Receive
You submit a file, text or public URL through the site or approved API.
Loading…
See which services receive your content, what we keep and when we delete it.
You submit a file, text or public URL through the site or approved API.
Only the providers needed for the selected format and analysis mode receive data.
The report brings together the findings and explains what they mean.
Personal checks save reports automatically and retain checked sources privately for 180 days. Earlier deletion can be requested by email. Business data, research copies and provider records follow their separate retention periods.
The research collection is limited to eligible B2C sources contributed with separate consent. Available report references can accompany those sources. Contributions support model development and evaluation; any training must be covered by the recorded consent and follow review. Neither using the service nor saving a report automatically authorises training.
B2B originals and reports are not retained for our own model training or copied into the B2C research archive. Confidential business submissions must use the company workspace or API. Temporary processing, customer workspace reports, API results, billing and security records still follow their stated retention periods.
The authorised service owner can review personal reports and retained sources privately for support and deletion handling. Other customers cannot access them. Automatic retention does not authorise research or training; research copies require separate consent.
Only the services needed for your selected check receive data. Some checks use a backup provider if needed. You must have the right to submit the content, including any personal data. The acceptable-use rules explain which sensitive material must not be uploaded.
The primary image and video analysis service receives the complete image and technical metadata. Audio uses the separate image/audio service; that service can also be selected for images. Reality Defender may receive the complete file when backup processing is enabled. When enabled, personal image checks send a reduced preview to OpenAI. Full business image checks include this separate automated visual review. Basic business image checks do not request it.
The external video analysis service receives the complete supported video and technical metadata. A separately configured private model may run only as shadow evaluation.
Pangram receives the submitted text within the published length limits. A private shadow model may receive the same text only when separately enabled.
PDF, DOCX and PPTX files are parsed in service memory. Importing prepares image previews and readable text without calling a detector. Selected images go through the image-analysis route. Text is sent to Pangram only if selected, separately from image checks; the original document is not sent to the text service. The older text-only document checker also uses extracted text or a representative sample.
DeepfakePolicy retrieves the selected public page or direct media/PDF link. The destination and media hosts see server requests, and Cloudflare DNS receives hostname lookups. Accessible files are downloaded for previews. Only the selected files are submitted for detection; optional text goes separately to Pangram. Private addresses and sign-in pages are excluded.
OpenAI may receive extracted text, the source name or final URL and, for image analysis, selected reduced images. Video investigation uses signed detector findings and the submitted filename instead of browser-generated frames. OpenAI may use web search to assemble public-source context.
When you start an evidence comparison, OpenAI receives the complete submitted JPEG, PNG or WebP images and PDF files, filenames, readable PDF text, your description and requested comparison fields. It reads documents and compares visible information across those sources. This route does not use web search. AI-generation detection remains a separate check.
Deleting our copy does not delete a provider’s logs or backups. The table distinguishes our records from those kept by other services.
| Data category | Current period | What this means |
|---|---|---|
| Company browser batch results and thumbnails | Seven days after completion; earlier deletion through authorised company controls | Results and report thumbnails expire together. Source files are removed after processing, with retry on failure. Downloads and customer-held copies follow the customer’s own retention rules. |
| Interactive source in DeepfakePolicy | B2C: 180 days from upload; earlier deletion by email. B2B: processing duration. | Personal checked files and text are saved automatically in private service storage, separately from reports and optional research. Import previews and unselected files are not archived. Webpage text checks retain the checked text and URL context. Expired sources are blocked and deletion failures retried. B2B sources are excluded from this archive. |
| Temporary analysis transfer object | Expiry marked after 3 minutes for site checks / 5 minutes for API checks; deletion attempted after use | The analysis service may retrieve the file through an unguessable URL. We request deletion after the check and retry expired objects. Expiry alone does not prove deletion. The external service’s own copy follows its agreement. |
| Evidence API private source | Until processing completes; scheduled deletion retry | Raw source is targeted for removal after processing. A failed delete remains actionable for retry; the selected report period does not extend ordinary raw-source storage. |
| Evidence API result | Customer selects 1 to 168 hours; default 24 hours; scheduled expiry | An authorised DELETE request can request earlier removal. Expiry clears the report, source details and webhook records. Basic billing and audit records remain. Scheduled deletion can take time to finish. |
| Business evidence comparison report | Seven days from submission; earlier deletion through authorised company controls | The report includes extracted values, short evidence excerpts, filenames, source hashes and citations. Complete files and full extracted document text are not stored in the report. Private comparison source files are removed after processing, with deletion retries on failure. Billing and audit records remain; downloaded copies follow the customer’s retention rules. |
| Saved interactive report | B2C: until an email deletion request or account erasure is completed. B2B: workspace deletion or agreed retention. | Contains the normalized result and source label or URL context, not the uploaded file or document body. Saving a report does not authorise model training. |
| B2C research contribution | Up to 180 days; scheduled deletion with retry | Separate research consent is required. Sources remain private and are reviewed before any permitted training or evaluation. B2B workspace and API data are excluded. Withdrawal blocks further research use and starts deletion; failures remain pending for retry. |
| Research consent and reward record | Account, legal and consent-demonstration period | Minimal status, consent/withdrawal time and credit-ledger information may remain after file deletion. |
| First-party product and funnel event | 90 days; scheduled deletion | With analytics consent, browser events use a random identifier and can be linked to the signed-in account and its recorded source and campaign. Operational checkout and completed-purchase events are recorded server-side with the account email for payment and revenue reconciliation, independently of browser analytics consent. Submitted content and payment-card data are excluded. |
| Provider operations telemetry | 180 days; scheduled deletion | Provider, route, status, latency, cost estimate and associated account or workspace for operational reconciliation. |
| Authentication session | 30 days maximum | Session token is stored only as a one-way hash and removed on expiry or sign-out. |
| Abuse-control hash | 24 hours maximum | Hash derived from the route or action and IP address, and from email where relevant; used for short rate-limit windows and removed by scheduled cleanup. |
| Account, workspace, cases and audit trail | Account or contract lifecycle, then verified erasure/anonymisation subject to legal records | There is no single automatic deletion period. Account erasure must preserve required records and other workspace members’ data. |
| Billing and credit ledger | Contract, accounting, tax, dispute and legal-retention period | Stripe handles checkout and payment details. Payment records follow Stripe’s terms and applicable accounting and legal requirements. |
| Cloudflare Workers, D1, R2, Images, Queues and logs | Depends on the service and account settings | Hosting is international. The operator has confirmed the current service arrangement; this page does not promise a particular region or one log/backup period for every Cloudflare service. |
| Transactional email at Resend | Standard plans: 30-day email-data period; customer and user data deleted within 90 days after account termination | Enterprise settings may differ. A separate backup period is not stated here. Reset and verification links expire before all email-provider records are necessarily deleted. |
| Optional Microsoft Clarity | Playback 30 days; aggregate/heatmap and selected sessions up to 9 months | Consent required. Limited to allowlisted public information pages and excluded from scanner, report, auth, account and admin routes. |
| Optional Google Analytics | GA4 property setting: 2 or 14 months; aggregated reports may persist | Consent required. The Google tag loads directly after acceptance. This table does not state a verified property-specific retention setting. |
The external media-analysis services and Pangram follow their account agreements for files, results, logs, backups and any human review. The recipient overview lists the arrangements confirmed by the operator. Storage periods follow each provider’s terms. OpenAI response storage is disabled with store: false; standard abuse-monitoring records may still remain for up to 30 days unless an approved zero-retention or modified-monitoring arrangement applies.
Analytics stays off until you accept it. Google Analytics receives selected page and product events. Clarity is limited to selected public information pages and is excluded from checks, results, sign-in and account pages. We do not intentionally include submitted content, results, passwords or payment-card details in analytics. See the privacy policy for payment-event handling and browser storage.
Your browser remembers your language and analytics choice. After acceptance, it also keeps a random analytics identifier and campaign details. Rejecting analytics clears our optional entries and tells loaded analytics services to stop permitted analytics storage.
Request deletion of a source, report or account by emailing deepfakepolicy@proton.me. State what should be deleted and include the report reference or check date if available. Do not attach the original again. Requests are handled without undue delay and within the applicable legal deadlines, with identity verification where needed.
Research consent can be withdrawn in the account to stop future research use and delete the separate research copy. Request deletion of operational sources and reports by email. Source and report deletion are separate; request both to remove both. Automatic expiry and deletion retries continue. Required billing and minimal audit records may remain. Business deletion controls are unchanged.