SubMorph Logo SubMorph Back to App

Privacy Policy

App: SubMorph: Subtitle Translator Android Package: com.submorph.translator Developer: MorphWorks Support: morphworks@proton.me Web: https://submorph.online
Effective Date: September 11, 2026

This Privacy Policy outlines how SubMorph ("we", "us", or "our"), developed and published by MorphWorks, collects, uses, protects, and discloses information when you download, install, or use our mobile application on Android devices (Google Play Package ID: com.submorph.translator) and our online web localization suite at https://submorph.online (collectively, the "Services").

We are dedicated to building privacy-respecting software. SubMorph operates primarily as a client-side utility. Except for the optional 72-hour ephemeral cloud archive provided exclusively to signed-in users, we do not operate persistent media storage servers, and we never commercialize or harvest your personal content.

1. Scope & Developer Identity

This Privacy Policy applies universally to:

The designated Data Controller for all operations governed by this policy is MorphWorks (morphworks@proton.me).

2. Client-Side Subtitle Processing, Guest Privacy & Optional 3-Day Ephemeral Cloud Archive

100% In-Memory Processing by Default: When using SubMorph as a guest (without signing in), all SRT subtitle parsing, timestamp calculations, pacing synchronization, and formatting occur 100% locally inside your device's RAM. SubMorph does not upload, log, or retain subtitle files for guest users on any central storage server.

SubMorph operates with two transparent privacy tiers based on user choice:

3. Third-Party AI Translation Engines

SubMorph connects directly to leading artificial intelligence models (such as Google Gemini, Groq, OpenRouter, DeepSeek, or OpenAI) to translate subtitle dialogues.

4. User Accounts, Cloud Sync & Subprocessors (Optional)

Using an account in SubMorph is completely optional. You can translate subtitles, configure local keys, and export SRT files without registering or signing in.

If you choose to sign in using Google Sign-In (facilitated via Google Play Services and Google Firebase), we collect only the minimal data required to synchronize your settings and provide the optional 3-day history across your phone and PC:

Data Category Specific Data Elements Purpose Retention & Storage
User Identity Google Account ID, Display Name, Email Address, Profile Picture URL. To authenticate your account session and display your avatar. Managed securely by Google Firebase Authentication. Stored until account deletion.
User Settings Encrypted personal AI API keys, subtitle pacing preferences, target language selection. Cross-device synchronization (allowing you to use your saved keys on both web and Android app). Stored in a private, authenticated Google Cloud Firestore record protected by strict security rules accessible only by your user UID. All data is encrypted at rest using AES-256 and transmitted via TLS 1.3.
Subtitle History (Optional) Translated SRT subtitle text, original filename, source/target language codes, creation timestamp. Cross-device translation archive (allows re-downloading translated subtitles on your phone or PC within 3 days). Stored in an encrypted, private Cloudflare R2 object storage bucket and referenced in your authenticated Firestore document. Encrypted at rest (AES-256) and in transit (TLS 1.3). Automatically and permanently purged after 72 hours (3 days). Can be wiped manually anytime via the in-app Clear History button or the Account Deletion Portal.

Cloud Security Architecture & Subprocessors: SubMorph utilizes industry-leading cloud infrastructure providers adhering to ISO 27001, SOC 2, and GDPR standards:

5. Mobile Advertising & Consent Management (Google AdMob & UMP SDK)

To keep SubMorph 100% free for global creators, the Android mobile application integrates Google AdMob (provided by Google LLC) to serve mobile advertisements (banner ads, interstitial ads upon translation completion, and app open ads).

In accordance with Google Play's Developer Policy on Advertising and regional data protection directives:

6. Android Device Permissions Declared in App Manifest

The SubMorph Android application (com.submorph.translator) declares only the following permissions, each strictly tied to user-facing features:

Permission Functional Rationale
android.permission.INTERNET Required to communicate directly with AI translation APIs, authenticate Google Sign-In, sync preferences, and load AdMob advertisements.
android.permission.ACCESS_NETWORK_STATE Allows the app to verify active Wi-Fi or cellular connectivity before initiating multi-batch translations.
android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_DATA_SYNC
Ensures uninterrupted translation when users minimize the app or switch windows during long movie subtitle translations (Service: ForegroundTranslationService).
android.permission.POST_NOTIFICATIONS Displays a non-intrusive progress notification bar while translating long files in the background and alerts you when the file is ready for download.
android.permission.WAKE_LOCK Prevents phone CPU sleep mode during active batch translation requests.
READ / WRITE_EXTERNAL_STORAGE (API ≤ 32) Allows reading user-selected SRT files and saving translated outputs on older Android versions (modern Android versions use the Storage Access Framework).

7. International Compliance: European Economic Area & UK (GDPR)

If you reside in the European Economic Area (EEA) or the United Kingdom, your data is protected under the General Data Protection Regulation (GDPR) and UK Data Protection Act 2018. SubMorph processes personal data under the following lawful legal bases:

Under GDPR, you hold the following enforceable rights:

  1. Right of Access & Portability: You may request an export of your cloud-stored preferences and account data.
  2. Right to Rectification: You may correct or update your saved API keys and settings at any time in the Settings menu.
  3. Right to Erasure ("Right to be Forgotten"): You may permanently delete your account and all associated cloud documents (see Section 10).
  4. Right to Restrict or Object to Processing: You may sign out or revoke Google Sign-In permissions.
  5. Right to Lodge a Complaint: You have the right to file a complaint with your national Data Protection Authority (DPA).

Statutory Response Timeline: In accordance with Article 12(3) of the GDPR, we will respond to and fulfill verified requests regarding access, rectification, portability, or restriction within thirty (30) calendar days of receipt. Account and data deletion requests are handled on an expedited schedule within 48 hours.

International Data Transfers & Standard Contractual Clauses (SCCs): SubMorph utilizes cloud infrastructure provided by Google LLC (Firebase / Google Cloud Platform) and Cloudflare, Inc. (R2 Storage). Where personal data or subtitle archives are transferred outside the European Economic Area (EEA) or the United Kingdom (such as to secure infrastructure located in the United States), such transfers are strictly governed by European Commission-approved Standard Contractual Clauses (SCCs) and participating commitments under the EU-U.S. Data Privacy Framework (DPF), guaranteeing an equivalent standard of data protection.

8. Notice to California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

"Do Not Sell or Share My Personal Information": SubMorph DOES NOT SELL your personal information, subtitle files, or translation data for monetary or other commercial consideration, nor do we share it for cross-context behavioral advertising.

9. Google Play Store Data Safety Declaration (1-to-1 Mapping)

To assist users and Google Play reviewers in auditing our Data Safety section, the table below reflects our exact Play Console declarations:

Data Type Collected? Shared? Purpose Ephemeral / Encrypted?
Personal Info (Name, Email) Yes (Optional) No Account Management & Cloud Settings Sync. Encrypted in transit (TLS 1.3) and at rest (Firestore AES-256).
Device or Other IDs (Advertising ID) Yes (by Google AdMob) Yes (with Google AdMob) Advertising, Analytics & Fraud Prevention. Encrypted in transit. User can reset or delete GAID anytime. Controlled via Google UMP CMP.
App Info & Performance (Crash Logs & Diagnostics) Yes No Diagnostics, Crash Analysis & App Reliability. Encrypted in transit. Anonymous crash logs and ANR metrics collected via Google Play Console Android Vitals and Google AdMob diagnostics. No separate third-party analytics trackers.
Files & Documents (SRT Subtitles) Yes (Optional) NO App Functionality (Optional 3-Day Ephemeral Cross-Device History for signed-in users only). 0% collected for guest users. Encrypted in transit (TLS 1.3) and at rest (Cloudflare R2 AES-256). Strictly auto-deleted after 72 hours (3 days), or immediately via in-app Clear History / Account Deletion Portal. Subtitle lines are transmitted ephemerally to user-selected AI APIs solely for translation.

Ephemeral AI Transmission Disclosure: Subtitle texts are processed in memory and transmitted ephemerally via secure HTTPS (TLS 1.3) directly from your device to user-selected AI APIs (Google Gemini, Groq, OpenRouter, DeepSeek, or OpenAI) solely to fulfill the requested real-time translation. We do not store, log, train foundation models on, or share this data with any other parties. SubMorph operates zero central storage or proxy servers for real-time translation payloads (guest files remain 100% local, and optional cross-device archives for signed-in users are strictly purged after 72 hours).

10. Dedicated Account & Data Deletion Portal

In full compliance with Google Play's mandatory Data Deletion Policy and global privacy standards, SubMorph provides an accessible web resource and in-app self-service mechanisms for users to request and execute permanent account and data deletion:

Dedicated Web Deletion Portal: Whether you have the app installed or uninstalled, you can submit an instant self-service deletion or 48-hour manual request anytime at:
https://submorph.online/delete-account

A. Instant In-App / Web Self-Service Deletion

  1. Open the SubMorph app or navigate to the web tool at https://submorph.online.
  2. Open the Settings panel (gear icon).
  3. Click Sign Out & Wipe Cloud Data (or Clear All Local Data).
  4. Your local cache, API keys, preferences, and session tokens are immediately wiped from device memory. If signed in, our synchronization engine automatically calls the Firestore deletion API to purge your user-isolated document. Alternatively, visit our Account Deletion Page while logged in to delete your Firebase Auth record in one click.

B. Direct Deletion Request via Email (Web & Account Deletion)

If you have uninstalled the app or prefer to request full deletion through developer support:

11. Target Audience & Age Limitation (Exclusively 18+)

SubMorph is designed as an advanced, professional AI subtitle localization and translation suite for film creators, content producers, and adult general audiences. Our services are strictly directed to, marketed for, and intended for use by individuals aged 18 and older.

We do not knowingly target, solicit, or collect personal information from individuals under 18 years of age. If a parent, legal guardian, or supervisory authority becomes aware that a minor under 18 has submitted personal information or created an account, please contact our Data Controller at morphworks@proton.me. Upon verification, we will promptly purge all associated records from our systems within 48 hours.

12. Changes to This Privacy Policy

We may update, revise, or amend this Privacy Policy periodically to reflect enhancements in SubMorph capabilities, shifts in operational workflows, or emerging international legal requirements. When updates are published, we will revise the "Effective Date" at the top of this document.

For material modifications that significantly affect your data privacy rights, we will provide prominent notification (such as an in-app notice or website banner) prior to the changes taking effect. We encourage you to review this policy periodically to stay informed about our data protection standards. Your continued use of SubMorph following the posting of an updated Privacy Policy constitutes your acknowledgment and acceptance of the revised terms.

13. Governing Law & Jurisdiction

This Privacy Policy and any disputes arising out of or in connection with SubMorph shall be governed by and construed in accordance with applicable general principles of international consumer data protection, electronic commerce standards, and fair trade practices, without prejudice to mandatory statutory consumer protections and data subject rights granted under the General Data Protection Regulation (GDPR) in the European Economic Area and the United Kingdom, or the California Consumer Privacy Act (CCPA/CPRA) in the United States.

14. Contact Information & Data Controller

If you have any questions, inquiries, regulatory requests, complaints, or feedback regarding this Privacy Policy or SubMorph's security practices, please contact our developer team: