1. Data Controller
The controller within the meaning of the General Data Protection Regulation is:
Acadeo GmbH
Rathausstraße 43, 57537 Wissen, Deutschland
Email: info@acadeo.ai
Contact for Data Protection Inquiries: info@acadeo.ai
2. Overview of Data Processing
Certentis processes data required for your account, Humanizer, AI scanner, plagiarism check, history, credits, and billing.
Customer texts are not used to train proprietary or third-party generative models. They are processed solely to provide, secure, and display the specifically requested service in the personal history.
- Account data: Email address, encrypted authentication information, display name, language settings, and session data.
- Text tools: Input text, generated text, detected language, word and character counts, protected text elements, check results, and technical status data.
- Plagiarism check: Uploaded or entered content, file name, report status, matches found, sources, and similarity scores.
- Billing: Credits, transactions, plan, Stripe, Apple App Store, and Google Play transaction references, and subscription status.
- Operations and security: IP address, timestamp, requested resource, status code, browser information, request ID, limited error and abuse signals.
- Optional mobile notifications: Expo push token, device platform, language setting, and sanitized delivery status.
3. Purposes and Legal Bases
- Performance of a contract and pre-contractual measures (Art. 6 para. 1 point b GDPR): Registration, text processing, reports, history, credits, checkout, and support.
- Legal obligations (Art. 6 para. 1 point c GDPR): in particular, documentation required under commercial and tax law.
- Legitimate interests (Art. 6 para. 1 point f GDPR): IT security, abuse prevention, service stability, error analysis, and legal defense.
- Consent (Art. 6 para. 1 point a GDPR): optional mobile result notifications, which remain disabled until you activate them.
- Consent (Art. 6 para. 1 point a GDPR): external processing of text submitted from the mobile app. Certentis requests this permission before the first transmission; it can be withdrawn at any time in Privacy & security.
4. Registration, Database, and Authentication
For registration, sign-in, session management, account data, and the application database, Certentis uses Supabase. This includes processing email addresses, encrypted authentication information, session identifiers, and account data.
Supabase sets technically necessary cookies for the logged-in session. Without these cookies, the protected account area cannot be provided.
Recipient: Supabase, Inc. Processing takes place on the basis of a data processing agreement. Insofar as data is processed outside the European Economic Area, the transfer is based on the applicable safeguards pursuant to Chapter V GDPR, in particular adequacy decisions or EU Standard Contractual Clauses.
5. Humanizer and Text History
For the requested text revision, the input text is transmitted server-side to Google Cloud Vertex AI. Technically protected text elements can be replaced by placeholders prior to transmission and subsequently reinserted.
Input, results, word counts, language, scan scores, and technical execution data are stored in your personal history. Completed Humanizer runs are automatically deleted after 30 days by default, unless retention is required for error clarification, legal defense, or compliance with legal obligations.
Please do not submit third-party trade secrets or unnecessary special categories of personal data. You are responsible for the lawfulness of the entered content.
6. AI scanner and probability values
For an AI scan, text is transmitted to a specialized external analysis service. Certentis processes its document and sentence scores and displays probabilities for human, mixed, and typical AI linguistic patterns.
The scores are statistical estimates, not a measurement of percentage text shares, nor proof of authorship. False-positive and false-negative results are possible. Scanner scores must not serve as the sole basis for academic, employment, or other significant decisions.
Standalone AI scan reports remain stored in your account until you request their deletion or the deletion of your account, provided no legal obligations or legitimate documentation interests conflict.
7. Payments and Subscriptions
Website checkout, payment processing, invoices, and subscription management are handled through Stripe. Purchases and subscriptions in the mobile app are processed by the Apple App Store or Google Play. The relevant store processes payment, contact, device, and transaction data under its privacy policy.
Certentis does not store complete card or bank account details. It stores the store, product and transaction identifiers, a cryptographic hash of the purchase token, plan details, payment status, credit ledger entries, and subscription lifecycle data. The unchanged purchase token is used server-side only for verification with the relevant store and is not stored permanently.
When switching to Stripe, technically necessary cookies and comparable technologies may be used there.
8. Transactional communications
Certentis sends necessary emails for account confirmation, sign-in, password resets, security notifications, and, where applicable, purchases and subscriptions. For this purpose, email addresses, message types, and the account or contract data required for the specific communication are processed.
Account-related authentication emails are triggered via the delivery function configured in Supabase. Promotional emails will not be sent without a required legal basis.
If you explicitly enable mobile result notifications, Certentis sends a generic completion or failure notice through the Expo Push Service. The notification contains no submitted text, scores, report titles, or findings. The device token is deleted when you disable notifications, sign out on the device, or delete your account.
9. Hosting and server logs
Certentis provides the website and server-side application functions through Vercel. Vercel operates global infrastructure; connection and operational data may therefore be processed in the United States and other countries. When the service is accessed, technically necessary data such as the IP address, timestamp, requested resource, status code, and browser information are processed.
Operational and security logs controlled by Certentis generally do not contain complete customer texts and are deleted after no more than 30 days. Vercel may process its own technically necessary logs under the applicable contractual, privacy, and retention terms. Logs required for a security incident or legal defense may be preserved until the matter is resolved.
10. Cookies and similar technologies
Certentis currently uses strictly necessary session, language, and security cookies exclusively for login, account protection, and explicitly requested features.
First-party or third-party analytics, advertising, or marketing cookies are not integrated. Therefore, no general consent banner is currently displayed.
If non-essential technologies are added in the future, they will be blocked until effective consent is given, and this privacy policy will be updated.
11. Recipients and third-country transfers
- Supabase for authentication and database.
- Vercel for hosting, delivery, and server-side application functions.
- Google Cloud Vertex AI for text rewriting.
- A specialized AI analysis service for text classification.
- PlagiarismSearch for generating plagiarism reports.
- Stripe for checkout, payment, and subscription management.
- Apple App Store and Google Play for mobile purchases, subscriptions, refunds, and store transaction verification.
- Expo Push Service for optional generic mobile result notifications.
- Authorities, courts, or advisors to the extent there is a legal obligation or as necessary for legal defense.
Certentis contractually requires service providers to protect personal data at least to the same standard described in this policy and permits processing only for the instructed service purpose. If a recipient processes data outside the European Economic Area, the transfer takes place only on the basis of legal requirements, such as an adequacy decision or EU standard contractual clauses with supplementary safeguards.
12. Data retention
Account data is stored until account deletion. A deletion request blocks the account immediately and is normally completed by a secure background process within five minutes; retried external cleanup may take longer. The Stripe customer object, including attached payment methods and subscriptions, is deleted before local account data is removed in a traceable manner. Deleting the Certentis account does not cancel an App Store or Google Play subscription. You can delete immediately, but must separately cancel the store subscription to prevent future charges. Transaction evidence required by law or contract may remain with the store.
Completed Humanizer runs and associated technical request data are stored for 30 days by default. Standalone AI scan and plagiarism reports remain stored until user-initiated or account-level deletion.
Billing and transaction data are stored until the expiration of statutory commercial and tax retention periods. Security and operational logs are generally kept for 30 days; necessary evidence data may be preserved in the event of a specific incident until its resolution.
13. Your rights
In accordance with statutory requirements, you have rights to access, rectification, erasure, restriction of processing, data portability, and objection. You can withdraw consent at any time with future effect.
You also have the right to lodge a complaint with a data protection supervisory authority. In particular, the authority of your habitual residence, your place of work, or the place of the alleged infringement is competent.
14. Data export and account deletion
In the account area, you can request a machine-readable export of your account data and saved history.
You can also initiate immediate account deletion there. Stripe subscriptions are terminated during the deletion process. An App Store or Google Play subscription is controlled by the relevant store and is not canceled by account deletion; use the in-app store-management link to stop future renewals. Sign in with Apple authorization is revoked when an Apple-linked account is deleted from the iOS app. Billing data required to be retained by law will be restricted until the expiry of the respective retention period and handled separately from active product data.
Contact: info@acadeo.ai
15. No automated decision-making with legal effect
Certentis does not base any solely automated decisions on Humanizer, AI scanner, or plagiarism scores that produce legal effects concerning you or similarly significantly affect you.
16. Data Security
Certentis implements technical and organizational measures appropriate to the risk. These include encrypted transmission, server-side protected secrets, row-level database access controls, signature-verified payment webhooks, request rate limiting, and separated service accounts.
No system is completely risk-free. Measures are continually reviewed and refined in line with technological developments and the risk situation.
17. Changes to this policy
This Privacy Policy will be updated whenever features, processing purposes, service providers, legal bases, or retention periods change. The version published on this page applies.
