Privacy Policy

Last updated September 11, 2026.

This Privacy Policy explains what personal data signator.ai collects, why, and what rights you have over it.

1. Who controls this data

signator.ai is operated by an individual. You can reach the controller using the contact details below. No Data Protection Officer has been appointed, as one isn't required at this scale under Article 37 — the contact below handles all privacy requests.

2. What we collect

Images you upload to run a check — the image file itself, plus the context you provide about it (your role as provider or deployer, and answers to the disclosure questions: whether it resembles a real person/place/event, whether it could reasonably appear authentic, whether it's artistic/satirical/fictional, and whether it already carries a disclosure). Collected directly from you when you use the tool.

Account information, if you sign in — your email address, via Clerk, our authentication provider. We don't collect or store passwords ourselves; Clerk handles credential storage.

Saved reports — if you save a check while signed in, the report is linked to your account so it appears on your dashboard.

Waitlist email — if you submit your email on the roadmap section to get notified of updates, we store that address for that purpose alone.

Technical data — your IP address is used transiently to enforce anonymous-usage rate limits (see Retention) and is not stored alongside your check results. We don't run analytics or advertising trackers on this site, and we don't collect any special-category data (Article 9) by design — the tool doesn't attempt to identify who is depicted in an uploaded image.

3. Why we process it, and on what legal basis

Article 6 GDPR requires a lawful basis for each purpose. Here is ours, purpose by purpose:

  • Running a check and returning a report — Article 6(1)(b), performance of a contract (the service you asked for when you submit an image).
  • Rate-limiting by IP address — Article 6(1)(f), our legitimate interest in keeping a free tool usable and resistant to abuse, balanced against the minimal, transient nature of the data used (see Retention).
  • Account creation and saved reports — Article 6(1)(b), contract, entered into when you create an account.
  • Waitlist emails — Article 6(1)(a), your explicit opt-in consent, which you can withdraw at any time (see Your rights).

We do not use your uploaded images, context answers, or check results to train any model, ours or a third party's, and we do not make any decision about you using solely-automated processing with legal or similarly significant effect — the disclosure verdict is about the image and its context, not about you as a person, under Article 22's meaning.

4. Who we share it with

We use a small number of infrastructure and processing vendors (sub-processors) to run the service. Each receives only what it needs to do its job, and each is bound by its own data processing agreement:

ProcessorRoleReceives
Hive AI (thehive.ai)AI-generation / deepfake detectionthe uploaded image
OpenAIWrites the plain-English report narrativethe provenance, detection, and disclosure findings — not the raw image
Cloudflare (R2)Object storage for uploaded imagesthe uploaded image
NeonPostgres databasecheck records, report text, account records, waitlist emails
ClerkAuthenticationyour email address and account credentials, if you sign in
UpstashRate-limit countersyour IP address, transiently

We do not sell personal data, and we do not share it with anyone for their own marketing purposes.

5. International data transfers

Several of the processors above are US-based, meaning your data may be transferred outside the EU/EEA/UK. Based on each vendor's own published terms: OpenAI and Cloudflare rely on the EU Standard Contractual Clauses for such transfers; Clerk and Neon rely primarily on the EU-U.S. Data Privacy Framework, falling back to Standard Contractual Clauses where the Framework doesn't apply; Upstash and Hive AI publish their own DPAs covering transfer safeguards on request. We link each vendor's DPA in the table above so you can verify the current mechanism directly at the source, since these arrangements can change.

6. How long we keep it

Unsaved, anonymous checks — our policy is to retain the uploaded image and its check record for no longer than 30 days, after which it is deleted. Automated enforcement of this window is being finalized as part of our production rollout.

Saved reports — kept for as long as your account exists, or until you delete the report or your account. To request deletion, email us — we will action it within 30 days.

Rate-limit counters — short-lived (rolling daily windows), not linked to your identity beyond IP address.

Waitlist emails — kept until you ask us to remove them or we send the update they signed up for.

7. Your rights

If GDPR applies to you, you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Have your data deleted (Art. 17)
  • Restrict or object to processing (Art. 18, 21)
  • Receive your data in a portable format (Art. 20)
  • Withdraw consent at any time, for processing based on consent (e.g. the waitlist)
  • Lodge a complaint with your local data protection supervisory authority

Because this is an early beta without self-service tooling for most of these yet, the way to exercise any of these rights right now is to email us (see Contact) — we will respond within 30 days, as GDPR requires.

California residents: we don't currently meet the CCPA/CPRA revenue or data-volume thresholds that trigger that law's obligations, and we don't sell or share personal information for cross-context behavioral advertising, so no "Do Not Sell or Share" mechanism applies today. If that changes as this grows, this section will be updated accordingly — until then, the same access/deletion/correction rights above are honored for California residents on request regardless.

8. Security and breach notification

We apply reasonable technical and organizational measures to protect your data, including byte-level file-type verification on every upload (not just the label the browser sends) and encryption of data in transit (HTTPS). If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, per Article 33, and notify affected individuals directly where Article 34's high-risk threshold is met.

9. AI-generated content in your report

Your report's plain-English narrative section is written by a language model (OpenAI), not by a human, and every report says so directly on the report page. That narrative only explains the findings — the disclosure verdict itself is produced by a deterministic rule engine, not by the AI, and the two are never blended. See our FAQ for how the three layers (provenance, detection, disclosure) relate to each other.

10. Cookies

We use only the session cookie set by Clerk to keep you signed in. We don't set advertising or cross-site tracking cookies, and we don't run analytics scripts on this site today. Because this is a strictly-necessary cookie, it doesn't require a consent banner under the ePrivacy Directive — if that changes, this section will too.

11. Children

This service is not directed at children and is not intended for use by anyone under 16.

12. Contact

Questions about this policy, or to exercise a data-subject right: email hello@signator.ai.