Privacy Policy & Zero-Retention Notice
Last revised: January 2026 · Compliant with GDPR, CCPA & FERPA standards
1. Executive Summary & Privacy Promise
At PlagiSure (“PlagiSure”, “we”, “us”, or “our”), student privacy and intellectual property confidentiality are fundamental pillars of our organization. We recognize that academic papers, research theses, and dissertations represent months or years of original scholarly effort.
Our privacy architecture operates on a strict Zero-Data-Monetization and Zero-Repository-Retention philosophy. We never sell, lease, commercialize, or share your submitted documents with third-party advertising networks, AI model training scrapers, or academic repository aggregators.
2. The Non-Repository Scanning Lifecycle
The core of our privacy commitment is our guaranteed No-Repository configuration:
Encrypted Upload
Your file is transmitted via 256-bit TLS/SSL encrypted channels into temporary volatile cache.
In-Memory Scan
Turnitin cross-checks your text against web & journal indexes without adding it to any database.
Auto-Purge (30 Days)
Files and reports are permanently deleted after 30 days or immediately upon your request.
When your university subsequently runs its official scan, your paper will never match against PlagiSure because no digital footprint was indexed in Turnitin’s global student repository.
3. Information We Collect
We adhere to data minimization principles and collect only the minimal data strictly necessary to fulfill your verification order:
- Account Identifiers: Your email address and hashed authentication tokens used to grant you secure access to your private report dashboard.
- Uploaded Document Content: The text and formatting of the file you submit solely for the duration of the scan and temporary delivery window.
- Transaction Records: Payment status, transaction reference numbers, date/time, and currency amounts processed through Paystack. (We never see or store your credit card CVV or full card numbers).
- Technical Telemetry: Anonymized server logs, IP addresses for rate-limiting and fraud prevention, browser user-agent, and session cookies.
4. How We Protect Your Data (Security Standards)
PlagiSure employs multi-layered technical and administrative safeguards:
- End-to-End Encryption: All data in transit is protected with TLS 1.3 encryption. All stored report PDFs are encrypted at rest using AES-256 standards.
- Isolated Cloud Architecture: Report generation queues operate in isolated sandboxes with strict access control lists (ACLs) preventing unauthorized cross-user access.
- No Employee Document Browsing: Our automated dispatch systems process files without human intervention unless you explicitly request our human AI Content Removal service or open a support ticket.
5. GDPR & International Privacy Rights
Regardless of your country of residence (European Union, UK, United States, Canada, Australia, Kenya, Nigeria, South Africa, or elsewhere), PlagiSure grants you full international privacy rights:
- Right of Access: You can review and download all historical submissions and generated reports from your dashboard at any time.
- Right to Erasure (“Right to be Forgotten”): You may request instantaneous, permanent deletion of your account and all associated documents by clicking “Delete Data” in your client portal or contacting support.
- Right to Restrict Processing: You may object to any automated processing or request manual review of any billing transaction.
6. Cookies & Tracking Technologies
PlagiSure uses essential session cookies and local storage items strictly necessary for user authentication, dashboard session persistence, and secure checkout routing. We do not deploy third-party behavioral tracking cookies, cross-site pixel trackers, or retargeting marketing tags that monitor your browsing behavior across other websites.
7. Third-Party Subprocessors
To deliver our high-speed service, PlagiSure engages select certified cloud subprocessors that comply with strict data protection agreements:
- Paystack: PCI-DSS Level 1 payment infrastructure for secure payment processing.
- Supabase / Cloudflare R2: Encrypted object storage and transactional database infrastructure.
- Resend / Nodemailer: Transactional email delivery for dispatching report download notifications.
8. Privacy Officer Contact Details
If you have questions regarding this Privacy Policy, wish to exercise your GDPR/CCPA data rights, or require immediate document purging, please reach out to our Data Privacy Officer:
PlagiSure Data Protection Office
Email: privacy@plagisure.online
General Inquiries: plagisure@gmail.com
WhatsApp Hotline: +254 701 066 845