signed in between requests, and to protect the session against misuse.
7.3 Analytics storage. Our product analytics is operated in a configuration that does not set analytics cookies. What the analytics events contain, and how long they are kept, is described in Sections 8 and 10.
7.4 Consent. Where applicable law requires consent before non-essential storage is used, we obtain that consent before enabling it.
8. How and why we use data, and legal bases
The table below covers the processing we carry out ourselves, on data we receive, store or control. It does not cover Google's own processing of your Google account, or an AI service provider's processing of task content in its own systems; those roles are described in Section 9.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the free tools | Technical and analytics data (Sections 3, 7) | Legitimate interests in operating and improving the site |
| Creating and operating your account | Sign-in and account data (Section 4) | Performance of a contract |
| Providing workspace features | Your content (Section 5) | Performance of a contract |
| Transmitting an AI task to the provider you ask us to use | Task text and selected context (Section 6) | Performance of a contract |
| Processing purchases, subscriptions and entitlements | Subscription and entitlement records (Section 4.3) | Performance of a contract; legal obligation for transaction records |
| Keeping the Service secure and diagnosing faults | Session data, error and security event data | Legitimate interests in the security and integrity of the Service |
| Understanding how the Service is used | Product analytics (Section 7.3) | Legitimate interests in improving the Service |
| Responding to you | Support correspondence (Section 4.4) | Legitimate interests; performance of a contract where the request concerns your account |
| Complying with law | As required | Legal obligation |
Where a purpose requires your consent under applicable law, we ask for it and you may withdraw it at any time (Section 11).
9. Service providers, processing relationships
We use third-party providers to operate the Service. Their roles are not all the same, and this policy does not describe them uniformly. Where a role cannot be summarised accurately in a single term, we describe what the party actually does rather than assign it a label.
9.1 Google — identity provider. Google provides sign-in. Your Google account is managed by Google, under its own terms and privacy policy. Google discloses to us the limited information shown on its consent screen; what we then keep is listed in Section 4.2. We do not administer your Google account and we do not have general access to it.
9.2 Paddle — Merchant of Record. Paddle is the seller of record for purchases and handles the transaction and payment layer under its own terms and rules. We do not receive or store your card details.
9.3 AI service providers. When you choose to run an AI task, the provider processes the text and context submitted for that task in its own systems (Section 6). Its handling of that content is governed by our contract with it and by any applicable data processing arrangement.
9.4 Other providers. Other providers supply services we need in order to operate the Service, and handle personal data only as far as providing those services requires. They are described by category: hosting and security providers; authentication and data-storage providers; email delivery providers; and analytics and error-monitoring providers.
We do not sell personal data, and we do not share it for advertising purposes.
10. Retention
We keep personal data only for as long as we need it for the purposes described in this policy, or for as long as the law requires.
| Data | Retention |
|---|---|
| Files and text processed by the free tools | Not retained; we do not receive them (Section 3) |
| Account data and abo Workspace content | For as long as the account exists |
| Subscription, purchase and entitlement records | For the period required by applicable tax and e-commerce record-keeping law |
| Diagnostic and error logs | Up to 90 days |
| Security and server logs | Short retention, in accordance with our providers' configuration |
| Support correspondence | For as long as needed to handle the matter and for a reasonable period afterwards |
| Product analytics data | Retained in aggregated or limited form, in accordance with our analytics configuration |
10.1 Account closure. Once a closure request has been processed, the account data and the abo Workspace content associated with that account are deleted. We do not apply any additional retention period after closure.
The only exception is records we are required by law to keep: transaction, tax and e-commerce records are retained separately for the period the applicable law requires, and are not used to continue providing the Service.
10.2 Data held by others. We do not set, and cannot commit to, the retention periods applied by Google, Paddle or an AI service provider to data held in their own systems.
We delete or anonymise personal data once it is no longer needed for the purposes above.
11. Your rights, and how to exercise them
Depending on where you are, you may have the right to: obtain access to your personal data; have it corrected; have it deleted; obtain a copy in a portable form; restrict or object to certain processing; and withdraw consent where processing is based on consent.
Scope of these rights as against us. Rights exercised with us apply to the data we actually hold or control. Your Google account remains under your control through Google, and data held by Paddle or by an AI service provider in their own systems is subject to their own procedures.
11.1 How to exercise them, and how to close your account. Contact our privacy officer at contact@abolabs.io. Requests are handled by our team; the Service does not currently offer self-service account closure or self-service deletion. We will respond within the period required by the applicable law.
To close your account, send a request to that address. Once the request has been processed, the account data and the abo Workspace content associated with the account are deleted, except for records we are required by law to keep (Section 10.1). No further retention period is applied by us.
11.2 Export. Translation rows and terminology can be exported by you from within abo Workspace. This does not depend on having an active subscription or any remaining AI usage entitlement. Where other data we hold about you or your projects cannot be exported from within the workspace, you may request a copy under 11.1.
12. Security
We protect data with reasonable technical and organisational security measures, including encryption in transit, access controls and least-privilege practices. We also seek to minimise the personal data included in diagnostic and error records. Error and diagnostic logs are retained as set out in Section 10.
We do not claim security certifications we do not hold.
No service can be guaranteed to be completely secure. If a breach affecting your personal data occurs, we will notify you and the competent authority where the applicable law requires it.
13. Children
The Service is not directed at children under 14, or under a higher age where the law of your country sets one. We do not knowingly collect personal data from children below that age; if we become aware that we have, we delete it.
14. Changes to this policy
We may change this policy. The version and effective date of the current policy appear at the top of this document, and a change takes effect on the date stated in the updated text.
Where a change is material, we will give notice by a reasonable means before it takes effect. Where applicable law, or the nature of a particular change, requires additional notice or requires your consent, we will follow that requirement.
15. Contact
For any question about this policy or about how we handle personal data, contact our privacy officer at contact@abolabs.io, or use the contact route published on our website.