Data and confidentiality
Where your text goes when you paste it into a writing tool
Nobody reads the terms before pasting in a draft. Then one day the draft is a client's unpublished results announcement, and the question becomes urgent and retrospective.
The question nobody asks until it matters
Writing tools are pasted into casually, because the interaction feels like using a calculator. It is not. A paste is an upload, and an upload is a disclosure to a third party.
For your own blog post, this is a non-issue. It stops being a non-issue the moment the text belongs to someone else — a client's unannounced product, a case study containing customer names, a report under embargo, anything covered by an NDA you signed. At that point you have made a decision on your client's behalf, using terms you did not read, with a company you cannot name.
What actually happens to a pasted document
The full path is longer than the interface suggests. A typical online checker does some or all of this:
- Transmission. The text leaves your browser for the vendor's server. Encrypted in transit, almost always — this is the part everyone gets right.
- Storage. It is written to a database so you can come back to it. How long it stays is a policy decision, and it is frequently longer than the session.
- Onward processing. This is the step people miss. Many tools are a front end over someone else's model or search API. Your document may be forwarded to an AI provider, a search provider, or a plagiarism database — each with its own terms and its own country.
- The plagiarism database question. Some originality checkers add your document to the corpus they compare future submissions against. That is how they get better. It also means your client's unpublished text now sits in a third party's index permanently.
- Training. Whether the vendor, or the provider behind it, may use your content to improve models. Consumer tiers and business tiers frequently differ here, and the difference is often the entire reason the business tier exists.
- Logs and backups. Even after you delete something, copies persist in backups until they rotate out. This is normal and unavoidable; it should simply be stated.
Points 3, 4 and 5 are where the real exposure sits, and they are the three least likely to be visible in the interface.
Five questions to ask any tool
These can be answered from a privacy policy in about ten minutes. If a policy does not answer them, that is itself the answer.
- Do you use my content to train models — yours or anyone else's? Look for an unambiguous no. "We may use aggregated or anonymised data to improve our services" is not a no.
- Which third parties receive my text, and for what? A trustworthy policy names them. A policy that says "trusted partners" is concealing a list.
- In which country is it processed? Matters for UK and EU clients, and for anyone in a regulated sector.
- How long do you keep it after I delete it? A specific period is a good sign. Silence is not.
- Is my document added to a database used to check other people's work? Ask originality checkers this one explicitly. It is the question with the most surprising answers.
Hello, Before we use [tool] on client material, could you confirm the following in writing: 1. Is content submitted to [tool] used to train any model, yours or a third party's? If there is a setting that changes this, please point me to it. 2. Which sub-processors receive submitted content, and for what purpose? 3. In which countries is content processed and stored? 4. What is the retention period for submitted content, and what happens to it after account deletion? 5. Is submitted content added to any corpus or index used to check other users' submissions? 6. Do you offer a data processing agreement under UK GDPR? We act as processor for our clients' content and need the chain documented. Thanks, [name]
If the text is a client's, UK GDPR has an opinion
Most agency writing contains no personal data and this section does not apply. But a case study with a named customer, an interview transcript, a testimonial, a document with employee names in it — those do, and the position is then quite specific.
Your client is the controller. You are their processor. The tool you paste into is your sub-processor. That chain carries three practical obligations:
- You need a data processing agreement with your client, and one with the tool. If the tool does not offer a DPA, you cannot properly document the chain.
- Your client is generally entitled to know who their data is being passed to. Adding a sub-processor without telling them is a contractual problem before it is a regulatory one.
- Processing outside the UK needs a lawful transfer mechanism. Most large vendors have one; you should be able to point to it.
The practical version for a small agency: keep a one-page list of every tool that touches client material, with what it does and where it processes. It takes an afternoon, it answers procurement questionnaires instantly, and it is the document that makes you look like a grown-up business.
General information, not legal advice. Take proper advice if you handle regulated or special-category data.
A rule of thumb worth adopting
Sort work into three buckets and decide once, rather than deciding under deadline pressure every time.
- Public or soon-to-be public — a blog post going live next week. Any reputable tool is fine.
- Commercially sensitive — unannounced products, pricing, strategy. Only tools that contractually do not train on your content, with a DPA in place.
- Confidential or personal data — under NDA, embargoed, or containing named individuals. Only tools you have actively checked, ideally processing in your own jurisdiction, and only with the client's knowledge.
The mistake is not using online tools. It is not knowing which bucket you are in at the moment you paste.
Where Wordcheck sits, plainly
It would be convenient to end a guide like this by claiming nothing ever leaves. That is not true of any tool that does web originality checking, ours included, so here is the actual position.
The analysis, the voice profiles and the built-in rewriting run on our own server in London. For those, your text does not leave the machine, and it is never used to train anything.
Three optional features do send text out, and you are told at the point you use them: AI rewriting goes to an external model provider; web originality checking sends short exact phrases — not whole documents — to a search provider; deep originality checking sends the document to Copyleaks. If you would rather nothing left the server, use the analysis and the built-in rewriting, which are the defaults and do not call out.
Your documents are never added to a database used to check anyone else's work. The full detail, including named sub-processors and retention periods, is in the privacy policy — which is written to answer the five questions above, because they are the right questions to ask us too.
Common questions
Is it safe to paste client work into an online checker?
It depends entirely on the tool and on the sensitivity of the work. For content that is about to be published anyway, the risk is low. For anything unannounced, under NDA, or containing personal data, check the vendor's position on training, sub-processors and retention first — and make sure your client knows which tools are in the chain.
Do plagiarism checkers keep my document?
Some do, and some add it to the corpus they compare future submissions against — that is how academic-facing services build coverage. It is worth asking explicitly, because it is rarely prominent in the interface, and it means an unpublished document can end up permanently in a third party's index.
What is a DPA and do I need one?
A data processing agreement sets out what a processor may do with personal data on a controller's behalf. If you handle client content containing personal data, you generally need one with your client and one with each tool in the chain. Most established vendors publish a standard DPA; if one will not offer any, that tells you something.
Does using a UK-hosted tool make us GDPR compliant?
No — it removes one specific complication, which is the international transfer question. Compliance still depends on your lawful basis, your agreements, your retention and your transparency with the client. Hosting location is one factor among several, not a certificate.
Know where your text goes
Wordcheck runs its analysis on a London server and tells you before anything leaves it. Free account, no card.
Read next
Holding one brand voice across several writers
Why brand guidelines never survive contact with a freelancer, and a method that does — with a voice brief template you can copy.
Writing an AI disclosure policy for client work
The three honest positions an agency can take on AI, what to put in the contract, and a policy template you can copy today.