Account and privacy
Where your documents live, how long they're kept, what we never do with them, and how to delete your data.
Where your data lives
Noplag's production infrastructure runs in the EU. Your documents and reports are stored there and protected with row-level isolation between accounts.
What we never do
Two hard commitments
We never train AI models on your documents — not ours, not anyone else's. And we never sell your content or share it with third parties beyond the processors needed to run the service (hosting, payments).
The Noplag Database
Documents submitted for checking may be added to the Noplag Database — the corpus that protects submitted work from being plagiarized later. If someone else checks text copied from your document, it will match, anonymously. You can opt out; The Noplag Database explains what it stores and what a match reveals.
Deleting your data
- Deleting a check permanently removes it and its report — available in the app today, from the check's actions menu.
- Self-serve account deletion is not in the app yet (it ships with the data-and-retention settings). Until then, contact support to request it; deletion removes your profile and sessions, checks and reports, uploaded documents, folders, and your documents' Noplag Database fingerprints.
For GDPR requests, contact support — the address is in the Privacy Policy.
Compliance posture
Noplag does not currently claim SOC 2, ISO 27001, or similar certifications — audits are on the roadmap, and we won't claim them before they're held. What we offer today instead is verifiable: the detection engine is open source and self-hostable, so the strongest privacy option — running it entirely on your own infrastructure — doesn't require trusting us at all.