Privacy policy
This policy explains what we collect, who receives it, how long we keep it and how you can manage your data.
Who is responsible for your data
DeepfakePolicy is operated by Código Solidário Lda, NIF/NIPC 519431553, Rua da Arriba, N.º 18-Ac, Condomínio Vigias da Arriba, 2560-046 A dos Cunhados, Torres Vedras, Lisboa, Portugal.
We decide how data is used for accounts, consumer checks, billing, security, support and running the service. In data-protection law, this makes us the controller. For business customers, we may process data on their instructions under the applicable business agreement and Data Processing Addendum (DPA). The parties’ actual work determines their roles.
What we collect
- Account details: email, display name, securely hashed password, Google sign-in identifier if used, workspace, role and invitations.
- Submitted content: files, pasted text, public URLs, filenames, file types and technical metadata.
- Results and workspace activity: findings, reports, source context, cases, notes, assignments, exports and who changed them.
- Service records: hashed sessions and API keys, short-lived abuse-prevention hashes, credit use, provider status and response times, webhook delivery and security logs.
- Payments and messages: credit transactions, Stripe references and payment status, support emails and account-email delivery records.
- Optional analytics: your consent choice, a random browser identifier, visited pages, campaign details and selected product events.
Only submit content you have the right to use. The acceptable-use rules explain what you can upload. Financial and confidential documents are supported when you have the right to process them. Children’s data, criminal-offence data, protected sensitive data and identification biometrics need extra legal safeguards. Check that you have a lawful basis and that the selected providers and agreements support the processing before you upload.
Who receives a check
An external specialist service checks supported images and audio; Reality Defender can act as a backup. An external video-analysis service checks supported video. Pangram receives pasted text or text extracted from documents and public webpages. Optional OpenAI checks can use a reduced image preview, extracted text and source context. Deep investigation can also search public sources. For video investigation, OpenAI receives detector findings and the filename, not frames generated in your browser.
Some image/audio checks use an unguessable temporary file URL, marked to expire after three minutes for interactive checks or five minutes for the API. We attempt deletion after the provider call and retry expired objects if needed. The backup and video-analysis services receive the complete supported file. Checking a public URL sends a request to that website.
A separately enabled research detector may also evaluate a submission without changing your result. Its host and terms must be checked before use. See data processing and retention for the processing details. Providers’ own copies, logs and backups follow their respective terms.
Business evidence comparison
Business evidence comparison sends complete submitted images and PDFs, filenames, readable PDF text, your description and requested comparison fields to OpenAI. It does not use web search. Private source files are removed after processing, with deletion retries on failure. Comparison reports are retained for seven days from submission and may include extracted values, short evidence excerpts and file or page references. Authorised company users can request earlier deletion. Billing and audit records follow their separate retention periods.
Link and document previews
Importing a public link or a PDF, DOCX or PPTX prepares previews in service memory and returns the extracted files to your browser. Public websites and media hosts receive retrieval requests; Cloudflare DNS receives hostname lookups. Previewing does not submit content to detection services. Selecting files and starting checks sends only those files for the corresponding analysis. Extracted text is an optional, separate Pangram check. Large text sources use the displayed sample.
Batch manifests store filenames, source links where supplied, file hashes and report references so you can resume and export results. Batch reports are saved automatically. Original files and extracted document bodies are not saved with that manifest. Preview rate counters are associated with your account and expire from the active rate window within 20 minutes, with cleanup on later requests.
Personal accounts (B2C): sources, reports and research
Checking a file. Personal checks automatically retain the checked file or text in private service storage for 180 days from upload, independently of research consent. For a webpage text check, we retain the checked text and URL context. Previewing an import alone does not archive its original document or unselected files. Earlier deletion can be requested by email. Expired sources become unavailable and deletion failures are retried. Providers have their own record and backup rules.
Saving a report. Reports are saved automatically for personal individual and batch checks. They contain the result, check type, date, credit cost and source label or URL. Source files are retained separately from the report. B2C reports remain until we complete a deletion request or account erasure.
Optional model research and training. Eligible B2C users can separately contribute a source for developing and evaluating our detection models. We store that source privately after a successful supported check, together with its consent record and available report reference. Contributions are reviewed before use; they are not automatically fed into production training. Any training use must be covered by the recorded research consent. Saving a report alone does not authorise training, and this policy does not enrol users in research.
Research-file deletion is scheduled 180 days after consent. You can withdraw earlier in your account or by email. Withdrawal stops future research use and starts deletion. If deletion fails, the file stays excluded from research while we retry. A minimal consent, withdrawal and bonus-credit record may remain.
Withdrawal does not undo lawful processing already completed. Requests about personal data already incorporated into a completed model are assessed under applicable law; your rights to erasure and objection remain.
Access to saved B2C materials
The authorised service owner can access saved personal reports and retained sources in the private admin area for support and deletion handling. Automatic service storage does not authorise model research or training. Research use requires separate recorded consent. Other customers cannot access these materials. Expired or deleted sources are unavailable. Access and deletion actions are recorded without copying content into the audit log.
Confidential business data (B2B)
Business workspace and API submissions are excluded from the B2C research and training collection. We do not retain B2B originals or reports for our own model training or copy them into the B2C admin research archive. Submit confidential company material through the company workspace or API; a personal-account research choice does not authorise use of company data.
Business checks still require operational processing. Temporary sources are deleted after processing, with retries if deletion fails. Workspace reports, case records and API results follow the customer workflow and the retention periods described below. Billing, security and audit records have separate purposes and periods; exclusion from training does not mean that every operational record is immediately erased.
API files and reports
Company browser batches keep results and report thumbnails for seven days after completion. Source files are removed after processing, with retries if deletion fails. Download reports before they expire. This does not change the separate storage rules for personal checks or existing workspace case records.
API files and inline text are private while queued or processed. We attempt deletion after processing and retry failures. You choose report retention from one hour to seven days; the default is 24 hours. An authorised DELETE request can request earlier removal. Scheduled deletion can take time to finish.
Expiry removes the result, errors, source details, idempotency key and webhook-delivery details. Basic workspace, requester, API-key, check-type, credit and time records remain for billing and audit. Your chosen webhook destination controls its own copy of a delivered report.
Companies we use
Cloudflare hosts the site and its databases, file storage, queues and operational logs. Stripe handles enabled payment flows. Specialist analysis services process the data needed for the selected check, which may include identifiable people, voices and ordinary personal data.
The recipient overview covers hosting, analysis, email, analytics, sign-in and payment services. Their terms differ: using the service does not mean every provider deletes all records immediately, rules out human review or keeps data only in the EU.
Cookies and optional analytics
Optional analytics stays off until you select “Accept all” or enable Analytics under “Customize”. Google Analytics then receives selected page and product events. Our own records use a random browser identifier and, with analytics consent, link source and campaign labels to your signed-in account, checks and payment references for up to 90 days. Google advertising measurement remains off unless you select “Accept all” or separately enable Advertising measurement under “Customize”; that setting permits Google to match ad clicks to visits and selected business events, including completed checks and confirmed company payments. Personalised advertising remains off; we do not use enhanced conversions or send hashed contact details. Earlier analytics choices remain valid for analytics only. The Google tag loads directly after consent; we do not use Google Tag Manager.
After acceptance, a 180-day consent cookie allows a pseudonymous Google browser identifier to be added to Stripe metadata for confirmed purchase and refund events. It is omitted when consent is absent or rejected. Separately, we record checkout starts and completed purchases with the account email for our own payment and revenue records, regardless of optional analytics.
Microsoft Clarity is limited to selected public information pages. It is excluded from the scanner, results, sign-in, account and admin pages. Recordings last 30 days; heatmaps, totals and selected sessions may remain up to nine months. Google Analytics keeps event/user data for two or 14 months according to the property setting; aggregated reports may remain longer. This page does not state a verified property-specific setting.
Your language choice is kept in a one-year cookie and local storage until changed or cleared. Your selected country or region is stored separately in a one-year preference cookie; it does not determine your billing address or tax treatment. With analytics consent, Google Analytics events include the selected market and interface language. Analytics and advertising measurement have separate choices, stored locally for up to 180 days. We also keep the current signed-in advertising choice and its time for up to 180 days to apply withdrawals to later business events. A consented random marketing identifier and campaign details use a first-party attribution cookie lasting 90 days. Consented source labels may be included in Stripe metadata, which follows Stripe’s retention rules. You can change either choice in Cookie settings. Under “Customize”, disabling Advertising measurement while keeping Analytics enabled withdraws advertising measurement, removes our advertising cookies and preserves permitted analytics. “Reject all” stops both and removes our optional analytics entries. Withdrawal affects future measurement; it does not erase earlier lawful processing, language or country preferences, or required payment records.
We do not intentionally send uploaded media, extracted text, report contents, passwords or payment-card details in analytics events.
Why we use this data
- To provide the service you request: accounts, checks, reports, company workspaces, API access and support.
- For our legitimate interests, balanced against your rights: security, preventing abuse, reliability, payment reconciliation, limited operational records and legal claims.
- With your consent: optional analytics, separately selected advertising measurement and separate research contributions. You can withdraw each consent.
- To meet legal duties: tax, accounting, sanctions, lawful requests and required records.
When we process data for a business customer, that customer determines the legal basis and gives the instructions.
Where data is processed
We are based in Portugal, but our hosting and analysis providers operate internationally. Data may be processed outside the European Economic Area or the UK. We do not promise EU-only storage or processing; OpenAI calls use its global endpoint.
Where required, transfers must use a valid safeguard for the relevant company, account and service. This may be an adequacy decision, EU Standard Contractual Clauses, UK transfer terms or another lawful mechanism.
How long we keep data
- API reports: one hour to seven days, as selected.
- Personal service sources: deletion scheduled 180 days after upload, or earlier on request. Separate research copies: 180 days after consent, or earlier after withdrawal.
- Our product and payment-funnel events: 90 days.
- Account-linked provider-operation records: 180 days.
- Sessions: up to 30 days. Authentication and event-rate hashes: up to 24 hours.
- Saved B2C reports: until a deletion request or account erasure is completed. Business reports follow workspace or API retention.
Account, case, billing and audit records follow the account or contract lifecycle and legal retention duties. There is no single period for every record. Failed file deletion is retried.
Providers have separate periods. For example, OpenAI abuse-monitoring records may remain up to 30 days even with response storage disabled, and Resend’s standard email-data period is 30 days. Cloudflare log and recovery periods depend on the service and account settings. See the full retention table.
How we protect data
We use encrypted connections, server-side secrets, hashed passwords and API keys, workspace access controls, signed webhooks and private storage. Automatic service retention and optional research are separate. No online service can guarantee complete security. See our security measures.
Decisions about people
Reports can be wrong. They do not automatically decide employment, credit, insurance, eligibility, law enforcement or access to a service. Important decisions require qualified human review and independent checks.
United States state privacy rights
Where an applicable United States state privacy law gives you additional rights, you may request access, correction, deletion or a portable copy and, where applicable, opt out of sale, sharing for cross-context behavioural advertising, targeted advertising or certain profiling. You may also have a right to appeal a denied request. We do not discriminate against you for exercising applicable privacy rights.
DeepfakePolicy does not sell personal information for money and does not use uploaded media, extracted text or report contents for targeted advertising. Optional analytics and related disclosures are described above. Where an applicable opt-out right covers those optional disclosures, rejecting optional analytics prevents them. Submit a request or appeal by emailing deepfakepolicy@proton.me; we may need to verify your identity and the law may allow or require exceptions.
Managing your data and requesting deletion
Depending on the law that applies, you can request access, correction, deletion, a portable copy, limits on use or object to processing. You can withdraw consent, appeal certain decisions and complain to a data-protection authority. We may need to verify your identity. Some records may need to remain for legal, security or accounting reasons.
To request deletion of a B2C original, saved report or account, email deepfakepolicy@proton.me. Tell us whether the request covers the source, report, both or the whole account, and include the report reference or check date if available. Do not resend the original or provide passwords. We handle requests without undue delay and within the applicable legal deadlines; opening an email link does not itself submit a request or delete data.
You can withdraw research consent directly in your account to stop future research use and start deletion of the separate research copy. This does not delete the operational source or report; request those by email. Automatic expiry continues. Source and report deletion are separate: request both if you want both removed. Other privacy requests can use the same email contact.
Business users should usually contact their organisation first. Authorised workspace and API deletion controls remain available. In Portugal, the authority is the Comissão Nacional de Proteção de Dados.
Children
The service is not intended for children under 16. Children should not create an account or submit personal media on their own. Material involving children requires lawful authority, any required parental permission and the applicable safeguards. Child sexual-abuse material is never allowed.
Questions and updates
Contact deepfakepolicy@proton.me about privacy. This is our privacy contact, not a separately appointed Data Protection Officer. We date and publish material changes here. Business customers receive any notices required by their agreement and DPA.