SI Detector Privacy

Privacy policy

Short version: your image or text is analysed and deleted unless you choose to share the result, we never store your IP address in clear text, and there are no advertising trackers. Details below. Last updated 30 September 2026.

Images you submit

Videos you submit

Videos sent to the SI video detector (beta) follow the same rules as images: written to a private directory under a random name, analysed on our own server, then deleted immediately, whether the analysis succeeds or fails. The video is never kept. So that you can see and decide to share your result, a few small still frames (8 at most, plus one frame of 800 pixels at most, all metadata removed) are kept privately for one hour; only you can see them, and they are published only if you share the result.

Audio you submit

Songs and audio files sent to the SI music detector (beta) are written to a private directory under a random name, analysed on our own server, then deleted immediately, whether the analysis succeeds or fails. The audio is never kept, never listened to by a person and never shown on a result page, even a shared one: a result link shows only the score, the clues and technical details such as duration, codec and bitrate. If you paste a link, we download that one file and delete it the same way.

Texts you submit

Texts pasted into the SI text detector are analysed, then kept privately for one hour with your result so that you can choose to share it; only you, in the browser session that ran the analysis, can see it, and it is deleted within the hour if you do not share. We log the score, the label, the word count and the list of clues. A result link that is not shared keeps at most three excerpts of 160 characters from the most SI-like sentences, for 7 days. If a submission is rejected (too short, for example) and your browser has JavaScript disabled, the text is kept in your session only long enough to refill the form once.

What we log

For each analysis we record: date and time, the source (upload or URL), the file type and dimensions (images and videos), the processing time, the score, the label and the list of technical clues. We do not store the file name, its EXIF content or the URL you pasted; the image itself is only kept as described above.

To count the 3 checks available without an account, we store a salted SHA-256 hash of your IP address, with a salt that changes every month. The hash cannot be reversed to your IP and the rows are purged after 31 days. Analysis logs, sign-up limits and login protection use a hash with a salt that changes every day.

Accounts

If you create an account we store your email address, your password as a one-way hash (never in clear text), your plan, the date you signed up and last logged in, whether and when you confirmed your email address, the page where you signed up, a daily-salted hash of the IP address used to sign up (to limit abuse), your usage counts per month (credits used, where an image or a song uses 1 credit and a video 5, and the number of text checks), your pack credit balance with a log of credits added and used, and the paid offers you asked to be notified about. Your analyses and result links are linked to your account to count them, to let you reopen your own results and, on Pro and Max, to show your 30-day history; your images and texts are handled exactly as described above. A signed cookie (siornot_auth) keeps you logged in for up to 30 days.

Transactional emails. We send your account emails only when needed: a welcome email with a link to confirm your address when you sign up, a new confirmation link if you ask for one, and a password reset link when you (or someone typing your address) ask for one on the "Forgot your password?" page. Confirmation links expire after 24 hours and reset links after one hour; each works once, and we store only a one-way hash of it, never the link itself. We record the date you confirmed your address. The emails contain no tracking pixel and no tracked links. They are delivered by an email delivery provider acting as our processor, which receives only your email address and the message; for our own statistics we log the type of email sent, whether it was delivered to the provider and when, without the address or the content. To limit abuse, reset requests are counted with a salted hash of the IP address and of the email address, deleted after two days.

We do not send marketing emails. We record which paid offers you click. Before payments open for everyone, that request puts you on a waiting list and we may email you about it once. After a payment we send a confirmation email, and we tell you when a subscription ends or a renewal payment fails. You can delete your account at any time from your account page: the account, its usage counts, its credit log and its waiting-list requests are erased immediately.

Payments

Paid plans and credit packs are paid on a secure page run by Stripe (Stripe Payments Europe, Ltd., Ireland), our payment provider. Your card number never reaches our servers and we never store it: Stripe collects your payment details, billing country or address and, where needed, what is required to prevent fraud and meet its legal obligations, under its own privacy policy. The payment page may set Stripe's own cookies.

To create the payment and link it to your account we send Stripe your email address, your account number and the offer you chose. From Stripe we keep: your Stripe customer and subscription identifiers, the plan and billing period, the currency, the subscription status, the renewal and cancellation dates, and for each purchase the offer, amount, currency and date. Invoices and receipts are issued by Stripe; accounting records are kept as long as the law requires, even if you delete your account. Stripe also sends us technical notifications (webhooks) about your payments, which we log without any card data.

If you delete your account, an active subscription is cancelled at the same time. You can see your invoices, update your card or cancel from your account page (Manage subscription), which opens Stripe's customer portal.

Shared result links

Every result (score, label, clues, technical metadata such as format, dimensions, camera model or C2PA generator) is stored under a random identifier (/r/...) for 7 days, or 30 days for Pro and Max accounts so that it appears in the account history.

Cookies

One technical session cookie (siornot) protects the forms against cross-site request forgery and keeps you logged in during a visit; the siornot_auth cookie is set only if you log in. If you pick a currency on the pricing page, a siornot_cur cookie remembers it for a year. The game stores your chosen player name in your browser's local storage. No analytics or advertising cookies are set. Fonts are loaded from Google Fonts, which receives your browser's request for the font files.

Leaderboard

If you save a game score, the name you type and the score are public on the leaderboard. Choose a nickname, not your real name, if you prefer.

Your rights

Under the GDPR you may request access to, correction of or deletion of data concerning you. Without an account we hold no identifier linking an analysis to you, so requests mainly concern opted-in images, leaderboard entries and account data. Contact: hello@siornot.com.

Hosting

The service is hosted on servers located in the European Union. The image-analysis provider used for the second opinion on some images processes them on our behalf, only to return a score. The email delivery provider sends our account emails on our behalf and uses the address only for that. Stripe processes payments as described in the Payments section.