Privacy Policy
How we collect, process, and protect your personal data in compliance with GDPR / DSGVO and the German TDDDG.
Last updated: October 4, 2026
Plagiarism & AI Check: Privacy Guarantee
- Your document is not added to any plagiarism pool or comparison database
- Never shared with third parties for AI model training or advertising
- Results sent exclusively to you by email
- Scan download tokens expire after 48 hours; physical file deletion occurs during cleanup
- Checks processed in Germany by our software partner PlagAware and deleted after report generation
- Company headquarters in Germany, Karlsruhe
- Web servers located in Germany (Strato AG)
- Fully encrypted data transfer (SSL/TLS)
AI Writing Tools & Free Tools: Privacy Guarantee
- Paid AI tools (Proofread, Rephrase, Summarize, Citation Check, Coach, Submission Check): text processed via Anthropic Claude under commercial terms (no AI training)
- Paid AI tool texts and results are encrypted; content becomes eligible for request-triggered cleanup after the deadlines (see Section 5a)
- Document Check, the free Writing Coach, and AI Usage Statement process text in your browser; Source Check and Citation Generator lookups use our server and Crossref (see Section 5b)
- Your work is never submitted to universities or institutional Turnitin repositories
- Company headquarters in Germany, Karlsruhe
- Fully encrypted data transfer (SSL/TLS)
Table of Contents
- Privacy at a Glance
- Controller & Contact
- What Data We Collect
- Purposes & Legal Bases
- Document Processing (Plagiarism Checks) and AI Writing Tools (5a)
- Free Writing Tools (5b)
- Contract Confirmation and Withdrawal Consent (5c)
- Payment Processing (Stripe)
- SSL / TLS Encryption
- Cookies & Consent (TDDDG)
- Hosting & Server Logs
- Contact Form
- Third-Party Services Overview
- Data Retention
- Your Rights Under GDPR
- Supervisory Authority
- Opposition to Advertising Emails
- Changes to This Policy
1. Privacy at a Glance
The following section provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to personally identify you. For detailed information, please refer to the full privacy policy below.
Data collection on our website
Some data is collected automatically by our IT systems when you visit the website, primarily technical data such as your browser, operating system, and the time of your visit. This collection is automatic as soon as you enter the site.
Other data is only collected when you provide it to us, for example when you upload a document for scanning, place an order, or contact us.
How we use your data
Data is collected to ensure the website functions securely and to perform the services you request (plagiarism scans, AI detection, AI writing tools). We do not run third-party advertising or commercial tracking networks on this website.
Your rights
You have the right to receive free information at any time about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction, restriction, or deletion of this data. You can contact us at any time at the address given in the imprint. You also have the right to lodge a complaint with the competent supervisory authority.
2. Controller & Contact
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Benjamin Lohrer
korrektur.de / plagiarism-checker-online.net
Karlsruhe, Germany
E-mail: privacy@plagiarism-checker-online.net
For all data protection inquiries, including requests to exercise your rights, please contact us at the email address above. We will respond without undue delay and within one month as required by Article 12 GDPR. Where legally permitted, we may extend this period by up to two further months and will explain the extension within the first month.
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g. names, email addresses).
3. What Data We Collect
We collect only the personal data that is necessary to provide our service. Depending on how you use the website, this may include:
When you place an order
- E-mail address (to send you your order confirmation and scan or tool result)
- Payment data processed by Stripe (we never receive or store your full card number or CVC, see Section 6)
- The document you upload for scanning or the text you submit for AI writing tools
- Order metadata: scan or product type, page count, amount, payment reference, timestamp, and the consent and confirmation records described below
When you browse the website
- IP address in server log files (for security and abuse prevention)
- Browser type and version
- Operating system
- Referring URL
- Time of the server request
- Cookie preference record stored in your browser (see Section 8)
When you contact us
- Name and e-mail address provided in your message
- Content of your inquiry
4. Purposes & Legal Bases
We process your personal data on the following legal bases under Article 6 GDPR:
- Art. 6(1)(b) GDPR: Contract performance: Processing your order, running the requested scan or AI analysis, delivering the result to your e-mail address, handling payment, and processing contact inquiries.
- Art. 6(1)(c) GDPR: Legal obligation: Retaining invoices, transaction accounting records, and evidence of contract and withdrawal consent where required by German commercial and tax law (§ 257 HGB, § 147 AO) or other legal obligations.
- Art. 6(1)(f) GDPR: Legitimate interests: Server log processing to ensure web application security, stability, and abuse prevention.
5. Document Processing (Plagiarism Checks)
When you upload a document for a plagiarism or AI scan, the file is saved temporarily on our German server with a secure, random 48-hour download token. This allows the check to be initiated and the resulting report to be generated and delivered to you.
To run the plagiarism scan, documents are forwarded to PlagAware GmbH (Germany). PlagAware acts as a data processor under Article 28 GDPR. We have a Data Processing Agreement in place with PlagAware.
- Documents are processed solely for the purpose of performing the requested plagiarism scan.
- Documents are not added to PlagAware's internal comparison database or to any public plagiarism pool. Future checks by other users will never match against your paper.
- Documents are not stored permanently by PlagAware: they are deleted after the report has been generated.
- Scan files are stored temporarily on our server. Their download tokens are valid for 48 hours. Expired files are removed opportunistically when another upload triggers cleanup or when our cleanup endpoint is run. There is no scheduled deletion timer, so files can remain physically stored beyond 48 hours even though their tokens no longer allow access.
- Documents are never used to train artificial intelligence models or shared with third-party AI companies.
- All data transfer and processing remains within Germany / the EU/EEA.
PlagAware's own privacy policy is available at www.plagaware.com/service/dataprotection.
5a. AI Writing Tools (Anthropic)
Our paid AI writing tools (AI Proofreading, Rephrase Text, Summarize Text, APA Citation Check, the AI rewrite of the Writing Coach, and the Submission Check) use the Claude AI model provided by Anthropic (Anthropic, PBC, San Francisco, USA, and its affiliates). These tools are separate from the plagiarism and AI scans described in Section 5, which never send documents to AI companies.
- What is processed: the text you enter or upload for the tool, your email address, and the order data. Your text is sent to Anthropic only after you have paid and only to create your result. Your email address is not sent to Anthropic.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Before you order, you also confirm that your text may be sent to Anthropic.
- Transfer to the USA: Anthropic processes the text on our behalf under its data processing terms, which include the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- No training: under Anthropic's commercial terms, content sent through its API is not used to train its models.
- Storage on our server: your submitted text, email address, contract snapshot, and results are encrypted in the server-side order files. Content becomes eligible for cleanup 72 hours after completion or failure. For orders still awaiting payment or being created, the threshold is 24 hours from creation. Paid orders that have not finished become stalled after 24 hours without an update; cleanup deletes their encrypted content and retains their order status for refund handling. Cleanup runs on AI endpoint requests, at most once an hour, not on a scheduled timer. Deletion can therefore occur later than these thresholds.
- Result link: we email you a private link to your result. Anyone with this link can open the result until it is deleted, so do not share it.
For older failed orders without a failure timestamp, cleanup measures the 72-hour window from the last recorded update, or from creation if no update timestamp exists. Cleanup attempts to remove order records once they are more than 90 days old, measured from creation. This is also request-triggered and is not a guaranteed deletion deadline. Accounting documents retained separately remain subject to statutory retention obligations.
Anthropic's privacy policy: www.anthropic.com/legal/privacy.
5b. Free Writing Tools
- Document Check, free Writing Coach, and AI Usage Statement: the document or text is processed locally in your browser. Using the paid Writing Coach rewrite is a separate AI order covered by Section 5a.
- Source Check: the reference entries you submit go to our server. It queries Crossref using the DOI, or the reference text when no DOI is supplied, and returns publication metadata. Do not include private information in reference entries.
- Citation Generator: citation formatting happens in your browser. Your bibliography and selected style are saved in your browser's localStorage so you can continue later; clear the bibliography or site storage to remove them. DOI lookup sends the DOI through our server to Crossref.
The lookup endpoints do not write submitted references or DOI queries to an application content store. Normal server logging and abuse-prevention processing still apply. Lookups are performed to provide the service you request (Art. 6(1)(b) GDPR).
5c. Contract Confirmation and Withdrawal Consent
For scan and paid AI tool orders, we record acceptance of the terms, your express request and consent to performance starting before the 14-day withdrawal period ends, and your acknowledgment that the withdrawal right expires when the service has been fully performed. The record includes a timestamp, the consent text, and its version 2026-10-04-service-v1.
Scan consent and a snapshot of the terms and withdrawal notice are stored in private server receipt files. The receipt is authenticated and bound to the order using an HMAC. For Stripe-paid scans and AI tools, the checkout metadata also contains the consent timestamp, version, text, and acceptance flags. For zero-price scan orders, the HMAC-authenticated order token includes the consent record. AI orders store the consent in the order record and the contract snapshot in its encrypted content.
We record whether the customer confirmation was accepted for sending by our SMTP server: scan orders use a server confirmation marker, and AI orders record a confirmation timestamp in their order file. SMTP acceptance is not proof that you opened or received the message.
Your contract confirmation email includes the provider details, order reference, service description, amount, page count, recorded consent and timestamp, and the full terms and withdrawal notice text. A paid scan sends this confirmation after payment verification and before the internal processing request. A zero-price scan sends it before the internal processing request. A paid AI tool sends it after payment verification and before processing starts or your text is sent to Anthropic. Processing does not start through these paths if the confirmation cannot be sent. Legacy orders without a versioned consent record are identified as such; no consent is invented.
These emails are sent through Strato SMTP using an encrypted connection to its mail server. Scan confirmations use the shared SMTP mailer or the equivalent mailer in the zero-price order endpoint; AI confirmations use the shared SMTP mailer. The recipient email address and the confirmation content pass through this mail service.
We process these records to perform and document the contract and to prove your consent to immediate performance and acknowledgment of loss of the withdrawal right upon full performance (Art. 6(1)(b) and Art. 6(1)(c) GDPR). Scan receipts and confirmation markers have no automatic retention-based deletion rule. They are retained for as long as needed for proof and applicable statutory retention obligations. AI order records and encrypted snapshots follow the cleanup rules in Section 5a; statutory accounting records may be retained separately.
6. Payment Processing (Stripe)
All payments are processed by Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). Stripe is an independent data controller for payment data.
- We never receive or store your full card number, CVC, or bank account details.
- Stripe provides checkout and payment information, including session and payment references, payment status, amount, currency, and customer email where supplied. We also send order and consent metadata to Stripe, as described in Section 5c.
- Stripe processes payment-related personal data to handle your payment (Art. 6(1)(b) GDPR). Other service providers receive data only for the purposes described in this policy.
- Stripe's privacy policy: stripe.com/privacy.
7. SSL / TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries, this website uses SSL or TLS encryption. You can recognize an encrypted connection by the address bar of your browser changing from http:// to https:// and by the padlock symbol in your browser bar.
When SSL/TLS encryption is active, data you transmit to us cannot be read by third parties.
Our web servers are located in Germany, operated by Strato AG. All data transfers are fully encrypted.
8. Cookies & Consent (TDDDG)
We use cookies and similar technologies on this website. Cookies do not harm your computer and do not contain viruses. They serve to make our service more user-friendly, more effective, and more secure.
In accordance with § 25 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz) and the GDPR, we only store non-essential data and access information on your terminal equipment after obtaining your explicit, informed, freely given consent.
You can configure your browser to inform you about cookie placement, allow cookies only in individual cases, exclude cookies for certain cases or in general, and activate automatic deletion of cookies when the browser is closed. Disabling cookies may limit the functionality of the website.
Essential cookies (no consent required, Art. 6(1)(f) GDPR)
These cookies are technically necessary for the website to function correctly. They cannot be disabled.
- cookie_consent: Stores your selected categories, preference version, and timestamp in your browser's localStorage. The current code has no automatic one-year expiry; the record remains until you clear it or it is replaced.
Analytics category (consent required, Art. 6(1)(a) GDPR)
No third-party analytics services (such as Google Analytics or Matomo) are loaded on this website. Our pages run without third-party tracking scripts.
Marketing cookies
No marketing or advertising cookies are active on this website.
Withdrawing consent
You can change or withdraw your cookie consent at any time by clicking the "Cookie Settings" link in the footer of any page. This will re-open the consent banner where you can adjust or revoke your selections. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
9. Hosting & Server Logs
This website is hosted by Strato AG (Otto-Ostrowski-Straße 7, 10249 Berlin, Germany) on servers located in Germany. When you visit any page, our web server automatically records the following data in server log files:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
These logs are processed on the basis of Art. 6(1)(b) GDPR (processing to fulfill a contract or pre-contractual measures) and our legitimate interest (Art. 6(1)(f) GDPR) in the secure and stable operation of the website. Logs are not merged with other data sources and are not used to identify individual users. Log retention is managed by the hosting provider; we do not promise an automatic 90-day deletion period.
10. Contact Form
If you send us inquiries via a contact form or email, your details from the inquiry, including the contact information you provide, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.
The processing of data entered in the contact form is carried out on the basis of contract performance or pre-contractual measures (Art. 6(1)(b) GDPR) or your consent (Art. 6(1)(a) GDPR). You can revoke consent at any time by sending us an email. The lawfulness of data processing operations carried out before revocation remains unaffected.
Data you submit will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after your inquiry has been fully resolved). Mandatory statutory retention provisions remain unaffected.
11. Third-Party Services Overview
We use the following external services that may process personal data to provide our website and services:
- PlagAware GmbH (Germany): Document processor for plagiarism analysis (Section 5).
- Stripe Payments Europe, Ltd. (Ireland): Payment processor (Section 6).
- Anthropic, PBC (USA): AI model provider for the paid AI writing tools (Section 5a).
- Strato AG (Germany): Web hosting and SMTP mail service (Sections 5c and 9).
- Crossref: Publication metadata lookups for Source Check and Citation Generator (Section 5b).
All fonts are self-hosted locally on our server; no font requests are made to Google or third-party servers. We do not sell, rent, or share your personal data with third parties for marketing purposes. Data is transmitted to third parties only where necessary to perform our contractual service or where required by law.
12. Data Retention
- Order data & invoices: Retained for the applicable statutory periods under German commercial (§ 257 HGB) and tax law (§ 147 AO). This does not mean that all runtime AI order files are kept for those periods; their cleanup is described in Section 5a.
- E-mail address: Used for order confirmations, scan reports, tool results, and customer support. It can remain in order-related emails; encrypted AI order content follows Section 5a. Scan duplicate markers do not store email addresses.
- Uploaded documents (plagiarism checks): Download tokens expire after 48 hours. Files are physically removed during opportunistic cleanup, which can occur later (Section 5). Documents sent to our partner PlagAware are deleted after report generation.
- Texts and results of AI writing tools: Stored encrypted; content becomes eligible for cleanup 72 hours after completion or failure, unpaid content 24 hours after creation, and stalled paid content after 24 hours without an update. Cleanup is request-triggered, not a guaranteed timer, so deletion may occur later (Section 5a).
- Server logs: Retention is managed by the hosting provider (Section 9).
- Contact form data: Deleted once the matter is fully resolved, unless statutory retention periods apply.
- Cookie consent records: Kept in your browser's localStorage without a coded time-based expiry until cleared or replaced.
- Contract and consent evidence: Scan receipts and confirmation markers are retained as long as needed for proof and statutory obligations, with no automatic day-count deletion rule. AI records follow Section 5a.
Deletion depends on the data category and the cleanup or retention rules described above. Completing an order does not immediately delete every record, receipt, or email.
13. Your Rights Under GDPR
Under the GDPR, you have the following rights with respect to your personal data:
- Right of access (Art. 15 GDPR): You may request free information at any time about the origin, recipients, and purpose of your stored personal data, as well as a copy of that data.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your data, subject to applicable statutory retention obligations.
- Right to restriction (Art. 18 GDPR): You may request that processing be restricted in certain circumstances.
- Right to data portability (Art. 20 GDPR): You may request your data in a structured, commonly used, machine-readable format, or request direct transmission to another controller where technically feasible.
- Right to object (Art. 21 GDPR): You may object at any time to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent, you may withdraw it at any time by sending us an email. The lawfulness of processing carried out before withdrawal remains unaffected. To withdraw cookie consent specifically, use the Cookie Settings link in the footer.
To exercise any of these rights, please contact us at privacy@plagiarism-checker-online.net. We will respond without undue delay and within one month, subject to the lawful extension described in Section 2. We may ask you to verify your identity before processing your request.
14. Supervisory Authority
In the event of data protection violations, you have the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection matters is the data protection commissioner of the German federal state in which our company is headquartered.
For Baden-Württemberg (our state of registration), the competent authority is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
A list of all data protection commissioners and their contact details can also be found at: bfdi.bund.de.
15. Opposition to Advertising Emails
The use of contact data published as part of the imprint obligation to send unsolicited advertising and information materials is hereby expressly prohibited. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example via spam emails.
16. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our services, technology, or legal requirements. We will post the updated version on this page with a new "Last updated" date at the top. We encourage you to review this policy periodically.
Material changes that affect your rights will be communicated via a notice on the website or, where we have your e-mail address, by e-mail.