Privacy notice
What this service stores, what it does not, and who else sees anything. The short version: the text you submit is discarded by default; signed-in scans keep a signed record — the hash and the numbers — and the text only if you choose to keep it; the only cookies are the ones that keep you signed in.
1. Who is responsible
ROGA AI LIMITED, registered in Gibraltar under number 125994, registered office Unit G02, Eurocity, Europort Avenue, Gibraltar, GX11 1AA, is the controller for personal data described here. Contact: legal@rogaai.com.
2. The text you submit is discarded by default
Text you paste — and any file you upload (.txt, .md, .docx, .pdf) — is processed in memory to produce a result and then discarded. Uploaded files are parsed to extract their text and are not saved to disk, object storage or anywhere else. If you run a source check, short quoted excerpts (about ten words each) are sent to our search service to find matching pages; the stored result keeps URLs, counts and character offsets — not your text. It is not written to a database, not logged, and not used to train anything. The text is sent from our servers to the inference service that runs Nota, scored in memory, and discarded there too; your browser never talks to a model host.
If you are signed in, each scan keeps its signed Nota Record: model version, word count, probability, band, whether the model abstained, the measured false-positive rate, the character check as counts, the source check when you ran it (URLs, counts and character offsets), and a SHA-256 of the submitted text — a fingerprint that identifies the exact bytes without containing them. The text itself is not stored by default; the complete, text-bearing record exists only in the file you download at scan time. If you switch on “keep the document in my record”, that scan’s stored record carries the text inside its signed body — your choice, per scan, off unless you turn it on. Batch jobs hold their input while queued or running and clear it when they finish, keeping only the result numbers and the file names you gave the documents.
3. What we do store
| Data | Why | Kept |
|---|---|---|
| Email address, and display name if given | To create and authenticate your account | Until you delete the account |
| Plan, subscription status, and a Stripe customer reference | To run the plan you bought | While you have an account; Stripe keeps its own billing records |
| Words used per day, and scan metadata | To meter your quota and show you your usage | Rolled up daily; deleted with the account |
| API key name, prefix, and a SHA-256 hash of the key | To authenticate API calls; the key itself is shown once and never stored | Until you revoke it or delete the account |
| Usage counts per endpoint per day, with timing | To keep the service running and show your usage | Rolled up daily; deleted with the account |
Usage counters record nothing about the content of requests. Anonymous use is rate-limited per address: a counter keyed by the address is kept for the length of the rate window (one minute) and then overwritten; it is tied to no account and no content, and is not used for anything else.
4. Cookies and browser storage
Signing in sets the authentication cookies of our identity provider (Supabase) so that your session survives a page load. They are strictly necessary and are removed when you sign out. Detect keeps the text you were about to check in your browser’s session storage only long enough to move from the home page to the detect page. No advertising or cross-site cookies are set.
5. Analytics
If we count page views we use a cookieless, aggregate tool that does not build a profile of you or follow you across sites, and it does not load unless you allow it.
6. Who else processes data
- Supabase — authentication and database hosting, for accounts, plans, quotas, API keys, scan history and usage counters.
- Vercel — hosting and delivery of the site. Vercel processes request metadata, including IP addresses, as part of serving and protecting the site.
- Railway and our inference provider — run batch jobs and the Nota model. They receive the text of a scan in memory and nothing about who you are beyond an opaque job identifier.
- Stripe — payment processing for paid plans. We never see your card details.
Typefaces are served through the site build rather than a third-party font host. We do not sell personal data, and we do not share it for advertising.
7. Legal basis and international transfers
Where the UK GDPR or EU GDPR applies, we rely on contract, for running an account or plan you asked for; legitimate interests, for keeping the service secure and for aggregate usage counts; and consent, for optional analytics, which you may withdraw at any time. Our processors may store or process data outside Gibraltar, including in the EU, the UK and the United States, under the transfer safeguards those providers offer.
8. Your rights
Subject to applicable law, you may request access to your personal data, correction, deletion, a portable copy, or restriction of processing, and you may object to processing based on legitimate interests. Deleting your account removes your profile, plan record, API keys, scan history and usage counters. Write to legal@rogaai.com. You also have the right to complain to your local data protection authority.
9. Security, children, and changes
API keys are stored only as SHA-256 hashes, passwords are handled by our authentication provider and never seen by us, and database access is restricted per user by row-level security. No system is perfectly secure, and we do not claim otherwise. The service is not intended for children under 16. We may update this notice; the effective date above will change, and material changes will be signalled in the interface.