Skip to content

Privacy Policy

Effective date: 13 July 2026
Last updated: 19 July 2026

This Privacy Policy explains how AIGator collects, uses, shares, stores, and protects personal data when you visit AIGator.com, create or use an AIGator account, submit text to the AIGator AI Checker, contact us, or use related pages and services.

1. Controller and contact details

The controller responsible for AIGator is:

Roth Media GmbH
Lorrainestrasse 19
3013 Bern
Switzerland

Privacy inquiries and requests may be sent to [email protected].

2. Scope

This policy applies to AIGator.com, api.aigator.com, the AIGator AI Checker, account registration and login pages, account dashboards, guest and account usage limits, the Prompt Library, the Blog, the Contact page, and other AIGator pages and features that link to this policy.

Third-party websites and services linked from AIGator are governed by their own privacy notices. AIGator is not responsible for the privacy practices of websites that it does not control.

3. Data we process

3.1 Text submitted for analysis

When you use the AIGator AI Checker, the text you submit is transmitted securely to api.aigator.com and processed to produce a probabilistic writing-origin assessment, classification, sentence-level composition, explanations, highlighted evidence, confidence information, and assessment limitations.

AIGator does not intentionally save the full submitted text in a persistent AIGator application database as part of the ordinary checker flow. The text is processed for the request and is disclosed to a specialized third-party AI processing provider as described in Section 7.

AIGator may temporarily cache a derived result in server memory using a cryptographic hash of normalized text, the analysis configuration, and the model or prompt version. This can allow an identical repeated check to be returned without another provider request. A cached result may include derived classifications, explanations, offsets, and short quotations from the submitted text, but it does not intentionally contain the complete submitted document. The cache normally expires within 24 hours or earlier when the application process restarts.

Do not submit confidential, legally privileged, secret, health-related, financial, identity-document, or other sensitive personal information unless you are authorized to process it through AIGator and accept the processing described in this policy.

3.2 Account registration and profile data

If you create an AIGator account, we process information including:

  • your email address;
  • your name or display name, where provided;
  • an automatically generated WordPress username;
  • your account role and account creation date;
  • a password hash generated and stored by WordPress;
  • email-verification status;
  • a hashed email-verification token and its expiry time until verification is completed or the token expires;
  • account preferences and security information required to operate the account;
  • your current plan label and available allowance as displayed in the account dashboard.

Passwords are processed through WordPress and are not available to AIGator in readable form. You are responsible for using a strong, unique password and protecting access to your account.

3.3 Login, session, verification, and password-reset data

When you log in, remain signed in, verify an email address, change a password, or request a password reset, WordPress and AIGator may process:

  • authentication cookies and session identifiers;
  • the email address submitted to the login or password-reset form;
  • verification and password-reset tokens;
  • form-security nonces;
  • timestamps and rate-limit information;
  • IP address and browser or device information in security and server logs;
  • whether the “keep me signed in” option was selected.

Email-verification links normally expire after 24 hours. Password-reset links expire automatically under the applicable WordPress security settings. Verification and reset messages are delivered using our email and hosting infrastructure and may be processed by the email delivery provider used by AIGator.

3.4 Short-lived account access tokens

When a verified, signed-in user runs an account check, WordPress creates a short-lived signed access token so that api.aigator.com can verify the account without receiving the WordPress login cookie. The token normally expires after approximately five minutes and contains an internal WordPress user identifier, verification status, plan label, issue and expiry times, and a unique token identifier. It does not contain the account email address or password.

3.5 Guest-check and browser quota data

To offer a limited check without requiring an account while reducing automated or abusive use, AIGator may store a randomly generated browser identifier and a guest-access status record in your browser’s local storage. The browser record can include a quota reset time and is used to display whether the no-account allowance has already been used.

api.aigator.com converts the browser identifier and network address into one-way keyed hashes for quota enforcement. The guest quota ledger may contain:

  • a one-way browser-identifier hash;
  • a one-way network-address hash;
  • usage counts and quota-window timestamps;
  • daily network and global capacity counters;
  • short-lived reservation identifiers and timestamps used to prevent double spending of an allowance.

The guest quota ledger does not intentionally contain the submitted text, the raw browser identifier, the raw IP address, an account email address, or a Turnstile token. Clearing local browser storage may remove the browser-side status display, but server-side network and quota protections may still apply.

3.6 Free-account usage and quota data

For verified free accounts, the detector API records a one-way account-identifier hash, the applicable calendar month, the number of checks used, the last-use time, and short-lived reservation data. The account quota ledger does not contain the submitted text, account email address, password, or readable WordPress user identifier.

The current free-account allowance resets at the start of each UTC calendar month. Failed provider requests are designed to return a reserved check to the account allowance.

3.7 Cloudflare Turnstile and abuse prevention

AIGator uses Cloudflare Turnstile to protect guest checks, account registration, login, and selected forms against bots and automated abuse. Turnstile may process technical and behavioral signals, IP address, browser and device characteristics, challenge results, hostname, form action, and related security data. The browser produces a short-lived token, which AIGator validates on the server through Cloudflare’s Siteverify service.

Turnstile tokens are not intentionally retained by AIGator after validation. Cloudflare may set or read security-related cookies or similar technologies, including a clearance cookie where configured. Cloudflare processes data under its own privacy terms.

3.8 Contact and support communications

If you contact us, use the contact form, request support, or communicate about an account, we process the information you provide, such as your name, email address, subject, message, attachments where accepted, and related correspondence.

Contact-form messages are sent to the relevant AIGator mailbox and are not intentionally stored as a separate public WordPress message archive. Copies may remain in mailboxes, backups, spam or security systems, and email-delivery logs.

3.9 Technical, security, and diagnostic data

Our hosting, content-delivery, security, application, and email systems may process technical data such as IP address, date and time, requested URL, HTTP method and status, browser and device information, referring page, request identifier, response time, error details, rate-limit events, security events, and suspected abuse indicators.

For account forms, AIGator may temporarily store a one-way hash derived from the network address to enforce an hourly attempt limit. The raw network address may still appear in ordinary server, Cloudflare, or security logs.

3.10 Analytics data

We use Google Analytics to understand how the website is used. Depending on your location, consent choices, and our configuration, Google Analytics may process page views, interactions, approximate location, device and browser information, referral information, and identifiers stored in cookies or similar technologies. We do not intentionally send submitted checker text, passwords, verification tokens, or full contact messages to Google Analytics.

4. How and why we use personal data

  • Provide the requested service: to analyze submitted text, display classifications and supporting evidence, operate account functions, and provide requested pages and features.
  • Create and administer accounts: to register users, verify email addresses, authenticate sessions, reset passwords, show account allowances, and provide customer support.
  • Enforce guest and account allowances: to reserve, commit, restore, and reset usage allowances and to prepare for future paid-credit accounting.
  • Protect the service: to prevent automated use, fraud, credential abuse, excessive requests, security incidents, and attempts to bypass limits.
  • Maintain and troubleshoot AIGator: to diagnose errors, monitor performance, manage capacity, and improve reliability.
  • Measure and improve the website: to understand page use, navigation, conversion, and technical performance, subject to consent where required.
  • Communicate with you: to send verification and password-reset messages, answer inquiries, and provide requested support.
  • Comply with law: to comply with legal obligations and establish, exercise, or defend legal claims.

5. Legal bases

Depending on the service used, your location, and the law that applies, AIGator relies on one or more of the following grounds:

  • Performance of a contract or steps requested before a contract: for providing checks, accounts, support, and requested services.
  • Legitimate interests: for operating and securing the service, preventing abuse, enforcing allowances, maintaining records, improving reliability, and protecting legal rights, where those interests are not overridden by your rights.
  • Consent: for non-essential analytics cookies or similar technologies where consent is required, and for any other processing presented as optional.
  • Legal obligations: where processing is required by applicable law, regulation, court order, or binding authority request.

Swiss data-protection law does not always use the same legal-basis terminology as the GDPR. The legal-basis information above is provided in particular for processing to which the GDPR, UK GDPR, or similar law may apply.

6. Automated analysis and important limitations

The AIGator AI Checker uses automated analysis to assess writing patterns. Results are probabilistic estimates and may be wrong. A result does not prove authorship, misconduct, plagiarism, intent, or whether a person used an AI tool.

AIGator does not use checker results to make legal or similarly significant decisions about users. You should not use an AIGator result as the sole basis for disciplinary, employment, educational, financial, legal, or other consequential action. Appropriate human review, context, source evidence, and an opportunity for the affected person to respond are essential.

7. AI processing provider

To perform live text analysis, AIGator sends the submitted text and the minimum technical information required for the request to a specialized third-party AI processing provider acting under commercial API terms. The provider processes the text to return structured classifications, evidence, and explanations to api.aigator.com.

Under the current provider’s standard commercial API terms, API inputs and outputs are not used for model training by default. The provider’s standard backend retention is generally up to 30 days, subject to exceptions for security, usage-policy enforcement, legal requirements, alternative contractual arrangements, or services with different retention controls. Provider and subprocessor information is available from AIGator on reasonable request.

AIGator may change or add processing providers when reasonably necessary for service quality, availability, security, or cost control. We will update this policy if a material change affects how personal data is processed.

8. Service providers and recipients

We may disclose personal data to service providers acting on our behalf, independent controllers, professional advisers, or authorities where necessary. Current categories include:

  • Hosting and server providers: including KnownHost in the United States, for WordPress, API, database, storage, logging, email, and infrastructure services.
  • Cloudflare: for content delivery, network security, traffic management, rate limiting, and Turnstile bot protection. See Cloudflare’s Privacy Policy.
  • Specialized AI processing provider: for live text-origin and writing-pattern analysis as described in Section 7.
  • Google: for Google Analytics, subject to consent choices where required. See Google’s Privacy Policy.
  • Email and SMTP providers: for verification, password-reset, contact, and support email delivery.
  • Professional advisers: such as legal, tax, accounting, security, and insurance advisers where reasonably necessary.
  • Authorities and courts: where disclosure is legally required or reasonably necessary to protect rights, users, or the service.
  • Business successors: in connection with a merger, acquisition, restructuring, financing, or sale of relevant assets, subject to appropriate confidentiality and legal safeguards.

AIGator does not sell submitted checker text, account passwords, or account contact information. We do not disclose submitted text to advertisers for targeted advertising.

9. International data transfers

Some providers may process personal data in countries outside Switzerland, the European Economic Area, the United Kingdom, or your country of residence, including the United States. Where required, transfers are based on adequacy decisions, recognized data-protection frameworks, contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism.

No transfer mechanism eliminates every risk associated with foreign laws or government access. AIGator selects providers and configurations with the aim of limiting data exposure and using only the information reasonably necessary for the service.

10. Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to protect and operate the service, or to meet legal, accounting, security, and dispute-resolution requirements. Retention may vary by record type.

  • Submitted checker text: not intentionally stored in a persistent AIGator application database after the request. It remains subject to the AI processing provider’s retention described in Section 7.
  • Derived in-memory result cache: normally up to 24 hours or until the API process restarts. Cached results may contain classifications, explanations, offsets, and short evidence quotations, but not the full submitted document.
  • Account profile: retained while the account remains active and afterward only as needed for security, dispute resolution, legal obligations, or a valid deletion exception.
  • Email-verification token hash: normally until verification is completed or the verification link expires, currently after 24 hours.
  • Password-reset data: retained until the reset link expires, is used, or is replaced, according to WordPress security settings.
  • WordPress authentication cookies: retained for the browser session or the longer “remember me” period selected at login, unless you log out or clear the cookie earlier.
  • Short-lived account API token: normally valid for about five minutes and not intended for long-term storage.
  • Free-account quota ledger: one-way account hash, current monthly usage, month, last-use time, and short-lived reservations are retained while needed to operate account allowances. Monthly counts reset at the start of a new UTC month. If an account is deleted, linked quota records will be deleted or anonymized unless retention is required for security, disputes, or law.
  • Guest browser identifier: remains in local browser storage until it is cleared, replaced, or removed by AIGator’s frontend logic.
  • Guest quota device hash: normally retained for the guest allowance window plus up to seven additional days for cleanup and abuse prevention.
  • Guest network and global daily counters: normally retained for up to three UTC days.
  • Incomplete quota reservations: normally released and removed after approximately ten minutes.
  • Account-form rate-limit records: normally retained for up to one hour.
  • Turnstile token: not intentionally retained by AIGator after validation. Provider-side records are governed by Cloudflare’s terms.
  • Aggregate API usage ledger: aggregate request counts, token totals, estimated API cost, and failure counts are stored for the current UTC day. The ledger does not contain submitted text or account email addresses. The previous daily aggregate is overwritten when usage is recorded on a new UTC day.
  • Server and security logs: retained under the log-rotation and retention settings of our hosting, content-delivery, email, and security providers for as long as reasonably necessary to operate, secure, troubleshoot, prevent abuse, investigate incidents, and comply with legal obligations. Records linked to an active incident, claim, or regulatory matter may be retained longer until the matter is resolved.
  • Google Analytics data: retained according to the period configured in our Analytics property, currently 14 months for applicable user and event data.
  • Contact and support communications: retained for as long as reasonably necessary to answer the inquiry, maintain an appropriate support record, and meet legal or record-keeping obligations.

Because submitted checker text is not stored in an AIGator account history, AIGator may be unable to retrieve or delete a specific past submission after processing has completed. This does not affect your ability to request deletion of account, quota, contact, or other records that AIGator still holds and can identify.

11. Cookies, local storage, and similar technologies

AIGator and its providers may use the following:

  • Essential WordPress cookies: for login, authentication, account sessions, security, and preferences.
  • Local browser storage: for a random guest browser identifier and guest-access status or reset information.
  • Cloudflare security cookies and technologies: for traffic management, bot protection, Turnstile, and security clearance where configured.
  • Analytics cookies or identifiers: for Google Analytics, subject to consent where required.

You can manage cookies and local storage through your browser and any consent controls displayed on the site. Blocking essential cookies may prevent login or account functions. Clearing local storage may remove the browser-side guest status, but it does not necessarily remove server-side quota or security records.

Google provides a Google Analytics opt-out browser add-on.

12. Data security

We use technical and organizational measures designed to protect personal data, including HTTPS, access controls, password hashing, short-lived signed account tokens, separate server-side secrets, one-way quota identifiers, rate limits, Turnstile validation, restricted file permissions, security monitoring, data minimization, and provider budget controls.

No internet service can guarantee absolute security. You should not submit information whose disclosure could cause serious harm, and you should contact us promptly if you believe an account or submission may have been compromised.

13. Your rights

Subject to the law that applies and any lawful limitations, you may have rights to:

  • request information about whether and how we process your personal data;
  • access personal data we hold about you;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain personal data in a portable format;
  • withdraw consent at any time for future processing where processing is based on consent;
  • complain to a competent data-protection authority.

Not every right applies in every jurisdiction or to every type of record. We may need to verify your identity and may retain information where required by law or where a valid exception applies.

14. Account access, correction, and deletion

You can review your email address, verification state, plan, and current free-check allowance on the Account page. You can change your password through the account interface.

To request correction or deletion of an account, email [email protected] from the account email address. Account deletion may require removal of both the WordPress account and the corresponding hashed API quota record. We may retain limited records where required for security, fraud prevention, dispute resolution, or legal compliance.

15. Children

AIGator is not directed to children under 16. A person under 16 should use AIGator only with appropriate authorization from a parent, guardian, school, or other responsible adult where required by law. If you believe a child has provided personal data without appropriate authorization, contact us.

16. Payments and paid plans

Paid checkout is not currently enabled. AIGator does not currently collect payment-card details through the account system described in this policy. Before paid subscriptions or credit packs are launched, this policy will be updated to explain the payment provider, billing identifiers, transaction records, subscriptions, credit ledger, invoices, refunds, and applicable retention.

17. Changes to this policy

We may update this Privacy Policy when the service, account system, providers, billing functions, security controls, or legal requirements change. The current version will be published on this page with an updated date. Where required, we will provide additional notice or request renewed consent.

18. Contact and supervisory authority

Privacy questions and requests can be sent to [email protected].

In Switzerland, the competent federal supervisory authority is the Federal Data Protection and Information Commissioner. If the GDPR applies to you, you may also have the right to complain to the data-protection authority responsible for your habitual residence, workplace, or the place of the alleged infringement.