Privacy Policy
Last updated: April 28, 2026 · Applies to all PixelTruth.APP users worldwide
1. Data Controller and Scope
PixelTruth AI Intelligence acts as the Data Controller for personal and technical data processed through the PixelTruth.APP mobile application. This policy applies to all users worldwide and covers all versions of the application available on Google Play.
2. Your Images Stay on Your Device
PixelTruth is built around a privacy-first principle: your photos never leave your device. Images you select for analysis remain in your device's local storage at all times. We do not upload, catalogue, or archive your photographs on our servers. Only technical analysis results and metadata are transmitted — never the image itself.
3. Data We Collect
Depending on how you use the application, we may process the following categories of data:
| Category | Details |
|---|---|
| Scan metadata | Verdict (REAL / AI / SUSPICIOUS), confidence score, scan date and a unique scan ID. The image itself is not included. |
| Account data | Email address, hashed password, chosen display name and subscription plan. Registered users only. |
| Device identifier | A randomly generated installation ID stored locally on your device, used to enforce guest scan limits. Cannot be linked to your personal identity. |
| Technical data | Device model, OS version and IP address. Used for security logging and rate limiting only. |
| Usage data | Number of scans performed, subscription status and in-app feature interactions. Used solely to deliver and maintain the service. |
| Beta testing activity | For users participating in our beta testing program, we may collect usage activity data including the timestamp of last app activity. This data is used solely for internal testing purposes and is accessible only to the development team. |
4. How Image Analysis Works
When you submit an image for analysis, the following process takes place:
- Technical feature data extracted from the image on your device is transmitted over an encrypted connection (TLS 1.3) to our analysis service. The original image file never leaves your device.
- The analysis engine processes the extracted feature data and returns a result (verdict and confidence scores). No image file is stored or retained at any point during this process.
- Only the result metadata (verdict, score, scan ID, date) is saved — never the image itself.
- For registered users, result metadata is stored on our servers to power your scan history. For guests, result metadata is stored only on your device.
Images submitted for analysis are never used to train, fine-tune or improve any AI model — whether operated by PixelTruth or any third-party provider.
5. Device Permissions
The application requests the following permissions on your Android device:
| Permission | Purpose |
|---|---|
| READ_MEDIA_IMAGES | Allows you to select images from your gallery for analysis. No images are accessed without your explicit action. |
| INTERNET | Transmits image analysis data (technical scan results and metadata) to our servers for processing, and synchronises your account and scan history. The original image file is never transmitted or stored — only the extracted analysis data leaves your device. |
| POST_NOTIFICATIONS | Sends scan completion alerts and service updates. Optional — can be revoked at any time in device settings. |
We do not request access to your camera, contacts, location, microphone or any other sensor beyond those listed above.
6. Guest Users vs Registered Users
The application can be used without creating an account (guest mode) or with a registered account. The data handling differs as follows:
| User type | Data handling |
|---|---|
| Guest | Scan history (result metadata only, no images) is stored exclusively on your device. We do not transmit or retain guest data on our servers. Limited to 3 scans per day, enforced via your device identifier. |
| Registered | Scan history (result metadata) is synchronised with our servers so your history is accessible across reinstalls and devices. Images are never uploaded. Account data (email, plan) is encrypted at rest as described in Section 11. |
7. Legal Basis for Processing
We process your data on the following legal grounds under GDPR Article 6:
| Legal basis | Scope |
|---|---|
| Consent | Push notifications and optional telemetry, obtained at first launch or in app settings. |
| Contract performance | Processing necessary to deliver analysis results and manage your subscription. |
| Legitimate interests | Security logging, fraud prevention and rate limiting to protect the integrity of the service. |
8. Third-Party Sub-Processors
To deliver the service, we engage the following categories of sub-processors. All sub-processors operate under binding Data Processing Agreements (DPA) and, where applicable, Standard Contractual Clauses (SCC) for international transfers:
| Category | Purpose |
|---|---|
| Cloud infrastructure | Hosting application back-end services and storing scan result metadata. |
| AI analysis providers | Processing of extracted technical feature data (see Section 4). No image files are transmitted to or retained by these providers — only anonymised analysis signals derived on your device. |
| Payment processors | Subscription billing handled by Google Play. PixelTruth does not store payment card details. Google Play's own Privacy Policy governs payment data. |
| Push notification services | Delivering notifications to your device (see Section 9). |
We do not sell, rent or otherwise disclose your personal data to third parties for their own marketing or commercial purposes.
9. Push Notifications
With your permission, PixelTruth may send push notifications to your device for the following purposes:
- Scan completion alerts for long-running analyses
- Important account or subscription updates
- Security alerts (e.g. login from a new device)
You can withdraw notification consent at any time through your device's notification settings or in the app's settings screen. Withdrawal does not affect the lawfulness of prior processing.
10. Data Retention and Account Deletion
| Data type | Retention period |
|---|---|
| Scan history | Retained for as long as your account is active. Delete individual records or your entire history at any time from within the app. |
| Account data | Retained until account deletion. All personal data is permanently removed within 30 days of deletion. Anonymised aggregate statistics may be retained indefinitely. |
| Guest data | Stored only on your device. Uninstalling the application removes all locally stored guest data. |
| Security logs | IP-based logs retained for a maximum of 90 days, then automatically purged. |
11. Data Security and Encryption
We apply appropriate technical and organisational measures to protect your data:
- All data in transit is encrypted using TLS 1.3
- Account passwords are stored as one-way bcrypt hashes — we cannot recover your password
- Scan history stored on our servers is encrypted at rest using AES-256
- Access to production infrastructure is restricted to authorised personnel and subject to regular security review
In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Article 33–34.
12. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you have the following rights regarding your personal data:
| Right | How to exercise it |
|---|---|
| Right of Access | Request a copy of the personal data we hold about you by contacting us at Section 14. |
| Right to Rectification | Request correction of inaccurate or incomplete data via the app settings or by email. |
| Right to Erasure | Delete your scan history directly in the app at any time, or request full account deletion by contacting us. |
| Right to Data Portability | Request an export of your scan history in a machine-readable format by contacting us. |
| Right to Object / Restrict | Object to processing based on legitimate interests or request restriction in certain circumstances. |
| Right to Withdraw Consent | Withdraw consent for push notifications or telemetry at any time in app settings. Does not affect prior lawful processing. |
| CCPA (California) | California residents may request disclosure of data collected and deletion under the California Consumer Privacy Act. |
To exercise any of the above rights, contact us at the address in Section 14. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
13. Cookies and Local Storage
PixelTruth.APP is a mobile application that uses a WebView component to render its interface. As a result, the application may use browser-level storage technologies, including:
| Technology | Purpose | How to control |
|---|---|---|
| Session cookies | Maintain your login session and authentication state during use. Deleted automatically when you close the app. | Cannot be disabled without breaking core functionality. |
| Local storage | Store user preferences, guest scan history and UI state locally on your device. Never transmitted to our servers. | Cleared by uninstalling the application or clearing app data in Android settings. |
| Functional cookies | Remember your language preference and display settings between sessions. | Can be reset by clearing app data in Android settings. |
We do not use advertising cookies, third-party tracking cookies or cross-site tracking technologies. We do not currently respond to "Do Not Track" (DNT) signals as no uniform standard has been adopted.
14. State-Specific Privacy Rights
California residents (CCPA / CPRA) — in addition to the rights listed in Section 12, California residents have the right to opt out of the sale or sharing of personal information. PixelTruth does not sell personal data. To submit a California privacy request, contact us at contact@pixeltruth.app with the subject line "California Privacy Request".
Nevada residents — Nevada law (NRS 603A) gives Nevada residents the right to opt out of the sale of certain personal information to third parties. PixelTruth does not sell personal data. If you are a Nevada resident and wish to submit an opt-out request regardless, contact us at contact@pixeltruth.app with the subject line "Nevada Do Not Sell Request". We will respond within 60 days.
15. Business Transfer (M&A)
In the event that PixelTruth AI Intelligence undergoes a merger, acquisition, asset sale, restructuring or other business transfer, personal data held by us may be transferred to the acquiring entity as part of that transaction. If such a transfer occurs:
- We will notify you via in-app notification or email at least 30 days before your data is transferred and becomes subject to a different privacy policy
- The acquiring entity will be required to honour the commitments made in this Privacy Policy or provide you with the opportunity to delete your account before the transfer takes effect
- If you do not wish your data to be transferred, you may request account deletion before the effective date of the transfer by contacting us at contact@pixeltruth.app
16. Children's Privacy
PixelTruth.APP is not directed at children under the age of 16 (or 13 for users in the United States under COPPA). We do not knowingly collect personal data from minors. If you believe a child has provided personal data through our application, please contact us immediately and we will delete the data without delay.
17. Contact and Data Protection Officer
For any privacy-related questions, requests to exercise your rights, or concerns about this policy, please contact our Data Protection Officer:
contact@pixeltruth.appWe may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification or email at least 14 days before they take effect. Continued use of the application after the effective date constitutes acceptance of the updated policy.