AIPWN / TRUST & PRIVACY DIRECTIVES
Privacy Policy
AIPwn separates browser-local tools from optional provider-backed cloud inspection and documents what each path sends and retains.
Local and cloud paths
C2PA and Unicode inspection run in your browser and do not send selected content to AIPwn. Cloud inspection sends the submitted bytes to AIPwn and the configured detection provider; the cloud control is disabled when no provider is configured.
Cloud report retention
AIPwn does not persist raw cloud inputs or source URLs. Reports retain the input SHA-256, byte size, media type, normalized provider findings, and a report-evidence digest. The configured provider processes submitted bytes under its own operational and retention terms.
Authentication data
Google and GitHub sign-in stores the provider identifier, verified email, display name, and avatar needed for the account. The requested scopes do not include Google Drive, personal messages, or private repository contents.
Cookies and optional analytics
A HttpOnly session cookie maintains sign-in; a separate language cookie and local preferences are readable by the browser. Google Analytics loads only after explicit consent and is disabled on the detector, Console, and report routes. Global Privacy Control is honored.
Export and deletion
The Console can export account metadata, reports, API-key metadata, and the credit ledger. Account deletion removes local reports, keys, sessions, and ledger data and deletes the linked Stripe customer before local deletion when a billing profile exists.