Last updated: 18 August 2026
Summary
Is It AI? processes content you submit for AI detection analysis and does not store it. We keep the detection result, the score and the timestamp, never the text itself. We collect minimal personal data required to provide our service. You have full rights over your data under GDPR.
Reviewing us for a school? The school data protection summary sets out what is sent where, and for how long, in one page for your DPO.
1. Data Controller
Is It AI? ("we", "us", "our") is the data controller responsible for your personal data.
Contact: hello@isitai.co.uk
2. Information We Collect
2.1 Information You Provide
- Account Data: Email address and password (encrypted) when you create an account
- Content for Analysis: Text or URLs you submit for AI detection. Your submitted text is not stored. It is held in memory only for as long as the scan takes, then discarded. We retain the detection result, the score and the timestamp, which is what produces your scan history if you have an account. To avoid re-billing repeated scans of identical text, we also keep, for up to 24 hours, a one-way content fingerprint (a SHA-256 hash) together with the scores and the positions of any flagged passages. That record contains no words from your text and no notes about it, and the text cannot be reconstructed from it.
- Contact Information: Name, email, and message content if you contact us through our contact form
- Payment Information: Processed securely by Stripe. We do not store your full card details
2.2 Automatically Collected Information
- Usage Data: Scan timestamps, feature usage, and aggregate statistics
- IP Address: Hashed for rate limiting (free users). Full IP is not stored
- Device Information: Browser type, operating system (for compatibility and analytics)
- Cookies: Essential cookies for authentication and optional analytics cookies (with your consent)
3. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract Performance (Article 6(1)(b)): Processing necessary to provide our AI detection service to you
- Legitimate Interests (Article 6(1)(f)): Rate limiting, fraud prevention, security, and improving the service using aggregate usage data, never your submitted text
- Consent (Article 6(1)(a)): Analytics cookies and marketing communications (where applicable)
- Legal Obligation (Article 6(1)(c)): Tax records and compliance with legal requirements
4. How We Use Your Information
- To perform AI detection analysis on your submitted content
- To create and manage your account
- To process payments and manage subscriptions
- To enforce rate limits and prevent abuse
- To improve our detection methodology, using our own labelled calibration corpora and aggregate usage statistics; submitted text is never retained or used for this
- To send account-related notifications (password resets, billing)
- To respond to your support requests
- To comply with legal obligations
5. Data Sharing and Third Parties
We share data with the following categories of recipients:
5.1 AI Analysis Provider
Your submitted content is sent to one external provider: Anthropic, whose Claude API performs the language-model part of the analysis. The text is transmitted securely, processed for the duration of the request, and handled under Anthropic's API data policy, which does not use API inputs to train its models by default. No other third party receives your submitted text.
5.2 Service Providers
- Anthropic: AI analysis of submitted text (see 5.1)
- Stripe: Payment processing (PCI-DSS compliant). Stripe never receives your submitted text
- Vercel: Hosting and infrastructure
- Prisma Postgres: Database hosting for account data and scan-history metadata
- Resend: Transactional email (welcome, password reset, billing). Emails never contain your submitted text
5.3 We Do Not
- Sell your personal data to advertisers or data brokers
- Share your data for marketing purposes without consent
- Store the content you submit for analysis, in whole or in part
- Share your submitted content with any third parties for purposes other than AI detection
6. International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Our providers (Anthropic, Stripe, Vercel, Resend, Prisma) process data under their published data-processing terms
- Encryption of data in transit and at rest
7. Data Retention
| Data Type | Retention Period |
|---|
| Submitted content | Not stored. Held in memory for the scan, then discarded. A one-way hash plus scores and passage positions (no text) is kept up to 24 hours to avoid re-billing identical scans |
| Hashed IP (rate limiting) | 24 hours |
| Account data | Until account deletion |
| Scan history (logged-in users) | Until account deletion |
| Payment records | 7 years (legal requirement) |
| Contact form submissions | 2 years |
Before 17 August 2026, a short preview (the first 200 characters) of submitted text was retained alongside the scan record. That practice ended on 17 August 2026 and every previously stored preview was deleted, along with all cache entries written before the change. No submitted text, in whole or in part, is stored anywhere since that date.
8. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data. You can export your data from your dashboard.
- Right to Rectification (Article 16): Request correction of inaccurate data
- Right to Erasure (Article 17): Request deletion of your data. You can delete your account from your dashboard.
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format (JSON export available)
- Right to Restrict Processing (Article 18): Request limitation of processing in certain circumstances
- Right to Object (Article 21): Object to processing based on legitimate interests
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time
To exercise these rights, email hello@isitai.co.uk or use the self-service options in your dashboard.
9. Cookies
We use the following types of cookies:
- Essential Cookies: Required for authentication and security. Cannot be disabled.
- Analytics Cookies: Help us understand how visitors use our site. Only set with your consent.
You can manage cookie preferences through our cookie consent banner or your browser settings.
10. Security
We implement appropriate technical and organizational measures to protect your data:
- 256-bit TLS/SSL encryption for all data in transit
- Encrypted database storage
- Passwords hashed using bcrypt
- API keys stored as SHA-256 hashes; the key itself is never stored (only a 12-character prefix is kept for display)
- Regular security audits
- Access controls and authentication for all systems
11. Children's Privacy
Is It AI? is not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by email (if you have an account) and by posting a notice on our website. The "Last updated" date at the top shows when this policy was last revised.
13. Complaints
If you have concerns about how we handle your data, you have the right to lodge a complaint with your local data protection authority. In the UK, this is:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113