UnPlagiarize ยท Web

Privacy Policy

Privacy Policy for UnPlagiarize on the web

1. Who we are

UnPlagiarize on the web, at unplagiarize.vibecoredigital.com, is built by VibeDeV and operated by VIBECORE DIGITAL, British Columbia, Canada (“we”, “us”, “our”). This policy explains what the website does with information, in the same plain language we try to use everywhere else in the product.

This page covers the browser version only. The Android and iOS apps behave differently in three ways that matter here — they can be used without an account, they show advertisements, and they are where purchases happen — so each has its own policy, and this one does not apply to them.

The short version. You do have to sign in here, and section 2 explains why the browser is the one place we ask. Your documents stay in this browser and are never uploaded, along with the reports and rewrites saved against them. Text leaves your browser only when you ask for a cloud check, rewrite, explanation or page reading, and when it does it is not kept as a record. One exception, and it is apart from a problem report you choose to send us, the only place your own text is held at all: a finished result can sit in a cache for up to one hour, keyed to that one request, so that a request interrupted by a lost connection can be handed back to you instead of charged to you a second time. It is swept automatically, and Settings → Delete my server data erases it. There is no advertising of any kind on this site, no advertising identifier, and no analytics. Nothing is sold here either. We do not sell your information to anyone, and nothing you write is used to train any model.

2. Signing in, and why the browser asks when the apps do not

The web version is behind a sign-in screen. A signed-out visitor sees that screen and nothing else. This is the one real difference from the Android and iOS apps, which sign you in anonymously and work with no account at all, so it is worth being straight about the reason.

A phone app can prove it is genuine. Android carries a Play Integrity verdict and iOS an App Attest assertion — hardware-backed statements that a real, unmodified copy of our app on a real device is calling us. A browser can produce neither. It is also the surface anyone can reach with a script and no install at all, against features that cost us real money on every call. A sign-in is what stands in for the attestation the phones get for free. It is not a data-collection exercise: we ask for an account because it is the only thing that makes the free tier defensible here.

You can sign in three ways, and all three are handled by Google’s Firebase Authentication rather than by us:

  • Google, in a pop-up window.
  • Apple, in a pop-up window. If you choose “Hide My Email”, we receive only the relay address Apple generates. We never see your real one.
  • An email address and a password. You can confirm the address and reset the password from inside the app.

What we process is your email address and the account identifier Firebase issues. We never ask for your name, your phone number, your date of birth or your location, and nothing else about the Google or Apple account you used is read. The same account reaches the same identity on your phone, which is the point: sign in here with the credential you already use in the app and any credits or Pro you bought there are simply there.

The site-integrity check

To tell a real person using the site from a script hammering it, requests carry a reCAPTCHA Enterprise assessment from Google, through Firebase App Check. It scores how the browser behaves on the page and produces a token saying “this looks like a genuine visitor on the real site”. Google receives browser and device information and interaction signals in order to produce that score, described in the Google Privacy Policy; it does not receive anything you have written, and the score tells us nothing about who you are. It is the browser’s weaker equivalent of the phones’ device attestation, which is the second half of the reason this version is gated.

The install identifier

Alongside your account, the app sends an install identifier that names this browser profile. It is a random value this browser generates for itself on first visit, of the form web- followed by a random UUID, together with a random secret that proves the identifier is ours. Both are kept in this browser’s local storage.

It is not an advertising identifier and there is nothing in it that came from your device. It is not Android’s ANDROID_ID, not Apple’s vendor identifier, not a fingerprint of your hardware, and because we generate it ourselves it cannot be used to recognise you on any other site. The web- prefix exists for an unglamorous reason worth stating plainly: without it we could not tell browser traffic apart from Android traffic in our own operational counts.

Being honest about how it behaves: clearing this site’s data, using a private window or switching browsers gives you a new one, and unlike the phones there is no secure store to keep it in. That is why it carries much less weight here than it does on a phone — your account is what your daily allowance and your credits hang off in a browser, not this identifier. Its job is to let a purchase made before you signed in still be claimed by your account, and to let us count usage at all when something goes wrong with a token.

3. What stays in your browser

These never leave your computer at all:

  • Every document you write, paste, scan or import, and your whole history of them, in the browser’s IndexedDB store. Since September 2026 that includes the reports and rewrites saved against each document, exactly as the phones keep them.
  • The offline rewriter, the local self-check, the difference view and word statistics, which run entirely in this browser and make no network request at all.
  • Text read out of a PDF you import. PDFs are opened and their text extracted in the browser; the file itself is never uploaded.
  • Your theme and rewrite preferences, whether you have seen the introduction, and the install identifier and secret from section 2 — all in local storage.
  • A short-lived note of any cloud request that was interrupted, so a result you already paid for can be picked up again rather than charged twice. It records a random key and never your text.

We set no cookies. This site uses browser storage rather than cookies, and it stores nothing for advertising or measurement. Google’s sign-in pop-up and the reCAPTCHA check run on Google’s own domains and may set cookies there under Google’s policies; we cannot read them, and we do not use them.

Settings → Delete all documents removes everything in the first bullet. Clearing this site’s data in your browser removes all of it, including the install identifier. Both are irreversible, in the same way that uninstalling a phone app is — nothing here is backed up to us, because nothing here was ever sent to us. Use Settings → Document backup to write a .unplag file you control if you want to keep or move your history; that file is written to your own disk and imports into the phone apps.

4. What is sent to our server, and when

Nothing is sent in the background. Text or an image is transmitted only in response to something you click. Every request also carries your sign-in token, the install identifier and its secret, so that the server knows whose allowance to count.

When youWhat is sentWhat happens to it
Run an originality checkYour document text Processed in memory to find matching passages, then discarded. The result, which is where the matches are and which pages they came from rather than your words, can sit in the one-hour cache described in section 6.
Run a cloud rewrite, or “Make it human”Your document text Processed in memory, rewritten text returned, then discarded. The result, which is the rewrite with the original sentences beside it, can sit in the one-hour cache described in section 6.
Scan a page, or import a scanned PDFThat page image Processed in memory to read the text, then discarded. The image itself is never cached; the text read off it can sit in the one-hour cache described in section 6. Unlike the phone apps, a browser has no on-device text recognition, so there is no free local pass here and every page you scan is sent to our server. The app says so before the button that spends it.
Click “Explain this match” The matched passage and its source Processed in memory, explanation returned, then discarded. The explanation can sit in the one-hour cache described in section 6.
Report a bad rewrite A short excerpt of the input and the output — capped, not the whole document — plus the reason you picked and anything you typed Stored, so a human can look at what went wrong. See section 6. The sheet shows you what will be sent before it is sent, and an offline rewrite is never offered this button because sending would upload text you kept in the browser on purpose.
Open the app, or a screen that shows your allowance Nothing you wrote — only your identity and the install identifier Answers with your plan, your credit balance and today’s counts.

“Discarded” above means that what you sent us is not kept as a record: it exists in the server’s memory for the seconds your request takes, and it is never written to a log file or a backup. There is one exception and it is deliberate, so we would rather name it here than have you find it. What comes back to you, the finished result, is held for up to one hour against the key this browser sent with that one request, so that a request interrupted by a lost connection can be handed back to you instead of charged to you a second time. For a rewrite that result contains your own sentences as well as the new ones. It is swept automatically when the hour is up, Settings → Delete my server data erases it sooner, and section 6 lists it with everything else we hold. The offline rewrite and the local self-check send nothing at all.

5. Who else processes your text

To do its job the server has to ask a few outside services for help. All act as processors on our behalf, under their own terms. None of the services that see your text is given your identity, not your email address and not your account identifier.

  • Google (Gemini API) for rewriting, explanations, and text recognition on scanned pages. Text submitted through the paid Gemini API is not used by Google to train its models.
  • Google (Firebase Authentication and App Check) holds the account described in section 2, including your email address, and produces the reCAPTCHA Enterprise assessment. It never sees your documents.
  • Web search providers to find where a passage already exists online. Short exact phrases from your document are sent as search queries. Phrases, not whole documents, and the query carries nothing that identifies you.

We do not sell personal information, we do not share it with data brokers, and we run no advertising at all — see section 8.

6. What we store, and for how long

WhatWhyHow long
A daily count of checks, rewrites, scans and explanations against your account To apply the free daily allowanceRolling, and expires on its own
Your entitlement: which product you bought in a phone app and whether it is live, and your credit balance So Pro and credits work on every device you sign in on, this browser included While the entitlement is live
Problem reports you submit, including the excerpt you chose to attach So a human can look at what went wrongUntil the report is resolved
A note that a particular purchase has already been credited So the same receipt cannot be counted twice. It records that the credit happened, not what you did with it While the entitlement is live
The finished result of one check, rewrite, page reading or explanation, held against the key this browser sent with that request. Apart from a problem report you chose to send us, this is the only place your own text is held at all, and for a rewrite it includes the sentences you started from So that a request interrupted by a lost connection can be handed back to you instead of charged to you a second time One hour, then swept automatically. Settings → Delete my server data removes it sooner
Which days this browser called in So we can tell whether the service is working for real people, and on which platform Rolling

Traffic to our server is encrypted with HTTPS. Server logs record that a request happened and whether it succeeded; they do not record your document text.

7. Deleting your data

In this browser: Settings → Delete all documents removes every document held here, with the reports and rewrites saved against them. Clearing this site’s data in your browser removes everything else it stored, including the install identifier and your preferences.

On our server: Settings → Delete my server data erases the text of any problem report you sent, our record of the purchase this browser claimed, which days this browser called in, and any result still cached from an interrupted request. It does not touch your credit balance, and it does not touch your documents, which were never on the server. Ticking also delete my account additionally removes the account itself, your email address and your credit balance, and signs you out.

You can also ask for a copy of what is held, from Settings → Export my data, or by emailing support@vibecoredigital.com.

Two things deliberately survive deletion, and we would rather say so than let you find out. The counters for the current day are kept, because clearing them would turn “delete my data” into an unlimited free-usage button; they expire on their own at midnight UTC. So is the note that a given purchase has already been credited, because without it the same receipt could be redeemed again. Neither contains anything you wrote.

If you delete your server data but keep your account, a Pro subscription bought in a phone app has to be re-linked from that app.

8. Advertising and tracking

There is no advertising on this website. No banners, no rewarded videos, no advertising SDK, and no advertising identifier — the phone apps have all of those and this does not. Nothing here is served by Google AdMob or by any other advertising network.

Because there are no advertisements, there is nothing here to consent to: no tracking prompt, and no advertising consent form in the EEA, the UK or Switzerland. There is also no analytics product, no tag manager and no third-party measurement script on the page. We do not track you across other websites and we could not, because nothing on this page is built to.

The only third parties your browser talks to are Google, for signing in and for the reCAPTCHA site-integrity check described in section 2, and our own server. That is the whole list.

9. Purchases

Nothing is sold on this website. Credits and Pro are bought in the Android and iOS apps and nowhere else; the browser shows you what you have and what Pro would add, and has no checkout, no payment form and no “buy” button. No payment details ever reach this page, because there is nothing here to pay for.

If you bought credits or Pro in a phone app, that purchase lives on your account and appears here when you sign in with the same credential. Google Play or Apple handled the payment, and the record we keep of it is described in section 6. Cancelling a subscription, and asking for a refund, happen in the store you bought it from — a browser cannot do either, and the Android and iOS pages cover that side.

10. Children

UnPlagiarize is a writing tool for students and professionals. It is not directed at children and we do not knowingly collect information from children. If you believe a child has provided us with information, contact us and we will delete it.

11. Your rights

Depending on where you live, under Canada’s PIPEDA and British Columbia’s PIPA, the GDPR in the EEA and the UK, or state privacy laws in the United States, you may have the right to access, correct, delete or port information about you, and to object to certain processing. Because the site stores almost nothing and your documents never reach us, most of those rights are satisfied by the steps in section 7, but you are welcome to write to us and exercise them formally.

Where the GDPR applies, our legal bases are: performing the service you asked for (your account, checks, rewrites, and honouring purchases made in the apps), and our legitimate interest in preventing abuse and keeping the service running (the site-integrity check, the install identifier and the usage counters). We rely on consent for nothing here, because there is nothing here we would need it for.

12. Changes to this policy

If this policy changes, the date at the top changes with it. Continuing to use the site after a change means you accept the updated policy.

Contact

Questions, deletion requests, or anything that looks wrong:
support@vibecoredigital.com

VibeDeV, operated by VIBECORE DIGITAL, British Columbia, Canada.

UnPlagiarize for the web · unplagiarize.vibecoredigital.com · © 2026 VIBECORE DIGITAL