English
1. Data processed
- Selected image: the visual content of a photo you choose from the library, capture with the camera, or import through the Share Extension. Images can contain faces, text, objects, or other personal information.
- Service-integrity data: Firebase App Check may process an app or device attestation token, IP address, and standard request diagnostics to protect the analysis service from abuse.
- Privacy-page request data: when you read this policy, Firebase Hosting may process the IP address, date and time, requested URL, browser user agent, and standard security diagnostics. This static page adds no developer analytics, tracking scripts, cookies, or form submission.
- Purchase state: Apple handles purchases. Fake or Not stores the remaining credit balance and processed transaction identifiers in the device Keychain.
- Local history: the image, result, confidence score, and date can be stored in the app’s local storage for the History feature. Depending on your Apple backup settings, this local app data may be included in an iCloud or computer backup.
Fake or Not does not require an account and does not ask for your name, email address, contacts, or location. The original filename and photo-library metadata are not intentionally sent for analysis.
2. How image analysis works
- You select an image and tap the Analyze button, or open a shared image in the app.
- Before the first transmission, the app names the data and processors and asks for your explicit permission.
- After permission, the app creates a resized JPEG copy, up to 2048 pixels on its longest side.
- Google Firebase securely receives the request and forwards the JPEG to Sightengine.
- Sightengine evaluates signs of AI generation and returns a confidence result.
If you choose “Not Now,” close the consent screen, or withdraw consent, no future image is sent unless you allow analysis again.
3. Third-party processors
Google Firebase / Google Cloud Functions provides the protected transport and server function. Firebase privacy and security information.
Sightengine (Kozelo SAS) is the third-party AI image-analysis processor. Sightengine Privacy Policy.
These processors may handle personal information to provide and secure the requested service, address technical issues, comply with legal obligations, and according to their applicable terms. Under their applicable service and data-processing terms, Google and Sightengine are required to provide the same or equivalent protection described in this policy and required by applicable law for data processed on behalf of Fake or Not.
4. Purpose and sharing
The selected image is shared only to provide the AI-image detection feature. Fake or Not does not sell personal information, use it for targeted advertising, track you across apps or websites, create a user profile, or use submitted images to train a developer-owned model.
5. Retention and deletion
- The Fake or Not server function does not write submitted JPEGs to a database or object-storage bucket and does not intentionally include image content in logs.
- A temporary Share Extension file is removed after the app imports it.
- Local analysis history remains in the app’s local storage until you delete entries in History or remove the app’s data. Depending on your settings, it may also be present in an Apple iCloud or computer backup until that backup is replaced or deleted.
- Firebase and Sightengine may retain limited service data for the periods described by their service agreements and privacy policies, including security, audit, dispute, and legal-compliance needs.
- Standard Firebase Hosting request logs created when this policy is viewed may be retained by Google for limited security and operational periods under its applicable terms.
For a privacy or deletion request involving processor data, email contact@steve-rioux.com. We will respond and coordinate with the relevant processor where applicable. Sightengine states that it assists subscribers with data-subject requests.
6. Consent and withdrawal
Consent is stored as an app preference and does not change or reset purchased analysis credits. You can review or withdraw it at any time from More (…) → Image Analysis & Privacy. Withdrawal prevents future transmissions; it does not automatically erase local history or data already processed. You can delete local history separately and contact us for a processor-data request.
7. Security and changes
Requests use encrypted HTTPS connections, Firebase App Check, and server-side credentials. No transmission method is guaranteed to be risk-free. We may update this policy when the app, processors, or legal requirements change. A material change to image processing will require renewed in-app consent.
8. Contact
Steve Rioux · contact@steve-rioux.com