Privacy Policy
Last updated:
This Privacy Policy explains how the Deeptect ("we," "us," or "our") processes your personal data when you visit our website, use our service or otherwise communicate with us (collectively, "Services"). It describes what data we collect, how and why we use it, how long we keep it, and the rights and choices available to you. For purposes of this Privacy Policy, "you" and "your" means the individual whose personal data we process under this Privacy Policy, including visitors, users of the Services, and individuals whose personal data appears in Content submitted to the Services.
Please read this Privacy Policy carefully. By using the Services, you acknowledge that your information will be collected, used, and disclosed as described in this Privacy Policy.
1. Controller
The controller responsible for your personal data is:
Niclas Pillath
Address: Am Scherfenbrand 47, 51375 Leverkusen, Germany
Email: legal@deeptect.ai
2. Data We Process
The Services do not require registration or an account. The Services are used anonymously. We nevertheless process the following categories of personal data:
2.1 Technical access data
When you visit our website or use our service, your browser automatically transmits certain technical data. We collect and process, including without limitation:
- IP address
- user-agent string (which typically includes browser type, version, and operating system)
- date and time of access
We use this data to operate the website, generate usage statistics, identify technical issues, and improve the service.
2.2 Correspondence
When you contact us (for example, by sending an email to one of the addresses listed in this Privacy Policy or in our Terms of Service), we process the content of your message, your email address, and any other personal data contained in the message. We use this data to respond to your enquiry, to keep a record of the correspondence, and to fulfil our legal obligations.
The Services accept material or information you submit for processing ("Input") and return material or information in response ("Output"). Input and Output are collectively "Content". The following subsections describe the personal data we process in connection with Content. Further information for individuals whose personal data appears in Content, including where that data concerns third parties who have not themselves interacted with the Services, is given in Section 13.
2.3 Input: payload bytes
The bytes of the material you submit for processing. This currently includes, without limitation, uploaded audio, image, or video files, as well as files we download on your behalf from URLs you submit as Input. We process these bytes to perform the requested analysis. They are evicted within 24 hours after processing completes; see Section 10.
2.4 Input: metadata
Metadata derived from your submission, currently including, without limitation:
- for directly uploaded files: file size, filename, and last-modified timestamp;
- for URL-based Input: the URL string, HTTP
ETag, and HTTPLast-Modifiedheader value; - where the URL points to a platform for which we operate a specialised downloader: the platform's external content identifier, uploader identifier, uploader account name, content title, content description, thumbnail URL, and upload timestamp.
Filenames, URLs, uploader identifiers, uploader account names, and thumbnails routinely contain or constitute personal data, often of third parties (for example, the platform uploader) who have not interacted with the Services directly.
2.5 Output
Any material or information the Services return in response to Input. This currently includes, without limitation, Detection Results (a probability score and classification). Output may indirectly reveal personal data through its associated Input metadata (URL, filename, uploader identity, thumbnail, and so on).
2.6 Association records and shareable references
For each submission we retain the internal record that binds an Input to its corresponding Output, together with a unique shareable reference (a link) returned to you at the time of submission. The reference is the sole handle by which a specific Input/Output pair can subsequently be located and retrieved.
3. Purposes and Legal Basis
| Data category | Purpose | Legal basis |
|---|---|---|
| Technical access data | Operating, securing, and improving the website and service; generating usage statistics | Legitimate interest (Art. 6(1)(f) GDPR): we have a legitimate interest in collecting technical data to detect and prevent abuse, diagnose errors, and understand how the service is used so we can improve it |
| Correspondence | Responding to your enquiries and support requests; keeping a record of the correspondence; fulfilling legal obligations | Legitimate interest (Art. 6(1)(f) GDPR) for responding to enquiries and keeping records; legal obligation (Art. 6(1)(c) GDPR) where retention is required by law |
| Input payload bytes | Performing the analysis you request | Performance of a contract (Art. 6(1)(b) GDPR): processing is necessary to fulfil the analysis you requested |
| Input metadata, Output, and association records | Serving Output back to you via the shareable reference; internal quality monitoring; abuse investigation; publication of aggregated statistics | Legitimate interest (Art. 6(1)(f) GDPR); see the balancing assessment below |
Where we rely on legitimate interests (Art. 6(1)(f) GDPR), in particular for Input metadata, Output, and the association records that bind them (categories that, notwithstanding the prohibition in Terms of Service Section 4.3, may concern individuals who have not themselves interacted with the Services), we have carried out a balancing assessment. Our interest lies in operating the deepfake detection service, serving the outcome back to the user via the shareable reference, monitoring service quality, investigating abuse, and publishing aggregated statistics that contribute to public awareness of AI-generated media. This processing is necessary for those purposes; less intrusive alternatives, such as discarding all metadata once analysis has completed, would defeat them. We have concluded that our interest is not overridden by the rights and freedoms of the data subject, having regard to the following safeguards: payload bytes are evicted within 24 hours; no biometric templates are extracted or persisted, and no cross-submission matching is performed; public display of Content is restricted where it would infringe the privacy of any person depicted or otherwise identified; and any data subject may invoke the removal mechanism described in this Privacy Policy.
4. Featuring Consent
When you submit Input for analysis, you may optionally consent to Deeptect featuring your submission, or a derivative such as a thumbnail, in the Deepfake Showcase, in blog posts, or in similar promotional or educational contexts (a "Featuring Consent"). Featuring Consent is given at the time of submission by selecting the corresponding option.
Where you give Featuring Consent, our processing of the submission for the featuring purposes described above is based on your consent (Art. 6(1)(a) GDPR).
You have the right to withdraw your consent at any time under Art. 7(3) GDPR. Because the Services do not require an account and we cannot re-identify you as the submitter of a specific submission on our own, withdrawal is exercised by requesting removal of the specific Content using the procedure described in Section 15. Withdrawal does not affect the lawfulness of processing that took place before the withdrawal was received.
5. Feedback
If you provide feedback in response to a Detection Result (for example, by rating the result), we store the associated Input, or a derivative such as a thumbnail, and the associated Input metadata as part of your feedback. Providing feedback is voluntary.
Where you provide feedback, the associated processing, including use of the feedback and stored material to train, fine-tune, or otherwise develop our detection models and other products and services, is based on your consent (Art. 6(1)(a) GDPR).
You may withdraw your consent at any time under Art. 7(3) GDPR by requesting removal of the specific feedback item using the procedure described in Section 15. Removal cannot reverse the incorporation of the feedback into aggregated statistics or trained model artefacts that already exist at the time the request is received.
6. Shareable references and public accessibility
When you submit Input, the Services return a unique link ("shareable reference") that lets you retrieve the associated Output and Input metadata. This reference has no access control: anyone in possession of it can retrieve the associated Content.
Once the reference is shared, whether by you or otherwise disclosed, the associated Content must be regarded as publicly available. If you submit Input that contains sensitive or private information, you should assume the associated Content may become public if the reference is shared or otherwise disclosed. The submission of personal data as Input is in any case prohibited under the Terms of Service.
7. Cookies
We use only strictly necessary (functional) cookies. These cookies are required for the website and service to function properly.
We do not use advertising cookies, tracking cookies, or third-party cookies.
8. Sharing of Data
Your personal data is processed by our internal team. We use netcup to host our servers within the European Economic Area (EEA); they act as a data processor under a data processing agreement and do not access your data for their own purposes. We use Render for content delivery and edge routing; Render's edge deployment for the Services is currently within the EEA.
We do not otherwise sell, rent, or share your personal data with third parties.
9. International Data Transfers
We do not transfer your personal data outside the European Economic Area (EEA). All data is stored and processed on servers located within the EEA.
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy:
- Technical access data (server logs, IP addresses, and related technical information) is deleted after 90 days.
- Correspondence is retained for as long as necessary to respond to your enquiry and to keep a record of the exchange, or longer where required by law.
- Input payload bytes are evicted within 24 hours after processing completes, by an automated cleanup routine.
- Input metadata, Output, and association records (including the shareable reference) are retained indefinitely.
11. Automated Decision-Making
We do not use the results of our analysis to make automated decisions about any person. Our service provides an informational assessment for review by the submitting user. Any final decision is made by a human, not by automated processing.
12. Special-category data (biometric data)
The Terms of Service prohibit submitters from including personal data in Input (Section 4.3). Notwithstanding that prohibition, Input submitted for analysis (in particular audio, image, and video files) may contain material that reflects biometric characteristics of natural persons, such as facial features and voice characteristics.
Article 9(1) GDPR prohibits the processing of biometric data "for the purpose of uniquely identifying a natural person" (Art. 4(14) and Art. 9(1) GDPR). Our purpose is deepfake detection: the analysis determines whether the submitted material is likely to be artificially generated or manipulated. It does not identify, and is not designed or used to identify, any natural person. On this basis we take the position that our processing does not fall within the scope of Article 9(1) GDPR.
We apply the following safeguards, which support this position and further reduce the impact of the processing on the individuals whose biometric characteristics are reflected in Input:
- No biometric templates are extracted or persisted. The analysis operates on the transient payload and does not produce a stored representation from which an individual can be re-identified.
- No cross-submission matching is performed. Each Input is analysed on its own; we do not compare biometric characteristics across submissions or to any reference database of natural persons.
- Payload bytes are evicted within 24 hours; see Section 10.
13. Information for Individuals Whose Personal Data Appears in Content
Although the Terms of Service prohibit submitters from including personal data in Input (Section 4.3), Content processed by the Services may contain personal data of individuals who have not themselves interacted with the Services. This includes, without limitation, individuals depicted or heard in submitted media, individuals identifiable in Input metadata (such as platform uploaders whose identifiers, account names, or thumbnails appear in the metadata associated with a URL-based submission), and individuals named or otherwise identified in content titles or descriptions.
Lawful basis. Processing of such personal data is based on our legitimate interests (Art. 6(1)(f) GDPR). The balancing assessment is summarised at the end of Section 3.
No individual notice. We are generally unable to notify each individual whose personal data appears in Content, as we do not know who these individuals are and have no means of contacting them. Providing individual notice would require disproportionate effort given the volume and nature of the material processed. We therefore rely on the exemption under Art. 14(5)(b) GDPR. The information required under Art. 14(1) and (2) GDPR is made accessible through this publicly available Privacy Policy.
Public display safeguard. Where the Services display Content publicly (for example in the Deepfake Showcase, in blog posts, or as thumbnails), such public display is limited to Content whose display does not infringe the privacy rights of any person depicted or otherwise identified. Where a privacy concern is identified, whether proactively by Deeptect or on the basis of a report, the Content will be withdrawn from public display and, where appropriate, the associated Input metadata and Output will be deleted or restricted.
How to exercise your rights. Individuals who believe their personal data has been processed through the Services may exercise the rights described in Section 15 by contacting us at legal@deeptect.ai. Where possible, please provide the shareable reference for the specific Content, or otherwise supply information sufficient to identify the submission and to substantiate your relationship to it. We will respond within the time limits set out in Art. 12(3) GDPR (one month from receipt, extendable by up to two further months where required by the complexity or number of the requests). Where a request is upheld, we may delete the associated Input metadata, Output, and any residual payload; restrict public display; or take such other action as is appropriate.
14. Obligation to Provide Data
Providing technical access data (such as your IP address) is a technical necessity. Your browser transmits it automatically when you visit any website, and we cannot provide the service without it. The Services do not require registration or an account and are used anonymously. Submitting Input for analysis is voluntary; if you do not submit Input, you will not receive Output.
15. Your Rights
The Services do not require an account or any persistent identifier. On its own, Deeptect is not in a position to re-identify who submitted a specific Input, Output, or association record. Under Art. 11(2) GDPR, the obligations under Arts. 15 to 20 GDPR do not apply where the controller can demonstrate that it is not in a position to identify the data subject, provided the data subject is informed of this and is permitted to supply additional information to enable identification.
The shareable reference returned at submission (see Section 6) is the identifier by which Deeptect can locate a specific Input, Output, and their association. If you wish to exercise your rights over specific Content, please supply the shareable reference together with information sufficient to substantiate your request (for example, context indicating that you are the submitter, or, if you are a third party whose personal data appears in the Content, an explanation of your connection to the Content). Where the shareable reference is not known, please supply as much information as you can to enable the specific Content to be identified. Where you supply sufficient identifying information, we will process your request in accordance with the rights set out below.
Depending on where you live, you may have some or all of the rights listed below in relation to your personal data. Under the GDPR, you have the following rights:
- Right of access (Art. 15) — you can request confirmation of whether we process your personal data and obtain a copy of it.
- Right to rectification (Art. 16) — you can request correction of inaccurate personal data.
- Right to erasure (Art. 17) — you can request deletion of your personal data where there is no compelling reason for continued processing.
- Right to restriction of processing (Art. 18) — you can request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20) — you can request to receive your personal data in a structured, commonly used, and machine-readable format, or to have it transmitted to another controller.
- Right to object (Art. 21) — you can object to processing that is based on our legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to lodge a complaint (Art. 77) — you can lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement.
How to exercise your rights
You may exercise any of these rights by contacting us using the contact details provided below. We may need to request additional information to verify your identity before responding to your request.
We will respond to your request without undue delay and in any event within one month of receipt. If your request is complex or we receive a large number of requests, we may extend this period by up to two further months; if so, we will inform you of the extension and the reasons for it within the first month.
If we are unable to act on your request, we will inform you of the reasons within one month and advise you of your right to lodge a complaint with a supervisory authority or seek a judicial remedy.
Exercising your rights is free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable administrative fee or refuse to act, in accordance with Art. 12(5) GDPR.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When changes are made, the updated Privacy Policy will be posted on the Services with a revised "Last updated" date.
Because user accounts and email addresses are not collected, notification of changes is made exclusively via a notice on the Services. The version identifier stored in your acceptance cookie will be compared against the current version of the Privacy Policy on each visit. If you have not yet acknowledged the current version, you will be presented with a banner requiring re-acknowledgement before you can continue using the Services.
17. Contact
If you have any questions about this Privacy Policy or our data processing practices, or if you would like to exercise any of your rights, please contact us at legal@deeptect.ai.