Privacy
ChronoVerify is built so that verifying a photo does not mean handing over the photo. Images you check are processed in memory, then discarded. They are not written to disk, not logged, and not shared. This page explains exactly what happens to a photo you submit and what little data we keep to run the service.
What happens to a photo you verify
- The image is read into memory, analyzed, and released when the response is sent. It is not written to disk, not saved to a database, and not written to any log.
- When you verify by URL, the fetched image is handled the same way and discarded after analysis.
- Your image is never used to train any model. The verdict pipeline is deterministic and does not send your image to a language model.
The free tools
- The hash checker and the signed-report verifier run entirely in your browser. The file or report you load is read locally and is never uploaded. You can confirm this in your browser's network panel: no request carries your file.
- The EXIF and XMP viewer and the C2PA inspector send the image to the server, where it is handled exactly like a verification: read into memory, analyzed, and discarded. It is not written to disk, saved, or logged.
Shareable verdict links (opt-in)
- If, and only if, you ask for one (the checkbox on the verifier, or
permalink=trueon the API), we store the verdict record so it can be shown again at its link: the verdict, the signals behind it, the file's metadata summary, and its SHA-256 and SHA-512 fingerprints. The image itself is never stored, with or without a link. - Links are unlisted and never indexed. We store no record of who created a link and no IP address with it. Anyone who has the link can view the verdict, so share it as you would the verdict itself.
- Links created on the free verifier stop resolving after 90 days, so the verdict can no longer be viewed at its link; the stored record is retained unless you ask us to remove it. Links created with an API key do not expire. To have a link removed and its record deleted, email support@chronoverify.com with the link.
- If you never opt in, nothing changes: no verdict is stored.
What we keep, and why
- For the free public verifier: a single per-day count of how many checks ran. It carries no image, no result detail, and nothing that identifies you. It exists only to watch load and abuse.
- For API keys: the email you provide (for receipts and key recovery), the key itself, a running usage count, and your prepaid credit balance. This is the minimum needed to operate billing.
- For free API keys: the email you provide when creating the key. It enforces the one-key-per-email limit and enables support; it is not used for marketing and we do not send mail to it.
- A verdict includes a SHA-256 and SHA-512 fingerprint of the exact file you submitted. The fingerprint is returned to you so you can re-check the file yourself. We do not keep a record linking that fingerprint to you.
- If you write to us through the contact form: the message and whatever name and email you chose to include, kept so we can read and answer you, and deleted on request. No IP address is stored with it, and nothing from it is used for marketing.
Payments
Card payments are handled by Stripe. We never see or store full card numbers. Stripe's own privacy terms govern that data.
After a $49 single-report purchase we send one receipt email to the address you gave at checkout, carrying the link back to your report. It contains no analysis output: no verdict, no capture time, no metadata, and never the image.
Email delivery
The receipt email above and our internal notification of a contact-form message are delivered through Resend, an email delivery service, which processes the recipient address and message content in transit. We send no marketing email, and no other data is shared with Resend.
Cookies and tracking
- The site sets no advertising or cross-site tracking cookies. If we measure traffic, we use a cookieless, privacy-respecting method.
- The dashboard stores your API key in your own browser so you do not have to paste it on each visit. It stays in your browser and is only sent in the authenticated API calls you make.
Transport and infrastructure
- Traffic is served over HTTPS. Cloudflare sits in front of the service and terminates TLS at its edge, which is standard for a site behind a content delivery network.
- The service runs on Render. Operational backups cover the billing database (keys, usage, balances). They do not cover your images, which are never stored in the first place.
What we do not claim
ChronoVerify is an independent product and does not currently hold SOC 2 or ISO 27001 certification. The hosting providers it runs on, Render for compute and Cloudflare for edge, DNS, and encrypted backups, each hold SOC 2 Type II and ISO 27001 for their platforms; those certifications cover the providers, not this application. We state that distinction plainly rather than imply an audit we have not completed. If you need a formal data processing agreement for a vertical pilot, contact us.
Contact
Questions about privacy, or a data request: the contact form, or support@chronoverify.com.