Free (Translator & Write): Trains on uploaded content to improve its neural networks · No BAA terms published · Retention duration not stated
Pro (Translator, Write & API): Texts not used to improve services · Deleted after contractual performance · No BAA terms published
DeepL’s security page states texts are "never stored or used for model training without your consent," which reads differently from the privacy policy’s free-service clause.
| Free - Translator & Write | Pro - Translator, Write & API | |
|---|---|---|
| HIPAA BAA | Not documentedDeepL announced HIPAA compliance by press release, but no public document states whether a BAA is offered, on which plans, or with what exclusions. HIPAA and BAA do not appear on DeepL's data security page | Not documentedHIPAA compliance announced by press release only; no BAA offer, plan scope or feature exclusions are published |
| Trains on your data | Yes"We process the content you upload and their translations or improvements for a limited period of time to train and improve our neural networks and algorithms" | Nofor DeepL Translator Pro, DeepL API Pro and DeepL Write Pro, "your texts will not be used to improve the quality of our services" |
| Survives deletion | Texts are retained temporarily for training purposes; the privacy policy does not state a duration | "After complete performance of the contractually agreed services all submitted texts or documents and their translations or improvements will be deleted." No specific deletion timing is stated |
| Deployer / admin log access | Not stated for the free service | Not stated in the documents reviewed in this pass |
| Third-party attestation | SOC 2 Type II stated on the data security page - "Certified for security, availability, and confidentiality." ISO 27001 and C5 Type 2 appear only in DeepL press releases and blog posts, not on the security page. Scope by plan not stated | SOC 2 Type II stated on the data security page. ISO 27001 and C5 Type 2 announced in press materials but absent from the security page |
DeepL Pro, where texts are contractually excluded from training and deleted after service performance. Also DeepL's own security-page claim that "Texts are never stored or used for model training without your consent," which conflicts with the privacy policy's free-service training clause
The free service, whose content is used for training. Also the security page's blanket "never stored or used for model training without your consent," which reads as covering every plan but conflicts with the privacy policy's free-tier clause
Vendor terms change without notice. This page reflects what DeepL published as of September 2, 2026. Re-verified quarterly.
If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.
See how AVRA works →Want all 13 tools in one file?
Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.