Your text and files are processed in memory and deleted the moment your verdict is delivered — never stored, never used for training, never shared.
That is the whole policy, and the rest of this page is really just us explaining how we make it true. There is no account to create, we set no cookies, we run no third-party trackers, and there is no consent banner because there is nothing for you to consent to. Below we go through what happens to the text and files you send us, how we prove on every release that we are not keeping them, and the few operational traces that any website still leaves behind, because we would rather you saw those too than had to take our word for it.
What happens to text and files you check
Everything you submit is processed entirely in memory. Our application code never writes your text or your files to disk, not to a database, not to a temp file, and not to a log. Here is what that looks like in practice, one case at a time.
- A normal scan holds your text in memory only for the seconds it takes to score it, and by the time the response has come back to you the text is already gone from our side.
- If the service is busy, your scan waits in an in-memory queue. The text is held in RAM only while it waits its turn, and it is freed the instant scoring finishes — before your verdict is even delivered.
- Your verdict is deleted the moment you fetch it. If you close the tab and never come back for a queued result, it is purged by a background timer within five minutes, even if nobody else ever visits. We put the timer in because we did not want a result sitting there until the next person happened to come along.
- Stored verdicts never contain your words. While a queued result waits to be fetched, what it holds is scores, numeric highlight positions, and signal names — not one character of your input. If you could look inside one, you would see a list of numbers and labels and nothing you could read.
- Uploaded files are parsed in memory too. When you run the provenance check, it reads your PNG, JPEG, DOCX, or PDF from memory, answers you straight away, and keeps nothing, so the response that comes back carries only the file kind and a few short metadata summaries and never the file itself.
- Errors never echo your input. When something goes wrong, what you get back is a typed code with a fixed message that we wrote in advance, and that is all you get. No stack traces, no quoted text, no request bodies in diagnostics — by construction, and by test.
- Never used for training. We do not use submitted text or files to train, tune, or evaluate anything. If you are looking for the opt-out, there is no opt-out because there is nothing to opt out of.
We test this automatically on every release
A promise like this is only worth something if breaking it would break the build, so that is how we set it up. Our release checks include an automated no-persistence test, and what it does is run real scans and real file uploads, each one seeded with a unique marker string that we would recognise if we saw it again, and then it goes looking for those markers everywhere they could have ended up: in any file on disk, in the in-memory result store after delivery, and in the process logs. It has to find them nowhere. There is also a companion check that deliberately plants leaks, because a test that never fails is not much of a test, and this way we know it would catch a real one if one ever happened. If Cobalynx ever kept your text, our own release pipeline would fail before that change shipped, and you would have found out here first.
Server logs, the part every website still keeps
Like every website, we keep standard connection logs so that we can keep the service up and block abuse. Ours are anonymized at write time, which means that before a request line touches disk, the last segment of your IP address is removed (the final octet for IPv4; IPv6 addresses are truncated). The full address exists only in memory while your request is being served.
- Connection logs hold: a timestamp, the truncated address, the URL path, the response status and sizes, and your browser's user-agent string. Your text travels only in request bodies, never in URLs, so it cannot end up in these logs.
- Operational logs hold: startup lines and typed error codes from our own processes, which is to say the kind of thing you would need to work out why a process fell over. Never request content.
- One aggregate statistic survives restarts, and we would rather tell you about it than have you find it later. It is the service's measured processing speed, a single words-per-second number that we use to tell you how long the queue is going to take. Nothing in it derives from any individual text. The machine is also configured without swap, so the memory holding your text is never paged out to disk by the operating system either.
Visit statistics
This is the section where most privacy pages get vague, so we would rather be specific. Any visit counting we do runs on a self-hosted, cookieless analytics instance on our own infrastructure: aggregate page-view counting, no cookies set, no cross-site identifiers, and no data leaving our infrastructure. What no version of this site has is a third-party analytics tag: no Google Analytics, no advertising pixel, no social widget, and no CDN-hosted script phoning home. If we ever add one, we will say so on this page, and we will say so here before it starts running rather than afterwards.
No cookies, no trackers, and why there is no banner
Consent banners exist to authorize cookies and trackers, and since we set no cookies and run no third-party trackers there is nothing for you to consent to, which is why you did not see a banner when you arrived. If that ever changes, this page changes first, and the date at the top of it will tell you when.
Content certifications
Ordinary scans are zero-retention, and so are free certifications: the certification report is self-contained, carrying the text’s SHA-256 fingerprint, score, date, and detector version, and nothing about it is stored on our servers. Hosted certificates, when they open from the waitlist, will be the one deliberate exception: creating one will mean asking us to store that exact text, its fingerprint, and its verdict so a public verification page can exist, and deleting the certificate will delete the stored text with it. That exception ships only after this policy states it in the same release.
If you want to know what a certification is and what it does and does not claim, that is all on the content certification page.
Your rights (GDPR)
Controller. Roviant S.r.l., Italy. Contact: contact@cobalynx.com.
The controller is a real, named operation: Roviant S.r.l. is an Italian limited liability company, registered in Italy, and it builds and runs Cobalynx itself. If you have a question about this policy or about your data, you send it to contact@cobalynx.com and it gets read and answered by the people who actually run the service.
What we process, and on what legal basis. Your submitted text and files are processed transiently, for the duration of the check you asked for, under Article 6(1)(b) GDPR (processing necessary to deliver the service you requested). The anonymized connection logs above are kept under Article 6(1)(f) (our legitimate interest in security, rate-limiting, and abuse prevention).
The honest shape of your rights here. You have the full set of GDPR rights: access, rectification, erasure, restriction, portability, and objection. For submitted content, the truthful answer is that there is usually nothing to exercise them against, because your text was deleted before our reply even reached you and nothing we have kept could be linked back to you. Under Article 11 GDPR we are not obliged to collect extra data just to identify you for a rights request, and we will not: if someone came to us and asked "who asked you to scan this?", we could not tell them, and that is by design.
Complaints. You can lodge a complaint with a supervisory authority. Ours is the Garante per la protezione dei dati personali (Italy), or you can go to the authority of your own country of residence.
Related pages
The rules for using the service are in the Terms of Service. If you want to know how verdicts are computed, and what error rates we measured behind them, that is on the methodology page and the evidence page.
This page states our own policy in plain language. If what it says and what the service does ever come apart, then what the service does wins and we come back and fix the page. The date at the top is the date we last did that, and if we change how we handle your information we change this page and that date with it.