From 83ef1f36a8b8ad49662ed67f6ec5db40da0cdfd6 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Mon, 21 Jul 2025 13:15:45 +0800 Subject: [PATCH] Add data privacy and security section to README Introduced a new section detailing data privacy, security features, best practices, and compliance considerations for the proxy. This provides users with clear information on how data is handled and how to securely deploy the project. --- README.md | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/README.md b/README.md index 207c4d9..da8bff3 100644 --- a/README.md +++ b/README.md @@ -143,6 +143,34 @@ export default defineNitroConfig({ }); ``` +## Data Privacy & Security + +### Privacy Considerations + +- **Proxy Operation**: XDPL acts as a transparent proxy, forwarding requests directly to DeepL's servers without storing or logging translation content +- **No Data Retention**: Translation requests and responses pass through the proxy without being cached or stored locally +- **Direct Communication**: Your data flows directly between your application and DeepL's secure infrastructure + +### Security Features + +- **HTTPS Support**: All communications are encrypted in transit when deployed with HTTPS +- **No API Key Exposure**: Your DeepL API credentials remain between your client and DeepL's servers +- **Minimal Attack Surface**: Lightweight proxy design reduces potential security vulnerabilities +- **Server-Side Processing**: Runs on secure server infrastructure (Vercel, Netlify, etc.) + +### Best Practices + +- **Use HTTPS**: Always deploy with HTTPS enabled for encrypted communication +- **Environment Variables**: Store sensitive configuration in environment variables, not in code +- **Regular Updates**: Keep dependencies updated to ensure security patches are applied +- **Monitor Usage**: Implement proper logging and monitoring for your deployment + +### Compliance + +- **GDPR Friendly**: No personal data is stored or processed by the proxy +- **Data Sovereignty**: Translation data flows directly to DeepL, maintaining your existing compliance posture +- **Audit Trail**: Server logs can be configured according to your compliance requirements + ## License This project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.