Plain-language commitment: we do not sell your personal data or submitted text. Use the full policy below for the details and feature-specific exceptions.
Who we are and what this policy covers
Detecting AI is operated by TEMURIYDEVS LTD, a company registered in England and Wales under company number 15282812. Our registered office is International House, 10 Churchill Way, Cardiff, United Kingdom, CF10 2HE. TEMURIYDEVS LTD is the controller of personal data described in this policy.
This policy applies to detecting-ai.com and the related services it provides through api.detecting-ai.com. It does not govern an external website merely because we link to it. You can verify our company details in the Companies House register.
Questions and privacy requests can be sent to support@detecting-ai.com.
Information we collect
Depending on how you use the service, we process:
- Submitted content: text you paste, text extracted from a file in your browser, URLs you exclude from a plagiarism search, and the resulting analysis. Submitted content may contain personal data if you include it.
- Account data: name, email address, sign-in method, language, account status, subscription entitlements, usage allowances, and API credentials if those features are enabled. Email accounts also use a password; Google sign-in is handled through Firebase Authentication.
- Transaction data: plan, subscription state, Paddle customer and transaction identifiers, and the billing details Paddle makes available to us. We do not receive or store your full payment-card number.
- Technical data: IP address, request time, browser or device information, security challenge results, and limited request metadata used to deliver, diagnose, and protect the service.
- Communications: your email address and the contents of messages you send to support, together with information needed to resolve the request.
We normally receive this information directly from you, your browser, or your chosen sign-in and payment provider. Do not submit another person's confidential or personal information unless you have a lawful reason and the right to do so.
How and why we use information
We use information to:
- run text checks and return reports requested by you;
- create, authenticate, secure, and support accounts;
- apply free and paid limits and administer subscriptions;
- detect abuse, prevent fraud, rate-limit requests, and debug failures;
- respond to support, privacy, and legal requests;
- understand service reliability through limited or aggregated usage information; and
- send essential account and subscription messages and, where permitted, product communications that include an unsubscribe option.
Our principal lawful bases are performance of a contract when you ask us to provide a service, our legitimate interests in operating and securing the product, and compliance with legal obligations. Where we introduce an optional activity that requires consent, we will ask separately and you may withdraw that consent.
Detecting AI produces automated content assessments, but we do not use those scores to make legal or similarly significant decisions about you. A score is a review signal for the person using the tool, not a decision about authorship, misconduct, eligibility, employment, or education.
How text and files are processed
Nothing is sent while you type. TXT, PDF, and DOCX files supported by the current tools are read in your browser. When you start a check, the extracted text, not the original file, is sent for processing.
AI detection requests are processed by our service infrastructure at api.detecting-ai.com. Fact-checking requests pass through that service and may be processed with Google Cloud Vertex AI. Paid plagiarism requests pass through our protected service, which sends bounded search queries to a search provider and retrieves public source pages needed to prepare the similarity report.
Anonymous checks are not intentionally added to account history by detecting-ai.com. Some signed-in tools may save the submitted text and result to account history so that you can return to it. The tool page will tell you when this can happen. If you create a public share link, anyone with that link may be able to see the shared report.
We do not claim ownership of submitted content and do not use it to train a general-purpose AI model unless you separately and expressly agree to such use.
Who receives information
We disclose only what is reasonably needed to:
- Google: Firebase Authentication for Google sign-in, Firestore for account scan history, Google Cloud Vertex AI for fact-check processing, and Google Analytics for automatic site-use measurement on eligible public pages. See Firebase privacy and security.
- Tolt: optional affiliate-referral attribution after consent.
- Paddle: checkout, tax, invoicing, subscription management, fraud checks, and payment support as merchant of record. Paddle handles payment details under its own privacy notice.
- Cloudflare: Turnstile security verification and abuse prevention.
- Search and public-source providers: bounded search queries and public source-page retrieval when a paid user starts a plagiarism check.
- SendPulse: email delivery and contact or subscription management. Account and subscription fields may be synchronised so we can send service communications and permitted product updates.
- Infrastructure and professional providers: hosting, transactional email, database, error monitoring, security, and advisers where necessary to operate the service or meet legal obligations.
We may also disclose information when required by law, to protect users and the service, or as part of a corporate transaction subject to appropriate confidentiality and notice requirements. We do not sell personal data or submitted text.
International transfers
We are established in the United Kingdom, while some providers operate globally. Your information may therefore be processed outside your country, including in the United States. Firebase Authentication, for example, is operated from US data centres.
Where data-protection law requires safeguards for a transfer, we rely on mechanisms made available by the relevant provider, such as adequacy regulations, approved contractual clauses, or equivalent protections. Contact us if you would like more information about a transfer relevant to your data.
How long we keep information
- Anonymous submitted content is not added to account history. It is processed to return the result and may remain briefly in necessary security or operational records maintained by us or the processor.
- Signed-in scan history is kept while needed to provide account history. We determine the period from the feature's purpose, account state, security and recovery needs, and legal obligations. You may ask us to delete it. Do not assume it disappears after a fixed period unless the relevant feature states one.
- In-memory rate-limit identifiers normally expire after about one hour. Authentication cookies and sign-in continuation storage expire on the schedules described above.
- Account data is kept while the account is active and for the period reasonably needed to complete deletion, resolve disputes, prevent abuse, and meet legal obligations.
- Subscription and transaction records are kept for the periods required by tax, accounting, fraud-prevention, and consumer law.
- Support correspondence is kept until the request is resolved and for a reasonable period afterward if needed to document the outcome.
Backups and provider systems may take additional time to complete a deletion. We use the shortest period reasonably compatible with the purpose, legal duties, security, and recovery needs.
Security
We use encrypted connections, restricted server-side credentials, secure HTTP-only session cookies, request-size limits, rate limits, provider response validation, and bot protection. Payment-card details are entered on Paddle's checkout rather than our sign-in pages.
No online system is perfectly secure. Protect your password, avoid submitting confidential material that is not necessary for a check, and contact us promptly if you believe your account or data has been compromised.
Your privacy rights
Depending on your location and the circumstances, you may have rights to access, correct, delete, restrict, or receive a portable copy of personal data, and to object to certain processing. If we rely on your consent, you may withdraw it without affecting earlier processing.
Right to object: you may object to processing based on our legitimate interests. We will stop unless we have compelling legitimate grounds or need the information for legal claims.
Send a request from the email connected to your account to support@detecting-ai.com. We may need to verify your identity and may retain limited information where the law permits or requires it. You can also complain to the UK Information Commissioner's Office through the ICO complaint process or to your local supervisory authority.
Children
The service is not directed to children under 13, and we do not knowingly create accounts for them. If local law requires consent from a parent or guardian at an older age, that requirement applies. A parent or guardian who believes a child provided personal data without appropriate consent should contact us so we can investigate and delete it where required.
Changes and contact
We may update this policy when the product, providers, or law changes. We will post the revised policy here, change the effective date, and provide additional notice when a change materially affects how we use personal data.
For privacy questions or requests, email support@detecting-ai.com. You may also write to TEMURIYDEVS LTD at International House, 10 Churchill Way, Cardiff, United Kingdom, CF10 2HE.