pullme
Privacy
Effective 28 August 2026. This page says what we collect, why, who else sees it, how long we keep it, and how to ask for yours back — in plain sentences, not a form contract.
Who’s responsible for this
pullme is a small product, and one person is accountable for what it does with your data: Ilan Wolberger, trading as pullme. Write to pullme@noproduct.com for anything on this page — a question, a correction, or a request under any of the rights below.
What we collect
An account. When you sign in, we keep the email address your sign-in gives us and the identifier that comes with it — that’s what lets a translation, a job or a payment be yours rather than anyone else’s.
Your site’s content. To translate your pages we read them, and to show you and your translator what’s changed we keep the text on both sides — the original and the translation — along with which language it’s in and who checked it.
Billing details. Stripe holds your card and handles the charge; we keep the record that you’re subscribed, to which languages, and what a translator has earned from it. We never see or store a card number ourselves.
What you send us. A message through the site, a translator application, a request for a language we don’t have yet — each of those carries whatever you typed into it, plus contact details where the form asks for them (an application asks for a name, email, phone and PayPal address so a translator can actually be paid). A translator can also give us a pen name: site owners see the pen name, and the legal name on the application is used only for payouts.
Your developer’s email, if you give us one. On your site page you can name the person who looks after your website. We use that address for one thing only: if the translations stop loading, we email them what we found and what fixes it. We never send them anything else, and it goes when your account goes.
Sentences you’re still writing. While a translator types, the workbench keeps a private copy of the words in the field so a closed tab doesn’t lose them. It’s never shown to anyone else, never published to a site, and never counted as finished work. It’s cleared the moment the sentence is accepted, and anything left unfinished is removed after 12 months with everything else below.
How the site’s being used. A few short-lived technical counters — how many requests your account, your API key or your IP address has made in the last few minutes — exist only to stop abuse of the free preview and the embed. They’re tied to your account or IP only for as long as it takes to enforce the limit, then expire and are discarded on their own.
Whether a translator is actually reading. We sample accepted sentences and have them checked independently. Accept only what you have read — that is the whole job. We keep the record of that check against the work it was checking, for as long as it takes to act on it, and it’s never shown to a site owner.
Cookies
Two kinds, and only two. The first kind is strictly necessary — signing you in, and remembering that you already answered the question below — and needs no consent of its own under the rules that govern cookies.
| Cookie | What it’s for | Kept for |
|---|---|---|
| tnp_session | Keeps you signed in. | 30 days |
| tnp_state | A short-lived check that stops a forged sign-in request. | 10 minutes |
| tnp_consent | Remembers that you already answered the referral question below, so we don't ask twice. | 1 year |
The second kind exists only if you arrive through a referral link — a translator’s, or a site owner’s. We don’t set it on presence alone: the page you land on shows a single line asking whether we can remember who sent you, right there, at that moment — never a site-wide banner. Accept, and we set the cookie below to credit whoever referred you. Decline, or just ignore it, and none of these are set — you sign in and check out exactly the same either way, we simply don’t know who sent you.
| Cookie | What it’s for | Kept for |
|---|---|---|
| tnp_ref | Credits the translator whose link brought you here. | 90 days |
| tnp_pv | Remembers which preview you looked at, so you can claim that exact translation if you sign up. | 90 days |
| tnp_by | Credits the site owner who referred you, if you arrived through their link. | 90 days |
Who else sees it
We don’t sell your data, and we don’t hand it to anyone for their own marketing. The companies below process it on our behalf, to run the product itself — each sees only what its job requires.
| Who | What they handle | Where |
|---|---|---|
| AWS (Amplify, Lambda, Cognito) | Hosts the site, signs you in, and reads your pages to build a translated copy. | United States (us-east-1) |
| Supabase | Holds the database — accounts, translations, jobs, billing records. | United States (AWS us-east-1) |
| Stripe | Handles payment and holds your billing details. We never see or store your card number. | United States, with its own global infrastructure |
| Anthropic | Reads the text on your site to draft and score a translation before a person checks it. | United States |
| Resend | Sends the emails pullme sends you — receipts, job notices, the messages a translator sends through the site. | United States |
| Sentry | Receives a technical error report when something breaks, so we can fix it. No page content, no session recording. | United States |
How long we keep it
- What’s about money — subscriptions, invoices, and what a translator has earned — is kept as long as your account exists, because it’s the record either of you may need later.
- Your translated content — stays live as long as you keep the language published, exactly like the rest of your site.
- Everything else that’s about behaviour, not money — a preview page once it’s expired, a closed integrity check, the trail of who clicked what before signing up — is removed after 12 months. We clear it out by hand, on a schedule, not by a standing background job watching the clock.
- A message you sent us — an application, a language request, a note through the site — is kept until it’s been acted on and then cleared the same way.
Your rights
You can ask to see what we hold about you, correct it, or have it deleted. Write to pullme@noproduct.com and we’ll act on it within 30 days. Deleting your account removes your personal details; it never erases money a translator has already earned from work she completed for you — that record stays, the same way a receipt would.
If you’re in the EU or UK and think we’ve got something wrong, you can also complain to your local data protection authority — we’d rather you wrote to us first, so we can actually fix it.
Children
pullme is a business tool. It isn’t directed at children, and we don’t knowingly collect anything from anyone under 16.
Changes
If this page changes in a way that matters, we’ll move the effective date at the top and, where we can, tell you directly rather than leave it to be noticed.