Privacy Policy
This Privacy Policy explains what personal data we process when you use Probator.ai, why, on what legal basis, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Portuguese law. It applies to the website, the editor, the API and our emails.
1. Who is responsible
The controller of your personal data is Spawncore Unipessoal Lda, NIPC [NIPC], [REGISTERED ADDRESS], Portugal. For any privacy question or request, write to privacy@probator.ai.
When a school, company or other organisation uses Probator.ai to check documents that contain personal data of other people (for example student essays or candidates' CVs), that organisation is the controller of that data and we act as its processor under our Data Processing Agreement. In that case, please direct requests about that data to the organisation.
2. What data we process
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, optional name, interface language, plan, date you accepted the Terms, sign-in times | You |
| Sign-in data | Hashed one-time codes; passkey public keys and device names; hashed session tokens; browser user-agent of each session | You, your device |
| Content | Texts and files you check or save, extracted text, reports and results, document titles | You |
| Usage data | Checks run, word counts, credits used, how many times you analysed each text (counted by its fingerprint, shown on certificates), API keys (stored as hashes) and when they were used | Generated by the Service |
| Billing data | Stripe customer ID, plan, subscription status, billing period, tax country and VAT number. Card details are handled by Stripe and never reach us. | You, Stripe |
| Technical data | IP address (used transiently for security and rate limiting), request logs, error reports | Your device |
| Anonymous trial data | A salted hash of your IP address that changes every day, and the credits used that day | Generated by the Service |
| Certificates | Certificate ID, results, word count, language, text fingerprint (SHA-256), and the document title and your name if you choose to show them; the signed PDF. If you add a human review record: the reviewer name you give, your statement, the time, fingerprint and AI likelihood of your first check, and the share of words changed (the text of the first check is used to compute this and is not stored) | You, generated by the Service |
| Correspondence | Messages you send us and our replies | You |
We do not ask for special categories of data. Your content may nevertheless contain any kind of information; please avoid submitting sensitive personal data unless it is necessary.
3. Why we use it and our legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the Service: running checks, storing documents, managing your account, credits and API keys, signing you in | Performance of our contract with you (art. 6(1)(b)) |
| Billing, invoicing and tax compliance | Contract (art. 6(1)(b)) and legal obligation (art. 6(1)(c)) |
| Security, abuse prevention, rate limiting, enforcing credit limits and our Terms | Our legitimate interest in a secure and fair service (art. 6(1)(f)) |
| Anonymous trial without an account | Legitimate interest in letting people try the Service while preventing abuse (art. 6(1)(f)) |
| Issuing certificates and running the public verification page for them | Contract (art. 6(1)(b)): you ask us to issue a verifiable certificate |
| Essential service emails (sign-in codes, billing notices, changes to the Terms) | Contract (art. 6(1)(b)) |
| Answering your messages and handling complaints | Contract or legitimate interest (art. 6(1)(b), (f)) |
| Defending legal claims | Legitimate interest (art. 6(1)(f)) |
Anonymous statistics. We keep daily totals of checks (for example, how many checks found hidden characters or which share of AI-detection results were inconclusive, by language) and publish them monthly on our blog. These totals contain no texts, fingerprints, account or device data, and groups of fewer than 20 checks are never published, so they are not personal data.
We do not sell your personal data, do not use it for advertising, and do not send marketing emails. We do not use your content to train AI models, ours or anyone else's.
Where we rely on legitimate interests, you can object at any time (see section 8).
4. AI processing and automated decisions
Your text is analysed by automated systems, including our own detection model and third-party language models, as described in our AI Policy. These results are information for you; we do not make decisions about you based on them, and the Service is not designed to make decisions that produce legal or similarly significant effects on individuals (GDPR art. 22). Customers who use results to make decisions about others must involve human review.
5. Who we share data with
We use carefully selected service providers ("sub-processors") that process data on our behalf under contracts that require confidentiality and security. The current list, with their role, location and transfer safeguards, is on our sub-processor page. In summary:
- Cloudflare hosts the Service, its database and file storage, sends our emails and runs the embedding model used by our detection model.
- OpenRouter routes requests to language models (currently from Google and Anthropic) used for grammar suggestions, the rewrite test and the expert reading. We send the text being checked, and require routing only to providers that do not store or train on it.
- Stripe processes payments. Stripe is an independent controller for some data, for example for fraud prevention.
- TOConline, our certified invoicing software, receives the name, address, country, VAT number and amounts needed to issue each invoice, which we must keep under Portuguese tax law.
- Search and academic services (web search, OpenAlex, Semantic Scholar) receive short phrases from your text during a plagiarism check, without any information that identifies you.
Certificates are public by design. If you create a certificate, anyone who has its ID (for example from the PDF or its QR code) can see its details on our verification page: the results, word count, language, text fingerprint, issue date, any human review record and, if you chose to show them, the document title and your name. The analysed text is never shown on that page.
We may also disclose data where required by law or by a court order, to protect our rights, or to a company that acquires the Service (in which case this policy continues to apply).
6. International transfers
Our database (accounts, credits, certificates and document records) and the documents you save are stored with Cloudflare in its European Union jurisdiction: that data is stored, and the database runs, only in the EU. Requests are handled by Cloudflare's global network, so a request may be processed briefly in the data centre closest to you, inside or outside the EU. Text sent to a language model for a check is processed by the providers described in section 5, which may be outside the EU. Some sub-processors are based in, or may process data in, the United States or other countries outside the European Economic Area. Where this happens we rely on an adequacy decision (including the EU–US Data Privacy Framework for certified companies) or on the European Commission's Standard Contractual Clauses, together with additional safeguards such as encryption in transit. You can ask us for a copy of the relevant safeguards.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and usage data | While your account exists; deleted when you delete your account |
| Saved documents and their reports | Until you delete them or your account |
| Text checked without saving | Not stored in your account. A copy of the report may stay in an internal cache for up to 24 hours so that an identical check is not charged twice. Plagiarism results are never cached. |
| Comparison library fingerprints | Until you delete your account |
| Certificates and their PDFs | Until you delete your account (revoked certificates stay visible as "revoked" until then) |
| One-time sign-in codes | 10 minutes (deleted once used) |
| Sessions | 30 days, or until you sign out |
| Anonymous trial counter | 1 day (the hash key changes daily) |
| Server logs | Up to 30 days |
| Database backups | Up to 30 days, after which deleted data is no longer recoverable |
| Billing and tax records | 10 years, as required by Portuguese tax law (held by Stripe and in our accounts) |
8. Your rights
You have the right to:
- access your personal data and receive a copy;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict processing in certain cases;
- data portability: receive your data in a structured, machine-readable format;
- object to processing based on legitimate interests;
- not be subject to decisions based solely on automated processing with legal or similar effects.
You can exercise several of these rights yourself: Account → Privacy & data lets you download all your data as a JSON file and delete your account. For anything else, write to privacy@probator.ai. We answer within one month. We may ask you to confirm your identity, for example by replying from your account's email address.
You also have the right to lodge a complaint with a supervisory authority, in particular the Portuguese Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt, or the authority in your country of residence.
9. Security
We protect your data with encryption in transit (TLS) and at rest, passwordless sign-in (email codes and passkeys), hashed storage of codes, session tokens and API keys, access controls, and per-account separation of stored documents. Only authorised staff can access production systems, and only when necessary. No system is perfectly secure; if a personal-data breach is likely to put you at risk, we will inform you and the supervisory authority as required by law.
10. Children
The Service is not intended for children under 13. People aged 13 to 16 may only use it with the consent of a parent or guardian or through an institution that has obtained it, as described in our Terms.
11. Cookies
We only use cookies and similar storage that are strictly necessary for the Service, such as the session cookie that keeps you signed in. We do not use analytics or advertising cookies. See our Cookie Policy.
12. Changes to this policy
We will publish any update on this page with a new date. If the changes are material, we will also tell you by email or in the Service before they take effect.