Privacy Policy

Effective date: July 29, 2026

Application: Plagiarism Checker - NestAI

Contact: elmelloukyd@gmail.com


This Privacy Policy explains how the independent developer of Plagiarism Checker - NestAI (the “Developer,” “we,” “us,” or “our”) collects, uses, shares, retains, and protects information when you use the application (the “App”). It also explains the choices and rights available to you.

The App can be used without creating an account. Please do not submit content that you do not have the right to process.


1. Information We Process

Content you choose to submit

Depending on the feature you use, we process:

- text, prompts, pasted content, questions, and chat messages;

- documents and files you select, including PDF, DOCX, PPTX, XLSX, CSV, TSV, and TXT files;

- images you select and text extracted from those images using optical character recognition (“OCR”);

- voice input and the resulting transcript when you choose dictation;

- generated answers, paraphrases, summaries, quizzes, flashcards, grammar corrections, classifications, originality or plagiarism results, AI-detection results, writing-quality feedback, and citations.

This content is processed only when you choose a feature and submit a request. Because free-form content may contain personal or sensitive information, do not submit passwords, payment-card details, government identifiers, health records, confidential legal documents, or another person’s personal information unless you have a lawful basis and understand the processing described below.

Usage, analytics, and diagnostics

Subject to applicable consent requirements and your choices, the App and its service providers may process:

- app launches, screen views, feature selections, button interactions, onboarding choices, paywall views, and request success or failure events;

- session duration, app version, device model, operating-system version, language, time zone, country or coarse region, network state, and technical logs;

- crash reports, stack traces, app state near a crash, performance information, and error diagnostics;

- installation identifiers and Firebase identifiers used for analytics, diagnostics, and push notifications;

- attribution and advertising identifiers only if the relevant attribution feature is enabled and you have granted permission through Apple’s App Tracking Transparency prompt where required.

We do not intentionally include the full text of your documents or prompts in analytics event names or analytics event parameters.

Purchases and subscriptions

Subscriptions are purchased through Apple’s In-App Purchase system. We may receive and process product identifiers, subscription and entitlement status, transaction status, purchase or restoration events, expiration information, and receipt-validation data. Apple processes your Apple Account and payment method. We do not receive or store your complete payment-card or bank-account details.

The App may offer weekly, monthly, annual, promotional, or introductory subscription options depending on your region and the offers configured in App Store Connect. The price, billing period, trial eligibility, and renewal terms shown in the Apple purchase interface at the time of purchase control. The three complimentary in-app uses offered to new users are usage allowances, not an Apple-billed subscription trial.

Support communications

If you contact us, we process your email address, message, attachments, and any information you voluntarily provide so that we can respond and keep an appropriate support record.

Information stored locally

The App stores certain information on your device, including settings, language and appearance preferences, free-usage counters, consent choices, and content or results that you choose to save to history. Document-chat and study-material histories are also stored locally. Locally stored content remains until you delete it in the App where that option is available, clear the App’s data, or uninstall the App, subject to device backups managed by you or Apple.


2. Device Permissions and User-Controlled Access

The App may request the following permissions only for the described purposes:

- Microphone: captures audio when you intentionally start dictation.

- Speech Recognition: converts your voice to text. Apple’s speech-recognition service may process audio as described in Apple’s policies. The resulting transcript can be submitted to the selected App feature.

- Selected Files and Documents: accesses only files you choose through Apple’s document picker or open with the App. Security-scoped access ends after processing.

- Selected Photos: accesses only images you choose through Apple’s photo picker. OCR is performed on device where supported; extracted text may then be submitted for the requested AI feature.

- Notifications: permits alerts, sounds, and badges for App communications. Firebase Cloud Messaging processes an installation identifier and push token to deliver notifications.

- Tracking: if tracking or cross-app advertising measurement is enabled, Apple’s App Tracking Transparency prompt is shown before access to the advertising identifier or tracking. Declining tracking does not restrict paid or core App functionality.

- Clipboard: the App reads clipboard text only after you tap a Paste control or use a system paste action. It does not continuously monitor the clipboard.

You can change microphone, speech-recognition, notification, photo, and tracking permissions in iOS Settings. Some related features will not work if their required permission is denied, but unrelated features remain available.


3. How We Use Information

We use information to:

- provide AI detection, plagiarism or originality analysis, paraphrasing, summarization, grammar correction, writing-quality analysis, text categorization, AI chat, document chat, OCR, study guides, flashcards, and quizzes;

- return results, maintain the context of a document-chat session, and save history when you request it;

- operate the three complimentary uses and determine Premium entitlement;

- process, validate, restore, and manage subscriptions and paywalls;

- provide notifications you have authorized;

- measure feature performance and understand how the App is used;

- diagnose crashes, errors, abuse, security incidents, and service failures;

- prevent fraud and protect the App, users, and service providers;

- respond to support and privacy requests; and

- comply with legal obligations and enforce applicable terms.

We do not sell your submitted text, documents, images, prompts, or chat messages. We do not use that content to build advertising profiles. We do not use submitted content to train our own AI models.


4. AI Processing and Explicit Permission

Most writing and analysis features require the selected text, extracted document passages, questions, recent relevant conversation context, or prompts to be transmitted over an encrypted connection to our Vercel-hosted backend and/or to one or more third-party AI processors.

Before the App first sends personal data to a third-party AI service, it must show an in-app disclosure identifying the categories of data to be sent, the purpose, and the recipients, and request your explicit permission. If you decline, the App will not transmit content to third-party AI services; features that require remote AI processing will be unavailable, while features that operate locally should remain available. You may withdraw this permission from the App’s privacy settings. Withdrawal applies to future transmissions and does not reverse processing already completed.

Depending on the feature, availability, configuration, model routing, and fallback behavior, recipients may include:

- Vercel, which hosts our secure request-processing backend;

- OpenRouter, which routes requests to the model provider selected for the request;

- OpenAI;

- Google Gemini / Google AI services;

- Originality.ai; and

- Hugging Face.

When OpenRouter is used, the underlying model provider shown or selected by the service may also process the submitted request. Provider availability can change. We configure and select services for App functionality, not advertising, and where controls are available we prefer settings that limit provider logging, retention, and training use.

Third-party AI providers process information under their applicable service agreements and privacy terms. We require service providers that receive user data from the App to provide the same or an equivalent level of privacy protection described in this Policy and required by Apple’s App Review Guidelines. We do not authorize them to use App content for their own advertising. If we cannot obtain appropriate protections from a provider, we will not use that provider for personal data.

AI-generated output may be inaccurate or incomplete. Do not rely on it as the sole basis for medical, legal, financial, academic-disciplinary, employment, or other high-impact decisions.


5. Other Service Providers

We use the following categories of providers as needed to operate the App:

- Apple StoreKit and App Store: purchases, subscription management, restoration, refunds, and receipt information;

- Firebase Analytics: app-usage events and product analytics;

- Firebase Crashlytics and Sessions: crash, diagnostic, performance, and session information;

- Firebase Cloud Messaging: push-notification tokens, delivery, and interaction information;

- Superwall: paywall presentation and subscription-flow events;

- RevenueCat: subscription entitlement and purchase-status management where enabled;

- AppsFlyer: install attribution and marketing measurement only where enabled and subject to required consent and Apple’s tracking rules;

- Vercel and AI providers listed in Section 4: backend hosting and requested AI processing.

These providers may process IP addresses and ordinary request metadata when your device connects to their services. We share only information reasonably necessary for the specified service. We do not currently display third-party banner, interstitial, or rewarded advertising in the App. If that changes, this Policy, the App Store privacy disclosures, and the consent flow will be updated before such processing begins.


6. Legal Bases Where Applicable

Where the GDPR, UK GDPR, or a similar law applies, we rely on:

- performance of a contract to provide features and Premium access you request;

- consent for third-party AI sharing, protected-resource permissions, optional analytics where required, notifications, and tracking;

- legitimate interests for narrowly tailored security, fraud prevention, debugging, and service reliability, provided those interests are not overridden by your rights; and

- legal obligation for tax, accounting, dispute, and regulatory requirements.

You may withdraw consent at any time for future processing. Withdrawal does not affect processing that was lawful before withdrawal.


7. Retention and Deletion

- On-device content and history: retained until you delete the relevant history, clear App data, or uninstall the App. Some information may remain in an iCloud or device backup controlled by you or Apple until that backup expires or is deleted.

- AI request content: our backend uses submitted content to service the request and is not intended to create a developer-operated cloud history. Content is retained by us only as long as reasonably necessary to complete the request, protect the service, investigate a reported failure, or comply with law. AI providers may retain request content for the periods stated in their business/API terms and configured data controls.

- Analytics and attribution information: retained according to our configured provider settings and only as long as needed for analytics, attribution, security, and service improvement. AppsFlyer states that it generally does not retain end-user data for more than 24 months unless otherwise directed or legally permitted.

- Crash and diagnostic records: retained only as long as reasonably necessary to identify and resolve reliability or security issues and under the configured Firebase retention controls.

- Purchase records: retained for the subscription lifecycle and as required for accounting, fraud prevention, dispute resolution, and legal compliance. Apple independently retains App Store transaction information under Apple’s policies.

- Support records: retained until the request is resolved and thereafter only as reasonably necessary for follow-up, security, dispute resolution, or legal compliance.

When information is no longer required, we delete it or de-identify it. De-identified information will not be used to re-identify you.

To request deletion of information held by us or our processors, email **elmelloukyd@gmail.com** with the subject “Privacy Request.” Because the App has no developer-operated user account, we may need information such as an installation or transaction reference to locate records, and in some cases we may not be able to link server or analytics records to you. We will respond within the period required by applicable law. We may retain limited records when required by law or necessary to establish, exercise, or defend legal claims.


 8. Your Choices and Privacy Rights

Depending on your location, you may have the right to request access, correction, deletion, restriction, portability, or objection to processing, and to withdraw consent. You may also have the right to complain to your local data-protection authority.

You can also:

- delete saved history using the controls available in the App;

- withdraw future third-party AI processing consent in the App’s privacy settings;

- change system permissions in iOS Settings;

- decline or revoke tracking permission without losing core or paid functionality;

- manage or cancel a subscription in **iOS Settings > Apple Account > Subscriptions**;

- restore eligible purchases using the App’s Restore Purchases control; and

- stop future processing by discontinuing use and uninstalling the App.

We will not discriminate against you for exercising applicable privacy rights.


 9. International Transfers

We and our providers may process information in countries other than the country where you live, including the United States. Where required, international transfers are protected by recognized safeguards such as adequacy decisions, Standard Contractual Clauses, contractual data-protection terms, and supplementary security measures.


10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information, including encrypted network transport, access controls, data minimization, and provider review. No network transmission or storage system is completely secure, so we cannot guarantee absolute security.


 11. Children’s Privacy

The App is not directed to children under 13 and is not offered in Apple’s Kids Category. We do not knowingly collect personal data from children under 13. In regions with a higher age of digital consent, a child must use the App only with any consent required from a parent or guardian. If you believe a child submitted personal data without appropriate authorization, contact us so we can take reasonable steps to delete it.


12. No Account Creation

The current App does not provide developer-operated account creation. Therefore, there is no App account to delete. Apple Account subscription management is controlled by Apple. If we introduce account creation, we will update this Policy and provide in-app account deletion before releasing that feature.


13. Changes to This Policy

We may update this Policy when the App, providers, or legal requirements change. We will update the effective date and provide additional notice in the App when a material change requires notice or renewed consent. Material changes do not apply retroactively where prohibited by law.


14. Contact

For privacy questions, consent withdrawal, or data-rights requests, contact:

Email: elmelloukyd@gmail.com