Privacy Policy.
How Noplag handles the documents you check, the fingerprints we store, and the rights you have over your data. Written to be read, not to hide behind. The short version: we never train models on your documents, and you can delete everything we hold in one click.
This policy explains what Noplag collects when you check a document, how we handle the text you submit, what the Noplag Database stores, and the rights you have under GDPR and similar laws. It applies to noplag.com, the Noplag API, and the self-hosted engine where we operate it on your behalf. Plain-language summaries open each section; the detail follows.
Who we are and what this covers
Noplag is an open-core plagiarism and AI-content detection service operated by Noplag Labs, Inc. For checks you run on noplag.com or through our hosted API, Noplag Labs, Inc. is the data controller. When your institution runs Noplag under its own contract — through an LMS integration, an enterprise agreement, or a self-hosted deployment — your institution is the controller and Noplag acts as a processor on its instructions.
This policy covers personal data only. The separate Terms of Service govern your use of the product, and the Data Processing Agreement covers institutional deployments.
What we collect
Account data — your name, email, and authentication identifiers (or, for SSO and LMS launches, only the opaque identifier your institution passes us). Billing is handled by our payment processor; we store a customer reference, not your card number.
Documents you submit — the text or files you check, held only as long as needed to produce and show you the report (see Retention).
Usage and technical data — check metadata, the engine commit a report ran on, IP address, and basic device information, used to operate the service and prevent abuse.
How we use your data
To run your checks and return reports; to maintain your account, history, and folders; to provide support; to bill paid plans; to keep the service secure; and to meet legal obligations. We do not sell your personal data, and we do not use it for advertising.
Your documents are never training data
The documents you submit are never used to train detection models, language models, or any other machine-learning system — ours or anyone else's. Our detector is pre-trained on public corpora and ships as an auditable Apache 2.0 engine; customer submissions are not added to it, ever. This is a contractual commitment, not just a policy preference, and it is restated in every institutional DPA.
Submitted text is reduced to non-reversible winnowing hashes for matching, shown back to you in your report, and then purged on the schedule below. The model never sees your corpus as training input.
The Noplag Database (opt-out)
Documents you check are added to the Noplag Database — a private index that lets a later check detect passages copied from an earlier submission. We store anonymized fingerprints, never the original text, and matches are always shown anonymously: a later user sees only that a passage “matches a private submission,” never your identity, the document's title, or when it was submitted.
Contribution is on by default, and you can opt out — at signup, per upload, or any time under Settings → Data & retention. It works the same on every plan: Free, Pro, and Enterprise all contribute and all benefit from the matching. We disclose this clearly at signup, not buried in the fine print.
Retention and deletion
Free-tier document content is purged 30 days after a check completes. Paid tiers can configure a shorter or longer window (30 / 60 / 90 days) or disable retention entirely. Account data is kept while your account is active and for a short period afterward for legal and accounting reasons.
Beyond the retention window the document text is deleted. Anonymized fingerprints stay in the Noplag Database to power future matching — unless you've opted out, or you delete the submission or your account, in which case they're hard-purged within 30 days too.
Your rights
Under GDPR, UK GDPR, and similar laws you can exercise the following rights over the personal data we hold. Most are self-serve in your account settings; for anything else, email privacy@noplag.com and we respond within 30 days.
- Access — get a copy of the data we hold about you.
- Erasure — delete your account and every fingerprint, document hash, and report we hold, completed within 24 hours.
- Rectification — correct inaccurate account data.
- Portability — export your checks and reports in a machine-readable format.
- Objection & restriction — object to, or restrict, specific processing.
- Opt out — turn off Noplag Database contribution at signup, per upload, or any time in settings.
Sub-processors and sharing
We use a short list of vetted sub-processors for hosting, payments, email, and error monitoring. The current list, with each provider's role and region, is published at noplag.com/legal/sub-processors and updated before any change takes effect. We never sell personal data, and we share it only with these sub-processors, with your institution where it is the controller, or where the law requires it.
Where your data lives
Our default infrastructure is EU-based. Paid plans can pin processing to an EU-residency endpoint, and enterprise customers can self-host the engine entirely inside their own network so that no submission ever leaves their infrastructure. Where data is transferred outside the EEA, we rely on Standard Contractual Clauses and equivalent safeguards.
Security
Data is encrypted in transit and at rest, access is role-scoped and logged, and every report is stamped with the engine commit and corpus snapshot that produced it so results stay reproducible and auditable. We publish our security posture and current compliance reports at noplag.com/security.
Changes and how to reach us
We'll post any material change here and, for significant changes, notify account holders by email before it takes effect. The date at the top of this page always reflects the current version.
Questions, requests, or a data-protection concern? Email privacy@noplag.com. EU and UK users can also contact our Data Protection Officer at dpo@noplag.com.