English Deutsch Nederlands

Privacy Policy

Last updated: March 2026 · GDPR-compliant

ImageWhisperer processes your images on dedicated EU hardware. We may store uploaded images for up to 12 months to improve our detection models — in practice, most data is retained for a shorter period. Paying members' images are never stored. Your data is handled transparently as described below.

1. Data Controller

The data controller for this service is:

For privacy-related inquiries, contact us at imagewhisperer.org/contact.

There's a name and address above. If anything goes wrong with your data, you know exactly who to contact and where they are.

2. What Data We Process

Data Purpose Retention Legal basis
Uploaded image AI/manipulation detection and model improvement Max. 12 months (members: not stored) Legitimate interest (Art. 6(1)(f))
Image hash (MD5) Duplicate detection, known-fake matching Max. 12 months Legitimate interest (Art. 6(1)(f))
Analysis result Detection model calibration and quality assurance Max. 12 months Legitimate interest (Art. 6(1)(f))
IP address Abuse prevention, content moderation, banning 90 days Legitimate interest (Art. 6(1)(f))
IP geolocation Regional analytics, abuse detection 90 days Legitimate interest (Art. 6(1)(f))
Browser type, region Service improvement, visitor analytics 90 days Legitimate interest (Art. 6(1)(f))
Browser fingerprint Free tier usage tracking (rate limiting) Until daily reset Legitimate interest (Art. 6(1)(f))
Email (if purchased) Account, magic-link login Duration of account Contract (Art. 6(1)(b))
Feedback & vote Verdict accuracy improvement 90 days max Consent (Art. 6(1)(a))
Contact form Respond to inquiry Until resolved Consent (Art. 6(1)(a))
We need your photo to check it, and your IP address to spot misuse. Never bought anything? Then we don't even know your email. The browser fingerprint just counts whether you've used your free turns today — tomorrow the counter resets.

3. Content Moderation & IP Banning

To maintain a safe platform, we monitor uploads for unacceptable material (illegal content, CSAM, extreme violence). If such content is detected:

IP addresses are stored for up to 90 days for all users. For banned users, the IP address and ban reason are retained indefinitely for platform safety.

We keep the door shut on anyone uploading illegal material like child abuse imagery. They get permanently blocked, and we may bring in law enforcement. Regular users won't notice this at all.

4. Image Storage

Uploaded images from free users are stored on our servers for a maximum of 12 months (usually shorter) for the following purposes:

Paying customers: If you have purchased a verification package, your uploaded images are not stored after analysis. They are processed in memory and deleted immediately upon completion. Only the analysis metadata (verdict, scores) is retained for your account history.

Free users: Images are stored on encrypted, dedicated hardware in Germany for a maximum of 12 months (usually shorter). They are not shared with third parties except as described in the third-party processing section below. After 12 months, images and associated analysis data are automatically deleted.

Free version? We might hold on to your photo to teach our AI to spot fakes better. Paid package? Your photo gets wiped right after the check — it never even hits the hard drive.

5. What We Do NOT Do

We're not in the advertising business. We don't know who you are, don't want to, and earn our money from verification packages. Your photos only serve to make our detector smarter.

6. Data Processing Location

Primary processing: dedicated server in Falkenstein, Germany (EU).

On-server processing (stays in EU): All deep-learning detection models (B-Free, SPAI, TruFor, IML-ViT, Sparse-ViT, Mesorch, ClipDet, CommFor, RIGID, Flux Probe) run entirely on our dedicated hardware in Germany. The majority of the analysis never leaves our infrastructure.

Third-party processing (may leave EU):

Service Purpose Data sent Location
Vertex AI Scene understanding, forensic narrative Encrypted image hash (temporary, not stored) US/EU (Google Cloud)
CloudVision Label detection, web entity matching Encrypted image hash (temporary, not stored) US/EU (Google Cloud)
External AI detection API AI detection cross-validation Encrypted image hash (temporary, not stored) EU (France)
Stripe Payment processing Email, payment info US (PCI-DSS compliant)
PostHog Product analytics (usage patterns, not personal data) Anonymised events (e.g. “image uploaded”, “verdict received”) US (PostHog Cloud)
ip-api.com IP geolocation for abuse detection IP address Germany (EU)

All third-party services process data under their own privacy policies and Data Processing Agreements.

Our own AI models run in a German datacenter. On top of that, we send your photo to Google (to understand what's in it) and a French AI service (as an extra check). Payments go through Stripe. Those last two may route through the US — we can't avoid that and still use their services.

7. Your Rights (GDPR Articles 15–22)

As an EU resident, you have the right to:

Send us an email and we'll show you everything we have on you. Want it gone? We'll delete it. We have 30 days. If we don't follow through, you can take it to the Dutch Data Protection Authority — no lawyer needed.

8. Right to Erasure

If you request deletion of your data, we will:

Erasure requests are processed within 30 days. Note: we may retain data where required by law (e.g., financial records) or where necessary for the protection of others (e.g., evidence of illegal uploads).

To exercise any of these rights, contact us at imagewhisperer.org/contact. We respond within 30 days.

Say "delete everything" and it's gone within 30 days: photos, analyses, account, the lot. Only two things we can't touch: invoices (the tax office requires 7 years) and evidence of illegal uploads (kept for law enforcement).

9. Cookies

ImageWhisperer uses only strictly necessary cookies:

We do not use advertising cookies or tracking cookies. PostHog analytics (see section 6) does not use cookies — it relies on anonymous event tracking only.

Two cookies, both needed to make the site work. One remembers your session, the other keeps you logged in if you have an account. That's it — which is why you didn't see a cookie banner when you arrived.

10. Data Security

Your data sits on our own machine in Germany, not on shared cloud hosting. Everything travels encrypted. We never see your credit card number — Stripe handles that. Backups live in the same datacenter, also encrypted.

11. Data Retention & Deletion

We apply the following retention schedule and automatically delete data after these periods:

Everything has a timer. Photos: one year max, then automatically gone. IP address: 90 days. Invoices: 7 years (legally required). When time's up, it gets wiped — you don't need to do anything.

12. Children

ImageWhisperer is a professional media verification tool. It is not directed at children under 16. We do not knowingly collect personal data from children.

This is a tool for professionals who need to verify photos. It's not an app for kids, and we don't collect data from minors.

13. Changes to This Policy

We may update this policy to reflect changes in our processing activities. Material changes will be announced on the homepage. The “last updated” date at the top always reflects the current version.

If something important changes — say we start storing data longer or share it with a new partner — you'll see it announced on the homepage.

14. Related Documents

Terms of Use explains what you can and can't upload. Benchmarks shows how well our detection actually performs. Contact is where you reach us for anything privacy-related.