United States privacy notice
This notice supplements our Privacy Policy for people in the United States. It describes US state privacy rights and how our existing data practices apply to them. If a state law does not apply to us or to a particular request, we will still handle the request under the rights and commitments that otherwise apply.
Who is responsible
DeepfakePolicy is operated by Código Solidário Lda, NIF/NIPC 519431553, Rua da Arriba, N.º 18-Ac, Condomínio Vigias da Arriba, 2560-046 A dos Cunhados, Torres Vedras, Lisboa, Portugal. For personal accounts and our own account, billing, security and support records, Código Solidário Lda determines the purposes of processing. For eligible business customers, we may instead process customer content as a service provider or processor under the Data Processing Addendum.
Categories of personal information
Depending on how you use the service, we may collect identifiers and account information; commercial and billing records; internet or device activity and optional analytics; submitted images, audio, video, text, documents, URLs and their metadata; analysis results and reports; workspace activity; support communications; and security, API and audit records. Submitted content can contain information about other people. We do not ask personal users to submit government identifiers, payment-card credentials, medical records, highly sensitive identity documents or biometric data for identification.
The detailed sources, purposes, recipients and retention periods are described in the Privacy Policy, Data Processing and Retention page and recipient overview.
Why we use information
We use personal information to provide requested checks and reports; operate accounts and company workspaces; process payments; prevent abuse and secure the service; provide support; maintain billing, tax and audit records; and, only where enabled, measure product use and acquisition. Personal B2C research contributions require a separate recorded consent. Company content is excluded from the B2C research and training collection.
Sale, sharing and targeted advertising
We do not sell personal information for money. We do not use submitted files, report contents or company customer content for cross-context behavioural advertising or targeted advertising. Optional analytics requires your choice. Google advertising measurement remains off unless you select “Accept all” or enable Advertising measurement under “Customize”; earlier analytics choices never imply this permission. This setting measures ad clicks, visits and selected business events. Personalised advertising and enhanced conversions remain off. In Cookie settings, use “Customize” to disable Advertising measurement while keeping Analytics enabled, or choose “Reject all” to stop both. We do not intentionally send uploaded media, extracted text, report contents, passwords or payment-card details in analytics events.
If our practices change so that an applicable US law treats an activity as a sale, sharing for cross-context behavioural advertising or targeted advertising, we will provide the required notice and opt-out mechanism before using personal information for that purpose.
Sensitive information
Financial records, confidential documents and other lawful content are not excluded solely because they contain sensitive information. Submit only what is necessary and ensure the selected workflow, required agreements and safeguards permit the processing. Health data, government identifiers, precise geolocation, biometric data and other legally protected information may require additional conditions under applicable law. Do not submit such data until those conditions are met. Redact live credentials, payment-card security codes and unnecessary secrets. We do not use sensitive personal information to infer characteristics about personal users for advertising.
Your US state privacy rights
Depending on your state and whether the relevant law applies, you may have rights to confirm processing; access or know the personal information we hold; receive a portable copy; correct inaccuracies; delete information; opt out of covered sales, sharing, targeted advertising or certain profiling; limit specified uses of sensitive personal information; and appeal a refusal. We do not discriminate against you for exercising an applicable privacy right.
California residents may also request the categories of personal information collected, the categories of sources, our business or commercial purposes, the categories of recipients and the specific pieces of personal information we hold, subject to legal exceptions. We do not offer financial incentives for selling or sharing personal information.
How to make a request
Email deepfakepolicy@proton.me with “US privacy request” in the subject. State the right you want to exercise and the email address associated with your account. Do not send passwords, payment-card numbers or a copy of the original media merely to verify a request. We may ask for information reasonably necessary to verify your identity and authority. An authorised agent may submit a request where state law permits; we may request proof of the agent’s authority and, where allowed, direct confirmation from you.
We respond within the period required by the law that applies to the request and will explain any permitted extension or refusal. If your state provides a right to appeal, reply to our decision with “Privacy appeal” and explain why you want it reviewed.
Retention and deletion
Storage periods depend on the data. Personal source files are scheduled for deletion after 180 days, or earlier on request. You choose API report retention from one hour to seven days. Company batch results and thumbnails expire after seven days; marketing attribution records after 90 days. Account, billing, security and audit records follow our retention schedule. Provider copies and backups follow their applicable terms.
Children
The service is not intended for children under 16. Children should not create an account or submit personal media on their own. Material involving children requires lawful authority, any required parental permission and the applicable safeguards. Child sexual-abuse material is never allowed.
Business customer data
When a US business customer determines the purpose of processing and we process its customer content on documented instructions, the DPA includes US state service-provider and processor restrictions: no sale of customer personal data, no cross-context behavioural advertising, no use outside the contracted business purpose except as permitted by law, required protection, assistance with rights requests and deletion or return obligations.
Contact and updates
Privacy requests and questions can be sent to deepfakepolicy@proton.me. We will update the date above when this US notice materially changes. This notice supplements, and does not replace, the main Privacy Policy or rights that cannot lawfully be waived.