Privacy
Privacy Policy
This policy explains which personal data Certentis processes, the purposes for which it does so, and the rights you have.
Last updated: 2026-09-07
1. Controller
The controller within the meaning of the General Data Protection Regulation is:
CERTENTIS
Brahmsstr. 6, 57577 Hamm, Deutschland
Email: info@certentis.com
Contact for privacy inquiries: info@certentis.com
2. Overview of processing
Certentis processes the data required for accounts, Humanizer, AI scanners, plagiarism checks, history, credits, and billing.
Customer texts are not used to train our own or third-party generative models. They are processed only to provide and secure the specifically requested service and display it in the personal history.
- Account data: email address, encrypted authentication information, display name, language settings, and session data.
- Text tools: input text, generated text, detected language, word and character counts, protected text components, check results, and technical status data.
- Plagiarism check: uploaded or entered content, file name, report status, matches, sources, and similarity scores.
- Billing: credits, transactions, plan, Stripe-, Apple App Store, and Google Play transaction references, as well as subscription status.
- Operations and security: IP address, timestamp, requested resource, status code, browser information, request ID, and limited error and abuse signals.
- Anonymous free trials: random device identifier in a necessary HttpOnly cookie, device and network pseudonyms generated exclusively as HMACs, tool type, quota status, and the requested result for a short time.
- Optional mobile notifications: Expo push token, device platform, language preference, and sanitized delivery status.
3. Purposes and legal bases
- Performance of a contract and pre-contractual measures (Art. 6 para. 1 lit. b GDPR): Registration, text processing, reports, history, credits, checkout, and support. If you explicitly start a text tool in the app, the entered text is transmitted to the processors named below only to the extent necessary to perform the requested tool.
- Legal obligations (Art. 6 para. 1 lit. c GDPR): in particular, records required under commercial and tax law.
- Legitimate interests (Art. 6 para. 1 lit. f GDPR): IT security, abuse prevention, service stability, error analysis, and legal defense.
- Consent (Art. 6 para. 1 lit. a GDPR): optional mobile result notifications, which remain disabled until you activate them. The same applies to the support chat on the public pages: it is loaded only after you click the chat button.
4. Registration, database, and authentication
For registration, login, session management, account data, and the application database, Certentis uses Supabase. In particular, email addresses, encrypted authentication information, session identifiers, and account data are processed.
Supabase uses technically necessary cookies for the logged-in session. Without these cookies, the protected account area cannot be provided.
Recipient: Supabase, Inc. Processing is carried out on the basis of a data processing agreement. Where data is processed outside the European Economic Area, the transfer is based on the applicable safeguards under Chapter V of the GDPR, in particular adequacy decisions or EU Standard Contractual Clauses.
5. Humanizer and text history
For the requested text revision, the input text is transmitted server-side to Google Cloud Vertex AI. Technically protected text elements may be replaced with placeholders before transmission and then restored afterward.
Input, result, word counts, language, scan scores, and technical runtime data are stored in the personal history. Completed Humanizer runs are automatically deleted by default after 30 days, unless retention is required for clarifying errors, legal defense, or compliance with statutory obligations.
Please do not submit other parties’ trade secrets or unnecessary special categories of personal data. You are responsible for the lawfulness of the content you enter.
6. AI scanner and probability scores
For an AI scan, the text is transmitted to a specialized external analysis service. Certentis processes its document and sentence scores and displays probabilities for human, mixed, and AI-typical language patterns.
The scores are statistical estimates, not measurements of the percentage of text accounted for by each category and not proof of authorship. False positives and false negatives are possible. Scanner scores must not be the sole basis for academic, employment-related, or other significant decisions.
Standalone AI scan reports remain stored in the account until you request their deletion or the deletion of the account, unless statutory obligations or legitimate interests in preserving evidence prevent this.
7. Payments and subscriptions
Checkout, payment processing, and invoice and subscription management on the website are handled through Stripe. Purchases and subscriptions in the mobile app are processed through the Apple App Store or Google Play. The respective store processes payment, contact, device, and transaction data in accordance with its privacy information.
Certentis does not store complete card or account details. The store, product and transaction identifiers, a cryptographic hash of the purchase token, plan, payment status, credit entries, and subscription lifecycle data are stored. The unmodified purchase token is used only server-side to verify the purchase with the respective store and is not stored permanently.
When switching to Stripe, technically necessary cookies and similar technologies may be used there.
8. Transactional communications
Certentis sends necessary emails for account confirmation, sign-in, password resets, security, and, where applicable, purchases and subscriptions. This involves processing the email address, message type, and the account or contract data required for the specific communication.
Account-related authentication emails are triggered via the sending function configured in Supabase. Marketing emails are not sent without a legal basis required for this purpose.
If you expressly enable mobile result notifications, Certentis sends a general completion or error notice via the Expo Push Service. The notification does not contain any entered texts, scores, report titles, or sources. The device token is deleted when you disable notifications, sign out on the device, or delete your account.
9. Hosting and server logs
Certentis provides the website and server-side application functions via Vercel. Vercel operates a global infrastructure; connection and operational data may therefore be processed in the United States and other countries. When the website is accessed, technically necessary data such as the IP address, time, requested resource, status code, and browser information is processed.
Operational and security logs controlled by Certentis generally do not contain complete customer texts and are deleted no later than 30 days later. Vercel may process its own technically necessary logs in accordance with the applicable contractual, data protection, and retention terms. In the event of a security incident or for legal defense, necessary logs may be secured until the matter is clarified.
10. Cookies and similar technologies
Certentis currently uses only technically necessary session, language, and security cookies for sign-in, account protection, and the expressly requested functions.
To protect registration and login from automated abuse, Certentis uses Cloudflare Turnstile. The service processes the connection, device, and browser signals required for the security check, in particular the IP address, browser and device information, timing data, and the check result. Cloudflare does not receive customer text entered into forms. Turnstile may use technically necessary cookies or comparable storage technologies.
For the support chat, Certentis uses the service Crisp. On the public pages the chat is not loaded along with the page: at first only a button is visible, and only your click on it loads the service and allows it to set its own cookies and local storage entries. In the signed-in account area the chat loads immediately, because support there is part of the contractual service; the email address and display name are transmitted so that an enquiry can be assigned to the account. Entered texts, report contents, and credit data are not transmitted.
No proprietary analytics, advertising, or marketing cookies are integrated. Therefore, no general consent banner is currently displayed.
If non-essential technologies are added in the future, they will be blocked until effective consent is given, and this notice will be updated.
10a. Google Analytics 4
Only with your explicit consent (Art. 6 para. 1 lit. a GDPR), Certentis Google Analytics 4 is used to measure page usage, scroll depth, sign-ins, purchases, subscription events, and conversion paths. The Google Analytics tag is not loaded before you give your consent.
This may involve processing pseudonymous client and session identifiers, the page path and page title, the referring page without query parameters, browser and device information, approximate location, language, scroll depth, interactions, and purchase- and plan-related events. No entered customer text, report content, complete URLs with query parameters, or complete payment data is transmitted to Google Analytics.
Google signals and personalized advertising are disabled. After consent, Google Analytics and the browser may use cookies or comparable storage technologies. The recipient is Google Ireland Limited; insofar as Google LLC or other entities outside the European Economic Area process data, the transfer is carried out on the basis of applicable safeguards, in particular adequacy decisions or EU Standard Contractual Clauses.
You can withdraw your consent at any time with effect for the future via the always-accessible cookie settings. The Certentis-associated Analytics identifiers and Analytics events not yet transmitted will then be deleted, and further transmissions will be stopped. Event data already transmitted is subject to the retention and deletion rules configured in Google Analytics; aggregated statistics without a direct account reference may remain for longer.
10b. Google Ads conversion measurement
Only with your express consent (Art. 6 para. 1 lit. a GDPR) does Certentis use the Google tag and Google Ads to measure whether a page visit leads to registration, use of a tool, checkout, or a purchase. Without consent, no Google Ads conversions are transmitted.
Pseudonymous advertising and click identifiers such as gclid, gbraid, or wbraid, approved campaign parameters, client and session identifiers, page path, conversion type, and, for purchases, value, currency, and a technical transaction identifier may be processed. No entered customer texts, report content, complete payment details, or uncontrolled URL parameters are transmitted to Google.
Certentis uses Google Consent Mode v2 with analytics and ad storage denied by default. The Google tag is loaded only after your consent. The ad_user_data and ad_personalization signals remain denied; Certentis therefore uses neither personalized advertising nor Enhanced Conversions with an email address or telephone number.
You can withdraw your consent at any time through the cookie settings, effective for the future. Certentis will then remove the associated local campaign data and Analytics identifiers and stop any further transmissions. Conversion data already transmitted is subject to the retention and deletion rules configured at Google.
10c. Support chat
On the public pages the support chat is loaded only after you click the chat button; that click is your consent (Art. 6 para. 1 lit. a GDPR). In the signed-in area it loads right away, because support there is part of the contractually owed service (Art. 6 para. 1 lit. b GDPR). The provider is Crisp IM SAS, based in France; it operates its core infrastructure in the European Union.
Once loaded, Crisp stores an identifier in your browser and links your messages to it; from the signed-in area your e-mail address and display name are added. You may withdraw your consent at any time with effect for the future: the button below ends the current chat session, deletes the identifier stored in this browser, and loads the chat on the public pages only after another click. Messages already sent remain in the support inbox and are deleted on request at the address named above.
11. Recipients and transfers to third countries
- Supabase for authentication and database services.
- Vercel for hosting, delivery, and server-side application functions.
- Cloudflare, Inc., with its Turnstile service, to protect registration and login from bots and automated abuse.
- Google Cloud Vertex AI for text editing.
- A specialized AI analysis service for classifying texts.
- PlagiarismSearch for generating plagiarism reports.
- Stripe for checkout, payments, and subscription management.
- Apple App Store and Google Play for mobile purchases, subscriptions, refunds, and store transaction verification.
- Expo Push Service for optional general result notifications in the mobile app.
- Crisp IM SAS, based in France, for the support chat. The provider operates its core infrastructure in the European Union.
- Authorities, courts, or advisors, insofar as there is a legal obligation or this is necessary for legal defense.
Certentis contractually requires service providers to maintain a level of protection for personal data at least equivalent to that described in this statement and permits processing only for the instructed service purpose. Where a recipient processes data outside the European Economic Area, the transfer takes place only on the basis of legally authorized safeguards, such as an adequacy decision or EU standard contractual clauses with supplementary protective measures.
12. Retention period
Account data is stored until the account is deleted. A deletion request immediately locks the account and is normally completed within five minutes via a secured background process; if external cleanup is attempted again, it may take longer. This deletes the Stripe customer object, including the payment methods and subscriptions linked to it, after which the local account data is removed in a traceable manner. Deleting the Certentis account does not cancel an App Store or Google Play subscription and is not blocked by its renewal status. You must stop future renewals separately in the respective store. Store transaction records required by law or contract may remain with the store.
Completed Humanizer runs and associated technical request data are stored by default for 30 days. Standalone AI scan and plagiarism reports remain stored until deleted by the user or through account deletion.
Billing and transaction data are stored until the statutory retention periods under commercial and tax law expire. Security and operational logs are generally retained for 30 days; necessary evidence may be secured until the matter is resolved in the event of a specific incident.
For anonymous free trials, the entered text is used only for the requested processing. For asynchronous plagiarism checks, it is removed no later than completion or in the event of an error; orphaned inputs and short-term replay results are deleted no later than after 24 hours. The pseudonymized network signal is deleted after 30 days, and the device entitlement after 180 days.
13. Your rights
Subject to the statutory requirements, you have the right to access, rectification, erasure, restriction of processing, data portability, and objection. You may withdraw your consent at any time, effective for the future.
You may also lodge a complaint with a data protection supervisory authority. In particular, the authority in your habitual place of residence, place of work, or the place of the alleged infringement has jurisdiction.
14. Data export and account deletion
In the account area, you can request a machine-readable export of your account data and saved histories.
You can also initiate immediate account deletion there. Stripe subscriptions are terminated during the deletion process. An App Store or Google Play subscription is managed by the respective Store and is not canceled through account deletion; you can stop future renewals using the link in the app. For an account linked to Apple, authorization for “Sign in with Apple” is revoked from the iOS app when the account is deleted. Billing data that must be retained by law is blocked until the applicable retention period expires and handled separately from active product data.
Contact: info@certentis.com
15. No automated decision with legal effect
Certentis does not make any solely automated decision based on Humanizer-, AI scanner, or plagiarism scores that produces legal effects concerning you or similarly significantly affects you.
16. Data security
Certentis implements technical and organizational measures appropriate to the risk. These include encrypted transmission, server-side protection of secrets, row-level database access controls, signature-verified payment webhooks, rate limiting, and separate service accounts.
No system is entirely risk-free. The measures are reviewed and further developed in line with the state of the art and the risk situation.
17. Amendments to this statement
This Privacy Statement is updated whenever functions, processing purposes, service providers, legal bases, or deletion periods change. The version published on this page at any given time shall apply.