Quick security facts (2026 scan)
| Chrome extension | DeepL Translate |
|---|---|
| Permission profile | Broader than typical |
| All-sites access | No |
| Permissions beyond typical | declarativeNetRequest, identity, webRequest, cookies, nativeMessaging |
| Privacy policy score | 7.7/10 (1 red flag) |
| Scan date / version | 2026-07-31 / 1.96.1 |
What permissions does DeepL Translate request?
The following permissions were declared in Chrome extension version 1.96.1 as of the 2026-07-31 scan. If you are asking is DeepL Translate for Chrome safe, this table is the primary evidence: it shows what the extension is allowed to do when installed.
| Permission | Risk | What it can do |
|---|---|---|
activeTab | low | Can act on the current tab only when you click the extension. |
storage | low | Can store data locally in the browser. |
contextMenus | low | Can add items to the right-click context menu. |
tabs | medium | Can see the URLs, titles, and open/close state of your browser tabs. |
scripting | medium | Can inject and run scripts on pages it has access to. |
declarativeNetRequest | medium | Can block or modify network requests using declared rules. |
identity | medium | Can get an OAuth token tied to your signed-in account. |
tts | low | Can use the browser's text-to-speech to read text aloud. |
alarms | low | Can schedule code to run at set times. |
webRequest | high | Can observe network requests your browser makes. |
cookies | high | Can read and modify cookies, which often include login sessions. |
sidePanel | low | Can display content in the browser side panel. |
nativeMessaging | high | Can exchange messages with programs installed on your computer. |
Permissions beyond the typical translation set
Compared with the permissions a typical translation extension needs, DeepL Translate also requests the following as of the 2026-07-31 scan. Extra permissions are not inherently a problem — each can support legitimate features. We list what each one can enable so you can weigh it for yourself.
declarativeNetRequest(medium) — can support blocking or rewriting network requests via declared rules, often used to reach an API or adjust headers.identity(medium) — can support obtaining a sign-in token tied to your account, typically to log you in.webRequest(high) — can support observing or modifying the network requests your browser makes, which can support rewriting or routing API traffic.cookies(high) — can support reading or setting site cookies, which can let it act inside web apps where you are already signed in.nativeMessaging(high) — can support exchanging messages with a companion app installed on your computer.
As of the 2026-07-31 scan, the extension requests permissions beyond the typical set for a translation tool. These include declarativeNetRequest and webRequest, which can support blocking, observing, or modifying network requests, often used to reach an API or adjust headers. The identity and cookies permissions can support obtaining a sign-in token and acting inside web apps where you are already signed in. Additionally, nativeMessaging can support exchanging messages with a companion app installed on your computer.
Where can DeepL Translate data flow?
Domains below are extracted by static analysis and represent a lower bound — an extension may contact additional endpoints at runtime that this method does not capture.
aka.msthird-partyapache.orgthird-partyauth0.comthird-partybit.lythird-partycloudflare-dns.comthird-partydeepl.comfirst-partydeepl.devthird-partydiscord.comthird-partyeuropa.euthird-partyexample.comthird-partyfacebook.comthird-partyfeatureassets.orgthird-partyfigma.comthird-partygithub.comthird-partygmail.comthird-partygoogle.comthird-partygoogleapis.comthird-partyjsdelivr.netthird-partylinguee.comthird-partylinkedin.comthird-partymathiasbynens.bethird-partymicrosoft.comthird-partymozilla.orgthird-partymths.bethird-partyoffice.comthird-partyprodregistryv2.orgthird-partyqualtrics.comthird-partyradix-ui.comthird-partyreactjs.orgthird-partyreddit.comthird-partysentry-cdn.comthird-partysentry.iothird-partyspotlightjs.comthird-partystatsig.comthird-partystatsigapi.netthird-partystatsigcdn.comthird-partytelegram.orgthird-partytwitter.comthird-partyw3.orgthird-partywhatsapp.comthird-partyyoutube.comthird-party
As of the 2026-07-31 scan, data can flow to the first-party domain deepl.com. The extension also references numerous third-party domains, including auth0.com, google.com, sentry.io, and statsig.com. This external-domain list is a static-analysis lower bound, meaning it may miss dynamically loaded endpoints.
Policy claims vs observed: the vendor publishes a privacy policy; the domains above reflect what static analysis observed as of the 2026-07-31 scan, which may differ from the policy's stated data handling.
Privacy policy findings
Policy score: 7.7/10 (as of the 2026-07-31 scan, reviewed against 11 fixed criteria — a measure of policy quality, not a safety verdict).
| Criterion | Score | Flag |
|---|---|---|
| collects only what the feature needs | 1/2 | — |
| sharing with third parties disclosed and limited | 2/2 | — |
| does not sell user data | 2/2 | — |
| retention period specified | 1/2 | — |
| user can request deletion | 2/2 | — |
| anonymization/pseudonymization practices stated | 1/2 | — |
| readable, specific, not boilerplate | 2/2 | — |
| GDPR/CCPA handling stated | 2/2 | — |
| notifies users of policy changes | 1/2 | — |
| children's data addressed | 1/2 | — |
| states whether user content trains AI models | 2/2 | red flag |
- May train AI models on user content
As of the 2026-07-31 scan, the extension's privacy policy scores 7.7 out of 10 based on how well it addresses 11 fixed criteria, which is not a safety verdict. The policy also contains a red flag indicating it may train AI models on user content.
Editor's analysis: is DeepL Translate safe?
DeepL SE is one of the more security-transparent machine translation providers. As of the 2026-07-31 scan, here is what the public record shows about DeepL's security posture.
Security certifications: DeepL has held ISO 27001 certification since 2021, covering its translation and writing services. ISO 27001 is the international standard for information security management systems. DeepL also publishes a SOC 2 Type II report covering security, availability, and confidentiality — this is the gold standard for cloud service security audits and confirms that controls are operating effectively over time, not just at a single point.
GDPR and data residency: DeepL SE is a German company. All user data is processed under GDPR and stored within the EU. Their privacy policy explicitly references GDPR and the German Federal Data Protection Act (BDSG). This matters because GDPR imposes the strictest data-protection requirements globally.
Data handling — free vs paid: This is the most important distinction most users miss. Free-tier users: text you translate may be used to train DeepL's neural networks (confirmed in their privacy policy). DeepL Pro, API Pro, and Write Pro users: text is not stored and not used for training. If you translate sensitive or confidential content, the paid tier is the appropriate choice.
Infrastructure: DeepL processes translations on infrastructure hosted by AWS and Microsoft Azure, both under formal data processing agreements. Data in transit is encrypted via TLS; data at rest uses AES-256 encryption.
For business use: DeepL offers additional security controls on business and enterprise plans, including SOC 2 Type II certification, signed data processing agreements (DPA), optional on-premise deployment for maximum data control, and SSO support. These are documented on DeepL's official security page.
Bottom line: DeepL's security practices are above average for the machine translation category. The ISO 27001 + SOC 2 Type II combination is rare among translation tools. The main trade-off is free-tier AI training — use Pro for sensitive content. The browser extension's broader permissions are consistent with what translation tools need to function.
Is DeepL safe? For translation of non-sensitive text, DeepL's public security posture (ISO 27001, SOC 2 Type II, EU/GDPR data residency) is stronger than most free browser translators. The free tier may use translations to improve models; paid Pro tiers do not use your text for training according to DeepL's policy. That free-vs-paid split is the most important safety control most users miss.
Is DeepL safe to use for confidential documents? Prefer DeepL Pro (or business plans with DPA) and avoid pasting regulated or secret material into the free web/extension path. The Chrome extension requests broader permissions than a minimal translator (network request APIs, cookies, nativeMessaging, identity) to support in-page translation and account features — legitimate for the product category, still worth reviewing if you lock down enterprise browsers.
Evaluate the machine translation company DeepL on security and controls: independent certifications exist; our privacy-policy rubric scored 7.7/10 as of 2026-07-31 with a red flag for AI training on free-tier content. Use this page alongside our extension comparison table when you need a documented permission snapshot rather than marketing copy.
FAQ: is DeepL Translate safe to use?
Is DeepL Translate safe?
DeepL is ISO 27001 certified and GDPR-compliant. Free-tier translations may train AI models; paid plans do not. The browser extension requests broader permissions than typical for translation tools, but they serve legitimate translation functionality.
Is DeepL Translate safe to use?
DeepL is ISO 27001 certified and GDPR-compliant. Free-tier translations may train AI models; paid plans do not. The browser extension requests broader permissions than typical for translation tools, but they serve legitimate translation functionality.
Is DeepL Translate for Chrome safe?
The DeepL Translate Chrome extension was scanned on 2026-07-31 (version 1.96.1). Requests broader permissions than typical for a translation tool. It does not request all-sites host access. Privacy policy quality score: 7.7/10 across 11 criteria.
Is DeepL Translate secure for business use?
Security certifications: DeepL has held ISO 27001 certification since 2021, covering its translation and writing services. ISO 27001 is the international standard for information security management systems. DeepL also publishes a SOC 2 Type II report covering security, availability, and confidentiality — this is the gold standard for cloud service security audits and confirms that controls are operating effectively over time, not just at a single point.
Does DeepL Translate use your data for AI training?
The privacy policy states: "We process the content you upload and their translations or improvements for a limited period of time to train and improve our neural networks and algorithms."
What permissions does the DeepL Translate Chrome extension request?
DeepL Translate version 1.96.1 declares: activeTab, storage, contextMenus, tabs, scripting, declarativeNetRequest, identity, tts, alarms, webRequest, cookies, sidePanel, nativeMessaging as of the 2026-07-31 scan. Profile: Broader than typical.
Similar extensions
Grammarly
Writing assistant with a broad certification portfolio; useful if your risk question is enterprise controls.
Sider
Multi-model AI sidebar — broader permission set; contrast with DeepL’s translator profile.
Compare other AI extensions we scanned
Still deciding? Read independent disclosures for other AI Chrome extensions — same methodology, same scan date window.
Is Grammarly safe?
Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.
Broader than typical · scanned 2026-07-31
Is Merlin AI Assistant safe?
Claims SOC 2/GDPR/ISO compliance for paid users only — not independently verified. Privacy policy scored 5.0/10 with three red flags: no data deletion rights, unclear GDPR handling, and AI training on user content.
Broader than typical · scanned 2026-07-31
Is Monica safe?
No ISO or SOC 2 certifications found. Privacy policy scored 4.1/10 with four red flags: no data deletion rights, no policy change notification, no children's data policy, and AI training on user content with no disclosed opt-out.
Typical for its category · scanned 2026-07-31
Is Sider safe?
No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.
Broader than typical · scanned 2026-07-31
Compare with every extension we have reviewed on theextension security index, or see how this disclosure is produced on our security methodology page. Looking for a tool by job-to-be-done? Try the AI Tool Finder.