Your images are yours.
Witness is built to check media, not collect it. This policy explains exactly what happens when you use the service.
Last updated: September 23, 2026
Who we are
Witness is operated by A Labs Inc., a Delaware C-Corporation based in Cambridge, MA. A Labs Inc. is the data controller for the purposes of GDPR and the business for the purposes of CCPA/CPRA. Contact: privacy@witness.vision.
What we collect
- Media you scan: images and videos you upload or that the Chrome extension captures for analysis. These are analyzed in real time and are not stored— we do not retain your uploaded media after your scan completes.
- Facial data (transient): when your media contains human faces, our models perform face detection and face-swap analysis to identify manipulated facial content. Facial data is processed in server memory only and is discarded immediately after analysis. We do not build facial recognition databases, biometric templates, or identity profiles from scanned faces.
- Scan results: detection scores, verdicts, generator attribution estimates (which AI model likely produced the content), and detection heatmap data (visual overlays showing which regions of the image influenced the detection) produced by our models.
- Account data: email and authentication info, if you create an account.
- Usage data: scan counts, feature usage, verdicts/scores, and device/browser type. We use PostHog for product analytics (events and properties only — never uploaded media).
- IP address: collected server-side on each scan request, used for abuse prevention and rate limiting.
- Payment data: if you subscribe to a paid plan, payment processing is handled entirely by Stripe (web) or Apple (App Store). We do not receive, store, or have access to your full credit card number. We receive only a transaction identifier, subscription status, and billing period from the payment processor.
We do not collect your contacts, browsing history, or GPS location.
How we handle scanned media
When you scan media, we analyze it to produce a verdict and then discard it. We do not retain your uploaded images or videos, do not use them to train our models, and do not sell or share them. We do not use your media, scan results, or personal information to train, fine-tune, or improve our detection models. Our models are trained on separate, dedicated datasets, and user-submitted content is never added to those datasets. Only the scan result (score, verdict, generator attribution, and detection heatmap overlay) and basic metadata are kept.
Face-swap and manipulation detection: if your media contains faces, our pipeline runs face detection and face-swap analysis as part of the scan. Facial data is held in server memory only for the duration of processing (typically under 10 seconds) and is never written to disk, stored in a database, or used to build biometric profiles.
Detection heatmaps: our models generate visual explanation overlays (detection heatmaps) that highlight which regions of your image influenced the AI/real verdict. These heatmaps are derived from model activations during analysis and are returned to you as part of the scan result. The underlying activation data is not stored after the response is sent.
Generator attribution: when possible, our models estimate which AI generator (e.g., Midjourney, DALL-E, Stable Diffusion) likely produced the content. This estimate is returned as metadata in the scan result. No additional data collection is required for this feature.
Legal bases (EU/UK users)
We rely on the following lawful bases under the UK/EU GDPR:
- Contract: providing the scan service and managing your account.
- Legitimate interests: abuse prevention, rate limiting, security, and error monitoring — balanced against your rights.
Device identifier & local storage
Witness generates a random identifier (a UUID) and stores it locally on your device — in your browser's localStorage for the web app, or in extension storage for the Chrome extension. This identifier is used solely for rate limiting and does not directly identify you. (Note: under GDPR, a persistent device identifier may still be treated as personal data.)
The Chrome extension additionally stores your authentication session token locally (in Chrome extension storage) if you choose to log in. This token is used only to authenticate your scan requests and is cleared when you log out.
Scan history: both the web app and the Chrome extension store your recent scan history (verdicts, scores, timestamps, and thumbnail previews) in your browser's localStorage. This data is stored entirely on your device and is never transmitted to our servers. Scan history is not synced across devices or browsers. You can clear your scan history at any time from the Witness interface or by clearing your browser's local storage.
You can delete all locally stored data at any time by clearing your browser or extension data. A new device ID will be generated on your next visit.
Data storage, security, and retention
Data is stored on encrypted cloud infrastructure. Access is restricted to A Labs Inc.
| Data category | Retention |
|---|---|
| Uploaded media | Not stored — discarded after scan completes |
| Facial data | Transient — held in server memory during processing only, never written to disk |
| Detection heatmap activations | Not stored — rendered and discarded after response is sent |
| Scan results & metadata | Retained to power scan history and analytics (includes verdicts, scores, generator attribution, and heatmap overlays) |
| Local scan history | Stored on your device only — never sent to our servers |
| Account data | Until you delete your account (deleted within 30 days of request) |
| IP logs | Only as long as needed for abuse prevention |
| Usage & analytics data | Per our analytics provider's configured window |
International data transfers
Our infrastructure and service providers are located in the United States. If you access Witness from the EU/UK, your data will be transferred to the US. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards for these transfers.
Error tracking and analytics
We use Sentry for error monitoring (crash reports and performance data — never uploaded media) and PostHog for product analytics (event counts and properties — never uploaded media, no session recordings).
Bot protection is applied to scan requests via an invisible challenge provided by Cloudflare Turnstile, which may process your IP address and device signals for security purposes.
Cookies and tracking technologies
Witness does not use cookies for advertising or cross-site tracking. We use localStorage for device identification and scan history (described above). PostHog analytics may use first-party cookies solely for product analytics. We do not serve advertisements, and we do not share data with advertisers or ad networks.
Data breach notification
In the event of a data breach that affects your personal information, we will notify affected users and relevant supervisory authorities as required by applicable law (including within 72 hours under GDPR where feasible). We maintain an incident response plan and will provide details about the nature of the breach, the data affected, and the steps we are taking to address it.
Your rights
You may request access to, correction of, or deletion of your data at any time: privacy@witness.vision.
- EU/UK users have rights under GDPR including access, rectification, erasure, restriction, data portability, and the right to object. You may also lodge a complaint with your local supervisory authority.
- California residents have rights under CCPA/CPRA including access, deletion, and correction. We do not sell your data, and we do not share it for cross-context behavioral advertising.
- Canadian residents have rights under PIPEDA including the right to access your personal information and to challenge its accuracy.
Account deletion
You may delete your account at any time by contacting privacy@witness.vision. Upon request, we will delete your account information, scan history metadata, and all associated data within 30 days, except where longer retention is required by applicable law (such as financial transaction records required for tax or accounting purposes, which may be retained for up to seven years). Locally stored data (scan history, device ID) must be cleared separately by you through your browser or extension settings.
Children
Witness is not intended for users under 13 (or the minimum age required in your jurisdiction, such as 16 in parts of the EU). We do not knowingly collect data from children.
Changes to this policy
We will notify users of material changes via the app or email. The current version will always be available at this URL with an updated date.
Contact
Questions about this policy? Reach out at privacy@witness.vision — A Labs Inc.