Privacy Policy
This version is in force from August 29, 2026
This sets out what data we collect, why, who we send it to and how long we keep it. The thing worth knowing first: checking a work means showing its text to external services — and exactly which ones, and how much of it, is stated below.
1. Who controls the data
The controller is the party named at the end of this page; the same place carries the address for any request described below.
2. Account data
- At registration: your name, email address, phone number and password. The password is stored only as an irreversible hash — we do not know it and cannot recover it.
- We store the fact and date you accepted these documents, your interface language, your notification settings and — if you filled them in — the billing details used on invoices: name, tax number and address.
- If an account is closed for breaking the rules, a note of that stays on it: the date, which member of our staff made it, and an internal free-text reason. The reason is written for the next operator and is not shown to you on screen — but it is about you, so you may obtain it on request together with the rest of your data.
- Technical data: your IP address and browser string are stored with the sign-in session, and on the account record itself — the address and browser the account was registered from. We additionally record your IP address in the rate-limit counter, in the record of every uploaded work, and in a support request. The one at registration exists for exactly one purpose: to see and stop mass automated sign-up, where accounts are created by the dozen from a single address.
- There are no third-party analytics or advertising trackers on the site.
3. The work you uploaded
- The source file is kept under protection in private storage: the application has no address that serves it, and no public link to it exists.
- Alongside the file we keep working extracts from it — the extracted and normalised text, the structure map and the state of the search. They exist so the report can be displayed without checking the work again.
- There is no time limit on storage: the file and the text live exactly as long as the work exists in your account. Deleting the work erases its whole folder at once.
- The person who uploaded a work can see it and its reports; where an organisation paid for the check, so can its owner and administrators. Beyond them, authorised staff of the Service may open a report and the text fragments it is built from — when handling a complaint about a result or checking a false positive.
4. Who the text of your work is sent to
Checking is impossible without external services, and we will not pretend that data stays inside. Here is the full list of what goes where.
- Search services (DataForSEO, Serper, Bright Data, CORE, Google Books — and through them, search engines): verbatim phrases from the work, six to ten words long, up to several hundred per work. The title page, contents, bibliography, appendices and properly formatted quotations are excluded from the search. No identifier of you or of the work is sent.
- The DeepSeek language model: fragments of the text. During the AI check, consecutive fragments covering the whole work are sent, not merely suspicious passages, and the title page is not stripped out. During the logic check, the tasks stated in the introduction, the work’s conclusions, pairs of sentences containing figures, and sentences carrying references are sent. No identifier of you or of the work is sent.
- Academic catalogs (CrossRef, OpenAlex, doi.org, the legislation registry, the web archive): entries from your bibliography — titles, full bibliographic descriptions, DOIs and addresses. We visit the addresses in your list to see whether they are still alive, so the owner of such a site sees the visit.
- The email delivery service: the address and the body of the message. The subject line of a “check finished” email contains the name of the file you uploaded.
- Bot protection (Cloudflare Turnstile): the registration, contact and password-recovery pages — and the sign-in page after several failed attempts — load its script in your browser, so Cloudflare sees your IP address and browser — on the registration page, before the account exists at all.
- The error-tracking service, when enabled: technical details of a failure. The request body, the query string, authorisation headers, report links and verification codes are stripped before sending; what remains is the request method and path, the browser, and internal record identifiers.
- Your own server, or your organisation’s, where a webhook is configured for the account: the file name, the title of the work, its internal number, its state and its page count. Neither the text of the work nor the report is sent there. The address of that server is chosen by you, or by an administrator of the organisation that paid for the check.
- The payment provider, where payment goes through one: your name, email address, the billing details you entered, and the amount and currency of the order. Which provider that is, if any, is named at the end of this page.
- Currency rates are fetched from public sources with a plain request — none of your data goes there.
5. Transfers outside the country
The services named above operate abroad, including outside the European Union — the DeepSeek language model is hosted in China. By ordering a check you instruct us to make that transfer; without it, that check cannot be performed.
There is no technical way to run these checks without those services: no mode exists in which a plagiarism check avoids search engines, or an AI check avoids a language model. The choice here is whether to order the check.
6. What stays with us after a check
- We do not add the texts of works to the accumulated source cache. It holds only external pages downloaded from the internet.
- The verbatim phrases sent to search engines are recorded in a query log and remain there after the work is deleted. They are separate six-to-ten-word windows rather than continuous text, and once the work is deleted they are tied neither to it nor to you.
- Where a member of staff has withdrawn a single finding from a report — on a complaint, or while checking false positives — the record of that decision keeps an excerpt of up to 300 characters: the very fragment that was withdrawn. It exists so the decision can be reviewed, and it lives as long as the decision does.
- The cache of search results is kept for fourteen days and purged daily.
7. The same file uploaded by two people
A report is stored against the content of the text, so two people who upload a file with the same text receive the result of one and the same search. Neither sees anything belonging to the other: the highlighting is built inside each person’s own file, and the title of the work, its author and anything else entered stay private.
The report row is deleted once no work with that text remains — otherwise one person deleting their work would erase another person’s report.
8. Report links and the verification code
- A report becomes available to anyone else only when you create a link to it yourself. That link shows not only the figures but the full text of the work with its highlighting — it is the same as handing over the report itself.
- Pages behind such a link are closed to search engines by a header in the response.
- Disabling a link closes access, but the address itself is kept and comes back to life if you enable the link again. To kill copies already sent to somebody, refresh the link — the old address then stops working for good.
- Every PDF carries a verification code, and it cannot be turned off: without it the report is worth nothing to the person you send it to. That code shows a stranger the figures of the check, its date and the length of the work, the number of sources and a masked file name — but not the text of the work, not its sources, and nothing about you.
- After a work is deleted the code stays valid for one answer only: that such a check existed and was deleted on such a date.
9. Deletion and export
- A work can be deleted at any time: the file, all working extracts and the report go with it, unless another work still refers to that report.
- An account is deleted in three steps: a request, confirmation through a link in an email (valid for 48 hours), and the expiry of a 30-day waiting period during which the decision can be cancelled. After that all your works and their files, reports, wallets and access keys are erased. The owner of an organisation must first hand it over or close it — until then a deletion request is not accepted.
- Accounting records — invoices, receipts and ledger entries — are kept after the account is deleted, as the law requires. They are detached from the account, but an issued invoice keeps a snapshot of the buyer details it carried when it was issued. Support conversations are kept in the same way.
- You can request a copy of your data in settings: the archive is assembled on demand, stays downloadable for seven days, and contains your profile, your works, reports, financial records and source files.
10. Cookies
- The session cookie is required: without it you cannot stay signed in. It lives for two hours from your last action, is unavailable to page scripts, and on the live site travels only over a secure connection.
- The language and currency cookies remember what you chose in the switchers, for a year. They are not used for anything else.
- The “remember me” cookie is set only if you tick that box yourself when signing in, and lets you skip the password for about 400 days. It disappears the moment you sign out.
- There are no advertising or analytics cookies.
11. Your rights
- You can find out what data we hold about you, correct it in settings, receive a copy as an archive, and delete your account together with your works.
- You can opt out of non-essential email in notification settings or through the link in the message itself. Service email — address confirmation, password reset, account-deletion confirmation — cannot be turned off.
- You can write to us at the address at the end of this page about anything concerning your data, and you may lodge a complaint with the data protection supervisory authority.
12. Security and age
- The connection to the site is encrypted, passwords are stored only as hashes, files sit in private storage outside the web root, and log records are scrubbed of sensitive values before they are written.
- None of that makes handing over data risk-free. The largest risk in this Service is created neither by you nor by us, but by a report link sent to the wrong person.
- If you are under 16, use the Service with the consent of a parent or guardian.
13. Changes to this policy
We may change this Policy — for instance when the list of processors changes. The version in force is dated under the heading. We will notify you by email of material changes affecting what data is sent out.
Who is bound by this
- Service:
- UniScan — https://uniscan.online
- Email:
- support@uniscan.online
For anything about these documents, write to the address above or use the form: Support.