1. Information processed by FauxGuard
When you use the detector, FauxGuard receives the image you choose, technical request information such as the content type and size, and network information needed to route and protect the request. The server may see an IP address or the forwarding headers supplied by the hosting platform, the browser user agent, the requested route, the time of the request, and error information. The client also sends the selected file name as part of the multipart upload, although the browser-generated compressed file may use a new name.
Image metadata is part of the image file. Depending on the format and editing history, it may contain camera make and model, an editing software name, timestamps, orientation, C2PA Content Credentials, a SynthID-related marker, or other descriptive fields. FauxGuard reads these fields to generate the result. It does not require your name, email address, account password, or payment information for the free detector.
2. How information is used
FauxGuard uses the upload to inspect metadata, identify known generator signatures, estimate an AI-generation probability, and return a result. Technical request information is used to deliver the response, enforce the temporary daily allowance, apply shared request limits, prevent abuse, troubleshoot errors, and protect the service. Aggregate operational information may be used to understand reliability and capacity needs.
FauxGuard does not use the free detector to train its own foundation model, build an advertising profile, or sell uploaded images. The service does not make automated decisions that directly produce legal effects. You decide what action, if any, to take from the result, and that action should include human judgment and other evidence.
3. Sightengine and other service providers
Metadata inspection can run inside the FauxGuard server without sending the image to a visual model. When a visual check is required, the processed image is transmitted to Sightengine so its generative and deepfake models can evaluate it. The request includes the image and the model selection. FauxGuard's API credentials are server environment variables and are not exposed in the browser.
Sightengine processes the image according to its own service terms and privacy practices. Hosting, network, and security providers may also process limited request data to deliver and protect the site. FauxGuard does not control every retention decision made by an independent provider, so do not upload content you are not authorized to disclose to a third-party detector.
4. Cookies and local storage
FauxGuard uses one essential cookie for the free daily allowance. It is signed, httpOnly, SameSite=Lax, and marked Secure in production. The cookie stores the current UTC date, the number of scans used, and a truncated hash of the network identifier. It exists to enforce the five-scan browser allowance and to reject a cookie that has been altered. It expires after a short period and is not used for advertising or cross-site tracking.
This cookie is not a paid entitlement, a fraud-prevention record, or a cross-device account limit. FauxGuard does not use advertising cookies, social pixels, or third-party analytics scripts.
5. Retention and deletion
FauxGuard does not maintain a user account database, scan history, or a gallery of uploaded images. The image is kept in request memory for the time needed to complete the detection and may be held briefly by infrastructure or the upstream provider during processing. Operational logs may be retained for security, debugging, capacity planning, and abuse prevention for a limited period. Logs are designed to avoid storing image content, but they may contain an identifier for the request and technical metadata.
Because FauxGuard does not provide an account or persistent scan record, there may be no stored image record to access or delete. If you have a specific privacy question or believe a log contains personal information, contact us with enough detail to identify the request without sending a new copy of sensitive content.
6. Security, international processing, and changes
FauxGuard uses server-side credentials, HTTPS, signed cookies, request-size limits, a shared request queue, and basic abuse controls. No internet service is completely secure, and no method of transmission or storage can be guaranteed. You should not upload highly sensitive material unless you have determined that the processing is appropriate for your situation.
The service and its providers may process information in countries other than your own, subject to the provider's safeguards and applicable law. We may update this policy when the service, retention practices, or providers change. The date at the top shows the latest revision. Material changes should be reviewed before you continue using the detector.
7. Children and contact
FauxGuard is not directed to children under 13, and the service should not be used to upload a child's personal or sensitive images. If you believe a child has submitted personal information, contact us so we can review the request. Privacy questions can be sent to hello@fauxguard.ai. For the rules that apply to use of the detector, read the Terms of Service.
Privacy FAQ
Does FauxGuard store my uploaded images?
FauxGuard does not create a user account history or save uploads in its own database. The image exists in request memory for the current detection and may be sent to Sightengine when visual analysis is needed.
How is the free daily allowance counted?
A signed browser cookie records the date, a hashed network identifier, and the number of free scans used. It supports the daily allowance and is not used for advertising.
Does FauxGuard sell personal information?
No. FauxGuard does not sell personal information or use uploaded images to build advertising profiles. Processing is limited to operating, securing, and improving the detection service as described in the policy.
Can I request deletion of data?
Because FauxGuard does not maintain an account database or scan history, there is usually no stored image record to delete. You can contact the privacy address to ask about a specific request or an operational log.