Privacy
Image files and third-party verifiers
Our API sends the image file alone, with no account or page data, to OpenAI's provenance endpoint and, when enabled, Google's. On-device only mode stops it entirely.
Updated
What is sent
When the extension sees an image, our API fetches the file from its public URL (up to 8 MB) and sends it to OpenAI's content provenance API to check for SynthID watermark and Content Credentials signals. Once Google grants access and we enable it, the same file goes to Google's AI Content Detection API for the same purpose. The Google adapter is currently dormant.
What is not sent
Your account data, your extension token, the page hostname, the page the image appeared on, or anything else. The verifier receives the file and nothing more.
Retention
Google states that its AI Content Detection API does not store or retain processed images. OpenAI's handling is governed by its API data usage policy. We discard the file after the check and keep only the content hash and the verdict.
Cloudflare Workers AI
Pro rechecks run on Cloudflare Workers AI, which receives the image or text submitted for recheck. Cloudflare is our hosting processor for everything.
Opting out
On-device only mode sends nothing to our API, so nothing reaches any verifier on your behalf. Turning the extension off for a site has the same effect for that site.
Where these companies are
OpenAI and Google process the files in the United States. Section 13 of the privacy policy covers transfers from the EEA, UK and Switzerland.