Translate anything. Keep nothing.
Teddy is a privately-run translation service: one API key and a POST call is the whole integration, translated by a private language model instead of a public translation API.
Wiring translation into a product usually means handing your users' text to an outside vendor through a third-party API. Teddy is the privacy-minded alternative: the same one-endpoint integration, but the text goes to a privately-run model instead of a commercial translation provider. It's still a hosted service a client connects to, the same as any other API. The difference is who's on the other end, and what happens to the text once it arrives.

One REST endpoint, a private model, no stored content: the whole pitch in four cards.
The call itself is deliberately plain: give it text and a target language, source is optional and gets auto-detected if left out, and the translation comes back synchronously. No login flow, no session, just an API key on every request. The in-browser translator anyone can click through is a thin convenience layer on the same endpoint every other integration calls.

Text in, a target language, a translation back. That's the whole call.
Confidentiality here isn't a policy promise, it's structural. Translation text, in and out, is never stored. What gets recorded is usage only: request counts, word and token counts, language pairs, timestamps, enough to meter and audit without retaining a word of anyone's actual content. Requests are served by a privately-run language model rather than routed out to a commercial translation vendor, so client text never leaves for an outside AI provider in the first place.

Every request logged and metered, without a single word of what was actually said.
Rolling this out across more than one integration is where the key model matters. A client gets one master key, and mints scoped sub-keys underneath it per app or per user, each seeing only its own usage and each independently revocable. One compromised or retired integration means rotating one key, not resetting everyone else's credentials too.

A master key, and as many scoped sub-keys underneath it as there are integrations to isolate.
What it does
- One REST endpoint: text and a target language in, a translation back, synchronously
- Source language named explicitly or auto-detected when left out
- Confidential by design: input and output text are never stored, only usage counts
- Served by a privately-run language model, not routed out to a public translation API
- Scoped sub-keys per app or user, each independently revocable without touching the others
- Usage metering with both an aggregated view and a full per-request log
- Fair, bounded access to the shared backend, so no single caller can crowd out the others
