1. Data controller
The person responsible under the General Data Protection Regulation is:
Acadeo GmbH
Rathausstraße 43, 57537 Wissen, Deutschland
E-mail: info@acadeo.ai
Contact for data privacy questions: info@acadeo.ai
2. Overview of data processing
Certentis processes the data wey account, Humanizer, AI scanner, plagiarism check, history, credits and billing need.
We no dey use customer texts to train our own or other people generative models. We only process dem to provide and secure the exact service wey you request, and show am for your personal history.
- Account data: E-mail address, encrypted authentication information, display name, language settings and session data.
- Text tools: Input text, generated text, detected language, word and character counts, protected text parts, check results and technical status data.
- Plagiarism check: Uploaded or entered content, file name, report status, found locations, sources and similarity scores.
- Billing: Credits, transactions, plan, Stripe-, Apple-App-Store and Google-Play transaction references, plus subscription status.
- Operations and security: IP address, time, requested resource, status code, browser information, request ID, limited error and misuse signals.
- Optional mobile notifications: Expo push token, device platform, language setting and cleaned delivery status.
3. Purposes and legal bases
- Contract performance and pre-contract steps (Art. 6 Sec. 1 para. b GDPR): Registration, text processing, reports, history, credits, checkout and support.
- Legal obligations (Art. 6 Sec. 1 para. c GDPR): Especially records required under commercial and tax laws.
- Legitimate interests (Art. 6 Sec. 1 para. f GDPR): IT security, preventing misuse, service stability, error analysis and legal defence.
- Consent (Art. 6 Sec. 1 para. a GDPR): Optional mobile result notifications, which remain off until you activate dem.
- Consent (Art. 6 Sec. 1 para. a GDPR): External processing of texts sent through the mobile app. Certentis go ask for this permission before the first transfer; you fit withdraw am anytime under Data Privacy & Security.
4. Registration, database and authentication
For registration, sign-in, session management, account data and the application database, Certentis dey use Supabase. In particular, e-mail address, encrypted authentication information, session IDs and account data dey processed.
Supabase dey use cookies wey the system need for your signed-in session. Without these cookies, we no fit provide the protected account area.
Recipient: Supabase, Inc. We process am based on a data processing agreement. If data dey processed outside the European Economic Area, the transfer dey rely on the applicable safeguards under Chapter V GDPR, especially adequacy decisions or EU Standard Contractual Clauses.
5. Humanizer and Text History
For the text revision wey you request, the input text dey transferred server-side to Google Cloud Vertex AI. Technically protected parts of the text fit be replaced with placeholders before transfer and put back afterwards.
Input, result, word counts, language, scan values and technical run data dey stored for your personal history. Completed Humanizer runs dey automatically delete after 30 days by default, unless we need to keep them to clarify errors, defend legal claims or fulfil legal obligations.
Abeg no send other people business secrets or unnecessary special categories of personal data. You dey responsible for making sure the content you enter dey lawful.
6. AI Scanner and Probability Values
For an AI scan, the text dey transferred to a specialised external analysis service. Certentis processes the document and sentence values from the service and shows probabilities for human, mixed and AI-typical language patterns.
The values na statistical estimates, no be measurement of the percentage of text and no be proof of authorship. False-positive and false-negative results fit happen. Scanner values must not be the only basis for academic, employment-related or other major decisions.
Independent AI scan reports remain stored in your account until you request their deletion or delete the account, unless legal obligations or legitimate interests in keeping evidence prevent this.
7. Payments and Subscriptions
Checkout, payment processing, billing and subscription management on the website dey handled through Stripe. Purchases and subscriptions in the mobile app dey handled through the Apple App Store or Google Play. The relevant store processes payment, contact, device and transaction data according to its privacy information.
Certentis no dey store complete card or account details. We store the store, product and transaction IDs, a cryptographic hash of the purchase token, plan, payment status, credit entries and subscription lifecycle data. The unchanged purchase token dey used only server-side to verify with the relevant store and no dey stored permanently.
When you switch to Stripe, technically necessary cookies and similar technologies fit be used there.
8. Transactional Communication
Certentis sends necessary emails for account confirmation, sign-in, password reset, security and, where applicable, purchases and subscriptions. For this purpose, we process the email address, message type and the account or contract data needed for the specific communication.
Account-related authentication emails dey triggered through the sending function configured in Supabase. We no dey send marketing emails without the legal basis required for them.
If you clearly activate mobile result notifications, Certentis go use Expo Push Service send general notice say result don complete or error happen. The notification no contain any text wey you enter, scores, report titles or sources. Dem go delete the device token when you disable notifications, log out from the device or delete your account.
9. Hosting and server logs
Certentis dey provide the website and server-side application functions through Vercel. Vercel dey operate global infrastructure; because of this, connection and operational data fit dey processed for the United States and other countries. When you open the website, technically necessary data like IP address, time, requested resource, status code and browser information dey processed.
Operational and security logs wey Certentis control generally no contain complete customer texts, and dem go delete them latest after 30 days. Vercel fit process its own technically necessary logs according to the applicable contract, data protection and retention terms. If security incident happen or for legal defence, necessary logs fit dey secured until the matter don clear.
10. Cookies and similar technologies
Certentis currently dey use only technically necessary session, language and security cookies for login, account protection and the functions wey you expressly request.
We no build our own analytics, advertising or marketing cookies. So, we no dey show general consent banner for now.
If we add technologies wey no dey necessary in future, we go block them until valid consent dey, and update this notice.
11. Recipients and transfers to third countries
- Supabase for authentication and database.
- Vercel for hosting, delivery and server-side application functions.
- Google Cloud Vertex AI for text rewriting.
- Specialized AI analysis service for classifying texts.
- PlagiarismSearch for creating plagiarism reports.
- Stripe for checkout, payment and subscription management.
- Apple App Store and Google Play for mobile purchases, subscriptions, refunds and checking store transactions.
- Expo Push Service for optional general result notifications in the mobile app.
- Government authorities, courts or advisers, where there is a legal obligation or this one necessary for legal defence.
Certentis dey make service providers agree by contract to protect personal data at least as well as this notice, and allow processing only for the instructed service purpose. If a recipient processes data outside the European Economic Area, dem go transfer the data only when legal requirements dey met, for example through an adequacy decision or EU Standard Contractual Clauses with extra protective measures.
12. How long we store data
Kontodaten go dey stored until dem delete di account. When person request deletion, di account dey locked immediately, and dem normally complete am within five minutes through one secured background process; e fit take longer if external cleanup dey tried again. As part of dis, dem go delete di Stripe customer object, including payment methods and subscriptions connected to am, then dem go remove di local account data in a traceable way. Deleting di Certentis account no cancel any App Store or Google Play subscription. You fit delete di account immediately; you must cancel di Store subscription separately to avoid more charges. Store transaction records wey law or contract require fit remain with di Store.
Completed Humanizer runs and related technical request data dey stored by default for 30 days. Independent AI scan and plagiarism reports dey stored until di user or account owner delete dem.
Billing and transaction data dey stored until legal commercial and tax retention periods expire. Security and operations logs dey generally kept for 30 days; necessary evidence fit dey secured until a specific incident don resolve.
13. Your rights
As long as di law requirements apply, you get di right to access, correct, delete, restrict processing, transfer data, and object. You fit withdraw your consent anytime, with effect for di future.
You fit also complain to a data protection supervisory authority. In particular, di authority for your usual place of residence, workplace, or di place of di suspected violation fit handle am.
14. Data export and account deletion
For di account area, you fit request a machine-readable export of your account data and saved histories.
For dat same place, you fit start immediate account deletion. Stripe subscriptions go end during di deletion process. Di App Store or Google Play subscription dey managed by di relevant Store and no go cancel because of account deletion; you fit stop future renewals through di link inside di app. If your account dey linked to Apple, di authorization for “Sign in with Apple” go revoke when dem delete am from di iOS app. Billing data wey law require dem to keep go dey locked until di relevant period expire and dem go handle am separately from active product data.
Contact: info@acadeo.ai
15. No automated decision with legal effect
Certentis no dey use only automated decision based on Humanizer-, AI scanner, or plagiarism scores wey get legal effect on you or seriously affect you in similar way.
16. Data security
Certentis dey use technical and organisational measures wey match di risk. Dem include encrypted transfer, secrets protected on di server, row-based database access controls, payment webhooks checked by signature, limited request rates, and separate service accounts.
No system dey completely free from risk. Dem dey review and improve di measures based on di current technical standard and risk situation.
17. Changes to dis notice
Dem go update dis privacy notice if features, processing purposes, service providers, legal bases, or deletion periods change. Di version published on dis page at any time na di one wey apply.
