Privacy Policy
Last updated September 11, 2026.
This Privacy Policy explains what personal data signator.ai collects, why, and what rights you have over it.
1. Who controls this data
signator.ai is operated by an individual. You can reach the controller using the contact details below. No Data Protection Officer has been appointed, as one isn't required at this scale under Article 37 — the contact below handles all privacy requests.
2. What we collect
Images you upload to run a check — the image file itself, plus the context you provide about it (your role as provider or deployer, and answers to the disclosure questions: whether it resembles a real person/place/event, whether it could reasonably appear authentic, whether it's artistic/satirical/fictional, and whether it already carries a disclosure). Collected directly from you when you use the tool.
Account information, if you sign in — your email address, via Clerk, our authentication provider. We don't collect or store passwords ourselves; Clerk handles credential storage.
Saved reports — if you save a check while signed in, the report is linked to your account so it appears on your dashboard.
Waitlist email — if you submit your email on the roadmap section to get notified of updates, we store that address for that purpose alone.
Technical data — your IP address is used transiently to enforce anonymous-usage rate limits (see Retention) and is not stored alongside your check results. We don't run analytics or advertising trackers on this site, and we don't collect any special-category data (Article 9) by design — the tool doesn't attempt to identify who is depicted in an uploaded image.
3. Why we process it, and on what legal basis
Article 6 GDPR requires a lawful basis for each purpose. Here is ours, purpose by purpose:
- Running a check and returning a report — Article 6(1)(b), performance of a contract (the service you asked for when you submit an image).
- Rate-limiting by IP address — Article 6(1)(f), our legitimate interest in keeping a free tool usable and resistant to abuse, balanced against the minimal, transient nature of the data used (see Retention).
- Account creation and saved reports — Article 6(1)(b), contract, entered into when you create an account.
- Waitlist emails — Article 6(1)(a), your explicit opt-in consent, which you can withdraw at any time (see Your rights).
We do not use your uploaded images, context answers, or check results to train any model, ours or a third party's, and we do not make any decision about you using solely-automated processing with legal or similarly significant effect — the disclosure verdict is about the image and its context, not about you as a person, under Article 22's meaning.
5. International data transfers
Several of the processors above are US-based, meaning your data may be transferred outside the EU/EEA/UK. Based on each vendor's own published terms: OpenAI and Cloudflare rely on the EU Standard Contractual Clauses for such transfers; Clerk and Neon rely primarily on the EU-U.S. Data Privacy Framework, falling back to Standard Contractual Clauses where the Framework doesn't apply; Upstash and Hive AI publish their own DPAs covering transfer safeguards on request. We link each vendor's DPA in the table above so you can verify the current mechanism directly at the source, since these arrangements can change.
6. How long we keep it
Unsaved, anonymous checks — our policy is to retain the uploaded image and its check record for no longer than 30 days, after which it is deleted. Automated enforcement of this window is being finalized as part of our production rollout.
Saved reports — kept for as long as your account exists, or until you delete the report or your account. To request deletion, email us — we will action it within 30 days.
Rate-limit counters — short-lived (rolling daily windows), not linked to your identity beyond IP address.
Waitlist emails — kept until you ask us to remove them or we send the update they signed up for.
7. Your rights
If GDPR applies to you, you have the right to:
- Access the personal data we hold about you (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Have your data deleted (Art. 17)
- Restrict or object to processing (Art. 18, 21)
- Receive your data in a portable format (Art. 20)
- Withdraw consent at any time, for processing based on consent (e.g. the waitlist)
- Lodge a complaint with your local data protection supervisory authority
Because this is an early beta without self-service tooling for most of these yet, the way to exercise any of these rights right now is to email us (see Contact) — we will respond within 30 days, as GDPR requires.
California residents: we don't currently meet the CCPA/CPRA revenue or data-volume thresholds that trigger that law's obligations, and we don't sell or share personal information for cross-context behavioral advertising, so no "Do Not Sell or Share" mechanism applies today. If that changes as this grows, this section will be updated accordingly — until then, the same access/deletion/correction rights above are honored for California residents on request regardless.
8. Security and breach notification
We apply reasonable technical and organizational measures to protect your data, including byte-level file-type verification on every upload (not just the label the browser sends) and encryption of data in transit (HTTPS). If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, per Article 33, and notify affected individuals directly where Article 34's high-risk threshold is met.
9. AI-generated content in your report
Your report's plain-English narrative section is written by a language model (OpenAI), not by a human, and every report says so directly on the report page. That narrative only explains the findings — the disclosure verdict itself is produced by a deterministic rule engine, not by the AI, and the two are never blended. See our FAQ for how the three layers (provenance, detection, disclosure) relate to each other.
11. Children
This service is not directed at children and is not intended for use by anyone under 16.
12. Contact
Questions about this policy, or to exercise a data-subject right: email hello@signator.ai.