Private by default.
How we collect, use, share, and protect your information, and the rights you have over it. Detection runs server-side; your report and the content you scanned are saved privately to your account, never public unless you share. Last updated 14 June 2026.
Too legal, didn’t read.
The short version, in plain language. It does not replace the full policy below, but it is honest.
Your scans and reports are saved only to your account, access-controlled to you. Nothing is public unless you create a share link.
Run a scan that stores nothing, no saved report, nothing to reopen or share. Built for sensitive material.
Your submissions are never used to train detection models. Calibration uses internal benchmarks and public datasets, not your inputs.
The full subprocessor list is on this page and changes only through a code review, the list and the code cannot drift.
Access, correct, export, or delete your data from Settings. Account deletion is permanent once it completes.
Japan’s APPI, the EU and UK GDPR, Indonesia’s PDP Law, Canada, and US state laws. We respond to requests within 30 days.
This Privacy Policy explains how PT Solusi Akal Imitasi (“Detecto”, “we”, “us”, “our”) collects, uses, shares, and protects personal information when you visit detecto.co, create an account, or use our AI-detection services (the “Services”). It also describes your rights and how to exercise them. This page is the authoritative description of our practices; the cards and tables are provided to make it easier to read. If you do not agree with this Policy, please do not use the Services.
1. What information we collect
Information you provide
- Account information, your name, email address, password or single sign-on identity, and contact preferences.
- Billing information, when you subscribe or buy credits, payment is processed by a third-party payment processor. We receive billing metadata (such as your billing email and the status of a payment); we do not store full card numbers.
- Content you submit for analysis, the text, documents (PDF, DOCX), images, audio, and video you upload or paste to be analyzed. This content may contain personal information about you or about third parties. By default it is stored privately to your account so you can reopen it; in ephemeral mode it is not stored at all (see “How long we keep your information”).
- Communications, messages you send us, for example through support.
Information collected automatically
When you use the Services we automatically collect log and usage data, IP address, browser and device characteristics, operating system, language preferences, referring URLs, timestamps, and the actions you take (such as which features you use and error reports). This information is used mainly to operate and secure the Services and for internal analytics. We also use the cookies listed in the “Cookies” section below.
Single sign-on
If you choose to sign in using a supported single sign-on provider (for example, Google), we receive basic profile information, such as your name and email address, from that provider. We use it only as described in this Policy. We recommend reviewing that provider’s own privacy notice.
Sensitive information
We do not seek to collect sensitive personal information about you beyond the credentials used to secure your account. Content you choose to submit for analysis may itself contain sensitive information; you decide what to submit, and you are responsible for having a lawful basis to submit it.
2. How we use your information
We process personal information to:
- provide, operate, and maintain the Services and run detections;
- create and manage your account and authenticate you;
- process payments and manage subscriptions and credits;
- communicate with you, service and support messages, and, where permitted, product updates you can opt out of;
- maintain security, prevent fraud and abuse, and keep an append-only audit log of billing-, credit-, and auth-impacting events;
- comply with legal obligations and enforce our terms;
- improve the Services. We do not use your submissions to train detection models. Calibration updates are based on internal benchmarks and curated public datasets, not on your inputs.
3. Legal bases for processing
If you are in the EEA or UK, we rely on these legal bases under the GDPR and UK GDPR: consent (which you may withdraw at any time); performance of a contract (to provide the Services you request); legal obligations; legitimate interests (to secure, maintain, and improve the Services in ways that do not override your rights); and vital interests where necessary to protect a person.
If you are in Canada, we process personal information with your express or implied consent, which you may withdraw at any time. Withdrawing consent does not affect processing already carried out, or processing on other lawful grounds.
Every third party that touches your data.
This list is the canonical source. Adding or removing a subprocessor is a code+content PR; the two cannot drift. Each operates under a written contract.
| Service | Purpose | Region | Data category |
|---|---|---|---|
| Compute | Primary hosting and application servers. | SG | Account, scan metadata |
| Detection │ text | AI text-detection processor. | US | Text submissions (transient) |
| Detection │ media | AI image, video, and audio detection processor. | US, EU | Media files (transient) |
| Authentication | Account auth, session, and database. | US, EU | Email, OAuth identity |
| Billing | Subscription billing and invoicing. | US, JP | Billing email, payment metadata |
| Transactional email delivery. | US | Email address, message contents | |
| Observability | Error monitoring and performance traces. | US, EU | Error metadata (PII scrubbed) |
Detection vendors are listed by the function they perform; their commercial names are deliberately not exposed in the product surface. The full Data Processing Agreement is available on request via privacy@detecto.co.
Beyond these subprocessors, we may disclose personal information: to comply with law or respond to a lawful request; to protect the rights, safety, and property of Detecto, our users, or the public; and in connection with a merger, acquisition, financing, or sale of assets (a business transfer). We do not sell your personal information, and we do not share it for cross-context behavioral or targeted advertising.
What we set, and why.
| Cookie | Purpose | Lifetime | HttpOnly |
|---|---|---|---|
| sb-access-token | Authenticated session. | 14 days | Yes |
| sb-refresh-token | Session refresh. | 14 days | Yes |
| theme | Light / dark / system preference for SSR. | 1 year | No |
| sidebar_state | Dashboard sidebar collapsed state. | 7 days | No |
| consent | Cross-border processing consent record. | 1 year | No |
Most of these are strictly necessary (authentication, security, and your consent record); a few store preferences such as theme. We do not use advertising or cross-site tracking cookies.
For usage analytics we run a self-hosted, cookieless tool on our own infrastructure (similar to Plausible or Umami). It measures aggregate usage without setting tracking cookies, and we do not share usage data with third-party advertising or analytics networks, which is why there is no analytics cookie in the table above.
Do-Not-Track: because there is no finalized industry standard for DNT signals, we do not currently respond to them. If a standard is adopted, we will update this Policy.
6. International transfers
Our primary servers are located in Singapore. We are established in Indonesia, where we also operate a small virtual server that runs our self-hosted, privacy-friendly analytics. In addition, the third-party subprocessors listed above process limited data in their own regions (currently the United States, the European Union, and Japan). Regardless of where you are located, your information may be transferred to, stored in, and processed in these locations.
Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant). For users in Japan, cross-border handling is described in the “Japan (APPI)” section below. A copy of the relevant safeguards is available on request.
The retention contract.
We keep personal information only as long as necessary for the purposes in this Policy, unless a longer period is required by law (for example, billing records).
Text, image, audio, and video submissions are stored privately, access-controlled to you, so you can reopen and manage them.
Score, confidence band, signals, modality, timestamp, scan id. Persisted so reviewers can reference the report.
Notes you attach to a scan persist with the report. Editing is logged with the editor and the timestamp.
Run a scan without saving anything, no stored report, nothing to reopen or share. Available for sensitive material.
You explicitly create a detec.to share link for a scan. Default is private.
Credit-consuming, billing-impacting, and auth-impacting events write to an append-only audit log scoped to your account.
When you delete your account from Settings, account-scoped data is permanently removed where possible and the action cannot be reversed after it completes. Some records may be retained where the law requires it, for example billing records. To store nothing in the first place, run a scan in ephemeral mode.
Cross-border processing consent
On the first scan in a session, Detecto presents a modal that names the third-party processors generically (compute, detection, authentication, billing, observability), discloses the regions those processors operate in, and asks for explicit consent before processing the submission.
The consent is logged with the timestamp and the scan id, and it is reversible from Settings. Revoke consent and you cannot run further scans until you re-consent, this is the design, not a bug.
8. How we keep your information safe
We implement appropriate technical and organizational measures designed to protect personal information. However, no method of transmission over the internet or storage is completely secure, so we cannot guarantee absolute security; you transmit information to the Services at your own risk. For more detail, see our Security page.
9. Students and younger users
Detecto is built for educational and professional review, and the Services may be used by students, including minors, for example, a student submitting their own work, or an educator reviewing a class’s assignments. We do not impose a strict age limit on use, and we do not knowingly collect more personal information from a younger user than is needed to provide the Services.
Where the Services are used by, or on behalf of, a minor, the school, educator, or parent/guardian who provides access is responsible for obtaining any consent required by applicable law (for example, COPPA and FERPA in the United States, the GDPR age-of-consent rules in Europe, or local equivalents). If you submit content that contains another person’s personal information, you confirm that you have the authority and a lawful basis to do so; for that content you act as the controller and Detecto acts as your processor.
If you believe a child has provided us personal information without the consent required in their jurisdiction, contact privacy@detecto.co and we will review and, where appropriate, delete it.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, to object to or restrict processing, to data portability, and to withdraw consent.
- EEA, UK, and Switzerland: the rights above, plus the right not to be subject to solely automated decisions that produce legal or similarly significant effects. You may lodge a complaint with your local supervisory authority.
- Japan: see “Japan (APPI)” below.
- Canada: the right to access your information and to withdraw consent.
- United States: state-specific rights are described below.
How to exercise your rights: manage your data directly from Settings, or email privacy@detecto.co. We respond within 30 days under the applicable regime, and we may need to verify your identity first. If we decline a request, you may appeal by replying to our decision; if an appeal is denied, you may contact your local regulator.
11. Japan (APPI)
Many of our customers are based in Japan, and we handle personal information in accordance with Japan’s Act on the Protection of Personal Information (個人情報保護法, “APPI”).
Business operator and purpose of use (利用目的)
The personal information handler is PT Solusi Akal Imitasi. We use personal information for the purposes set out in “How we use your information” above, principally to provide and secure the detection Services, to manage your account and billing, and to respond to you. We do not use it beyond those purposes without notifying you or obtaining consent where the APPI requires it.
Cross-border transfer (外国にある第三者への提供)
To provide the Services, personal information may be handled outside Japan. Our primary servers are in Singapore; our company and a self-hosted analytics server are in Indonesia; and the third-party subprocessors listed above operate in the United States, the European Union, and Japan. On request, we provide information about the data-protection regimes of these countries and the safeguards each recipient takes. We obtain consent for cross-border handling through the disclosure described in “Cross-border processing consent” above.
Your requests (開示等の請求)
You may request disclosure, correction, addition, deletion, suspension of use, or suspension of third-party provision of your retained personal data. Use Settings or email privacy@detecto.co, and we will respond within a reasonable period. For our full APPI posture see the APPI compliance page, and for paid-service disclosures see our 特定商取引法に基づく表記 notice.
12. Indonesia (PDP Law)
As a company established in Indonesia, we process personal data in accordance with Indonesia’s Personal Data Protection Law (Law No. 27 of 2022). The data controller is PT Solusi Akal Imitasi. You may exercise your rights, including access, correction, erasure, objection, and withdrawal of consent, by contacting privacy@detecto.co.
13. United States
If you live in California or another US state with a comprehensive privacy law, you may have the right to know, access, correct, delete, and obtain a copy of your personal information; to opt out of the “sale” of personal information, sharing for targeted advertising, and certain profiling; and not to be discriminated against for exercising these rights. As noted above, we do not sell your personal information and we do not share it for cross-context behavioral advertising. To exercise these rights, use Settings or email privacy@detecto.co; you may use an authorized agent, and California residents may also request “Shine the Light” disclosures at the same address.
14. Updates to this Policy
We may update this Policy from time to time. We will revise the “Last updated” date at the top, and for material changes we will provide a more prominent notice or contact you directly. We encourage you to review it periodically.
15. How to contact us
For privacy questions or to exercise your rights, email privacy@detecto.co. For general enquiries, use hello@detecto.co. You can also write to us by post:
PT Solusi Akal Imitasi
Jl. Cik Di Tiro, Terban, Gondokusuman
Kota Yogyakarta, Daerah Istimewa Yogyakarta 55223
Indonesia