Privacy & Transparency

We use cookies to secure the credit system and to serve personalized ads through our advertising provider. Your uploaded media is deleted immediately after analysis and is never added to any database.

Privacy Policy

Last Updated: August 2026

Your photos and videos are never stored

We do not keep the media you upload. It is analysed and then deleted straight away — never added to a database, never backed up, never used to train anything. What we do keep is the result of the analysis, and Section 2 sets out exactly what that contains and how long we hold it.

What this policy covers

This policy applies both to the FauxLens website at fauxlens.com and to the FauxLens Android app. The two share one account system and one analysis backend, but they use different providers for payments, analytics, crash reporting and advertising. Wherever they differ, the sections below say which product a statement applies to.

Data Controller

Faux Lens AI

Zohar 6, Haifa 3540233, Israel

support@fauxlens.com

1. Data We Collect

We collect the minimum data necessary to provide the Service:

  • Account data: Email address, collected when you create an account or sign in.
  • Uploaded media: Images and videos you upload are processed solely to perform the requested analysis, then deleted. They are never retained on our servers. In the Android app, a copy also stays on your own device — see Section 2.
  • Usage data: Analytics events (page views, feature interactions, scan outcomes) used to improve the product, on both the website and the Android app. These events never contain your media. When you are signed in, these events are linked to your account: on the website your account ID and email address are attached to your analytics profile, and in the Android app your account identifier is attached to both analytics events and crash reports. Analytics collected before you sign in are not linked to an account.
  • Payment data: On the website, card and transaction details are processed by our merchant of record. In the Android app, purchases are processed by the app store's billing system. In both cases payment details are handled entirely by that provider and are never stored on FauxLens servers — we receive only a confirmation token and the transaction amount.
  • Error data: Crash reports and performance metrics used to identify and fix bugs, collected on the website, in the Android app, and on the analysis backend that serves both products. No media content is included in error reports. If you are signed in, your account identifier is attached so we can trace a fault back to the affected account — on the website your email address is attached too, and backend reports also carry the request's IP address.
  • Contact form messages: If you write to us through the contact form on the website, your name, email address and message are processed by a form provider, which delivers them to our support inbox.
  • Device identifier: Both products send a device identifier with each request, to allocate free credits fairly and to detect automated abuse. In the Android app it is a random value generated on first launch: it is not your device's hardware ID and does not contain your name or contact details, and uninstalling the app discards it. It is still personal data under the GDPR, because it distinguishes your device from others. On the website it is a browser fingerprint calculated in your own browser, derived from your browser and device configuration and is designed to stay stable across visits. If you watch a rewarded ad in the app, this identifier — or your account ID, if you are signed in — is passed to our advertising provider so the reward can be verified against your account.
  • Advertising identifier (Android app only): If you choose to watch a rewarded ad to earn credits, our advertising provider may access your device's advertising ID. See Section 4.

2. Media Retention

FauxLens does not retain your uploaded media. While an analysis is running, your file is held in temporary working storage on the processing server, and it is deleted the moment the analysis ends, on every outcome including errors and cancellations. It is never added to any database, never backed up, and never accessible once the analysis completes.

The result of an analysis is kept, and is not the same thing as the media. Each scan produces a record holding the verdict and confidence score, the evidence notes our checks produce, and technical details read from the file itself, such as the camera or device that captured it, the software that last wrote it, and any content-provenance signature. We keep that record for 24 hours, together with a fingerprint derived from your file that lets us return the same verdict if an identical file is scanned again. The record never contains a description of what your image depicts.

Images you edit with our object remover carry a standard IPTC provenance tag identifying them as AI-edited. The tag records only that an AI tool altered part of the image. It contains no account, device or location information. Many messaging and social platforms strip image metadata when they re-compress an upload, so this tag may not survive re-sharing.

If you publish a result as a shareable report, that record becomes viewable by anyone who has the link, without signing in, and we keep it for 14 days from the day you publish. If the link is still being opened as it nears expiry we extend it, so a live link does not break. You can ask us to delete a shared report at any time using the contact address below.

On your own device. Both products keep a local copy of your results so your history is available to you.

In the Android app, each entry stores a downscaled copy of the analysed image — for a video, a single frame from it; for an object removal, the edited result — in the app's private storage. These copies stay on your phone: they are not uploaded to us, not readable by other apps, and excluded from both cloud backup and device-to-device transfer. The app keeps the 20 most recent entries for each account used on the device, plus 20 for signed-out use, and discards older ones automatically. Entries are not deleted when you sign out; they reappear when you sign back in.

On the website, your 10 most recent results are stored in your browser's local database, including a thumbnail of the image and its original filename. That local copy stays on your device, and clearing your browser's site data removes it.

Filenames. When you upload a file from the website, its filename is sent to us as part of the upload. We do not store it: our server logs record only the file type, such as .jpg, which is the part we actually need to diagnose a problem. A filename can still appear briefly in an error report if something fails mid-upload, and those reports are retained for a limited period and then deleted. The Android app does not send the filename at all — it uploads under a generic name of its own.

You can delete any single entry, or clear a whole history tab at once, from the History screen in the app; uninstalling the app removes all of them. On the website you can delete individual entries from your scan history.

3. Third-Party Services

We rely on a small number of specialist providers to run the Service. They act on our instructions only: they may not use what they receive for their own purposes, and they do not sell it. Each is bound by its own privacy policy and by a data processing agreement with us.

  • AI and GPU processing providers. To produce your result, your image or video — or still frames taken from it — is processed by our analysis providers and an assessment is returned to us. They do not keep your media afterwards and do not use it to train their models.
  • Identity and account providers. Authentication and session management on both products. Accounts are created by signing in with a third-party account you already have, so that provider knows you signed in to FauxLens.
  • Payment providers. On the website, a merchant of record handles the transaction; in the Android app, purchases go through the app store's billing system. Card details are handled entirely by them and never reach us — we receive a confirmation and the amount.
  • Analytics and error-monitoring providers. Product analytics and crash reporting for both products, including on the shared analysis backend. These receive event and error records with your account identifier where you are signed in, an IP address, and the type of any file involved. They never receive your media or your filenames.
  • Advertising providers. Advertising on the website, and the optional rewarded videos in the Android app. See Section 4.
  • Abuse-prevention providers. Human verification challenges and app-integrity checks, used when unusual activity is detected.
  • Infrastructure providers. Hosting, log storage, short-term result caching, and the content delivery networks that serve the images and fonts in our interface. Like any network service, these receive your IP address and browser or device type when your device makes a request.
  • Support tooling. If you write to us through the contact form on the website, a form provider delivers your name, email address and message to our support inbox.

We will name any of these providers on request — email us at the address in Section 12. If we add a provider that receives your media, we will update this page.

4. Cookies & Advertising

On the website, we use cookies for authentication sessions and product analytics. We also use Google advertising services, which use cookies to serve relevant ads based on your prior visits to our website or other websites on the Internet.

In the Android app. The app does not use cookies for advertising or analytics. Cookies are used in one place only: the human-verification challenge, which runs in an embedded web view and needs them to complete the check. Advertising is limited to optional rewarded videos, shown only when you choose to watch one in exchange for credits — never automatically and never between screens. To serve them, our advertising provider may access your device's advertising ID.

  • Where required by law, we ask for your advertising consent through our advertising provider's official consent flow the first time it is relevant. Once that flow has run, an "Ad privacy choices" control appears on the app's Help & about screen, where you can change your answer.
  • You can reset or delete your advertising ID at any time in your Android system settings, under Privacy → Ads (the exact path varies by device), independently of this app.
  • Declining personalised ads does not remove any feature, and credits you have already earned from ads remain available. Rewarded ads are one way to obtain credits; the other is to buy them, which requires signing in.

5. Legal Bases for Processing

If you are in the European Economic Area, the United Kingdom or Switzerland, we need a lawful basis under Article 6 of the GDPR for everything we do with your personal data. These are ours:

  • Performance of a contract — Art. 6(1)(b). Creating and authenticating your account, running the analysis you ask for and returning the result, delivering and accounting for the credits you buy or earn, and keeping the history we show you. We cannot provide the Service without this.
  • Legitimate interests — Art. 6(1)(f). Keeping the Service working and secure: server logs, error monitoring, human verification and app-integrity checks. Preventing abuse of the free-credit allowance, which is what the device identifier in Section 1 is for — our interest is in a free tier that is not exhausted by automated abuse, weighed against your interest in not being tracked, which is why that identifier is not a hardware ID and carries no contact details. Product analytics in the Android app also rest on this basis; the app sets no cookies and uses no advertising identifier for analytics. You can object to any of this — see Section 8.
  • Consent — Art. 6(1)(a). Non-essential cookies on the website, including analytics and advertising cookies, and, where required, the advertising consent asked for in the Android app before a rewarded ad is shown. We ask separately for this and never make it a condition of using the Service. You can change your answer at any time, and withdrawing consent does not affect anything done while it was in force — Section 4 explains how on each product.
  • Legal obligation — Art. 6(1)(c). Keeping records of purchases for tax and accounting.

6. How Long We Keep Data

We keep each kind of data only as long as the purpose in Section 5 requires. In summary:

DataHow long we keep it
Uploaded mediaDeleted the moment the analysis finishes, on every outcome including errors and cancellations.
Verdict record — scores, evidence notes, and details read from the file24 hours.
A report you publish as a shareable link14 days from the day you publish it, extended only if the link is still being opened as it nears expiry. We will remove one sooner if you ask.
Account record — email address, credit balance, linked devicesUntil you delete your account, which takes effect immediately.
History held on your deviceAndroid app: the 20 most recent entries for each account used on the device, plus 20 for signed-out use. Website: the 10 most recent. Removed when you delete them, uninstall the app, or clear your browser's site data.
Server logs and error reportsKept for a limited period for troubleshooting, security and abuse investigation, then deleted. Ask us and we will tell you the period currently in force.
Analytics eventsHeld under our analytics provider's retention schedule. We will delete the events linked to your account on request.
Purchase and financial recordsKept after your account is deleted, because tax and accounting law requires it. These cannot be deleted on request.
Deletion record — a one-way hash of your email address, the date, and the account ID the account hadKept indefinitely, so the one-time new-account credit grant cannot be claimed again by deleting and re-registering. Explained in full on the account deletion page.
Block records for devices blocked for abuseKept after account deletion, so the block is not undone by it. Nothing is kept here unless a device linked to your account was blocked.

7. Where Your Data Is Processed

FauxLens is operated from Israel, which the European Commission has recognised as providing an adequate level of data protection. A transfer of your personal data to us from the European Economic Area or the United Kingdom therefore does not require additional safeguards. The providers described in Section 3 are a separate matter: they process data in the United States and — for content delivery and hosting — in other countries, so if you use the Service from the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred outside your own country by those providers.

Not all of those countries have been found by the European Commission to offer protection equivalent to the GDPR. Where a transfer is not covered by an adequacy decision, we rely on the transfer mechanism the provider concerned makes available: the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or that provider's certification under the EU–US Data Privacy Framework and its UK extension. Ask us and we will tell you which mechanism applies to a particular provider and give you a copy of the relevant terms.

8. Your Rights

Depending on where you live, you may have rights under the GDPR, the UK GDPR, the CCPA or other applicable privacy laws. Where the GDPR applies, these are yours:

  • Access — a copy of the personal data we hold about you, and confirmation of what we do with it.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion of your account and the data attached to it. You can delete your account yourself here, which also lists exactly what is removed and the limited records we are required to keep.
  • Restriction — to have us pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability — the data you gave us, in a structured, machine-readable format, or sent directly to another provider where that is technically feasible.
  • Objection — to processing we base on legitimate interests, including the abuse-prevention identifier in Section 1. Tell us your grounds and we will stop unless we can show compelling reasons that override them.
  • Withdrawal of consent — at any time, for anything we do on the basis of consent, without affecting what was done while it was in force. Section 4 explains how on each product.
  • Complaint to a supervisory authority — see below.

Automated processing. The analysis itself is automated: our checks produce a score and an opinion about a file. That is a judgment about the file, not a decision about you, and it produces no legal or similarly significant effect on you, so the rules on automated decision-making in Art. 22 do not apply to it. We do not use it to make decisions about people, and we do not profile you with it.

Exercising them. Several you can exercise directly, without contacting us. In the Android app, delete the scans and images stored on your device from the History screen, and delete your account and its associated data from the account menu on the home screen. On the website, delete individual entries from your scan history, and clear your browser's site data to remove the local copies entirely. For anything else, email support@fauxlens.com. We answer within one month, free of charge, and exercising a right never costs you access to the Service.

Complaints. If you think we have handled your data wrongly, we would rather you told us first — but you do not have to. You can complain to the data protection authority where you live, work, or where you think the problem happened. In the EEA you can find yours through the European Data Protection Board's list of national authorities ↗. In the United Kingdom it is the Information Commissioner's Office ↗.

9. Data Security

All data in transit is encrypted using TLS 1.2+. Account credentials are managed entirely by our identity provider and are never stored in plain text by FauxLens. We hold no database of your media.

10. Children's Privacy

FauxLens is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@fauxlens.com and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top of this page reflects the most recent revision. If a change materially affects how we handle your personal data, we will note it prominently at the top of this page for at least 30 days from the day it takes effect. We do not operate a mailing list and do not send marketing email, so please check this page rather than waiting to hear from us.

12. Contact

For privacy-related questions or requests, please contact:

Faux Lens AI

Postal address is in the Data Controller block at the top of this page.

support@fauxlens.com