Legal
Last updated: 6 October 2026
1.1. The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Morphica Technologies
Inhaber: Dino Dervisevic
(operating as ThesisDraft)
Rathenaustraße 132, 80937 Munich, Germany
Email: contact@thesisdraft.com
1.2. This Policy covers thesisdraft.com and the services offered on it without an account: the free tools, the AI check, and the Academic Rewrite. Services that require an account have their own privacy notice. In this Policy, “you” (the “Data Subject”) means the person whose data is processed.
When you open a page or use a tool, your browser sends technical data to our servers: IP address, browser and operating system, the page requested, the referring page, and the date and time. We use it to deliver the website, keep it secure and fix errors. The typefaces on the website are loaded from Google Fonts, so your browser also sends your IP address to Google. Legal basis: Article 6(1)(f) GDPR; our legitimate interest is a secure, working and consistently presented website.
We use Google Analytics 4 to understand how the website and the tools are used: pages visited, device and browser type, approximate location, and events such as a completed check. Analytics never receives the text you submit, your name, your email address or your payment details. Google Analytics sets cookies (§ 5). Legal basis: Article 6(1)(f) GDPR; our legitimate interest is improving the website and the tools. You can object at any time (§ 7.1).
Payments are handled by Stripe on its own checkout page. Stripe processes your payment details and email address; we do not receive your card details. We receive confirmation of the payment and the email address, and keep the records tax and commercial law require. Legal basis: Article 6(1)(b) GDPR (performing the contract) and Article 6(1)(c) GDPR (legal obligations).
The email address given at checkout is used to send your receipt (Article 6(1)(b) GDPR). As an existing customer, you may also receive information by email about our own similar services; the content may be adapted to the result of your paid check, which is kept only until that email has been handled. Legal basis: Article 6(1)(f) GDPR, read with § 7(3) of the German Act Against Unfair Competition (UWG); our legitimate interest is informing customers about related services. You can object at any time, free of charge, using the link in every email or by writing to us. We then delete your address and keep only a record that you objected, so that you are not contacted again.
If you write to us, we process your message and email address to answer it (Article 6(1)(b) or (f) GDPR; our legitimate interest is answering enquiries). If you have asked to be notified about a new product, we use your address only for that, with your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
After you pay for the Full Thesis Check, the Academic Rewrite or both, we send one email to the address you gave at Stripe's checkout. It contains your access code: a short code derived from your payment with which you can unlock what you bought on any device at thesisdraft.com/code for fourteen (14) days. The email is part of your purchase, is sent once, and contains no advertising. Stripe passes us your address for this purpose; we use it to send this email and do not store it, and it is never linked to your document. To avoid sending twice, we keep a record that the email was sent, identified only by a hashed form of the payment reference, without your address. Legal basis: Article 6(1)(b) GDPR.
If you subscribe to a check plan (Check, Check + Humanizer or the Semester pass) in the ThesisDraft app at app.thesisdraft.com, which requires an account, we store with your account: the plan, its status and renewal date as Stripe reports them, your Stripe customer reference, and how many checks and rewrites you started in the current month, to apply the plan's fair-use limit. We do not store which documents you checked with your account. Before each check the app obtains a token that is valid for fifteen (15) minutes and confirms only that a paid check may run; it contains no name, email or account identifier. The check itself is then processed exactly as in § 2.1.4, identified only by its analysis reference, and is never linked to your account. Legal basis: Article 6(1)(b) GDPR. Deleting your account deletes these records and cancels the plan; the account itself is described in the privacy notice of the account services.
About an hour after you pay for the Full Thesis Check, the Academic Rewrite or both, our founder sends you one short plain-text email to the address you gave at Stripe's checkout, asking how your experience was and what we could do better. To greet you, we read the first name from the name given at checkout, if there is one. We use the address and the first name only to send this email and store neither; the email does not refer to your document or your result. If you reply, we process your reply to read and answer it and to improve our services. To avoid sending twice, we keep a record that the email was sent, identified only by a hashed form of the payment reference, without your address or name. Legal basis: Article 6(1)(f) GDPR, read with § 7(3) of the German Act Against Unfair Competition (UWG); our legitimate interest is learning from our customers how to improve our services. You can object at any time, free of charge, by replying "stop" or by writing to us; we then keep only a record that you objected, as in § 2.1.5, so that you are not contacted again.
3.1. We use the following service providers, as processors or, where stated, as independent controllers:
3.2. Some of these providers are based in the USA or may process data there. Transfers are based on the EU-US Data Privacy Framework (Article 45 GDPR) where the provider is certified, and otherwise on the EU Standard Contractual Clauses (Article 46(2)(c) GDPR). You can request a copy of the safeguards from us.
3.3. We do not sell personal data and do not pass it to anyone else, unless the law requires us to.
5.1. Google Analytics sets cookies that recognise a returning browser, for up to two years (§ 2.1.2). The notice shown on your first visit informs you about this Policy; it does not switch analytics on or off. You can block or delete cookies in your browser settings, or install Google's opt-out add-on at tools.google.com/dlpage/gaoptout. Every tool works the same without these cookies.
5.2. The website also stores information in your browser that is strictly necessary for services you request, such as a purchased pass, a check waiting for payment to complete, your language, a sign-in state, and whether you have closed the notice (§ 25(2) No. 2 TDDDG). This stays in your browser and is not sent to us.
6.1. You have the right to access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and to withdraw consent at any time with effect for the future (Article 7(3)). Write to contact@thesisdraft.com; it is free of charge.
6.2. Because submissions are stored without your name (§ 2.1.4, § 2.1.6), we can only find them with the analysis reference (Article 11(2) GDPR).
6.3. You have the right to lodge a complaint with a supervisory authority, for example the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
7.1. You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR, including analytics and the retention of submissions. We then stop, unless we can show compelling legitimate grounds or need the data for legal claims.
7.2. You may object at any time, without giving reasons, to the use of your data for direct marketing, including the customer emails in § 2.1.5. We then stop using your data for that purpose. Use the link in any email or write to contact@thesisdraft.com.
8.1. You are not obliged to provide personal data. Without a submitted text we cannot run a check, and without an email address at checkout a purchase cannot be completed.
8.2. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you (Article 22 GDPR). A check result is information for you, not a decision about you.
8.3. We protect data with appropriate technical and organisational measures, including encrypted transmission, encrypted storage and restricted access.
8.4. We may update this Policy when our services or the law change. The current version is always published on this page.