For personal data contained in event speech and transcripts, the
organization running the event (the church, conference, or host) is the
controller and we act as its processor under the
Data Processing Addendum. For the
account, billing, and website data we handle to run the service, we are
the controller. For events on live.openchurch.cz that we
host ourselves, the Operator is the controller for those events —
see "Special-category data" below.
No accounts, no tracking. Listening requires no registration; audience pages set no cookies and we do not use advertising or analytics trackers. Operational metrics (listener counts, connection health) are aggregated and contain no identity. Our servers do process the IP address and connection metadata of each connection — solely for rate limiting, abuse protection, and per-IP capacity limits (legitimate interest, Art. 6(1)(f)) — and we build no profiles from it; the "Listener metadata" paragraph below states exactly how little of this we keep, and for how long. The service itself writes no event audio to disk; see "Speech content and AI processing" below for how long our translation provider may retain session data. Transcript text is stored only where archiving is enabled (see below).
Connection setup (STUN). To establish the low-latency audio
connection (WebRTC), your browser contacts Google's public STUN service
(stun.l.google.com) when you connect; the same applies to the
browser-based sender page an organization may use. STUN is a
network-connectivity step (NAT traversal): it lets your device discover a
working network path to our server, which itself uses a public address and
no STUN. Google's STUN service receives your IP address and connection
metadata only — never audio, captions, or any event content — for the
sole purpose of establishing the connection. Google operates this public
STUN service as an independent service (it is separate from the paid
Gemini API and its data-processing agreement); processing may occur in
the United States. We treat this as a disclosure to a third-party
recipient. On the current official service and certification evidence, the
identified transfer safeguard is Google LLC's active EU–U.S. Data Privacy
Framework certification for non-HR personal data; the evidentiary basis and
its limits are recorded in our transfer-accountability file. The Gemini
data-processing addendum and its SCCs do not govern this independent STUN
endpoint. We are evaluating self-hosted connectivity so that this step no
longer involves a third party.
Listener metadata and religious belief. LiveInterpret does not
collect, infer or use the listener's religious belief. Access to a publicly
available translation page is not treated as reliable evidence of belief.
Nevertheless, the contextual sensitivity is recognized and addressed through
strict minimization: listener IP data is held in memory only (as
per-IP capacity counters), is never written to logs on audience
routes (our reverse proxy keeps no access logs), is cleared on
disconnect or server restart, and is never combined with
accounts, billing, or cross-event histories. Its retention is therefore
the duration of your connection. Beyond that, the connectivity step
described above shares the IP address with Google's STUN service, and on
liveinterpret.ai (including its liveinterpret.app
alias) the Cloudflare edge listed under
"Recipients" sits in front of our servers.
We process: contact details from access requests and sign-up (name, e-mail, message); operator account names and credentials (passwords are stored only as salted hashes); linked sender-device names; and usage and billing records (language-minutes, credits, payments via Stripe). Legal basis: performance of the contract with your organization (Art. 6(1)(b)); our legitimate interest in operating, securing, and billing the service (Art. 6(1)(f)); and, for retaining billing and invoicing records, our legal obligations under Czech accounting and tax law (Art. 6(1)(c)).
Live audio is streamed to our EU servers and forwarded to our translation model provider, Google (Gemini API), for real-time processing. Translation is generated by an automated model; we do not review event content. Four things are true about how this audio is handled:
Optional archiving stores caption text only (never audio) on our EU
servers. It is off by default for organizations created on
LiveInterpret.AI and must be switched on per organization. Archived event
transcripts are retained for 90 days by default and then deleted
automatically. An organization can shorten this window; retention
longer than 90 days applies only where the organization has explicitly
chosen it for its instance. Because transcripts can contain sensitive
content (see below), we recommend keeping the retention window as short as
your needs allow. The live.openchurch.cz instance keeps
archiving on for its own events and uses the same 90-day
default.
Speech at religious or similar events may reveal beliefs and therefore
special-category data under Art. 9 GDPR. For customer organizations, the
organization running the event is the controller and is responsible for its
Art. 9 basis for capturing, translating, and (if enabled) archiving its event
audio (see the DPA). For events on
live.openchurch.cz, the operational legal basis for translating
or archiving an identifiable speaker's audio is Art. 9(2)(a) — the
explicit consent of the speaker, obtained before streaming by the
Operator or by the event organizer acting on the Operator's behalf, and
recorded in the Operator's consent register. Consent is requested separately
for (1) live translation, (2) storage in the private text archive, and
(3) public or third-party redistribution, such as YouTube live captions
or subtitles distributed with a recording. A speaker may withdraw any of
these choices at any time; withdrawal stops the corresponding future
processing, and the Operator maintains the consent record. The Operator is the controller
for the OpenChurch deployment; Art. 9(2)(d) is not relied upon — it is
unavailable to the Operator and not used for the publicly available
stream. The source feed must be limited to the venue's
sound-desk/stage feed and configured to exclude ambient audience voices.
Identifiable incidental speech, testimonies, floor questions, collective
singing, or responses must be muted or excluded unless an appropriate legal
basis and consent workflow has been established; they are not assumed to be
anonymous. During the limited organizational launch, speech by a person
under 18 is not transmitted to the AI provider, even with parental
authorization, unless the Operator has first approved a separate workflow
in writing after reviewing the upstream-provider terms or an alternative
processing path.
LiveInterpret is provided primarily to organizations. Accounts and AI-control functions are intended only for persons aged 18 or over. Audience members ordinarily receive translated audio or captions selected by the event organizer. They do not need to create an account and are not permitted to prompt or control the AI system. The service is not designed as an interactive AI service for children. The event organizer determines which source audio is transmitted and who receives the resulting translation. For event content and information about speakers or attendees, the organizer is generally the controller and LiveInterpret processes that information on the organizer's instructions, as described in the Data Processing Addendum. The organizer is responsible for providing appropriate notices and establishing a lawful basis, including where event content relates to minors. During the limited organizational launch, event organizers must exclude under-18 speakers from the translated feed unless the Operator has approved a separate workflow in writing as described above. LiveInterpret separately acts as controller for account, billing, security and limited connection information necessary to operate and protect the platform. This may include IP addresses and technical request data (see "Listeners" above). Such data is not used to build advertising profiles, and we do not knowingly collect personal data from children through account sign-up.
Our primary hosting, storage, and payment processing use EU-based infrastructure and entities. Real-time translation uses Google's Gemini API (developer API) on a paid (billed) plan, under which Google does not use the data to train or improve its models. Google processes this data on a global basis, which may include processing outside the EEA, under Google's Gemini API terms; Google's data-processing terms rely on the EU–U.S. Data Privacy Framework for eligible U.S. recipients (Google LLC is DPF-certified; adequacy under Art. 45 GDPR) and on the EU Standard Contractual Clauses (Art. 46 GDPR) as a fallback for other restricted transfers. An EEA data-residency option for this translation model is not currently available (the model is not yet offered on Google Vertex AI); we will reassess residency if Google releases it there. The browser's STUN connectivity step (see "Listeners" above) is separate from the Gemini processing and may process the IP address and connection metadata in the United States. On the current official service and certification evidence, this disclosure relies on Google LLC's active DPF certification for non-HR personal data; the Gemini SCCs do not apply to the independent STUN endpoint. Transactional e-mail (Resend), error monitoring (Sentry), and edge/DNS/CDN services (Cloudflare) may also process limited data outside the EEA under the EU Standard Contractual Clauses (Art. 46 GDPR) in their data processing agreements.
Which provider sees which data follows our two roles. Event and transcript data processed for customer organizations goes only to the subprocessors authorized in the DPA (the infrastructure, translation, and monitoring providers below). Stripe and Resend receive account and payment data only, for which we are the controller — they are not subprocessors of event audio or transcripts; Stripe also acts partly as an independent controller for payment processing under its own terms.
| Provider | Purpose and data | Region / safeguard |
|---|---|---|
| Google (Gemini API, developer API, paid tier) | real-time speech translation (event audio; session state incl. audio/text retained up to 24 h for session resumption) | global processing per Google's Gemini API terms; no training on paid-tier data; EU–U.S. DPF for eligible U.S. recipients, SCCs as fallback |
| Google (public STUN connectivity service) | network connectivity (NAT traversal): the listener's or sender's browser contacts stun.l.google.com to establish the audio connection; IP address and connection metadata only — no audio, no event content | US/global processing; independent Google public service (separate from the Gemini API and its data-processing agreement); on the current official service and certification evidence, Google LLC's active EU–U.S. DPF certification for non-HR personal data is the identified safeguard; Gemini SCCs do not apply; self-hosted alternative under evaluation |
| Hetzner Online GmbH | hosting and compute (event and account data) | Germany (EEA) |
| DigitalOcean, LLC | managed PostgreSQL for account, credit and billing records | Germany (fra1, EEA) |
| Cloudflare, Inc. | DNS, TLS, CDN/proxy and bot protection (liveinterpret.ai) | global edge; EU SCCs |
| Sentry (Functional Software, Inc.) | error monitoring and diagnostics for the service | US; SCCs |
| Stripe (Stripe Payments Europe, Ltd.) | payment processing (account and payment data only; partly independent controller) | EU entity for EU customers |
| Resend | account and transactional e-mail (sign-in, account data only) | US; SCCs |
A current list is available on request. We announce material changes to organizations in advance (see the DPA).
We use only strictly-necessary cookies:
lt_session (HttpOnly operator-dashboard session),
lt_grant (short-lived, one-time sign-in hand-off), the control-plane
admin session, and — on liveinterpret.ai and its
liveinterpret.app alias only — Cloudflare's
security/bot-management cookies (e.g. __cf_bm). We set no
analytics, advertising, or cross-site tracking cookies, and audience pages set
no cookies at all, so no consent banner is required.
Listener connection data (IP address, connection metadata) is held in memory only, for the duration of the connection (see "Listeners" above). Billing and invoicing records are kept as required by Czech accounting and tax law. Access requests and sign-up messages are deleted on request once handled. Operator accounts and sender devices are deleted when the organization removes them or closes its account. Transcripts follow the retention rules above. Backups roll off on their own cycle.
You have the GDPR rights of access, rectification, erasure, restriction, portability, and objection. For event/transcript data where your organization is the controller, contact your organization; we will assist it as its processor. Contact us via the request form on the homepage, by e-mail at [email protected], or the postal address in the Legal Notice. You may lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7.
TLS on all connections; hashed operator passwords; per-organization isolation; per-device revocable sender credentials; audit logging of control actions; EU-only primary hosting; and access limited to the Operator. See the DPA for the processor security measures.
We may update this policy; material changes are announced to the contact e-mail on file and reflected in the version line above.
Internal compliance and legal review completed and updated through 2026-07-23. This policy is maintained by the Operator and reviewed against the live platform. Changelog: v1.7 (2026-07-23) records the platform's domain migration from liveinterpret.app to liveinterpret.ai (the .app domain remains a serving alias for existing links and posters; same infrastructure and operator, no change to any processing). v1.6 (2026-07-20) separates speaker choices for live translation, private archive storage, and public/third-party redistribution; requires exclusion or separate lawful handling of identifiable incidental audience sound; excludes under-18 speakers during the limited launch unless a separate workflow is approved in writing; and aligns the STUN transfer statement with the dated service/DPF evidence while expressly excluding the Gemini SCC framework. v1.5 (2026-07-19) implements the round-4 legal-review corrections: the STUN transfer statement no longer references the Gemini DPA/SCC framework (Google's public STUN is an independent service; identified mechanism = Google LLC's DPF certification to the extent applicable; self-hosting under evaluation), and speaker consent is stated as obtained by the Operator or by the event organizer acting on the Operator's behalf and recorded in the Operator's consent register. v1.4 (2026-07-19) implements the round-3 legal-review launch conditions (same-day clarification: the controller for live.openchurch.cz is the Operator, confirmed 2026-07-19; Art. 9(2)(d) unavailable and not used): discloses the Google STUN connectivity step used to establish listener/sender audio connections (IP address and connection metadata only, no audio or content; Recipients and international-transfers sections updated; self-hosted connectivity under evaluation); states the listener-metadata position — no collection, inference or use of the listener's religious belief, addressed through strict minimization (in-memory only, no audience-route logs, cleared on disconnect/restart, never combined with accounts, billing or cross-event histories; retention = duration of the connection); and rewrites the Art. 9 basis for live.openchurch.cz — explicit speaker consent (Art. 9(2)(a)) obtained and recorded by the organization before streaming and withdrawable at any time, Art. 9(2)(d) no longer relied upon for the publicly available stream, controller identification for the OpenChurch deployment being formalized, and the sound-desk-feed rule for incidental audience speech and child speakers added. v1.3 (2026-07-19) merges the children and roles passages into the new "Organizations, audiences and minors" section following the legal review follow-up (accounts and AI-control functions 18+; audiences receive, they do not prompt or control the AI), and sets archived transcripts to a 90-day default retention with automatic deletion — shorter configurable, longer only by the organization's explicit choice — adopted for live.openchurch.cz as well (owner decision 2026-07-19). v1.2 (2026-07-19) incorporates the legal review — audience IP and connection-metadata processing stated, Google's session-resumption retention (up to 24 h) and security logging disclosed, Art. 9 bases named for live.openchurch.cz, DPF plus SCC fallback for Google transfers, recipients listed by role (Stripe and Resend account data only; Sentry added; no tax-calculation claim), and the archive retention note made explicit. v1.1 (2026-07-18) adds the DigitalOcean subprocessor (managed database), the Art. 6(1)(c) basis for retained billing records, and the EU–U.S. Data Privacy Framework note for Google's U.S. processing. v1.0 published 2026-07-12.