Privacy, storage, and preview status
Before you upload
Only upload a file if you are authorized to submit it. IDs and selfies can contain identity, document, and biometric information. If indefinite retention or link-based access is unsuitable for that information, do not use the public checker.
What is stored
The current service keeps the original uploaded files, derived forensic artifacts, method results, report and case metadata, an abuse-prevention fingerprint, and access or audit events. Derived evidence may include document, OCR, and face-comparison outputs when those checks apply. These records have no scheduled deletion date.
Who can view a result
Each public case receives a long, random result URL. Result pages send noindex headers and are excluded from the crawl directives, but they are not protected by an account or a viewer identity check. Anyone with the URL can open the report and request the original files and derived evidence, and a recipient can share the URL again. Treat the link as sensitive; the URL itself is the access control.
Evidence, not a verdict
The detectors produce research evidence and concern signals for human review. They do not issue an automatic authenticity verdict, verify an identity, or make an accept-or-reject decision. A result with no warning does not prove that a file is genuine, and a warning does not prove fraud.
How uploads are used
In the current implementation, uploads are not used to train models, placed in a public gallery, or sent to paid model APIs. The default detector pipeline runs on self-hosted infrastructure.
Deletion and rights requests
There is no automatic expiry and no public self-service deletion flow. The software has an administrative deletion path for operator-led legal, security, and abuse response, but a public privacy or rights-request contact has not yet been published.
Before regulated or EU use
This preview is not presented as ready for regulated decision workflows or EU production use. Before such use, the responsible operator must publish its controller identity and privacy contact, document the lawful basis and any special-category or biometric data handling, complete a DPIA or other required risk assessment, and establish enforceable retention, deletion, and data-rights processes. This page describes the current behavior; it is not a claim that those requirements have been completed.