PanelLingo Privacy Policy

Last updated: 2026-09-13.

Who we are

PanelLingo is operated by PawChef LLC, a Wyoming limited liability company. This policy covers the PanelLingo Chrome extension and getpanelpal.com. Contact support@getpanelpal.com for privacy, account or deletion requests.

PanelLingo translates comic images you choose to read. It does not provide a third-party comic catalog, bypass publishers' access controls or grant rights to third-party content. Our website includes original demonstration artwork and example translation results.

Reading pages and selected areas

The extension checks page structure, image/canvas characteristics and reader context locally to make translation controls available. It accesses page and image addresses to retrieve reading images and display results. Area translation temporarily captures the visible tab to process the region you select. Automatic translation is off by default; if you enable it, eligible content is processed using your chosen mode. We do not use this access to build an unrelated browsing-history profile or for advertising.

Free local translation

Free text detection, OCR and translation run locally using the extension's image-processing models and supported Chrome translation capabilities. Comic images and recognized text are not uploaded to PanelLingo for Free translation.

First use or a new language pair may require network downloads. Image-processing models and dictionaries are downloaded from Hugging Face and its delivery infrastructure; Chrome manages its own translation-language resources. Loading original page images also contacts their source servers. Those providers receive the network information needed to deliver the requested resources, such as IP address and request metadata. Local processing does not mean that no network requests occur.

Advanced cloud translation and recovery

Advanced uses your signed-in account and points. The extension sends images or text-region crops prepared for translation, source and target languages, region/layout information, applicable glossary entries, image fingerprints, installation/account identifiers and task information to our backend. Depending on the translation operation, image context may also be included. Our backend uses Google Gemini and, where applicable, Google Cloud Vision to process the requested content.

We store translation results, which can include recognized/translated text, layout information and returned image data, together with task status, usage/cost records, delivery confirmations and point transactions. This supports delivery, recovery of already-paid results, duplicate-charge prevention and resolution of failures. These records are not a public comic library.

Saved Advanced translations also keep original image data, the translation request, source-site information, language choices and account/installation-scoped recovery information on your device. They are separate from the disposable translation cache. Removing a saved item locally does not itself delete related server-side account, delivery or financial records.

Website batch translation

The website can translate local files without an installed extension. Selecting images and previewing them does not upload image content or charge points. A quote sends resized dimensions, image hashes, filenames and target language to Supabase. Starting the quoted batch sends resized images through Supabase to Google Gemini for recognition and translation. Uploaded image binaries are not persisted in the website batch database. Translation text, layout coordinates and usage information are retained for delivery and recovery.

The browser downloads image-processing models from this website, checks their integrity and caches them locally. It uses local text/bubble detection and image processing to prepare downloadable output. These downloads do not upload your selected images.

Account, purchases and payment reviews

If you sign in, we process your email, account identifier and authentication/session credentials. Google sign-in, when available, shares your basic identity information, including email and potentially name/profile picture, with our authentication provider, Supabase. We do not request Gmail, Drive or contacts permissions. Email-code sign-in processes the email and verification information needed to authenticate you. If you choose password sign-in, your email and password are sent over HTTPS through our authentication endpoint to Supabase for verification. We do not store your plaintext password in the extension or include it in diagnostics; the extension stores the resulting session credentials to keep you signed in.

If you purchase or use points, we process order and payment-provider identifiers, pack/amount/currency information, point balances and activity, account ownership, and the policy acknowledgment recorded before checkout, including its version and time. Refund/dispute records and point allocations are used to verify payment outcomes and make adjustments to the original purchase. Stripe handles payment entry and payment-card details; PanelLingo does not store your full card number or card security code.

Browser and website storage

  • Extension preferences use Chrome storage.sync when available, so Chrome may synchronize those preferences under your browser settings. A local-storage fallback is used when needed.
  • Your Advanced cloud-processing acknowledgment is stored locally on this device and is not synchronized as a preference. Extension account sessions and pending sign-in information are stored in extension-local storage. Model caches, translation caches, glossary entries and saved-recovery data use browser storage appropriate to those features, including IndexedDB.
  • The website stores a random installation identifier and pending checkout information in localStorage. Pending checkout information links an attempt to its account, pack and policy context to help prevent duplicate attempts.
  • Website session credentials use sessionStorage for the current tab. Signing out clears the active website session; it does not delete every stored preference or server record.
  • The website batch queue stores originals, resized processing copies, progress and available translated output in IndexedDB, associated with your account. Guest selections may transfer to the account you sign into. These copies survive reloads. Signing out hides that account's queue; Clear this queue while signed in, or clearing this site's browser data, removes the local copies. This storage is not an encrypted personal vault; people controlling the same device/browser profile may have access to it.

Diagnostics and feedback

Local diagnostic events are designed to exclude reading URLs, page images, recognized/translated text, passwords and API keys. They are not automatically uploaded. You can clear or export diagnostics in Settings under Help & diagnostics. Local events are bounded to 200 events and up to seven days; a report awaiting confirmation can be kept for 24 hours to support retrying the same submission. If you choose to send a diagnostic report while signed in, its sanitized events and extension version are sent to support and associated with your account. Diagnostic collection is bounded and may omit events during bursts of errors or abrupt shutdowns.

Feedback from the extension or website can include your description, optional contact email and screenshot, submission source, and account identity if signed in. A salted identifier derived from your account or network address is used to limit abusive submissions. Draft feedback stays in memory until you submit it. Submitted feedback is stored privately for authorized administrators to review. Feedback is a one-way submission with a confirmation, not a reply inbox or public tracker. A screenshot may contain information you choose to include; remove unrelated personal information before submitting it.

Service providers and data use

We use Resend to deliver authentication emails. Support email is routed through Cloudflare to our support mailbox hosted by Google. Cloudflare also sends minimal support-mail metadata to our backend for authorized staff to review in the administration dashboard. This metadata includes sender, subject, a message identifier and timestamps; the dashboard does not retrieve email bodies or attachments. Support correspondence may contain personal information you choose to send; avoid including unrelated private information, passwords or full payment-card details.

Supabase provides authentication, backend services and storage. Google AI/Cloud services process Advanced translation requests; Google also supplies optional sign-in and Chrome language capabilities. Stripe handles payments. Cloudflare delivers and protects our website. Hugging Face and its delivery infrastructure supply local model resources. Network/service providers process request information needed to operate, protect and troubleshoot these features. Their own applicable terms and privacy policies govern their handling of data.

We do not sell personal data or use extension data for advertising. Our use and transfer of information received through the extension follow the Chrome Web Store User Data Policy, including its Limited Use requirements. We use it for the disclosed translation, recovery, account, billing, security and support features, and share it only as necessary to provide those features or comply with legal obligations. We do not use it to determine creditworthiness or for lending purposes. Human access is limited to user-authorized support and permitted security or legal purposes, with access restricted to authorized personnel. The website does not add third-party advertising trackers or analytics scripts.

Retention

Routine operational events are scheduled for deletion after 30 days. Error events, submitted diagnostic reports, and submitted feedback/screenshots are scheduled for deletion after 90 days. Scheduled cleanup may run in batches rather than deleting each record at an exact instant.

For operational reporting, minimal daily activity records (account identifier and date, without translation content) may be retained for up to 400 days to count distinct active accounts over time. These records are removed when the account is deleted, including by the next scheduled collection after a soft deletion. Operational notification metadata, including support-email sender and subject, is scheduled for deletion after 90 days. These schedules apply to our active administration records; they do not promise immediate deletion from mailboxes, backups or independent email-service copies.

Completed Advanced translation content is scheduled for deletion from our active result and delivery stores after 30 days. Content needed for an unresolved delivery issue is retained while it is being resolved, and for 30 days after resolution. Cleanup runs in batches; recovery access to finalized results expires at the applicable deadline even if the cleanup batch has not yet run. This removes recognized/translated content and result images, not the separate financial receipts or point ledger. Account, usage/cost, purchase, point-ledger, consent, payment-review and administrator-audit records are maintained separately for service operation, accounting and dispute resolution. Contact us to request deletion; we will review what can be deleted and explain any records that need to be retained for legitimate operational or legal reasons. This policy does not promise that backups or independent service-provider copies are erased immediately.

Local saved originals remain until removed through Saved translations or cleared with the relevant extension/browser data. Ordinary Clear cache does not remove the separate saved-original recovery store. Browser-managed model storage and synchronized preferences also depend on your browser controls.

Website batch translation content expires 30 days after a task begins and is deleted by an hourly cleanup. Point transactions and non-content task receipts remain separate. Clearing a website queue removes local copies, not server or financial records. Contact support for deletion or a delivery problem before results expire. This does not promise immediate deletion from provider systems or backups.

Your choices and security

You can use Free without signing in, switch translation modes, turn automatic translation off, clear ordinary caches, remove saved local translations, and clear/export diagnostics. Signing out ends the active local account session; it is not an account-deletion request. Contact support@getpanelpal.com for access, correction or deletion requests, and do not send passwords, verification codes, full card details or unrelated private images.

Managed service API keys remain server-side. Account and Advanced requests to our managed services use HTTPS. Access controls restrict private backend records to the appropriate service/account functions and authorized administrators. We do not claim that storing data in browser storage makes it encrypted by PanelLingo or inaccessible to someone controlling your device.

Changes

We will publish policy updates with an effective date and keep the store disclosures consistent with our actual practices. Material changes to data handling will be disclosed as appropriate before they take effect.

Contact support