Local inspection and cleanup
The Unicode inspector, character map, limited payload decoding and character cleanup all run in your browser. Using them doesn't send your document to Zyphh's server or an AI provider. Input and results stay in page memory until you clear them or leave the page. Anything you download stays on your device. The site doesn't put documents in localStorage, and it doesn't create a public result URL.
Local detection and paraphrasing
Both tools run our own code in a browser worker. The detector runs a learned classifier and calculates style features, and the paraphraser applies curated editing rules. Neither sends submitted text to our server or to an external AI service. Neither needs API credentials or an account.
Your browser downloads the code and fetches public configuration, but those requests don't contain your passage. The app holds text and results in memory. Exporting a report or a revised file creates a local download of your choosing. That file can include your original document, so treat it accordingly.
Document uploads
PDF, Word DOCX, TXT and Markdown files are read in your browser. File bytes and extracted text are not uploaded to our server or a document-conversion vendor. Parser libraries and detector parameters download as site assets; those requests contain no document content.
The file name and extracted text appear in the current page. Cancel, clear the editor or leave the page to discard application state. Your browser may retain its own clipboard or restored form state. No uploaded document is used for training. The published classifier was trained separately on the public RAID benchmark.
Optional statistical-watermark verification
An operator may connect a separate authorized watermark-verifier service. If it's enabled, using it is a distinct action from local inspection and requires your explicit consent before any passage is transmitted. The actual recipient has to be named in the public privacy notice before the integration is offered. No verifier is connected in the default configuration.
Local style scores and Unicode inspection never trigger this remote check silently. When no compatible service is connected, the statistical check shows as not tested. Don't send a confidential document to an optional verifier without permission and a look at its processing terms.
Hosting and request metadata
Cloudflare hosts the site and handles network metadata such as IP addresses, request headers and timing when you load it. The application uses no third-party analytics SDK. It doesn't intentionally log document bodies. Hosting providers may handle security and operational metadata under their own policies.
Turnstile verification, short-term network limits and an aggregate daily counter apply only to an enabled remote watermark-verifier action. The counter stores a date and a request count, with no document content. The local detector and rewriter skip the challenge and send no processing requests.
Advertising and consent
We use Monetag for advertising on educational guide pages. Its page scripts load only after you choose Allow selected ads. The formats include Onclick popunders, vignette banners and in-page ads. Ad requests may share your IP address, device and browser details, page address and interaction information with Monetag and its delivery partners. These providers may use cookies and identifiers to personalize ads and measure delivery. Our integration does not pass pasted text, imported documents or tool results to Monetag.
Promotional push notifications are a separate, unchecked option. If you enable them, your browser asks for notification permission. Monetag uses a service worker registered for this site, and notifications may arrive when you are away from it. Rejecting ads or disabling that option attempts to unsubscribe and unregister our push worker. You can also block this site's notifications in your browser settings; our controls cannot reset a browser permission or remove cookies on another provider's domain.
Use Ad preferences in the footer to change or withdraw your choice. We store only your ad choices, their version and the time saved in browser localStorage for up to 180 days. This is separate from your text, which we do not store there. If storage is unavailable, the choice applies to the current page. Unknown, expired or rejected choices keep ad scripts off. Global Privacy Control also keeps ads off. AdSense is not currently enabled.
Your choices and contact
Clear the text fields or leave the page to discard the in-memory document. Your browser may keep its own history, clipboard contents or session restoration, and downloaded copies are yours to manage. Review exported reports before sharing them.
For privacy questions or corrections, use the contact page. The application has no document-history database, so there are no past passages to retrieve. Questions about an optional external verification service may need to go to the named recipient.