Skip to content
ParaTrace

Unlimited free credit top-ups, for a limited time. Running low? Ask for more credits and we top you up, as often as you need. This offer ends soon, so catch it while it lasts.

Data protection

Privacy policy

How ParaTrace handles your data, and the rights you have under the GDPR. Updated 9 October 2026.

Diese Datenschutzerklärung auf Deutsch

Who is responsible

Empirisch Tech GmbH, Rennweg 88, 1030 Vienna, Austria, runs paratrace.net and the ParaTrace API and is responsible for the data processed here. For anything about your data, use the contact form, write to us at that address or call +43 1 2396082. The Impressum has our full company details.

In short

  • We use your data to run ParaTrace, and we don't sell it.
  • Texts you check on the website stay in your history until you delete them. Texts checked without an account, and texts sent to the developer API, are scored and not stored.
  • Fonts and the site itself come from our own server. Code from others loads only for the bot check on our forms and for Google's sign-in button on the sign-in and sign-up pages, and on the front page once its free checks are used up.

Visiting the website

When you open a page, your browser sends us its IP address, the page it asks for, the time, the page it came from and its name and version. Our web server needs these to deliver the page, and records them in a log to find faults and fend off attacks.

Legal basis
Our legitimate interest in running a working and secure website (Art. 6(1)(f) GDPR).
Kept for
14 days, then the log is deleted.

Signing up and your account

You get an account at once by signing in with Google or Microsoft, or by signing up with your email address. To sign up you give us your email address, a password you choose, your role and what you want to check. We email you a link to confirm your address, and the account works once you open it. The link works once and expires after 48 hours. Your account holds your email address, role, password, credit balance, whether the address is confirmed and whether the account is active. Signing in with a password sends your email address and password with each request.

If you ask for more credits, we receive your message and email address by email so that we can answer.

Purpose
Confirming your email address, running your account and counting your credits.
Legal basis
Providing the service you asked for (Art. 6(1)(b) GDPR).
Kept for
As long as your account exists. You can delete it yourself any time on the Your account page, which also deletes your history, your API key and your sign-ins with Google and Microsoft.

Signing in with Google

You can sign in with your Google account instead of a password. Google's sign-in button on our sign-in and sign-up pages, and on the front page once its free checks are used up, loads from Google, so Google receives your IP address and details of your browser when you open those pages. You choose your account in Google's own window, and Google tells us your email address, your name and an ID for your Google account. We never see your Google password.

If you have no ParaTrace account yet, one is created at once with your email address. If you have one with the same email address, Google sign-in is added to it, and its address counts as confirmed. Your browser then gets a sign-in token from us, valid for 30 days, and signing out ends it.

Google Ireland Limited handles the sign-in under its own privacy policy.

Legal basis
Providing the service you asked for (Art. 6(1)(b) GDPR). Loading Google's button on those pages rests on our legitimate interest in offering sign-in with Google (Art. 6(1)(f) GDPR).
Kept for
As long as your account exists. Deleting it removes the link to your Google account and signs out every browser signed in with Google.

Signing in with Microsoft

You can also sign in with a Microsoft account, personal or from work or school. No code from Microsoft loads on our pages: its button takes you to Microsoft's own sign-in page, so Microsoft receives your IP address and details of your browser only once you choose it. You choose your account there, and Microsoft tells us your email address, your name and IDs for your account and, for a work or school account, your organization. We never see your Microsoft password.

If you have no ParaTrace account yet, one is created at once with your email address. If you have one with the same email address, you are signed in to it. Your browser then gets a sign-in token from us, valid for 30 days, and signing out ends it.

Microsoft Ireland Operations Limited handles the sign-in under its own privacy statement.

Legal basis
Providing the service you asked for (Art. 6(1)(b) GDPR).
Kept for
As long as your account exists. Deleting it signs out every browser signed in with Microsoft.

Contacting us

When you write to us with the contact form, we receive your name, email address, subject and message, and use them to answer you.

Legal basis
Answering questions about using ParaTrace (Art. 6(1)(b) GDPR), and otherwise our legitimate interest in answering the people who write to us (Art. 6(1)(f) GDPR).
Kept for
As long as we need it to deal with your message.

Checking texts

When you check a text on the website, we receive the text or file and the time. The detector scores them, and we store the texts with their verdicts and the credits they cost in your history.

Please don't submit texts that contain personal data, such as names, contact details or anything about someone's health or private life. If you check texts written by others, such as essays, make sure you are allowed to.

Purpose
Scoring your texts, showing the results and keeping your history.
Legal basis
Providing the service you asked for (Art. 6(1)(b) GDPR).
Kept for
Until you delete the check in your history or delete your account. Either removes its texts, verdicts and files from our server.

Free checks without an account

On the front page you can check a few texts a day without an account. We receive the text and your IP address. The detector scores the text and we send back the verdict, without storing the text or the verdict.

To count the free checks, the server keeps your IP address in its memory until the next midnight UTC, then forgets it. Everyone on the same network shares one count.

Purpose
Scoring your text, and limiting free checks per network so the service stays available.
Legal basis
Providing the service you asked for (Art. 6(1)(b) GDPR) for the text, and our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR) for counting by IP address.
Kept for
The text is not stored. Your IP address stays in memory until the next midnight UTC.

The browser extension

The ParaTrace extension for Chrome checks texts with your ParaTrace account. It reads a page only when you ask it to, by clicking Check this page or by choosing a check from the right-click menu. It then sends us the page's text, or the text you selected, and the page's title, and we handle them as a check on the website. The title becomes the check's name in your history. The extension doesn't send us the page's address, and it reads nothing from pages you don't ask it to check.

On a YouTube video, the extension checks the video by its transcript, when you click Check this video or choose a page check from the right-click menu. It asks YouTube for the transcript from your browser, with your YouTube session, as the Show transcript panel under the video does, and opens that panel if YouTube doesn't answer otherwise. To YouTube this looks as if you had opened the transcript yourself. We receive only the transcript and the video's title, and nothing about your YouTube account.

The extension keeps your sign-in in Chrome, together with your credit balance. After a password sign-in, your email address and password stay in Chrome's memory until Chrome closes. After signing in with Google, your email address and a sign-in token stay until you sign out, and the token expires after 30 days. Signing in with Google opens Google's own window, and Google tells us the same details as on the website. The extension sends nothing to anyone but us.

Purpose
Checking the texts you choose, and keeping you signed in.
Legal basis
Providing the service you asked for (Art. 6(1)(b) GDPR).
Kept for
Checks as on the website. The sign-in until you sign out, Chrome closes or the token expires. Removing the extension deletes everything it keeps.

The developer API

Your API key comes with your account. You create it on your API key page, where you can look it up whenever you need it, and it is never emailed. A new key has 1,000 free credits. We keep the key and how many credits it has used. Texts and files you send to the API are scored and not stored, and neither are their results.

Legal basis
Providing the service you asked for (Art. 6(1)(b) GDPR).
Kept for
As long as your account exists. Deleting your account deletes the key too.

Usage records

For every check, on the website and through the API, we record the date, the number of words, the credits it used and whether it was a fast or a detailed check, together with the email address of the account or API key. We need these records to keep track of credits and to see how ParaTrace is used. They contain no texts and no verdicts.

Legal basis
Keeping track of credits (Art. 6(1)(b) GDPR), and our legitimate interest in knowing how ParaTrace is used (Art. 6(1)(f) GDPR).
Kept for
Until you delete your account. Then your email address is removed, and only anonymous counts remain that can't be linked to you.

Bot check

The forms for signing up, contacting us and free checks use Turnstile from Cloudflare, Inc. to tell people from bots. To do that, Cloudflare receives your IP address and technical details of your browser.

Legal basis
Our legitimate interest in keeping automated abuse out (Art. 6(1)(f) GDPR).

What we store in your browser

These are all the items ParaTrace keeps in your browser. Only the ones marked as needing consent wait for your answer. The others are needed for the features you use (§165(3) of the Austrian TKG 2021), and none of them is sent to anyone else.

Items stored in your browser
NameWhat it holdsKept until
paratrace.sessionLocal storage after signing in with Google or Microsoft, otherwise session storageYour email address and either a sign-in token from signing in with Google or Microsoft, so you stay signed in in every tab, or your password, so a reload keeps you signed in. They are sent with each request you make.You sign out. With a password also when you close the tab, with Google or Microsoft after 30 days at most
paratrace.returnToSession storageWhile you sign in with Microsoft, the page to take you back to afterwards.You are signed in, or you close the tab
paratrace.marketplaceTokenSession storageWhen you come from the Azure Marketplace, the token that names your subscription, until it is linked to your account.Your subscription is linked, or you close the tab
msal.*Session storageMicrosoft's sign-in library keeps the state of a sign-in with Microsoft here, to finish it once Microsoft sends you back, and briefly Microsoft's answer.You are signed in, or you close the tab
paratrace.submissionsSession storageThe texts of your last 20 checks in this tab, to show them next to their results.You sign out or close the tab
react-router-scroll-positionsSession storageWhere you were on each page, to take you back there.You close the tab
paratrace.consentLocal storageYour answer to the cookie question, so we don't ask again.You change it or clear your browser data

Who receives data

We don't sell your data or share it for advertising. These companies process data for us.

  • Cloudflare, Inc. runs the bot check on our forms.
  • Google Ireland Limited handles signing in with Google.
  • Microsoft Ireland Operations Limited handles signing in with Microsoft.
  • Our email provider delivers the emails we send you, such as the link to confirm your email address.

Some of these companies may process data in the USA. They are certified under the EU-US Data Privacy Framework, for which the European Commission has decided that the protection is adequate (Art. 45 GDPR).

Your rights

You have the right to

  • know what data we hold about you and get a copy (Art. 15 GDPR)
  • have wrong data corrected (Art. 16)
  • have your data deleted (Art. 17)
  • have its processing restricted (Art. 18)
  • get the data you gave us in a machine-readable form (Art. 20)
  • object to processing based on our legitimate interest (Art. 21)
  • withdraw a consent any time, without affecting what happened before (Art. 7(3))

To use them, use the contact form, write to us at the address above or call us. You can also complain to the Austrian data protection authority, the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

Automated decisions

The detector scores texts automatically, but its verdicts are statistical estimates about a text, not decisions about you. We make no decisions about people based on them, and nobody should use a verdict as the sole basis for a decision about a person.

Changes to this policy

When ParaTrace changes what it does with data, we update this page and its date. If a change needs your consent, we ask for it again.