PrivacyGDPRSchoolsData HandlingAI Detection

What Happens to Text You Paste Into an AI Detector?

When a teacher pastes a students essay into a free AI detector, where does it go? Retention, model-training use and deletion policies across every major detector, what GDPR actually requires of UK and EU schools, and the questions to ask before pasting anything confidential.

Paul Byrne··5 min read


Here is a moment that happens thousands of times a day. A teacher suspects an essay, finds a free AI detector, pastes the whole thing in and clicks scan. In three seconds they have a percentage. What they usually have not asked is where the essay just went, how long it will be kept, and whether it is now training data for someone's model.

That question matters more than the score, because a student essay is not anonymous text. It is a child's personal data, often with their name at the top, and pasting it into a third-party service is a data transfer whether or not anyone thought of it that way.

What each detector does with your text

This table summarises published vendor policies as of July 2026. Policies change; the linked source is always the authority.

DetectorStores submissions?Used to train models?Notes

Is It AI?No, on any tierNoText is processed for the scan and not stored after it completes
PangramWhile account is open; deleted within 30 days of closureStates no training useActs as a FERPA 'School Official' for US education customers
GPTZeroYesFor model improvement, unless on an enterprise planThe default for the free tier most teachers use
CopyleaksYes by defaultPer published termsEnterprise tier offers a no-storage option
TurnitinYes, institutional repositoryPer the school's licence agreementGoverned by the DPA your school signed
Originality.aiYes, per default settingsPer published termsBuilt for content teams, not children's data
Winston AIYes, per default settingsPer published termsReview the DPA for education use
ScribbrRetained per published policyPer published termsEU hosted
ZeroGPTYesUnclearLimited public retention policy; poorest fit for confidential text

The pattern is worth stating plainly: most detectors store what you paste, several reserve the right to learn from it, and the free tiers, the ones teachers actually use, generally have the weakest protections.

Why this is a legal question for UK and EU schools, not a preference

Under UK and EU GDPR, a school is the data controller for its students' work. Paste an essay into a detector and the school has engaged a data processor, which formally requires a lawful basis and a Data Processing Agreement, the thing nobody signs before using a free web tool at 9pm on a Sunday. The DfE's generative AI guidance for schools points the same direction: know where pupil data goes before a tool touches it.

Two specific clauses decide everything in a review. Retention: how long is the text kept and can the school have it deleted? And training use: does the vendor reserve the right to improve its models on submissions? Our position in the schools comparison stands: a model-training clause on student work needs to be removed, or the supplier ruled out.

There is also a fairness dimension the JCQ guidance on AI in assessments implies but schools rarely operationalise: if a student's work is scanned, stored and flagged by a system the student cannot see, the process is hard to defend in an appeal. Data handling and fair process are the same conversation.

If you are a writer rather than a teacher

The same table applies with a different threat model. Unpublished client copy, embargoed announcements and manuscripts are confidential commercial material. Pasting them into a storing detector puts them on someone else's server under terms you have not read, and in the worst case into a training set. For casual checks of your own public writing, any tool is fine. For client work, use a detector that does not store, or get your client's view first, and see our content-creator comparison for how the popular tools differ.

Five questions to ask any detector vendor

  • Is submitted text stored after the scan completes, and for how long?

  • Is it ever used to train or improve models, and can that be switched off in writing?

  • Where is it processed and hosted, and does that survive a UK/EU transfer review?

  • Will you sign a Data Processing Agreement suitable for children's data?

  • Can the student or writer see what was flagged, so the process is defensible?

A vendor that answers all five quickly is telling you something. So is a vendor that cannot.

Our position, including the trade-off

Is It AI? does not store submitted text, on any tier including free. Not stored means not breachable, not trainable and not subject to a retention argument, which keeps a school's GDPR review short.

Honesty requires naming the cost: because we keep nothing, we cannot show you a scan history, re-open last week's report, or de-duplicate a resubmission. Tools that store your text can do those things, and for some workflows they are genuinely useful. That is the trade. We think, for children's coursework and confidential writing, it is the right one, and it is why the no-storage line has been our design constraint from the start rather than a feature toggle.

Run a scan with reasons at isitai.co.uk, three free checks a day. The essay stays yours.

Frequently asked questions

Do AI detectors store the text you paste in?

Most do. GPTZero stores submissions and uses them for model improvement unless on an enterprise plan, Copyleaks and Winston store by default, ZeroGPT stores with a limited public retention policy, and Turnitin keeps work in the institutional repository under the school's licence. Pangram deletes within 30 days of account closure and states no training use. Is It AI does not store submitted text on any tier.

Is it a GDPR problem to paste a student essay into a free AI detector?

It can be. A student essay is personal data, the school is the data controller, and a detector vendor processing it is a data processor, which formally requires a lawful basis and a Data Processing Agreement. Free-tier tools are rarely covered by any agreement the school has signed. The safest positions are a tool that does not store text at all, or a vendor under a proper DPA with retention and training-use clauses reviewed.

Can AI detectors use my text to train their models?

Several reserve that right in their published terms, and GPTZero states free-tier submissions may be used for model improvement. For schools, a model-training clause on student work should be removed by agreement or the supplier ruled out. For writers, it means unpublished client copy could become training data. Ask the vendor to confirm training use in writing, and whether it can be switched off.

What should a school ask a detector vendor about data handling?

Five things. How long is submitted text stored and can deletion be guaranteed? Is it used to train models, and can that be excluded in writing? Where is it processed and hosted, and does that survive a UK or EU transfer review? Will the vendor sign a Data Processing Agreement appropriate for children's data? And can the student see what was flagged, so the process is defensible in an appeal?

Try Is It AI?

Detect AI-generated content instantly. 3 free scans per day.

Scan Content Now

Free AI text check

Free, no signup

Try Now