Privacy Policy
Last updated: July 21, 2026
OriginVerdict provides image-origin analysis tools. This policy explains what data is processed when you visit originverdict.com, upload an image, or create an account.
Uploaded images
When you run an image check:
- Your browser uploads the selected image over HTTPS to a private, temporary Cloudflare R2 object controlled by OriginVerdict.
- OriginVerdict reads that temporary object to perform the requested check and attempts to delete it immediately after the request completes, including when analysis or quota checks fail.
- If immediate cleanup is interrupted, an automatic R2 lifecycle rule deletes temporary detector objects after one day.
- OriginVerdict sends the image to Sightengine, our detection provider, for synchronous analysis.
- OriginVerdict does not intentionally retain the original image or a thumbnail beyond this temporary processing window, and does not save GPS coordinates or Sightengine's raw response.
- OriginVerdict extracts only a limited set of file metadata for the result: camera make, camera model, capture time, image dimensions, and editing-software name when present. GPS parsing is disabled.
Sightengine processes submitted data as our service provider. Its processing locations and retention practices are governed by its own terms, privacy policy, and our service arrangement. Do not upload an image if you do not have the right to process it or if sending it to a third-party detection provider is inappropriate for your use case.
Usage and abuse-prevention data
To enforce the free daily allowance, OriginVerdict stores a one-way HMAC-derived identifier, the UTC usage date, and a scan count. Signed-in checks use the account ID as the HMAC input so the allowance follows the account; guest checks use request network and browser information. We do not store the raw identifier used to create either value in the quota table.
Standard hosting and security logs may include IP address, browser type, request time, requested URL, response status, and diagnostic information. These logs are used to operate, secure, and troubleshoot the service.
Account data
If you create an account, we may process your email address, display name, authentication records, account settings, credit balance, payment status, and related support correspondence. Password authentication is handled using the application's authentication system; passwords are not stored in plain text.
Payments
When paid plans become available, payment details will be handled by Stripe. OriginVerdict will receive transaction identifiers, payment status, product or plan information, amount, currency, and limited billing details needed for accounting and support. OriginVerdict will not receive or store your full card number.
Service providers
We use service providers to operate OriginVerdict, including:
- Sightengine for image analysis;
- Cloudflare R2 for private temporary image transfer;
- Vercel for application hosting and delivery;
- Neon for managed PostgreSQL database infrastructure; and
- Stripe for payments when billing is enabled.
These providers may process data in countries other than your own. Their handling of data is subject to their applicable terms and privacy notices.
Cookies and local storage
OriginVerdict may use essential cookies or browser storage for authentication, security, locale, theme, and dismissal preferences. We do not currently use advertising cookies. If analytics or additional non-essential tracking is introduced, this policy and any required consent controls will be updated.
Retention
We keep account, transaction, security, and operational records only for as long as reasonably needed to provide the service, prevent abuse, comply with legal obligations, resolve disputes, and enforce agreements. Daily quota records are keyed by date and are not intended to build a cross-service identity profile.
OriginVerdict attempts to delete each temporary uploaded image immediately after the synchronous analysis request. If that cleanup is interrupted, the R2 lifecycle rule deletes the object after one day. Third-party providers may retain submitted data according to their own policies and contractual obligations.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal data associated with you. You may also object to certain processing or withdraw consent where consent is the legal basis.
To make a privacy request, email support@originverdict.com. We may need to verify your identity before completing a request.
Children
OriginVerdict is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Security
We use reasonable technical and organizational safeguards, but no Internet service can guarantee absolute security. Avoid uploading highly sensitive images or using a detector result as the sole basis for a consequential decision.
Changes
We may update this policy as the service changes. The date at the top of this page identifies the latest version.
Contact
Questions about this policy can be sent to support@originverdict.com.