Your content is inspected in your browser.
Scanning happens locally. If you sign in and clean a result, only a content-free evidence report is saved—not your text, media, or filename.
You can scan without an account. Pasted text and media bytes are processed locally and are not sent to Firebase or an LLM. Cleanup requires an account; after cleanup, the app saves hashes, findings, scanner versions, and timestamps so you have an evidence record without storing the content itself.
What stays on your device
- The text you paste into the checker.
- The bytes of PNG, JPEG, WebP, MP4, MOV, or M4V files you select.
- Cleaned text, image, and video copies until you choose to download or copy them.
- External C2PA manifest URLs found in structured text; the checker recognizes them but never opens them.
Network requests the site makes
Loading the website requests its HTML, JavaScript, styles, image assets, and C2PA validation module from the site host. When media Content Credentials are validated, the browser also requests the current public C2PA signing and timestamp trust lists from the C2PA organization's public GitHub repository. Those requests do not contain the selected file or pasted text.
Hosting data
Like any hosted website, ordinary page requests reach the hosting infrastructure and may be recorded in security or operational logs, such as an IP address, user agent, requested path, and time. The checker does not intentionally place pasted text, selected file contents, or scan results into those requests.
Accounts and saved evidence reports
Firebase Authentication handles email/password and Google sign-in. Depending on the method you choose, Firebase receives account identifiers such as your email address, Google profile details, and authentication metadata. The app stores a small account profile—email, display name, sign-in provider, verification status, and last-seen time—to operate accounts and measure product use. The app uses a sign-in session to keep your reports private.
After an authenticated cleanup, Cloud Firestore stores the report type, scan and save times, scanner version, SHA-256 fingerprints, finding counts, exact supported findings, validation results, and cleanup verification. It does not store pasted text, image or video bytes, cleaned content, or filenames. You can view, download, and delete your saved reports from your account.
Contact messages
If you use the contact form, the name, email address, subject, and message you enter are stored in Cloud Firestore so the administrator can read and reply to them. Scanner content and account reports are not attached automatically. Do not include private scanner content unless you intentionally want it included in your message.
Cookies and usage measurement
The site records a small set of first-party, cookieless service counters whether or not you allow optional analytics. They show the administrator daily page-category views, completed text, image, and video scans, completed cleanups, and the broad country and region supplied by Vercel. These counters are aggregated by day and are not profiles or unique-visitor counts. They may include reloads and automated traffic.
The first-party counter does not set an analytics cookie or persistent identifier, and its records contain no IP address, account ID, pasted text, media, cleaned content, filename, hash, finding details, or contact message. It exists to show which product areas are being used and what to improve next.
The site asks before loading Google Analytics or Microsoft Clarity. If you allow analytics, the Google tag uses measurement ID G-TLTQNZKZRH to measure page visits and content-free product events such as completed scans or cleanups. This is the same Analytics property surfaced through the Firebase console. Event parameters can include the media format, result category, and number of supported findings. Microsoft Clarity project y1pb14nzdm provides heatmaps and session playback to help identify confusing interfaces. If you turn analytics off, neither analytics service is loaded. You can change this choice from “Cookie settings” in the footer.
The three scanner workspaces are explicitly masked from Clarity, and Clarity masks form inputs by default. Analytics is disabled entirely on the account and admin routes. The app never intentionally sends pasted text, media bytes, cleaned content, filenames, report hashes, contact messages, account email addresses, or Firebase user IDs to either analytics service. Advertising storage is denied.
Google Analytics and ordinary hosting or Firebase operational logs may receive technical request data such as an IP address, browser information, requested page, and time. Saved-report counts separately show authenticated cleanup usage.
Your responsibility
Use the checker only with content you own or may inspect and modify. A cleaned copy does not change ownership, copyright, platform rules, or disclosure obligations. For technical scope, see the versioned methodology.