What Happens to Text You Paste Into an AI Detector?
Paste a student essay into a free AI detector and where does it go? Retention, training use and deletion policies by tool, and what GDPR requires of schools.
The short answer. It depends which detector you use. Most, including GPTZero's dashboard, Copyleaks, Turnitin and Originality.ai, store what you submit, and several reserve the right to train their models on it. Is It AI? does not store submitted text on any tier: it is held in memory for the scan, sent to Anthropic for analysis, and discarded afterwards, with only a one-way hash kept for 24 hours to avoid re-billing identical scans. For UK and EU schools this is a GDPR question, not a preference, since pasting a student essay into a storing detector makes the school a data controller engaging an unassessed processor.
Here is a moment that happens thousands of times a day. A teacher suspects an essay, finds a free AI detector, pastes the whole thing in and clicks scan. In three seconds they have a percentage. What they usually have not asked is where the essay just went, how long it will be kept, and whether it is now training data for someone's model.
That question matters more than the score, because a student essay is not anonymous text. It is a child's personal data, often with their name at the top, and pasting it into a third-party service is a data transfer whether or not anyone thought of it that way.
What each detector does with your text
This table summarises published vendor policies as of August 2026. Policies change; the linked source is always the authority.
Updated August 2026: every row re-checked against live vendor policies. Scribbr corrected, its detector page now states "we do not store or share your data", with its terms moving to Learneo on 21 August 2026; GPTZero split by dashboard versus API; Copyleaks and Originality.ai training clauses now quoted directly; Winston's consent language added; ZeroGPT reclassified as "not disclosed" because its policy never addresses pasted text at all.
The pattern is worth stating plainly: most detectors store what you paste, several reserve the right to learn from it, and the free tiers, the ones teachers actually use, generally have the weakest protections.
Why this is a legal question for UK and EU schools, not a preference
Under UK and EU GDPR, a school is the data controller for its students' work. Paste an essay into a detector and the school has engaged a data processor, which formally requires a lawful basis and a Data Processing Agreement, the thing nobody signs before using a free web tool at 9pm on a Sunday. The DfE's generative AI guidance for schools points the same direction: know where pupil data goes before a tool touches it.
Two specific clauses decide everything in a review. Retention: how long is the text kept and can the school have it deleted? And training use: does the vendor reserve the right to improve its models on submissions? Our position in the schools comparison stands: a model-training clause on student work needs to be removed, or the supplier ruled out.
There is also a fairness dimension the JCQ guidance on AI in assessments implies but schools rarely operationalise: if a student's work is scanned, stored and flagged by a system the student cannot see, the process is hard to defend in an appeal. Data handling and fair process are the same conversation.
The multi-year contract question
Schools rarely buy a detector for one term. The questions that matter in a multi-year deal are not the ones on the pricing page: what happens to five years of accumulated student submissions when the contract ends, does the leaving school get a deletion certificate, and does the training clause survive termination? A vendor that cannot answer those in writing is telling you the answer.
The clause to ask for exists in the market, so there is no need to accept its absence. Pangram commits to deleting personal data within 30 days of account closure, and Winston publishes a 30 to 90 day purge schedule after deletion. Those are the shapes of a real exit clause: a number, a timeline, and a mechanism, written into the DPA rather than promised in a sales call.
For the institution-level version of this question, the Turnitin case is now the reference point: does Turnitin use student essays to train AI? breaks down what the 2026 policy says, what Southampton decided, and the questions a data-protection officer should ask before renewal. The ownership side, who holds copyright in an archived paper and how deletion works, is covered in who owns the work you submit to Turnitin?
If you are a writer rather than a teacher
The same table applies with a different threat model. Unpublished client copy, embargoed announcements and manuscripts are confidential commercial material. Pasting them into a storing detector puts them on someone else's server under terms you have not read, and in the worst case into a training set. For casual checks of your own public writing, any tool is fine. For client work, use a detector that does not store, or get your client's view first, and see our content-creator comparison for how the popular tools differ. The contract and payment side of the same problem is covered in AI detection for freelance writers.
Five questions to ask any detector vendor
- Is submitted text stored after the scan completes, and for how long?
- Is it ever used to train or improve models, and can that be switched off in writing?
- Where is it processed and hosted, and does that survive a UK/EU transfer review?
- Will you sign a Data Processing Agreement suitable for children's data?
- Can the student or writer see what was flagged, so the process is defensible?
A vendor that answers all five quickly is telling you something. So is a vendor that cannot.
Our position, including the trade-off
Is It AI? does not store submitted text, on any tier including free. Not stored means not breachable, not trainable and not subject to a retention argument, which keeps a school's GDPR review short.
Honesty requires naming the cost. If you have an account we can show you a list of your past scans, because we keep the result, the score and the date, but we cannot re-open the text of last week's report or show you what changed between two drafts, and beyond the 24-hour dedup window we cannot recognise a resubmission. Tools that store your text can do those things, and for some workflows they are genuinely useful. That is the trade. We think, for children's coursework and confidential writing, it is the right one.
Run a scan with reasons at isitai.co.uk, three free checks a day. The essay stays yours.
Frequently asked questions
Do AI detectors store the text you paste in?
Most do. GPTZero stores submissions and uses them for model improvement unless on an enterprise plan, Copyleaks and Winston store by default, ZeroGPT stores with a limited public retention policy, and Turnitin keeps work in the institutional repository under the school's licence. Pangram deletes within 30 days of account closure and states no training use. Is It AI does not store submitted text on any tier.
Is it a GDPR problem to paste a student essay into a free AI detector?
It can be. A student essay is personal data, the school is the data controller, and a detector vendor processing it is a data processor, which formally requires a lawful basis and a Data Processing Agreement. Free-tier tools are rarely covered by any agreement the school has signed. The safest positions are a tool that does not store text at all, or a vendor under a proper DPA with retention and training-use clauses reviewed.
Can AI detectors use my text to train their models?
Several reserve that right in their published terms, and GPTZero states free-tier submissions may be used for model improvement. For schools, a model-training clause on student work should be removed by agreement or the supplier ruled out. For writers, it means unpublished client copy could become training data. Ask the vendor to confirm training use in writing, and whether it can be switched off.
What should a school ask a detector vendor about data handling?
Five things. How long is submitted text stored and can deletion be guaranteed? Is it used to train models, and can that be excluded in writing? Where is it processed and hosted, and does that survive a UK or EU transfer review? Will the vendor sign a Data Processing Agreement appropriate for children's data? And can the student see what was flagged, so the process is defensible in an appeal?