Privacy policy
1. Controller and contact
The controller responsible for the processing described here is manimedia, proprietor Markus Nick, Hinterm Zaun 24, 76228 Karlsruhe, Germany. Email: kontakt@manimedia.de. Telephone: +49 1577 7043630. Contact form: manimedia.de/kontakt/. Further provider information is available in the legal notice.
2. Website access and server logs
This website is hosted by STRATO. When you open a page, the hosting provider processes technical request data needed to transmit and secure the website. This can include the IP address, date and time, requested URL, referrer, browser and operating-system information, transferred data volume and response status. The purpose is reliable delivery, abuse prevention, fault diagnosis and system security. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is operating a secure and functional website.
Log data is retained only for as long as it is needed for those operational and security purposes and is then deleted or anonymised, unless a specific incident or legal obligation requires longer retention.
On the German and English homepages, the browser obtains a country code from GeoJS to choose the initial language automatically. This technically transmits the IP address to GeoJS and its Cloudflare delivery network. The request sends neither credentials nor a referrer; we use only the returned two-letter country code and do not store it. Germany, Austria and Switzerland are routed to the German homepage; every other country is routed to the English homepage. GeoJS states that it keeps no access logs and only anonymised error logs. The purpose and legal basis are a proportionate language choice and our legitimate interest in an internationally usable website under Article 6(1)(f) GDPR.
Inter and Poppins fonts are served from our own web server without a Google Fonts connection. Following an external link, including the contact form on manimedia.de, opens another website with its own privacy information.
3. Local document analysis and upload
For supported formats, the browser reads the selected file locally to estimate the number of standard pages. It then sends the complete file, its name, size and selected scan type to our web server. The server stores the file under a generated internal name. This upload occurs before you enter payment details and can therefore remain on the server even if you do not complete an order.
The purposes are page-count calculation, preparing the requested checkout, performing the selected check and delivering the result. For a completed order, the legal basis is Article 6(1)(b) GDPR. For an upload that is not followed by an order, processing is based on the steps you requested before a possible contract under Article 6(1)(b) GDPR and on our legitimate interest in operating and securing the upload workflow under Article 6(1)(f) GDPR.
4. Analysis and report workflow
After an order is accepted, authorised operational systems and personnel retrieve the uploaded file or extracted text to produce the selected report. For a plagiarism check, the test text is processed using PlagAware. PlagAware states that it temporarily stores the original file, extracts the text and processes that text for the check; its own account and retention settings govern the copy held in that service. AI-writing checks and report preparation can involve other technical analysis systems used for the selected product.
Processed data can include the document content, internal filename, scan type, detected standard-page count, order reference, result data and technical workflow status. The legal basis is performance of the contract under Article 6(1)(b) GDPR. See PlagAware’s data-protection information and its document-protection information.
AI writing and citation tools
The local tools read text and supported files in your browser. When you confirm transmission and request a price preview for proofreading, rephrasing, summarisation or an AI citation check, the entered text is transmitted to our server. We do not create a persistent text record for the price calculation. Creating an order stores the text, order email, contract documents and payment reference in encrypted private storage before payment. Incomplete orders expire after no more than 24 hours; the regular cleanup then removes their text and email contents. The legal basis is the pre-contractual steps you request and performance of the contract under Article 6(1)(b) GDPR.
After confirmed payment and the order confirmation, we transmit the text to Anthropic. These four tools do not upload the original file. Results and submitted passages are accessible using a personal access file for up to 24 hours after completion and are then removed by regular cleanup. Your browser holds access information for the session; you manage and delete any access file you download. Technical order journals retain product, amount, contract version, hashes, timestamps and payment, delivery and refund status for settlement and evidence. After content cleanup, they contain neither submitted text nor the order email. The tool displays purchase availability before payment.
Provider retention is separate. Anthropic processes the text under the terms and settings applicable to our API account. We do not promise processing exclusively in Europe or zero retention at Anthropic. See its API retention information and data processing and international transfer terms.
5. Storage and deletion of uploads
Regular scan uploads on our web server have a 30-day retention period from file storage. Access is blocked after expiry; an automatic scheduled task removes the associated upload files and expired token records. An internal download token may expire earlier; token expiry does not itself delete the uploaded file. Older files that cannot be assigned to a regular scan are reviewed separately. This period covers our upload storage; email copies, order records and copies held by analysis providers are separate. The four AI tools use the shorter content periods described above.
You can request earlier deletion at kontakt@manimedia.de. Quote the order number and delivery email so that the record can be located. A deletion request can be refused or restricted where continued storage is required by law or necessary for legal claims. Deletion from a service provider or short-lived backup can occur after a technical delay.
6. Order data and Stripe payment
When you proceed to payment, we process the delivery email, selected scan, standard-page count, amount, discount information, internal filename, language, acceptance status and order metadata. We send the information needed for payment to Stripe; the document itself is not sent to Stripe through the checkout integration. Stripe can also collect payment-method, billing, device, IP, fraud-prevention and transaction information directly from you.
The legal basis for creating and fulfilling the order is Article 6(1)(b) GDPR. Fraud prevention and payment security can also be based on Article 6(1)(f) GDPR, and statutory accounting or tax retention on Article 6(1)(c) GDPR. Stripe can act as processor and as an independent controller for purposes such as payment processing, fraud prevention and legal compliance. Details are available in the Stripe privacy policy and Stripe Privacy Center.
7. Order confirmation, report delivery and support
We use email infrastructure to send the order confirmation, processing information and the result and to answer support requests. These messages can contain the delivery email, order number, product, page count, amount, report information and links required for the workflow. Depending on file size, an uploaded file can be attached to an internal processing email or supplied to authorised processing systems through a time-limited download link.
The legal basis for transactional email and delivery is Article 6(1)(b) GDPR. Support and the defence of legal claims can also rely on Article 6(1)(f) GDPR. Email and support records are retained while needed to handle the order or request and afterwards according to applicable legal retention and limitation periods.
Electronic withdrawal
The withdrawal form processes your name, contract details, confirmation email address, declaration, receipt time and reference. We record the declaration in restricted storage outside the public web directory and confirm it by email. The legal bases are Article 6(1)(b) and (c) GDPR, including Section 356a BGB. Temporary request counters derived from the IP address help prevent abuse. Receipt and processing records are retained until processing is complete and thereafter only where legal obligations or specific legal claims require this; they are then deleted. Submitting a declaration does not automatically issue a refund.
8. Cookie choice and essential browser storage
The site stores the decision “accepted” or “declined”, a consent version and the date in your browser’s local storage under cookie_consent. This is used to remember and implement your choice. The legal basis for access to strictly necessary browser storage is Section 25(2) TDDDG and, where personal data is processed, Article 6(1)(f) GDPR. Our legitimate interest is respecting and documenting the selected privacy setting.
If you deliberately use the DE/EN switch on a homepage, that choice is stored under ps_language_choice only in the current browser tab’s session storage. This prevents the automatic country choice from overriding your deliberate selection. The entry ends with the tab session.
You can reopen the cookie choice at any time through “Cookie settings” in the footer. Clearing the site’s local storage removes the saved consent choice and causes the banner to appear again.
9. Google Ads conversion measurement
The Google Ads tag with identifier AW-17873038225 is loaded only after you choose “Accept all”. It can process the page and time, browser and device data, IP address, advertising-click identifiers, selected scan category, value and currency, and can set identifiers such as _gcl_*. The site’s event allowlist does not intentionally send document content, filename, email address or discount code to Google.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw consent for the future through “Cookie settings”. Google can process data in countries outside the European Economic Area under the transfer mechanisms described in its privacy policy and advertising information.
On the confirmation page, payment references are removed from the visible URL. They remain usable in tab session storage under ps_order_return_v1 for at most one hour to repeat the requested confirmation retrieval, and are discarded on a subsequent visit after expiry or when the tab closes. The legal bases are Article 6(1)(b) GDPR and Section 25(2)(2) TDDDG. Page addresses supplied to advertising measurement contain no URL parameters or fragments. A local technical purchase marker prevents duplicate reporting of the same confirmed order.
10. Recipients and international transfers
Depending on your use of the site, recipient categories are the hosting provider, GeoJS and its Cloudflare delivery network for automatic language selection, authorised processing personnel, PlagAware and other analysis systems used for the selected check, Stripe and participating payment providers, email infrastructure providers, and Google after advertising-measurement consent. Professional advisers, courts or authorities receive data only where this is legally required or necessary for legal claims.
GeoJS, Cloudflare, Stripe, Google and their service providers can process data outside the European Economic Area. Depending on the processing context, the safeguards can include an adequacy decision such as the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses. The linked provider notices explain the applicable entities and transfer mechanisms.
Right to object: You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons. A delivery email and an analysable document are required to perform the requested check. Advertising consent is voluntary.
11. Retention of order and payment records
Order, payment and accounting data is retained for the statutory retention periods that apply to commercial and tax records. Other contract and support records are kept only while required to perform the contract, answer requests or establish, exercise or defend legal claims. When a purpose and any applicable legal duty end, the data is deleted or anonymised.
12. Your rights
Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction and data portability. You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. Where processing is based on consent, you may withdraw that consent for the future without affecting the lawfulness of earlier processing.
Send requests to kontakt@manimedia.de. We may request information needed to verify your identity and locate the relevant order. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for our German establishment is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.
13. No legally significant automated decision
The checks automatically analyse textual patterns and produce technical indicators. We do not use those results to make a decision about you that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR. Universities, employers or other third parties may apply their own rules; they are responsible for their own decisions and processing.
14. Security and changes
The website uses TLS encryption in transit. Access to operational data is limited to the systems and persons required for the service. No internet transmission or storage system can be guaranteed completely risk-free.
We update this policy when the service, providers or legal requirements change. The version displayed when you use the service is the current published version.
Submission workspace and private AI pilot
The new AI pilot is not publicly activated yet. Local tools read inputs in your browser. Only an explicit save action stores body text, references and checklist in this browser profile; you can remove that saved copy in the workspace.
For a requested AI revision, after your confirmation we send extracted original text, report text, editable paragraph information and language through our server to Anthropic. Processing for the requested service is based on Article 6(1)(b) GDPR. The original files themselves are not uploaded or stored in this new workflow.
To recover a completed response, we retain the result, including affected passages, encrypted outside the public web directory. Access requires a valid code and the same request, for at most 24 hours and no longer than the code remains valid. A cleanup run subsequently removes the result data. A technical journal of request and entitlement hashes, timestamps and status prevents duplicate processing; after cleanup it contains no result passages. Keep the access code confidential.
Anthropic's processing and retention are separate and depend on the terms and settings applicable to our API access. We do not promise exclusively European processing or zero retention at Anthropic. See API data retention and data processing and international transfers.