Privacy Notice
Stratlate is built to know as little about you as possible: no analytics scripts, no advertising, no tracking. It is not built to know nothing. Converting requires an account, and your conversions are saved against it — that is how your history and your monthly allowance work. This page says exactly what is kept, for how long, and what it is and is not used for.
1. The code you submit
Validation, linting and the feasibility check need no account. Their text is sent to our servers, processed in memory in a serverless function, and returned in the same response; nothing is written down and when the request ends it is gone.
A conversion is different, and this changed on 6 September 2026. When a conversion succeeds we store a record of it against the account that made it. The record holds the source code you submitted, the converted output, the warnings and errors the engine raised, the languages and the version of the engine that ran, and the time. It is stored encrypted and it is deleted automatically 12 months after it is written.
We do this for three reasons, and no others: so you have a history of your own conversions; so the monthly allowance can be counted against your account rather than your network address; and so that when a conversion comes out wrong we can look at the exact input and the exact output instead of guessing. These records are never sold, published or redistributed.
Storing your code so the service can work is not the same as using it to improve our conversion engine. That second purpose is separate and is governed only by the opt-in choice in section 2. Ticking nothing means your stored conversions stay in your account and are used for nothing else.
2. Optional corpus contribution
The converter has a checkbox labelled "Help improve Stratlate". It is off by default. If you tick it, then each time a conversion succeeds we keep an anonymous copy of the script you submitted, together with its language, size, a checksum and the time it was received. We use these copies only internally, to test and improve the conversion engine. They are never sold, published or redistributed.
Nothing that identifies you is stored with the copy: no account, no email address, no IP address, no browser identifier. Your choice is remembered in your own browser and you can untick the box at any time; unticking stops future copies but cannot recall a copy that was already anonymised, because we have no way to connect it back to you.
3. Accounts, free-tier counting and API keys
Signing in creates an account with Amazon Cognito, which holds your email address and sign-in credentials. Conversions are counted against that account. Where a conversion is made without an account, the counter uses your network (IP) address as its key instead; in that case the stored conversion record is keyed by a one-way hash of the address, never by the address itself. The counter records only the number of conversions in the current month, and nothing about the code you converted.
If you have a paid plan, your API key identifies your subscription and your usage is counted against it. If you save the key in the converter it is stored only in your browser's local storage; we do not receive it except when you make a request.
4. Payments
Paid plans are handled through Stripe. Stripe collects and processes your payment details under its own privacy policy; we never see your full card number. We receive from Stripe the information needed to run your subscription, such as its status and the customer identifier it assigned.
5. Browser storage and cookies
We do not use tracking cookies or analytics. The site uses your browser's local storage for a few conveniences only: whether you have accepted the current Terms of Use, whether the corpus-contribution box is ticked, and a saved API key if you chose to save one. Clearing your browser's site data removes all of them.
6. Deleting what we hold
Conversion records delete themselves 12 months after they are written. If you want yours removed sooner, or your account and everything under it deleted, email hello@stratlate.com and we will do it. Anonymous corpus copies made under section 2 cannot be removed on request, because nothing connects them to you — that is the point of anonymising them, and it is stated there too.
7. Server logs
Our hosting provider (Amazon Web Services) keeps standard technical logs for the serverless functions, such as request timestamps, response codes and error messages, for 14 days for troubleshooting. These logs do not contain the code you submitted.
8. Email
If you email us, we keep the correspondence for as long as needed to deal with your request and any follow-up.
9. Who is responsible, and your rights
The controller for any personal data processed through the Service is the operator of stratlate.com, established in Geneva, Switzerland. Processing is governed by the Swiss Federal Act on Data Protection (FADP). If you are in the European Economic Area or the United Kingdom, the GDPR or UK GDPR may also apply to you.
You have the right to ask what personal data we hold about you, to have it corrected or deleted, and to object to its processing. For an account that means your email address, your monthly conversion count, and your conversion records with the code in them. Contact hello@stratlate.com and we will respond. You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EEA, to your local supervisory authority.
Our servers are operated by Amazon Web Services. Depending on the region in use, data may be processed outside Switzerland; where that happens it is under safeguards recognised by Swiss law.
10. Changes
If we change what we collect, we will update this page and its effective date.