Privacy Policy
The short version: text you scan is processed in memory and discarded when the result is returned. It is never written to a database, never reviewed by a person, and never used to train a model.
Last updated
01 Text you scan
This is the part most people care about, so it comes first.
When you paste text or upload a document, the content is held in server memory only for as long as the analysis takes. Once the result is sent back to your browser, the content is released. We do not write it to disk, we do not queue it, and we do not keep a copy for quality review.
- Not stored. No database record of your text is created.
- Not trained on. Your content is never added to a training or calibration set.
- Not shared. It is not sold, rented, or passed to advertisers or data brokers.
- Not read by us. There is no human review queue because there is nothing retained to review.
Uploaded files are parsed to extract their text, then the file buffer is discarded along with the text. Nothing is kept in a temporary uploads folder after the request completes.
The practical consequence is that we usually cannot help you recover a past scan, because there is no past scan to recover. That tradeoff is deliberate.
02 What we do collect
Running a website still produces some data. Here is the complete list.
Server logs
Standard web server logs record the request time, the URL requested, the HTTP status, a truncated IP address, and the browser user agent. These exist to diagnose errors and detect abuse such as automated scraping. They are retained for 30 days and then deleted.
Aggregate usage counts
We count events, not content. For example, how many scans ran in a given hour, or how often a document upload failed. These counters contain no text and cannot be linked back to an individual scan.
Messages you send us
If you email us or use the contact form, we keep that correspondence so we can answer you and refer back to it if you write again. We use it only for support. It is not added to a marketing list.
What we do not collect
No account is required to use the detector, so we hold no passwords. We do not collect payment details on this site, and we do not build advertising profiles.
04 Third parties in the request path
We keep external dependencies to a minimum, but a few sit in the page delivery path and will therefore see your IP address as a normal consequence of serving the page.
- Our hosting provider, which runs the servers and holds the request logs described above.
- A web font provider, which serves the typefaces used across the site.
- A content delivery network, which serves static assets.
None of these receive the text you scan. Analysis happens on our own servers, not through a third-party API.
05 Legal basis and your rights
Where the GDPR applies, our legal basis for processing server logs and aggregate counts is legitimate interest: keeping the service available, secure and working. For support correspondence, the basis is legitimate interest in answering your question.
You have the right to request access to any personal data we hold about you, to ask for correction or deletion, to object to processing, and to lodge a complaint with your local supervisory authority.
In practice, because scanned text is never retained, a data request will usually return only support emails you have sent us and, if you can identify the time window, the relevant truncated log lines. Email [email protected] and we will respond within 30 days.
If you are covered by the CCPA, note that we do not sell or share personal information as those terms are defined in the statute.
06 Security
All traffic is served over HTTPS using TLS 1.2 or higher, so your text is encrypted in transit between your browser and our servers.
Because scanned content is never written to persistent storage, there is no archive of user text that could be exposed in a breach. This is the strongest privacy property the service has, and it comes from the architecture rather than from a policy promise.
Administrative access to servers is restricted and audited. If we ever become aware of a breach affecting personal data, we will notify affected users and the relevant authority without undue delay, and in any case within 72 hours of becoming aware, where the law requires it.
Found a security issue? Email [email protected] with the details. We will acknowledge within two business days and will not pursue action against good-faith research that avoids privacy violations and service disruption.
07 Children
This service is not directed at children under 13, and we do not knowingly collect personal information from them. Because no account is required, we collect no age data. If you believe a child has sent us personal information through the contact form, email us and we will delete it.
08 Changes to this policy
If this policy changes, the date at the top of the page changes with it. Material changes, particularly any change to the retention position described in section one, will be announced on the homepage before taking effect.
We will not quietly begin retaining scanned text. If that ever changed, it would be a headline, not a footnote.
Questions about this document? Email [email protected] or use the contact form. This page describes our practices in plain language and is not legal advice.