Privacy policy

How AuditImage handles the pictures you upload, what it stores, for how long, and what you can ask for.

Effective date: 21 September 2026

Uploaded pictures

Pictures you upload are parsed in server memory only. The pixel data is never written to disk, never cached, and never used for any other purpose. Once parsing completes the picture data is discarded immediately.

What is stored

Each inspection stores one record containing:

  • file name, size, format and dimensions;
  • the file's SHA-256 hash;
  • the parsed metadata: EXIF, XMP, IPTC, PNG text chunks, the contents of any C2PA manifest, and the analysis result.

Note that metadata itself may contain personal information, such as GPS coordinates in EXIF, an author name, or a device serial number. It appears in the report as is. If you do not want it stored, remove it before uploading, or do not upload.

Report links

Each report has a randomly generated link. Anyone with the link can view the report. Report pages carry a noindex tag and are not indexed by search engines. We never publish reports ourselves.

Retention

Reports are kept by default. You can request deletion through the contact page by providing the report link; we handle requests within a reasonable time.

Server logs

The web server keeps ordinary access logs (IP address, time, request path, User-Agent) for operations and abuse prevention, retained for no more than 30 days.

Cookies

AuditImage uses one cookie of its own, locale, to remember your language choice, valid for one year.

Analytics

This site uses Google Analytics to count page visits: which pages, where visitors come from, and which browser they use. It sets its own cookies (_ga and similar) and the data is handled by Google under its privacy policy. The script only records page views; it never touches the pictures you upload or the contents of reports. Blocking it does not affect any feature of the site.

Third parties

Apart from the analytics above, AuditImage does not send your pictures or reports to any third-party service.

Changes

If this policy changes, the effective date at the top of this page is updated.