← Back to Homepage

Legal

Privacy Policy

Last updated: 6 October 2026

§ 1 — Controller

1.1. The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Morphica Technologies
Inhaber: Dino Dervisevic
(operating as ThesisDraft)
Rathenaustraße 132, 80937 Munich, Germany
Email: contact@thesisdraft.com

1.2. This Policy covers thesisdraft.com and the services offered on it without an account: the free tools, the AI check, and the Academic Rewrite. Services that require an account have their own privacy notice. In this Policy, “you” (the “Data Subject”) means the person whose data is processed.

§ 2 — What We Process and Why

2.1.1. Visiting the Website

When you open a page or use a tool, your browser sends technical data to our servers: IP address, browser and operating system, the page requested, the referring page, and the date and time. We use it to deliver the website, keep it secure and fix errors. The typefaces on the website are loaded from Google Fonts, so your browser also sends your IP address to Google. Legal basis: Article 6(1)(f) GDPR; our legitimate interest is a secure, working and consistently presented website.

2.1.2. Analytics

We use Google Analytics 4 to understand how the website and the tools are used: pages visited, device and browser type, approximate location, and events such as a completed check. Analytics never receives the text you submit, your name, your email address or your payment details. Google Analytics sets cookies (§ 5). Legal basis: Article 6(1)(f) GDPR; our legitimate interest is improving the website and the tools. You can object at any time (§ 7.1).

2.1.3. Purchases

Payments are handled by Stripe on its own checkout page. Stripe processes your payment details and email address; we do not receive your card details. We receive confirmation of the payment and the email address, and keep the records tax and commercial law require. Legal basis: Article 6(1)(b) GDPR (performing the contract) and Article 6(1)(c) GDPR (legal obligations).

2.1.4. Texts and Documents Submitted to Our Checks

  • To run the check — we process the text or file you submit to produce your result and report. For a paid check, excerpts are also processed by an external AI provider (§ 3). Legal basis: Article 6(1)(b) GDPR.
  • Web search — for a plagiarism check, free or paid, individual sentences of your text are sent as search queries to a web search provider (Brave Search, § 3) to find published web pages with the same wording; we then retrieve those public pages and compare them with your text on our servers. Never the whole document, the file or anything that identifies you. We keep the passages that match, with the address of the page, as part of your result, but not the search results themselves. Legal basis: Article 6(1)(b) GDPR.
  • What we keep — the analysed text, the result, a copy of any report you generate, and technical attributes of the file (such as its format, the software that created it and its dates). We use them to measure and improve the accuracy of our checks, to develop our services, and to compare new submissions statistically with earlier ones. Legal basis: Article 6(1)(f) GDPR; our legitimate interest is accurate and reliable checks, including fewer cases of honest writing being wrongly flagged.
  • Without your identity — we do not ask for your name, university or any other identifier, and we do not store your IP address or the file name with a submission. A submission is identified only by the analysis reference shown in your report or with your result.
  • Never shown to others — submissions are never shown to other users, never sold, and not used to train third-party AI models.
  • Deletion — we keep your analyses and their scores until you ask us to delete them at contact@thesisdraft.com. Include the analysis reference; we delete the submission and everything derived from it within thirty (30) days.

2.1.5. Emails to Customers

The email address given at checkout is used to send your receipt (Article 6(1)(b) GDPR). As an existing customer, you may also receive information by email about our own similar services; the content may be adapted to the result of your paid check, which is kept only until that email has been handled. Legal basis: Article 6(1)(f) GDPR, read with § 7(3) of the German Act Against Unfair Competition (UWG); our legitimate interest is informing customers about related services. You can object at any time, free of charge, using the link in every email or by writing to us. We then delete your address and keep only a record that you objected, so that you are not contacted again.

2.1.6. Documents Submitted to the Academic Rewrite

  • To rewrite — we process your document to produce the rewrite; the passages to be rewritten are processed by external AI providers (§ 3). Legal basis: Article 6(1)(b) GDPR.
  • What we keep — the uploaded file as submitted, the extracted text, the record of the run (each sentence before and after), and the document returned to the Data Subject. We use them to maintain and improve the quality of our rewriting and analysis tools. Legal basis: Article 6(1)(f) GDPR; our legitimate interest is the quality and reliability of a paid service.
  • Without your identity — as in § 2.1.4: no name or identifier is asked for, stored documents are kept apart from payment data, and a run is identified only by its reference. Documents are never shown to other users, never sold, and not used to train third-party AI models.
  • Retention, and deletion at any time on request — we keep these until you ask us to delete them. Email contact@thesisdraft.com with the reference; the uploaded file, the extracted text, the record of the run, the document returned to the Data Subject and everything derived from them are deleted within thirty (30) days.

2.1.7. Contacting Us and Product Notifications

If you write to us, we process your message and email address to answer it (Article 6(1)(b) or (f) GDPR; our legitimate interest is answering enquiries). If you have asked to be notified about a new product, we use your address only for that, with your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.

2.1.8. Your Access Code After a Purchase

After you pay for the Full Thesis Check, the Academic Rewrite or both, we send one email to the address you gave at Stripe's checkout. It contains your access code: a short code derived from your payment with which you can unlock what you bought on any device at thesisdraft.com/code for fourteen (14) days. The email is part of your purchase, is sent once, and contains no advertising. Stripe passes us your address for this purpose; we use it to send this email and do not store it, and it is never linked to your document. To avoid sending twice, we keep a record that the email was sent, identified only by a hashed form of the payment reference, without your address. Legal basis: Article 6(1)(b) GDPR.

2.1.9. Check Plans in the ThesisDraft App

If you subscribe to a check plan (Check, Check + Humanizer or the Semester pass) in the ThesisDraft app at app.thesisdraft.com, which requires an account, we store with your account: the plan, its status and renewal date as Stripe reports them, your Stripe customer reference, and how many checks and rewrites you started in the current month, to apply the plan's fair-use limit. We do not store which documents you checked with your account. Before each check the app obtains a token that is valid for fifteen (15) minutes and confirms only that a paid check may run; it contains no name, email or account identifier. The check itself is then processed exactly as in § 2.1.4, identified only by its analysis reference, and is never linked to your account. Legal basis: Article 6(1)(b) GDPR. Deleting your account deletes these records and cancels the plan; the account itself is described in the privacy notice of the account services.

2.1.10. A Question From Us After a Purchase

About an hour after you pay for the Full Thesis Check, the Academic Rewrite or both, our founder sends you one short plain-text email to the address you gave at Stripe's checkout, asking how your experience was and what we could do better. To greet you, we read the first name from the name given at checkout, if there is one. We use the address and the first name only to send this email and store neither; the email does not refer to your document or your result. If you reply, we process your reply to read and answer it and to improve our services. To avoid sending twice, we keep a record that the email was sent, identified only by a hashed form of the payment reference, without your address or name. Legal basis: Article 6(1)(f) GDPR, read with § 7(3) of the German Act Against Unfair Competition (UWG); our legitimate interest is learning from our customers how to improve our services. You can object at any time, free of charge, by replying "stop" or by writing to us; we then keep only a record that you objected, as in § 2.1.5, so that you are not contacted again.

§ 3 — Recipients and Transfers Outside the EU

3.1. We use the following service providers, as processors or, where stated, as independent controllers:

  • Google Cloud / Firebase (Google Ireland Ltd.): hosting, servers and storage in the EU.
  • Google Analytics and Google Fonts (Google Ireland Ltd., Google LLC): analytics (§ 2.1.2) and typefaces (§ 2.1.1).
  • Google Gemini API (Google LLC): AI processing of excerpts in paid checks and of passages in the Academic Rewrite.
  • Brave Software, Inc. (USA): web search for sentences of paid checks (§ 2.1.4).
  • Mistral AI SAS (France): AI processing of passages in the Academic Rewrite when the Google Gemini API is unavailable.
  • Stripe (Stripe Payments Europe Ltd., Stripe, Inc.): payments, as an independent controller.
  • Resend, Inc. (USA, EU sending region): sending emails.

3.2. Some of these providers are based in the USA or may process data there. Transfers are based on the EU-US Data Privacy Framework (Article 45 GDPR) where the provider is certified, and otherwise on the EU Standard Contractual Clauses (Article 46(2)(c) GDPR). You can request a copy of the safeguards from us.

3.3. We do not sell personal data and do not pass it to anyone else, unless the law requires us to.

§ 4 — How Long We Keep Data

  • Server logs: thirty (30) days.
  • Analytics data: twenty-six (26) months.
  • Submissions to the checks and the Academic Rewrite: until you ask for deletion (§ 2.1.4, § 2.1.6).
  • Email address for customer emails: until you object; the record of an objection for as long as we send such emails. The address and first name used for the email in § 2.1.10 are not stored.
  • Payment and tax records: up to ten (10) years, as required by § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB).
  • Messages to us: as long as needed to deal with them, and longer only where the law requires.
  • Product notification addresses: until the notification is sent or you withdraw consent.

§ 5 — Cookies and Browser Storage

5.1. Google Analytics sets cookies that recognise a returning browser, for up to two years (§ 2.1.2). The notice shown on your first visit informs you about this Policy; it does not switch analytics on or off. You can block or delete cookies in your browser settings, or install Google's opt-out add-on at tools.google.com/dlpage/gaoptout. Every tool works the same without these cookies.

5.2. The website also stores information in your browser that is strictly necessary for services you request, such as a purchased pass, a check waiting for payment to complete, your language, a sign-in state, and whether you have closed the notice (§ 25(2) No. 2 TDDDG). This stays in your browser and is not sent to us.

§ 6 — Your Rights

6.1. You have the right to access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and to withdraw consent at any time with effect for the future (Article 7(3)). Write to contact@thesisdraft.com; it is free of charge.

6.2. Because submissions are stored without your name (§ 2.1.4, § 2.1.6), we can only find them with the analysis reference (Article 11(2) GDPR).

6.3. You have the right to lodge a complaint with a supervisory authority, for example the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

§ 7 — Right to Object (Article 21 GDPR)

7.1. You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR, including analytics and the retention of submissions. We then stop, unless we can show compelling legitimate grounds or need the data for legal claims.

7.2. You may object at any time, without giving reasons, to the use of your data for direct marketing, including the customer emails in § 2.1.5. We then stop using your data for that purpose. Use the link in any email or write to contact@thesisdraft.com.

§ 8 — Other Information

8.1. You are not obliged to provide personal data. Without a submitted text we cannot run a check, and without an email address at checkout a purchase cannot be completed.

8.2. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you (Article 22 GDPR). A check result is information for you, not a decision about you.

8.3. We protect data with appropriate technical and organisational measures, including encrypted transmission, encrypted storage and restricted access.

8.4. We may update this Policy when our services or the law change. The current version is always published on this page.