Legal

Security Policy

Effective October 4, 2026. Version 2.

LangoSync handles passports, birth certificates, and other sensitive documents, so we keep as little as we need, protect it while we have it, and delete it on schedule. This page describes the safeguards we use. No system is completely secure, but these measures greatly reduce risk.

Encryption

Every connection to LangoSync uses HTTPS with modern TLS encryption, including uploads, the review editor, and downloads. Uploaded documents and finished translations are stored encrypted at rest with our cloud storage provider.

Sign-in protection

There are no passwords to steal. You sign in with a one-time 6-digit code sent to your email. Codes expire after 10 minutes, work only once, and are stored only in scrambled form. We limit sign-in attempts to block guessing, and you can sign out of all devices from your account settings.

Payment security

Payments are handled by Stripe, a payment processor certified to the highest level of the PCI Data Security Standard. Card details go directly to Stripe and never pass through or stay on LangoSync's servers.

Access to your documents

  • Self-Certify documents are visible only to you.
  • Certified and Notarized documents are visible only to you, the translator assigned to your order, and the staff who certify, notarize, and mail it.
  • Translators and staff must accept a confidentiality agreement before they can open any document, and every time a document is opened is logged.
  • Administrators cannot open document contents for support unless you give permission.
  • Admin and translator accounts require a second sign-in factor.
  • Download links are private to your account and expire.

Automatic deletion

We delete documents on a fixed schedule: Self-Certify files 24 hours after upload and Certified and Notarized files 30 days after delivery, or sooner when you click Delete now. Order and payment records are kept without the documents, as described in our Privacy Policy. Deletion covers every copy we create, including page images, editor copies, temporary files, and the translated text in our database.

Hosting and service providers

The app runs on Railway, files are stored with an encrypted cloud storage provider, and payments run through Stripe. Draft translations are created by our AI provider, which does not use your documents to train its models and deletes them within 30 days, or sooner under a zero data retention arrangement. We choose providers with strong security programs and share only what each one needs.

Application safeguards

We check every uploaded file type and size, protect forms against cross-site request forgery, limit request rates to prevent abuse, use secure and HTTP-only session cookies, keep software dependencies updated, and monitor errors so problems are fixed quickly. We scan every upload for malware, remove hidden metadata from the files we deliver, and never record document content in our logs.

If something goes wrong

We have a written plan for security incidents. If a breach exposes your personal information, we will contain it, investigate, and notify you and the authorities as required by law, including the Virginia Attorney General when Virginia law applies.

Reporting a security concern

If you find a security problem, email support@langosync.com with the subject "Security." Please give us reasonable time to fix it before sharing it publicly, and do not access other people's data while testing.

Contact

Dala Holdings Inc., 30 N Gould St, Ste 50801, Sheridan, WY 82801. Email: support@langosync.com. Phone: (307) 442-8001.