New: Original View reports — findings directly on the original document See what's new
Legal

Privacy policy

This policy explains what data iOriginally processes on behalf of an institution, why, and the controls an institution has over it. It is a plain-language summary and forms part of our data-processing terms.

Last updated: July 2026

Who controls the data

The institution is the data controller for the documents and user records it submits to iOriginally. iOriginally acts as a data processor, handling that data only to provide the service and only under the institution's instructions.

What we collect

  • Account data — names, institutional email addresses, roles, and department membership for the users an institution invites.
  • Submitted content — the documents uploaded for checking and the extraction, similarity, AI-writing, and integrity results derived from them.
  • Operational data — audit logs of authentication, admin actions, and report or certificate downloads, plus service logs kept for reliability and security.

How we use it

We use submitted content solely to produce the requested integrity report and certificate for the institution that uploaded it.

Our core commitment: customer documents are never used to train detection models and are never shared across institutions — except where an institution explicitly opts a document into a shared global repository.

Retention and deletion

Each institution sets its own retention window. A scheduled job purges documents and derived artifacts past that window, unless a legal-hold flag is set.

An institution can request a full export of its data as an archive, or a full deletion, at any time.

Security

Files are stored with signed, expiring access URLs and scanned for malware on upload. Access is isolated per tenant at the database level and enforced again in the service layer.

Passwords are hashed with argon2, admin roles can require two-factor authentication, and all sensitive actions are audit-logged. Read more on our security page.

DPDP (India) readiness

We present consent text at sign-up, maintain a data-processing terms page, and provide a breach-contact channel. Contact privacy@ioriginally.com for any data-protection request.


Related policies: Terms of service · Refund & service policy · Contact us with any question about this policy.