Browser-Based vs Server-Based AI Detectors: The Privacy Difference
Where does your text go when you paste it into a “free” AI detector? For most tools, the answer is: to their servers. A smaller, newer group of detectors — including TextVerdict — works differently. Here’s why that difference matters more than most people realize.
The two architectures
Server-based detectors (GPTZero, Copyleaks, ZeroGPT, and nearly every Turnitin-branded clone) send the text you paste to a backend API. The analysis happens on their hardware. That design has consequences most users never think about:
- Your text is transmitted and processed on someone else’s infrastructure, governed by their privacy policy — which may allow logging, retention, or training use.
- Every scan costs them money, which is why free tiers come with word caps, queues, and sign-up walls — and why “unlimited” claims tend to have an asterisk.
- Your relationship with the tool is gated by an account, because they need to meter your usage.
Browser-based detectors flip the model: the detection model (~100–200 MB) is downloaded to your browser once and cached. Scanning runs on your own device via WebAssembly:
- The text is never transmitted. You can disconnect from the internet after the model loads and keep scanning.
- There is no per-scan cost, so there is nothing to meter — no caps, no queues, no account.
- When you close the tab, your text is gone. There is nothing stored server-side because there was never a server in the loop.
Why this matters for students and writers
The typical use case for a free detector is checking draft work before submission — an essay, a personal statement, a job application letter. Ask yourself:
- Do you want that draft sitting in a third party’s database, tied to your account email?
- Would you paste unpublished work into a service whose data-retention policy you haven’t read?
- If the tool is free, what are you implicitly trading for it?
For published content none of this matters much. For unpublished, personal, or sensitive writing, it is the whole ballgame — and it is the reason browser-based detection exists.
How to check which type a site is (30 seconds)
You don’t have to trust anyone’s marketing. Verify it yourself:
- Open the detector and press F12 (DevTools) → Network tab.
- Paste your text and hit Detect.
- Watch the requests:
- A request containing your text (usually POST to an
/api/...or/detectendpoint) → server-based. - No new request at scan time, or a one-time download of an
.onnx/.wasmmodel file → browser-based.
- A request containing your text (usually POST to an
We encourage you to run this exact test on TextVerdict — the scan works with your network connection to the site severed.
The honest trade-offs
Browser-based detection is not free of compromises:
- First load takes time — the model download is a one-time ~120 MB cost.
- Models are open-source — an independent statistical opinion, not a proprietary system trained on millions of institutional submissions (see what Turnitin actually uses).
- No fancy dashboards — no scan history (nothing is stored!), no team features.
If you need workflow, reports, and integrations for an institution, commercial server tools are built for exactly that. If you need a fast, private check of how your writing reads — that is the browser’s home turf.
Try it
Scan your text now — free, no account, sentence-level highlights, and your text never leaves your device. Then run the DevTools test above on any competitor and compare.
Related: free AI detector with no word limit · why human writing gets flagged
Check your text now — free and private
Run the same scan the guides above describe: paste your text below and get an instant AI-score with sentence-level highlights. Nothing is uploaded.
🔒 Your text never leaves your browser — analysis runs 100% on your device.