Legal Português

Privacy Policy

Last updated: 6 October 2026 · Draft pending legal review

This Privacy Policy explains what personal data we process when you use Probator.ai, why, on what legal basis, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Portuguese law. It applies to the website, the editor, the API and our emails.

1. Who is responsible

The controller of your personal data is Spawncore Unipessoal Lda, NIPC [NIPC], [REGISTERED ADDRESS], Portugal. For any privacy question or request, write to privacy@probator.ai.

When a school, company or other organisation uses Probator.ai to check documents that contain personal data of other people (for example student essays or candidates' CVs), that organisation is the controller of that data and we act as its processor under our Data Processing Agreement. In that case, please direct requests about that data to the organisation.

2. What data we process

CategoryExamplesSource
Account dataEmail address, optional name, interface language, plan, date you accepted the Terms, sign-in timesYou
Sign-in dataHashed one-time codes; passkey public keys and device names; hashed session tokens; browser user-agent of each sessionYou, your device
ContentTexts and files you check or save, extracted text, reports and results, document titlesYou
Usage dataChecks run, word counts, credits used, how many times you analysed each text (counted by its fingerprint, shown on certificates), API keys (stored as hashes) and when they were usedGenerated by the Service
Billing dataStripe customer ID, plan, subscription status, billing period, tax country and VAT number. Card details are handled by Stripe and never reach us.You, Stripe
Technical dataIP address (used transiently for security and rate limiting), request logs, error reportsYour device
Anonymous trial dataA salted hash of your IP address that changes every day, and the credits used that dayGenerated by the Service
CertificatesCertificate ID, results, word count, language, text fingerprint (SHA-256), and the document title and your name if you choose to show them; the signed PDF. If you add a human review record: the reviewer name you give, your statement, the time, fingerprint and AI likelihood of your first check, and the share of words changed (the text of the first check is used to compute this and is not stored)You, generated by the Service
CorrespondenceMessages you send us and our repliesYou

We do not ask for special categories of data. Your content may nevertheless contain any kind of information; please avoid submitting sensitive personal data unless it is necessary.

3. Why we use it and our legal bases

PurposeLegal basis (GDPR art. 6)
Providing the Service: running checks, storing documents, managing your account, credits and API keys, signing you inPerformance of our contract with you (art. 6(1)(b))
Billing, invoicing and tax complianceContract (art. 6(1)(b)) and legal obligation (art. 6(1)(c))
Security, abuse prevention, rate limiting, enforcing credit limits and our TermsOur legitimate interest in a secure and fair service (art. 6(1)(f))
Anonymous trial without an accountLegitimate interest in letting people try the Service while preventing abuse (art. 6(1)(f))
Issuing certificates and running the public verification page for themContract (art. 6(1)(b)): you ask us to issue a verifiable certificate
Essential service emails (sign-in codes, billing notices, changes to the Terms)Contract (art. 6(1)(b))
Answering your messages and handling complaintsContract or legitimate interest (art. 6(1)(b), (f))
Defending legal claimsLegitimate interest (art. 6(1)(f))

Anonymous statistics. We keep daily totals of checks (for example, how many checks found hidden characters or which share of AI-detection results were inconclusive, by language) and publish them monthly on our blog. These totals contain no texts, fingerprints, account or device data, and groups of fewer than 20 checks are never published, so they are not personal data.

We do not sell your personal data, do not use it for advertising, and do not send marketing emails. We do not use your content to train AI models, ours or anyone else's.

Where we rely on legitimate interests, you can object at any time (see section 8).

4. AI processing and automated decisions

Your text is analysed by automated systems, including our own detection model and third-party language models, as described in our AI Policy. These results are information for you; we do not make decisions about you based on them, and the Service is not designed to make decisions that produce legal or similarly significant effects on individuals (GDPR art. 22). Customers who use results to make decisions about others must involve human review.

5. Who we share data with

We use carefully selected service providers ("sub-processors") that process data on our behalf under contracts that require confidentiality and security. The current list, with their role, location and transfer safeguards, is on our sub-processor page. In summary:

Certificates are public by design. If you create a certificate, anyone who has its ID (for example from the PDF or its QR code) can see its details on our verification page: the results, word count, language, text fingerprint, issue date, any human review record and, if you chose to show them, the document title and your name. The analysed text is never shown on that page.

We may also disclose data where required by law or by a court order, to protect our rights, or to a company that acquires the Service (in which case this policy continues to apply).

6. International transfers

Our database (accounts, credits, certificates and document records) and the documents you save are stored with Cloudflare in its European Union jurisdiction: that data is stored, and the database runs, only in the EU. Requests are handled by Cloudflare's global network, so a request may be processed briefly in the data centre closest to you, inside or outside the EU. Text sent to a language model for a check is processed by the providers described in section 5, which may be outside the EU. Some sub-processors are based in, or may process data in, the United States or other countries outside the European Economic Area. Where this happens we rely on an adequacy decision (including the EU–US Data Privacy Framework for certified companies) or on the European Commission's Standard Contractual Clauses, together with additional safeguards such as encryption in transit. You can ask us for a copy of the relevant safeguards.

7. How long we keep data

DataRetention
Account and usage dataWhile your account exists; deleted when you delete your account
Saved documents and their reportsUntil you delete them or your account
Text checked without savingNot stored in your account. A copy of the report may stay in an internal cache for up to 24 hours so that an identical check is not charged twice. Plagiarism results are never cached.
Comparison library fingerprintsUntil you delete your account
Certificates and their PDFsUntil you delete your account (revoked certificates stay visible as "revoked" until then)
One-time sign-in codes10 minutes (deleted once used)
Sessions30 days, or until you sign out
Anonymous trial counter1 day (the hash key changes daily)
Server logsUp to 30 days
Database backupsUp to 30 days, after which deleted data is no longer recoverable
Billing and tax records10 years, as required by Portuguese tax law (held by Stripe and in our accounts)

8. Your rights

You have the right to:

You can exercise several of these rights yourself: Account → Privacy & data lets you download all your data as a JSON file and delete your account. For anything else, write to privacy@probator.ai. We answer within one month. We may ask you to confirm your identity, for example by replying from your account's email address.

You also have the right to lodge a complaint with a supervisory authority, in particular the Portuguese Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt, or the authority in your country of residence.

9. Security

We protect your data with encryption in transit (TLS) and at rest, passwordless sign-in (email codes and passkeys), hashed storage of codes, session tokens and API keys, access controls, and per-account separation of stored documents. Only authorised staff can access production systems, and only when necessary. No system is perfectly secure; if a personal-data breach is likely to put you at risk, we will inform you and the supervisory authority as required by law.

10. Children

The Service is not intended for children under 13. People aged 13 to 16 may only use it with the consent of a parent or guardian or through an institution that has obtained it, as described in our Terms.

11. Cookies

We only use cookies and similar storage that are strictly necessary for the Service, such as the session cookie that keeps you signed in. We do not use analytics or advertising cookies. See our Cookie Policy.

12. Changes to this policy

We will publish any update on this page with a new date. If the changes are material, we will also tell you by email or in the Service before they take effect.