Where it runs, and what it sends
The product posture and the website posture are separate things, so they are separate sections here. The last section says what this site does not certify, because the published privacy notice explicitly declines to.
The model runs on your machine
Translation is computed by a model loaded from your own disk, through BetterRuntime over llama.cpp, in a supervised child process. No cloud translation provider appears anywhere in the application source.
The model loads from your disk into a process on your machine. Chats and the index sit in a local database under your profile. The only outbound request is your model download.
The one outbound request
The product's own code derived feature matrix records exactly one outbound HTTP request path in shipped code. It is reached only from the download command and carries no identifying header.
Where it goes: every artifact the built-in catalogue resolves is hosted on Google's user content domain, and you may instead paste a Hugging Face page or a direct model file link.
Integrity is checked in three steps, and the third has a limit worth stating. A download is checked for byte length, then for the file's magic bytes, then against a SHA-256 where the manifest carries one. The manifest carries one for two of the sixteen artifacts, the two CUDA redistributables. For the rest the manifest says outright that no published checksum exists, so the contents are unverified. Downloads stream to a partial file, resume where they left off, and are promoted only after the checks pass. There is no signature check and no certificate pinning.
Nothing is reported anywhere
No telemetry, no analytics, no crash reporting and no update check. That is recorded as a negative finding over the whole application source, the tests and every project file, and extending the same check to the native bootstrap finds no networking there either.
Two precisions the claim needs to survive scrutiny. The bootstrap does write a local file, rolled at one megabyte, which is a log on your disk and not a report: %LOCALAPPDATA%\SZEINER\BetterTranslator\logs\bootstrap.log
And no update check also means there is no automatic patch delivery. A fresh machine needs internet once, for the runtime and the models. After that it runs offline.
The agent endpoint
The agent endpoint is off by default, binds loopback, and refuses to bind a public address without a token. Read how the agent surface works
Two limits belong here rather than in the small print. A deliberately configured non loopback bind is plain HTTP, because the host has no encrypted branch. And a file job from an agent is not restricted to any particular folder. Separately, the in process inference endpoint is pinned to loopback by an explicit constant, on the stated ground that the runtime is local by design and must not be reachable from anywhere else on the network.
What is stored, and where
Everything the application keeps sits under your profile, in a database plus a models folder and a cache folder: %LOCALAPPDATA%\BetterTranslator
The database runs in write ahead logging mode, because the window and an agent can both be writing, so its two companion files sit beside it as derived state. It opens with foreign keys on and an ordered migration list. The data folder is redirectable by a one line pointer file written from Settings, and deleting that file reverts it.
Signing and SmartScreen
Release executables are unsigned unless a certificate is supplied at build time. An unsigned executable downloaded from the internet raises the Windows protected your PC dialog until the artifact is signed with a certificate that has built reputation.
This is published here rather than left for a first user to discover. Signing runs after the payload is appended, never before, and the packer refuses an input that is already signed.
What this website does
Exactly five measures, which are the ones the serving code implements. Nothing beyond them is claimed.
- A Content Security Policy.
- A no sniff content type header.
- A strict origin when cross origin referrer policy.
- Cookies set with SameSite Lax, and Secure over HTTPS.
- Self hosted fonts, map data and the two JavaScript libraries.
Two precisions the list must not drop. The policy allows the Google tag and analytics hosts for images and connections, so it is not first party only outside scripts. And the self hosting statement covers fonts, map data and those two libraries: the Google tag still loads, after consent.
The build refuses to start if the inline consent snippet stops matching its recorded hash, so the policy and the code it permits cannot drift apart.
Where to report a vulnerability
This site publishes a security contact file at /.well-known/security.txt, in the format RFC 9116 defines. The product repository carries no security policy file. One address receives vulnerability reports, and it is the same address the rest of this site publishes.
Send a report to: [email protected]
This section is incomplete. The details below have to be supplied before publication.
- Whether coordinated disclosure is offered.
What this site does not certify
The published privacy notice declines to confirm the application's local only behaviour as a processing fact, because the application source is not part of the repository that serves this site and no document there describes what it sends. Until the controller confirms it, that statement is a product description and not a commitment made in the notice.
Read the privacy notice and the terms of use