A setup you can trust.
Keep credentials on the service, limit application access, and preserve a recoverable approved release.
Your infrastructure, your content
EveryLocale stores sources, translations, jobs, spending, and approvals in your SQLite database. Configured generation and review providers receive the content necessary for their tasks. Their data policies apply to those requests.
The marketing website has no analytics scripts, advertising trackers, account system, or contact form. Cloudflare delivers this website; its infrastructure policies apply.
Limit access where it matters
Provider API keys remain in server configuration. Project tokens carry scoped permissions, expiry, and revocation. Applications and CI generally need import, translation, read, and export permissions; approval remains a separate responsibility.
Browser review sessions use HttpOnly cookies, origin checks, and CSRF protection. Expose the service through HTTPS. Keep administrative access private.
Protect optional account sessions
ChatGPT sign-in uses OAuth with PKCE and verified identity tokens. Saved renewable credentials are encrypted in SQLite with an independent key. Refreshes serialize across processes. Disconnect removes local tokens and attempts remote revocation.
Recover the data and the release
Create online backups through the maintenance command, verify them, and store a protected copy away from the host. Restore into a new destination with the same secrets. Test recovery rather than relying on a backup file alone.
Catalog releases retain previous revisions for rollback. Old approved translations remain live while replacements are pending; withdrawn source content is removed. Notification receivers must verify signatures and deduplicate event IDs.
Inspect the implementation
Read the deployment and recovery guidance and access contracts. Review the source for the version you deploy.