Privacy Policy for the Loqalit Chrome Extension

Last Updated: July 21, 2026

Overview

Loqalit is a Chrome extension for localization QA professionals that scans web pages and analyzes translation quality using AI. This privacy policy describes how the Extension collects, uses, and protects your information.

Information We Collect

1. Page Content (During Scans)

When you click “Scan Page,” we extract text content from the active webpage:

  • Text content, including headings, paragraphs, buttons, form labels, and related interface copy

  • Optional language and text-direction attributes for each text block

  • A minimal source-type hint when text comes from a non-default source, such as an ARIA attribute or CSS pseudo-element

We intentionally do not collect DOM locators such as CSS selectors or element positions. Scan payloads contain text content and the metadata above only.

Storage: Scan data is stored locally in your browser: IndexedDB for history and chrome.storage.session for active scans. Data is sent to our servers only when you run AI analysis or, for signed-in users who opt in, through scan-history sync.

Purpose: To display scan results, perform quality checks, enable highlighting, and persist scan history locally.

2. Scan-History Sync (Opt-In, Signed-In Users)

If you are signed in and explicitly enable scan-history sync through the dashboard prompt or Settings → Account, the dashboard uploads your local scan history to your Loqalit workspace: page URLs, scan timestamps, block and word counts, and quality scores.

Sync is off until you enable it; no scan history is uploaded before that. Disabling sync stops future uploads but does not delete entries already uploaded. Resetting local data or uninstalling the extension also does not delete server-side copies. You may request deletion of synced data at any time.

3. Authentication Data (AI Features)

If you use AI analysis with a signed-in account, you sign in through a Clerk browser popup. Your email and user ID are stored on our backend to manage access and usage quotas. Session state is managed via cookies on the authentication host domain; no tokens are stored locally.

4. Usage Data

Our backend logs AI analysis requests, including timestamp and response time, page URL and domain, block count, character count and token usage, model used, cost and error information, and finding count. For signed-in analyses, the backend also stores the AI finding contents so results are available in the dashboard. When R2 storage is configured, the backend may additionally store the full request payload, including system and user prompts and raw text blocks. This helps us monitor service health, enforce usage limits, and improve analysis quality.

5. Guest Analysis Data

Guest users can use AI analysis with limited quota. They are identified by a locally generated UUID device ID; the same request data is logged as authenticated users, with device ID instead of user ID. The default quota is one analysis per device.

6. Crowdin Integration (Optional, User-Configured)

If you configure the optional Crowdin integration with your own Personal Access Token, the token is stored in chrome.storage.local on your device and is sent only to Crowdin’s API to act on your behalf. Access to api.crowdin.com is requested only when you set up the integration. When you explicitly push a finding, the Extension sends the AI finding text, page URL and title, and a short rendered-page excerpt to your Crowdin project as an issue. When screenshot evidence is included, the visible tab is captured and uploaded to your project. Crowdin data goes directly from your browser to Crowdin; Loqalit does not receive or store your Crowdin token or pushed content.

7. Product Diagnostics

The Extension can save operational diagnostic entries locally when expected product operations partially fail, such as skipped screenshot evidence capture. Backend upload is disabled by default and controlled by release configuration. When enabled, uploaded diagnostics are limited to diagnostic and event identifiers, source context, operation, severity, stable error codes, app and browser version, redacted page origin/path, bounded counts, and bounded per-target metadata. Diagnostics do not include screenshots, DOM snapshots, full page text, raw AI payloads, cookies, authorization headers, Clerk tokens, raw request headers, or raw query strings. Vendor crash monitoring is currently disabled; any future exception reporting would be sanitized and would not include session replay.

8. User Preferences

Configuration preferences include quality thresholds, scan configuration, onboarding completion state, and scan-history sync consent. Most preferences use chrome.storage.sync. Onboarding state, sync consent, and a few local-only UX flags use chrome.storage.local.

Data Processing

Local Processing

Page scanning happens entirely in your browser. Scan history is stored locally in IndexedDB. Quality checks and MQM scoring run client-side.

Server Processing

When you click “Analyze with AI,” extracted text blocks and the page URL are sent to our Convex backend. Our backend builds prompts server-side and calls Google Gemini. Analysis results return to your browser, and for signed-in analyses the finding contents are stored in our backend database. When R2 storage is configured, full request payloads may additionally be stored for quality review. Request metadata, including page URL, domain, block count, and token usage, is always logged.

Third-Party Services

  • Clerk — authentication; receives email and sign-in session data.

  • Convex — backend infrastructure; receives AI analysis payloads, request logs, and synced scan history.

  • Cloudflare Pages — authentication interface hosting; receives standard web request data.

  • Google Gemini — AI analysis; receives extracted page text through our backend.

  • Crowdin — optional, user-run issue handoff; receives finding text, page context, excerpts, and optional screenshots for your project.

  • Dodo Payments — merchant of record; receives billing and payment details entered in hosted checkout. Loqalit never receives card data.

  • OneSignal — transactional email delivery; receives recipient email and workspace or billing notification content.

We do not sell user data. We do not include analytics or ad tracking libraries, and the Extension’s production manifest allowlists no telemetry endpoints. Clerk SDK telemetry is disabled.

Permissions

  • scripting and activeTab — inject the content script to scan the current page.

  • storage — save preferences and scan state locally.

  • sidePanel — display results in Chrome’s side panel.

  • cookies — required by Clerk for session synchronization and never used to read site cookies.

  • Loqalit backend and authentication hosts — allow AI analysis and sign-in.

  • api.crowdin.com — optional and requested only when you set up Crowdin.

  • All sites — optional and requested only for site scanning or reliable screenshot evidence capture; revocable anytime in Chrome settings.

Data Security

  • All server communication uses HTTPS.

  • Authentication tokens are not stored; a fresh short-lived JWT is fetched per request.

  • We never store passwords; Clerk handles authentication.

  • No LLM API keys are stored client-side.

Your Rights

You can clear local data with the Reset button or by uninstalling the extension, though this does not delete server-side copies of synced or analyzed data. You can disable scan-history sync in Settings → Account, sign out from Dashboard Settings → Account, and contact us to request deletion of your account and associated server-side data.

Data Retention

  • Local data is retained until you clear it or uninstall the extension.

  • AI request logs are retained for 180 days, then deleted by a scheduled backend cleanup job.

  • Detailed backend diagnostic events are retained for 30 days; aggregate rollups are retained for 180 days.

  • Analysis findings and synced scan history are retained while your account is active, or until you request deletion.

  • R2 payloads are retained when configured for quality improvement. Account data is managed to support access and quota enforcement.

No Tracking or Ads

We do not use analytics or ad tracking scripts, display advertisements, or sell or share data with third parties beyond the service providers listed above.

Children’s Privacy

This extension is not intended for users under 13 years of age.

Changes to This Policy

We may update this privacy policy. Changes will be reflected in the “Last Updated” date above.

Contact

For privacy questions or data deletion requests:

Email: info@loqalit.com

Website: https://loqalit.com

Last Updated: July 21, 2026

Privacy Policy for the Loqalit Chrome Extension

Last Updated: July 21, 2026

Overview

Loqalit is a Chrome extension for localization QA professionals that scans web pages and analyzes translation quality using AI. This privacy policy describes how the Extension collects, uses, and protects your information.

Information We Collect

1. Page Content (During Scans)

When you click “Scan Page,” we extract text content from the active webpage:

  • Text content, including headings, paragraphs, buttons, form labels, and related interface copy

  • Optional language and text-direction attributes for each text block

  • A minimal source-type hint when text comes from a non-default source, such as an ARIA attribute or CSS pseudo-element

We intentionally do not collect DOM locators such as CSS selectors or element positions. Scan payloads contain text content and the metadata above only.

Storage: Scan data is stored locally in your browser: IndexedDB for history and chrome.storage.session for active scans. Data is sent to our servers only when you run AI analysis or, for signed-in users who opt in, through scan-history sync.

Purpose: To display scan results, perform quality checks, enable highlighting, and persist scan history locally.

2. Scan-History Sync (Opt-In, Signed-In Users)

If you are signed in and explicitly enable scan-history sync through the dashboard prompt or Settings → Account, the dashboard uploads your local scan history to your Loqalit workspace: page URLs, scan timestamps, block and word counts, and quality scores.

Sync is off until you enable it; no scan history is uploaded before that. Disabling sync stops future uploads but does not delete entries already uploaded. Resetting local data or uninstalling the extension also does not delete server-side copies. You may request deletion of synced data at any time.

3. Authentication Data (AI Features)

If you use AI analysis with a signed-in account, you sign in through a Clerk browser popup. Your email and user ID are stored on our backend to manage access and usage quotas. Session state is managed via cookies on the authentication host domain; no tokens are stored locally.

4. Usage Data

Our backend logs AI analysis requests, including timestamp and response time, page URL and domain, block count, character count and token usage, model used, cost and error information, and finding count. For signed-in analyses, the backend also stores the AI finding contents so results are available in the dashboard. When R2 storage is configured, the backend may additionally store the full request payload, including system and user prompts and raw text blocks. This helps us monitor service health, enforce usage limits, and improve analysis quality.

5. Guest Analysis Data

Guest users can use AI analysis with limited quota. They are identified by a locally generated UUID device ID; the same request data is logged as authenticated users, with device ID instead of user ID. The default quota is one analysis per device.

6. Crowdin Integration (Optional, User-Configured)

If you configure the optional Crowdin integration with your own Personal Access Token, the token is stored in chrome.storage.local on your device and is sent only to Crowdin’s API to act on your behalf. Access to api.crowdin.com is requested only when you set up the integration. When you explicitly push a finding, the Extension sends the AI finding text, page URL and title, and a short rendered-page excerpt to your Crowdin project as an issue. When screenshot evidence is included, the visible tab is captured and uploaded to your project. Crowdin data goes directly from your browser to Crowdin; Loqalit does not receive or store your Crowdin token or pushed content.

7. Product Diagnostics

The Extension can save operational diagnostic entries locally when expected product operations partially fail, such as skipped screenshot evidence capture. Backend upload is disabled by default and controlled by release configuration. When enabled, uploaded diagnostics are limited to diagnostic and event identifiers, source context, operation, severity, stable error codes, app and browser version, redacted page origin/path, bounded counts, and bounded per-target metadata. Diagnostics do not include screenshots, DOM snapshots, full page text, raw AI payloads, cookies, authorization headers, Clerk tokens, raw request headers, or raw query strings. Vendor crash monitoring is currently disabled; any future exception reporting would be sanitized and would not include session replay.

8. User Preferences

Configuration preferences include quality thresholds, scan configuration, onboarding completion state, and scan-history sync consent. Most preferences use chrome.storage.sync. Onboarding state, sync consent, and a few local-only UX flags use chrome.storage.local.

Data Processing

Local Processing

Page scanning happens entirely in your browser. Scan history is stored locally in IndexedDB. Quality checks and MQM scoring run client-side.

Server Processing

When you click “Analyze with AI,” extracted text blocks and the page URL are sent to our Convex backend. Our backend builds prompts server-side and calls Google Gemini. Analysis results return to your browser, and for signed-in analyses the finding contents are stored in our backend database. When R2 storage is configured, full request payloads may additionally be stored for quality review. Request metadata, including page URL, domain, block count, and token usage, is always logged.

Third-Party Services

  • Clerk — authentication; receives email and sign-in session data.

  • Convex — backend infrastructure; receives AI analysis payloads, request logs, and synced scan history.

  • Cloudflare Pages — authentication interface hosting; receives standard web request data.

  • Google Gemini — AI analysis; receives extracted page text through our backend.

  • Crowdin — optional, user-run issue handoff; receives finding text, page context, excerpts, and optional screenshots for your project.

  • Dodo Payments — merchant of record; receives billing and payment details entered in hosted checkout. Loqalit never receives card data.

  • OneSignal — transactional email delivery; receives recipient email and workspace or billing notification content.

We do not sell user data. We do not include analytics or ad tracking libraries, and the Extension’s production manifest allowlists no telemetry endpoints. Clerk SDK telemetry is disabled.

Permissions

  • scripting and activeTab — inject the content script to scan the current page.

  • storage — save preferences and scan state locally.

  • sidePanel — display results in Chrome’s side panel.

  • cookies — required by Clerk for session synchronization and never used to read site cookies.

  • Loqalit backend and authentication hosts — allow AI analysis and sign-in.

  • api.crowdin.com — optional and requested only when you set up Crowdin.

  • All sites — optional and requested only for site scanning or reliable screenshot evidence capture; revocable anytime in Chrome settings.

Data Security

  • All server communication uses HTTPS.

  • Authentication tokens are not stored; a fresh short-lived JWT is fetched per request.

  • We never store passwords; Clerk handles authentication.

  • No LLM API keys are stored client-side.

Your Rights

You can clear local data with the Reset button or by uninstalling the extension, though this does not delete server-side copies of synced or analyzed data. You can disable scan-history sync in Settings → Account, sign out from Dashboard Settings → Account, and contact us to request deletion of your account and associated server-side data.

Data Retention

  • Local data is retained until you clear it or uninstall the extension.

  • AI request logs are retained for 180 days, then deleted by a scheduled backend cleanup job.

  • Detailed backend diagnostic events are retained for 30 days; aggregate rollups are retained for 180 days.

  • Analysis findings and synced scan history are retained while your account is active, or until you request deletion.

  • R2 payloads are retained when configured for quality improvement. Account data is managed to support access and quota enforcement.

No Tracking or Ads

We do not use analytics or ad tracking scripts, display advertisements, or sell or share data with third parties beyond the service providers listed above.

Children’s Privacy

This extension is not intended for users under 13 years of age.

Changes to This Policy

We may update this privacy policy. Changes will be reflected in the “Last Updated” date above.

Contact

For privacy questions or data deletion requests:

Email: info@loqalit.com

Website: https://loqalit.com

Last Updated: July 21, 2026

info@loqalit.com

Built with ❤️ by the Loqalit team.

© 2026 Loqalit. All rights reserved.

info@loqalit.com

Built with ❤️ by the Loqalit team.

© 2026 Loqalit. All rights reserved.