SynthID Detector

Privacy policy

Last updated: October 8, 2026

This policy explains how SynthID Detector (“we”, “us”) handles personal data when you use SynthID Detector.

Images you check are not stored

When you check an image, your browser uploads it to our server over an encrypted connection. We read its Content Credentials (C2PA manifest) and embedded metadata in memory and send back the report. The image is discarded when the response is sent; we do not write it to disk or keep a copy. The free check does not send your image to any third party.

Embedded metadata can contain personal information, such as a camera serial number, the software used, a creator name or a location. The report shows the provenance fields we read so you can see what your own file carries.

AI visual analysis

If you choose to run an AI visual analysis, we resize the image to at most 1536 pixels, re-encode it without its metadata and send that copy to fal.ai, which routes it to an AI vision model (Google Gemini by default) to describe visible generation artifacts. We ask these providers to process the image only to return the analysis; they handle it under their own data terms. Before sending, an automated check blocks explicit nudity. We store the resulting report — file name, file size, a SHA-256 fingerprint of the file, the provenance findings and the model’s analysis — in your account. We do not store the image.

Information we collect

Account data. Signing in is needed only for AI visual analysis and saved reports. With Google or email sign-in we receive your account identifier, name, email address and profile image.

A copy in your own browser. If you start an AI visual analysis before signing in, the image (up to 3.5 MB) is kept in this browser tab’s session storage so you do not have to choose it again after sign-in. It is removed as soon as the page reads it back and never leaves your device except for the analysis you requested.

Billing data. The payment provider selected at checkout (Stripe or Waffo Pancake) processes payment details. We receive the checkout session, subscription, payment status, amount and transaction identifiers, but not full card numbers.

Technical and analytics data. Essential logs may include IP address, browser details, timestamps, security events and errors; IP addresses are also used for short-term rate limits. We keep our own anonymous count of page views and button use linked to a random identifier in your browser. If you consent, Google Analytics 4 and Microsoft Clarity may collect page use, interaction, device and session data on public information pages. Session recording never runs on pages with the image checker, and analytics never receive your images, file names or reports.

How we use data

We use data to produce the reports you request, keep your report history and credit balance, process payments, secure accounts, prevent abuse, support customers and meet legal or tax obligations. We do not use your images or reports to train models, for advertising or to identify people, and we never sell them.

Processing partners

We share only what is needed with Google for sign-in and optional analytics, Stripe or Waffo Pancake for payments, Microsoft for optional Clarity analytics, fal.ai and the model provider it routes to for an AI visual analysis you request, and our hosting and database providers. These partners may process data in other countries under their terms and legally recognized transfer safeguards.

Retention and deletion

Saved reports are kept while your account is active. Request deletion of specific reports or of your account by emailing support. Payment and tax records may be retained for the period required by law.

Cookies

Essential cookies keep your session and choices. Optional analytics run only after you choose “Allow analytics”, and you can change that choice in the cookie policy.

Where Clarity is enabled, with your analytics consent we associate signed-in visits on approved public pages with a site-prefixed internal account ID to understand visits across devices. Clarity hashes this identifier before transmission. We do not supply your email or name through this feature. Signing out or switching accounts ends the current recording and clears Clarity cookies. Private pages remain excluded. You can withdraw analytics consent in Cookie preferences.

Your rights

Depending on where you live, you may request access, correction, deletion, portability, restriction or objection, and may withdraw consent at any time. Email [email protected]. We may need to verify your identity. You may also complain to your local data-protection authority.

Children

The service is not directed to anyone under 18.

Security and changes

We use access controls, secured cookies, server-side credentials, verified payment-provider callbacks and encrypted transport. No system is completely secure. Material changes will be posted here with a new date.

Contact

Data controller: SynthID Detector. Privacy questions: [email protected].