← Back to Home
Privacy Policy
Last updated: September 11, 2026
Introduction
AI Detector is operated by {{LEGAL_ENTITY_NAME}}, {{ENTITY_TYPE_AND_STATE}}, of {{BUSINESS_ADDRESS}} ("we", "our", or "us"). We are the data controller for the personal data described in this policy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our browser extension, our website scanner, and our API.
You can reach us about anything in this policy at {{PRIVACY_EMAIL}}.
Information We Collect
Information You Provide
- Account Information: If you create an account, we collect your email address and password (encrypted).
- Payment Information: If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card details.
Content You Submit for Analysis
Everything in this section is sent to our servers, and onward to the third-party detection providers listed under "Third-Party Services" below, for the sole purpose of producing the analysis you asked for.
- Page text: When you analyze a page, its text content is sent for analysis.
- Files you upload: Images, video, audio and documents you submit are sent for analysis. Documents and images may contain sensitive personal information — identity documents, invoices, bank statements, tax paperwork. Please consider this before uploading, and do not upload material you are not entitled to share with a third-party processor.
- Audio captured for live checking: If you start a live fact-check, the audio from that browser tab is streamed to our transcription provider for as long as the session runs. Capture only happens while you have explicitly started a session.
- URLs: URLs of analyzed pages, used to assess source credibility. URLs are not linked to your identity unless you have an account.
- Usage data: Counts of checks and features used, to enforce plan limits and improve the service.
What We Do NOT Do
- We do NOT track your general browsing history. The extension analyzes a page only when you ask it to, or on the specific sites you have enabled it for.
- We do NOT collect personal information unless you create an account.
- We do NOT sell your data, and we do NOT use your submitted content to train our own models.
- We do NOT retain your uploaded files after an analysis completes. See "Data Retention" below for what is kept, which includes a short excerpt of analyzed text when you are signed in.
How We Use Your Information
- To provide and improve our fact-checking service
- To analyze content for misinformation detection
- To check source credibility
- To process payments (if applicable)
- To send important service updates (if you have an account)
Third-Party Services
No single model can detect AI-generated content reliably, so an analysis is run through several independent detectors and the results are combined. That means the content you submit is shared with the providers below. Which ones receive it depends on what you submitted — an image check does not involve the speech providers, and vice versa. Some are optional components that are only used when enabled.
Detection providers — these receive the content you submit
- Google (Gemini API and Cloud Vision): text, image, video, document and audio analysis, and transcription. Subject to Google's Privacy Policy.
- SightEngine: image and video-frame AI detection. Privacy Policy.
- Hive AI: image AI detection. Privacy Policy.
- Reality Defender: image and voice deepfake detection. Privacy Policy.
- Resemble AI: synthetic-voice detection. Privacy Policy.
- Deepgram: live audio transcription during a live fact-check session. Privacy Policy.
- Hugging Face, ZeroGPT, Sapling and GPTZero: optional additional text-detection models, used to cross-check text results.
- Apify: used only when you request a deep analysis of a social media or video URL, to retrieve that public page's content.
Reference sources — these receive a claim or a domain name, not your content
- Google Fact Check Tools: receives the text of a specific claim being checked.
- NewsGuard: receives only the domain name of a site whose credibility is being rated.
Infrastructure and operations
- Supabase: database hosting for accounts, scan history and cached results.
- Railway and Vercel: hosting for our API and website respectively.
- Stripe: payment processing on paid plans. We never receive or store your card details.
- Resend: transactional email, such as address verification and password resets.
- Sentry: error monitoring. Receives technical diagnostic data about failures, not the content you submitted.
If you would like to know exactly which providers were involved in a specific analysis, the result page lists the detectors that contributed to it.
Data Retention
- Uploaded files: Images, video, audio and documents are processed in memory and are not written to permanent storage by us. Retention by the detection providers listed above is governed by their own policies.
- Scan history (signed-in users): When you are signed in, each analysis is saved to your history so you can return to it. That record contains the verdict, the per-detector signals, the page title, the URL and domain, and a short excerpt of the analyzed text. It is kept until you clear your history or delete your account. Signed-out checks are not saved to any history.
- Cached results: Analyses of public URLs may be cached briefly so that repeat checks of the same page do not re-run every detector.
- Account data: Retained until you delete your account.
- Usage counters: Daily check counts, retained to enforce plan limits.
Data Security
We implement appropriate security measures including:
- HTTPS encryption for all data transmission
- Passwords stored only as salted hashes, never in recoverable form
- Rate limiting and abuse protection on all analysis endpoints
- Limited access to user data, restricted to what is needed to operate the service
No service can promise perfect security. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law.
Legal Basis for Processing
If you are in the European Economic Area, the United Kingdom or Switzerland, we process your personal data on the following bases:
- Performance of a contract: running the analysis you requested, maintaining your account, and providing your scan history. Without this processing we cannot deliver the service you signed up for.
- Legitimate interests: enforcing plan limits, preventing abuse of our analysis endpoints, diagnosing errors, and securing the service. We balance these against your rights and use the minimum data needed.
- Legal obligation: retaining billing records where tax or accounting law requires it.
- Consent: optional marketing email, where we ask for it. You can withdraw consent at any time, and withdrawing it does not affect processing already carried out.
International Data Transfers
We are established in the United States, and the detection providers listed above operate in the United States and elsewhere. If you use the service from the European Economic Area, the United Kingdom or Switzerland, your personal data will be transferred outside your country.
For those transfers we rely on {{TRANSFER_MECHANISM}}. You may request a copy of the relevant safeguards by contacting us at {{PRIVACY_EMAIL}}.
Our representative for the purposes of Article 27 of the UK and EU GDPR is {{EU_UK_REPRESENTATIVE}}.
Your Rights
Wherever you are, you have the right to:
- Access the personal data we hold about you, and receive a copy of it
- Correct data that is inaccurate or incomplete
- Delete your account and the data associated with it
- Export your data in a portable format
- Opt out of non-essential communications
If you are in the European Economic Area, the United Kingdom or Switzerland, you additionally have the right to object to processing carried out on the basis of our legitimate interests, to request that we restrict processing, and to withdraw any consent you have given.
To exercise any of these rights, email {{PRIVACY_EMAIL}}. We will respond within one month, and will tell you if we need longer because the request is complex. We will not charge you or make the service worse for asking.
You also have the right to complain to your data protection authority. In Norway this is Datatilsynet; elsewhere in the EEA it is your national supervisory authority; in the UK it is the Information Commissioner's Office. We would rather you came to us first so we can put things right.
If You Are in California
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use the content you submit to train our own models. You have the right to know what we collect, to request deletion, to request correction, and not to be discriminated against for exercising those rights. The categories we collect and the purposes we use them for are described above. To make a request, email {{PRIVACY_EMAIL}}.
Children's Privacy
Our service is not intended for children under 13, and we do not knowingly collect information from them. Some countries set a higher age of consent for online services; where the applicable minimum age in your country is higher than 13, that age applies instead. If you believe a child has given us personal data, contact us at {{PRIVACY_EMAIL}} and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes via email or in-app notification.
Contact Us
If you have questions about this Privacy Policy, or want to exercise any of the rights described above, contact us at:
Email: {{PRIVACY_EMAIL}}
{{LEGAL_ENTITY_NAME}}
{{BUSINESS_ADDRESS}}
← Back to Home