Data protection
Privacy policy
How ParaTrace handles your data, and the rights you have under the GDPR. Updated 9 October 2026.
Diese Datenschutzerklärung auf Deutsch
Who is responsible
Empirisch Tech GmbH, Rennweg 88, 1030 Vienna, Austria, runs paratrace.net and the ParaTrace API and is responsible for the data processed here. For anything about your data, use the contact form, write to us at that address or call +43 1 2396082. The Impressum has our full company details.
In short
- We use your data to run ParaTrace, and we don't sell it.
- Texts you check on the website stay in your history until you delete them. Texts checked without an account, and texts sent to the developer API, are scored and not stored.
- Fonts and the site itself come from our own server. Code from others loads only for the bot check on our forms and for Google's sign-in button on the sign-in and sign-up pages, and on the front page once its free checks are used up.
Visiting the website
When you open a page, your browser sends us its IP address, the page it asks for, the time, the page it came from and its name and version. Our web server needs these to deliver the page, and records them in a log to find faults and fend off attacks.
- Legal basis
- Our legitimate interest in running a working and secure website (Art. 6(1)(f) GDPR).
- Kept for
- 14 days, then the log is deleted.
Signing up and your account
You get an account at once by signing in with Google or Microsoft, or by signing up with your email address. To sign up you give us your email address, a password you choose, your role and what you want to check. We email you a link to confirm your address, and the account works once you open it. The link works once and expires after 48 hours. Your account holds your email address, role, password, credit balance, whether the address is confirmed and whether the account is active. Signing in with a password sends your email address and password with each request.
If you ask for more credits, we receive your message and email address by email so that we can answer.
- Purpose
- Confirming your email address, running your account and counting your credits.
- Legal basis
- Providing the service you asked for (Art. 6(1)(b) GDPR).
- Kept for
- As long as your account exists. You can delete it yourself any time on the Your account page, which also deletes your history, your API key and your sign-ins with Google and Microsoft.
Signing in with Google
You can sign in with your Google account instead of a password. Google's sign-in button on our sign-in and sign-up pages, and on the front page once its free checks are used up, loads from Google, so Google receives your IP address and details of your browser when you open those pages. You choose your account in Google's own window, and Google tells us your email address, your name and an ID for your Google account. We never see your Google password.
If you have no ParaTrace account yet, one is created at once with your email address. If you have one with the same email address, Google sign-in is added to it, and its address counts as confirmed. Your browser then gets a sign-in token from us, valid for 30 days, and signing out ends it.
Google Ireland Limited handles the sign-in under its own privacy policy.
- Legal basis
- Providing the service you asked for (Art. 6(1)(b) GDPR). Loading Google's button on those pages rests on our legitimate interest in offering sign-in with Google (Art. 6(1)(f) GDPR).
- Kept for
- As long as your account exists. Deleting it removes the link to your Google account and signs out every browser signed in with Google.
Signing in with Microsoft
You can also sign in with a Microsoft account, personal or from work or school. No code from Microsoft loads on our pages: its button takes you to Microsoft's own sign-in page, so Microsoft receives your IP address and details of your browser only once you choose it. You choose your account there, and Microsoft tells us your email address, your name and IDs for your account and, for a work or school account, your organization. We never see your Microsoft password.
If you have no ParaTrace account yet, one is created at once with your email address. If you have one with the same email address, you are signed in to it. Your browser then gets a sign-in token from us, valid for 30 days, and signing out ends it.
Microsoft Ireland Operations Limited handles the sign-in under its own privacy statement.
- Legal basis
- Providing the service you asked for (Art. 6(1)(b) GDPR).
- Kept for
- As long as your account exists. Deleting it signs out every browser signed in with Microsoft.
Contacting us
When you write to us with the contact form, we receive your name, email address, subject and message, and use them to answer you.
- Legal basis
- Answering questions about using ParaTrace (Art. 6(1)(b) GDPR), and otherwise our legitimate interest in answering the people who write to us (Art. 6(1)(f) GDPR).
- Kept for
- As long as we need it to deal with your message.
Checking texts
When you check a text on the website, we receive the text or file and the time. The detector scores them, and we store the texts with their verdicts and the credits they cost in your history.
Please don't submit texts that contain personal data, such as names, contact details or anything about someone's health or private life. If you check texts written by others, such as essays, make sure you are allowed to.
- Purpose
- Scoring your texts, showing the results and keeping your history.
- Legal basis
- Providing the service you asked for (Art. 6(1)(b) GDPR).
- Kept for
- Until you delete the check in your history or delete your account. Either removes its texts, verdicts and files from our server.
Free checks without an account
On the front page you can check a few texts a day without an account. We receive the text and your IP address. The detector scores the text and we send back the verdict, without storing the text or the verdict.
To count the free checks, the server keeps your IP address in its memory until the next midnight UTC, then forgets it. Everyone on the same network shares one count.
- Purpose
- Scoring your text, and limiting free checks per network so the service stays available.
- Legal basis
- Providing the service you asked for (Art. 6(1)(b) GDPR) for the text, and our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR) for counting by IP address.
- Kept for
- The text is not stored. Your IP address stays in memory until the next midnight UTC.
The browser extension
The ParaTrace extension for Chrome checks texts with your ParaTrace account. It reads a page only when you ask it to, by clicking Check this page or by choosing a check from the right-click menu. It then sends us the page's text, or the text you selected, and the page's title, and we handle them as a check on the website. The title becomes the check's name in your history. The extension doesn't send us the page's address, and it reads nothing from pages you don't ask it to check.
On a YouTube video, the extension checks the video by its transcript, when you click Check this video or choose a page check from the right-click menu. It asks YouTube for the transcript from your browser, with your YouTube session, as the Show transcript panel under the video does, and opens that panel if YouTube doesn't answer otherwise. To YouTube this looks as if you had opened the transcript yourself. We receive only the transcript and the video's title, and nothing about your YouTube account.
The extension keeps your sign-in in Chrome, together with your credit balance. After a password sign-in, your email address and password stay in Chrome's memory until Chrome closes. After signing in with Google, your email address and a sign-in token stay until you sign out, and the token expires after 30 days. Signing in with Google opens Google's own window, and Google tells us the same details as on the website. The extension sends nothing to anyone but us.
- Purpose
- Checking the texts you choose, and keeping you signed in.
- Legal basis
- Providing the service you asked for (Art. 6(1)(b) GDPR).
- Kept for
- Checks as on the website. The sign-in until you sign out, Chrome closes or the token expires. Removing the extension deletes everything it keeps.
The developer API
Your API key comes with your account. You create it on your API key page, where you can look it up whenever you need it, and it is never emailed. A new key has 1,000 free credits. We keep the key and how many credits it has used. Texts and files you send to the API are scored and not stored, and neither are their results.
- Legal basis
- Providing the service you asked for (Art. 6(1)(b) GDPR).
- Kept for
- As long as your account exists. Deleting your account deletes the key too.
Usage records
For every check, on the website and through the API, we record the date, the number of words, the credits it used and whether it was a fast or a detailed check, together with the email address of the account or API key. We need these records to keep track of credits and to see how ParaTrace is used. They contain no texts and no verdicts.
- Legal basis
- Keeping track of credits (Art. 6(1)(b) GDPR), and our legitimate interest in knowing how ParaTrace is used (Art. 6(1)(f) GDPR).
- Kept for
- Until you delete your account. Then your email address is removed, and only anonymous counts remain that can't be linked to you.
Bot check
The forms for signing up, contacting us and free checks use Turnstile from Cloudflare, Inc. to tell people from bots. To do that, Cloudflare receives your IP address and technical details of your browser.
- Legal basis
- Our legitimate interest in keeping automated abuse out (Art. 6(1)(f) GDPR).
What we store in your browser
These are all the items ParaTrace keeps in your browser. Only the ones marked as needing consent wait for your answer. The others are needed for the features you use (§165(3) of the Austrian TKG 2021), and none of them is sent to anyone else.
| Name | What it holds | Kept until |
|---|---|---|
paratrace.sessionLocal storage after signing in with Google or Microsoft, otherwise session storage | Your email address and either a sign-in token from signing in with Google or Microsoft, so you stay signed in in every tab, or your password, so a reload keeps you signed in. They are sent with each request you make. | You sign out. With a password also when you close the tab, with Google or Microsoft after 30 days at most |
paratrace.returnToSession storage | While you sign in with Microsoft, the page to take you back to afterwards. | You are signed in, or you close the tab |
paratrace.marketplaceTokenSession storage | When you come from the Azure Marketplace, the token that names your subscription, until it is linked to your account. | Your subscription is linked, or you close the tab |
msal.*Session storage | Microsoft's sign-in library keeps the state of a sign-in with Microsoft here, to finish it once Microsoft sends you back, and briefly Microsoft's answer. | You are signed in, or you close the tab |
paratrace.submissionsSession storage | The texts of your last 20 checks in this tab, to show them next to their results. | You sign out or close the tab |
react-router-scroll-positionsSession storage | Where you were on each page, to take you back there. | You close the tab |
paratrace.consentLocal storage | Your answer to the cookie question, so we don't ask again. | You change it or clear your browser data |
Who receives data
We don't sell your data or share it for advertising. These companies process data for us.
- Cloudflare, Inc. runs the bot check on our forms.
- Google Ireland Limited handles signing in with Google.
- Microsoft Ireland Operations Limited handles signing in with Microsoft.
- Our email provider delivers the emails we send you, such as the link to confirm your email address.
Some of these companies may process data in the USA. They are certified under the EU-US Data Privacy Framework, for which the European Commission has decided that the protection is adequate (Art. 45 GDPR).
Your rights
You have the right to
- know what data we hold about you and get a copy (Art. 15 GDPR)
- have wrong data corrected (Art. 16)
- have your data deleted (Art. 17)
- have its processing restricted (Art. 18)
- get the data you gave us in a machine-readable form (Art. 20)
- object to processing based on our legitimate interest (Art. 21)
- withdraw a consent any time, without affecting what happened before (Art. 7(3))
To use them, use the contact form, write to us at the address above or call us. You can also complain to the Austrian data protection authority, the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
Automated decisions
The detector scores texts automatically, but its verdicts are statistical estimates about a text, not decisions about you. We make no decisions about people based on them, and nobody should use a verdict as the sole basis for a decision about a person.
Changes to this policy
When ParaTrace changes what it does with data, we update this page and its date. If a change needs your consent, we ask for it again.