سياسة
الخصوصية
كيف تتعامل FalsiFind مع المعلومات الشخصية عبر الموقع التسويقي ومنصة الكشف.
Effective Date: May 6, 2026
Last Updated: May 6, 2026
FalsiFind is operated by Obscurae Intelligence Inc., a Delaware corporation (“FalsiFind,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, share, and protect personal information in connection with our marketing website at falsifind.com (the “Website”) and our deepfake detection platform delivered at app.falsifind.com and api.falsifind.com (the “Platform”). It also explains the rights available to individuals under applicable privacy laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), other US state comprehensive privacy laws, the Personal Information Protection and Electronic Documents Act (PIPEDA), and Quebec’s Law 25.
١. النطاق والهيكل الثنائي
This policy is structured in two tracks because the data we handle in each context is fundamentally different.
Track 1, Website Data. Personal information we collect from visitors to the Website, from people who request demos, sign up for our newsletter, download gated resources, or interact with our AI chat assistant. For this data, FalsiFind acts as a data controller (or “business” under US state privacy laws).
Track 2, Platform Data. Personal information processed by the Platform on behalf of our enterprise customers, including any media files, account telemetry, or end-user information that customers submit for analysis. For this data, FalsiFind acts as a data processor (or service provider under US state privacy laws), and our processing is governed by the written subscription agreement and Data Processing Addendum (DPA) we sign with each customer, not by this policy. Where this policy and a customer DPA conflict regarding Platform Data, the DPA controls.
This policy does not address employment-related personal information, which is covered under separate internal notices.
٢. المعلومات التي نجمعها (بيانات الموقع)
We collect Website Data in the following ways.
Information you provide directly. When you request a demo, you provide your name, business email, company name, role or title, country, and any free-text message you choose to include. When you subscribe to our newsletter, you provide your business email and, optionally, your name and company. When you download gated resources such as white papers or data sheets, you provide your business email and, optionally, your name, company, and role. When you interact with our AI chat assistant on the Website, we collect the conversation history, including the prompts you submit and the responses generated, along with session metadata (timestamps, page context, and an anonymous session identifier). We do not require you to log in to use the AI chat assistant.
Information collected automatically. When you visit the Website, we collect technical information through cookies and similar technologies as described in Section 9 (Cookies and Tracking) and consistent with your choices in our cookie banner. This includes IP address (truncated where feasible), browser type and version, operating system, referring URL, pages viewed, time spent on pages, and approximate location derived from IP. Strictly necessary cookies are always on. Analytics, Marketing, and Functional cookies operate only with your consent.
Bot detection and fraud prevention. We use Cloudflare Turnstile to verify that interactions with our Website forms (including demo requests, newsletter signups, gated content downloads, and the AI chat assistant) come from human users rather than automated bots. Turnstile processes your IP address, browser and device characteristics, and limited interaction signals to produce a verification token. This processing is necessary for the security of the Website and the integrity of our forms. We rely on it as a strictly necessary security function under the ePrivacy Directive’s “strictly necessary” exemption, on legitimate interests under GDPR Article 6(1)(f), and on the security purposes exception under the CCPA/CPRA. Turnstile is provided by Cloudflare, Inc., which acts as a sub-processor on our behalf and is identified in our sub-processor list in Section 6.
Information from third parties. We may receive information from analytics providers, marketing partners (where you have consented to Marketing cookies), and from publicly available sources such as professional networking sites where you have made information public.
We do not knowingly collect personal information from anyone under the age of 16. The Website is not directed to children. If you believe a child has provided us with personal information, please contact us at privacy@falsifind.com and we will delete it.
٣. كيف نستخدم بيانات الموقع
We use Website Data for the following purposes:
- Responding to demo requests, sales inquiries, and support questions
- Sending newsletters, product updates, and marketing communications you have opted into, with an unsubscribe link in every message
- Delivering gated content you have requested
- Operating the AI chat assistant, including generating responses and improving the assistant’s performance against our internal quality benchmarks (we do not use chat content to train or fine-tune third-party foundation models)
- Measuring Website performance, debugging, and improving navigation and content (Analytics cookies)
- Measuring marketing campaign performance and showing you relevant FalsiFind content on third-party sites (Marketing cookies, only with your consent)
- Enabling functional features such as embedded media, chat widgets, and saved UI preferences (Functional cookies, only with your consent)
- Detecting and preventing fraud, abuse, and security incidents
- Complying with legal obligations and exercising or defending legal claims
٤. الأسس القانونية للمعالجة (GDPR و UK GDPR)
For individuals in the European Economic Area, the United Kingdom, and Switzerland, we rely on the following legal bases under Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): newsletter subscriptions, non-essential cookies, marketing communications, and AI chat assistant interactions where consent is required
- Performance of a contract (Art. 6(1)(b)): responding to demo requests and providing gated resources you have requested
- Legitimate interests (Art. 6(1)(f)): measuring Website performance, securing the Website, communicating with business contacts about products relevant to their professional role, and defending legal claims, in each case balanced against your privacy interests
- Legal obligation (Art. 6(1)(c)): retaining records as required by tax, accounting, and other applicable laws
You have the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
٥. الاحتفاظ ببيانات الموقع
We retain Website Data for the following periods:
- Demo requests, gated content downloads, and other sales-related contacts: up to 24 months from last contact, after which we either delete the record or anonymize it, unless a longer period is required by law or to defend legal claims
- Newsletter subscriptions: until you unsubscribe, plus a short suppression-list retention to honor your unsubscribe request
- AI chat assistant conversation history: up to 30 days from the date of the conversation, after which conversation content is deleted from production systems
- Cookie data: as described in our cookie banner, with maximum retention of 13 months for analytics and marketing cookies
- Server and security logs: up to 12 months, except where a longer period is needed for incident investigation
If you exercise a deletion right under Section 8, we will delete or anonymize the relevant data within the time periods required by applicable law, subject to legal-hold and statutory retention exceptions.
٦. كيف نشارك بيانات الموقع
We do not sell Website Data, and we do not “share” Website Data for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, except to the extent that enabling Marketing cookies through our cookie banner involves third-party advertising partners that may be classified as a “sale” or “share” under California law. You can opt out at any time using the cookie banner or by selecting “Reject all.”
We disclose Website Data to the following categories of recipients:
Sub-processors and service providers. We use a small set of vetted third parties to operate the Website and the Platform. The current list is:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, including selected AI inference services | United States |
| Google Cloud Platform | Cloud infrastructure and selected workspace services | United States |
| Microsoft Azure | Cloud infrastructure and selected workspace services | United States |
| Cloudflare | Bot detection and fraud prevention on Website forms via Cloudflare Turnstile | United States |
| Okta | Identity and access management for our internal staff and for customer SSO | United States |
| Vercel | Website hosting, DNS management, and edge delivery | United States |
We sign written agreements with each sub-processor that include confidentiality, security, and data protection obligations consistent with applicable law. An updated sub-processor list is maintained for our enterprise customers under their DPA.
Professional advisors. Our lawyers, auditors, accountants, and insurers, under duties of confidentiality.
Legal and safety disclosures. Where we are required by law, court order, subpoena, or regulatory authority to disclose information, or where we believe disclosure is necessary to protect rights, safety, property, or to investigate fraud or security incidents.
Corporate transactions. In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, we may transfer Website Data as part of the transaction, subject to confidentiality protections and continued application of this policy or an equivalent successor policy.
٧. نقل البيانات الدولي
We are headquartered in the United States, and our sub-processors are primarily located in the United States. When we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States or another third country, we rely on one or more of the following transfer mechanisms:
- The EU-US Data Privacy Framework, the UK Extension to the DPF, and the Swiss-US Data Privacy Framework, where the receiving entity is certified
- Standard Contractual Clauses adopted by the European Commission, supplemented by the UK Information Commissioner’s International Data Transfer Addendum where applicable
- Transfer Impact Assessments documenting the legal regime of the destination country and any supplementary technical, contractual, or organizational measures
- Other valid mechanisms recognized under applicable law
Copies of the relevant transfer mechanisms are available on request to privacy@falsifind.com.
٨. حقوق الخصوصية الخاصة بك
Depending on where you live, you may have the following rights with respect to your personal information. We honor these rights for all individuals to the extent applicable law permits.
Access and portability. You can request a copy of the personal information we hold about you and, where technically feasible, in a portable format.
Correction. You can ask us to correct inaccurate or incomplete information.
Deletion. You can ask us to delete your personal information, subject to legal-hold, statutory retention, and other lawful exceptions.
Objection and restriction. You can object to processing based on legitimate interests and ask us to restrict processing in certain circumstances.
Withdrawal of consent. Where processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Opt-out of sale, sharing, and targeted advertising. California, Colorado, Connecticut, Virginia, and other US state residents can opt out of any sale, sharing, or targeted advertising at any time using our cookie banner or by emailing privacy@falsifind.com. We honor Global Privacy Control signals as a valid opt-out request for browsers from which they are received.
Limit use of sensitive personal information. California residents can ask us to limit our use of sensitive personal information, although we do not currently use such information for purposes that trigger this right.
Non-discrimination. We will not discriminate against you for exercising any of these rights. We do not offer financial incentives in exchange for personal information.
Quebec residents (Law 25). You have the additional right to be informed about the use of automated decision-making and to request human review where automated decisions produce legal or similarly significant effects. We do not currently use automated decision-making to make decisions about Website visitors that would produce such effects.
EU/UK residents (GDPR). You have the right to lodge a complaint with your local supervisory authority. Our EU representative under Article 27 of the GDPR is [EU Representative to be appointed] and our UK representative under Article 27 of the UK GDPR is [UK Representative to be appointed].
How to exercise your rights. For Fay chat sessions, you can export or delete your data immediately and without verification via our self-service data request page. For all other data (Website usage, demo submissions, etc.), send a request to privacy@falsifind.com with enough information for us to verify your identity and locate your records. We will respond within the time period required by applicable law (generally 30 to 45 days, with a possible extension where permitted). You may use an authorized agent where applicable law permits, in which case we will require proof of authorization.
If you are an end user of an enterprise customer’s deployment of the Platform, please direct your request to that customer in the first instance, since they are the controller of that data. We will support our customer in responding to your request as required under our DPA.
٩. ملفات تعريف الارتباط والتتبع
We use cookies and similar technologies on the Website. You can manage your preferences at any time through the cookie banner and the Cookie preferences modal accessible from the Website footer. Our cookie categories match the banner exactly. For full details, see our Cookie Policy.
Strictly Necessary (always on). Required for the site to function: routing, security, and remembering your cookie choices. These cookies do not require consent under applicable law.
Analytics (off by default; opt-in). We use Umami, a privacy-respecting traffic analytics tool, to understand which pages are useful. Umami does not perform cross-site tracking and does not build advertising profiles.
Marketing (off by default; opt-in). Used to measure marketing campaign performance and to show you relevant FalsiFind content on third-party sites. Enabling Marketing cookies may constitute a “sale” or “share” under the CCPA/CPRA and equivalent state laws.
Functional (off by default; opt-in). Optional features such as embedded media, chat widgets, and saved UI preferences.
You can choose Reject all, Save preferences with custom selections, or Accept all through the banner. We honor Global Privacy Control as an opt-out signal for Analytics and Marketing categories.
A full list of cookies, their purpose, the party that sets them, and their retention period is available in the Cookie preferences modal.
١٠. بيانات المنصة (المسار 2)
When our enterprise customers use the Platform, FalsiFind acts as a processor or service provider under applicable law. Customers are the controllers of the data they submit to the Platform, including any media files analyzed for synthetic-content detection, any account telemetry, and any end-user information embedded in submissions.
Privacy-first architecture. The Platform is designed to minimize the persistent storage of raw customer media. Raw media submitted for analysis, along with associated analysis artifacts, are retained for up to 45 days solely for evidence integrity, audit, chain-of-custody verification, dispute resolution, and incident response purposes, after which they are deleted from production systems. Cryptographically signed JSON evidence bundles, which contain analysis results and metadata but not the raw media, are retained according to the customer’s configuration under the subscription agreement.
No training on customer data. We do not use customer-submitted media or customer Platform Data to train, fine-tune, or otherwise improve our detection models or any third-party foundation model. Model improvement is performed exclusively against licensed and synthetic training datasets governed by our internal data sourcing standards.
Customer instructions and DPA. All processing of Platform Data is performed in accordance with the customer’s documented instructions, the subscription agreement, and our DPA, which incorporates Standard Contractual Clauses where required, the UK International Data Transfer Addendum where applicable, and additional safeguards consistent with the customer’s regulatory environment (including GLBA, NYDFS Part 500, HIPAA where applicable, and sector-specific frameworks).
End-user inquiries. If you are an end user whose information has been processed through the Platform, please contact the FalsiFind customer that initiated the processing. We will assist that customer in responding to your inquiry as required under our DPA.
١١. الأمن
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These include encryption in transit and at rest, role-based access control, multi-factor authentication, network segmentation, vulnerability management, monitoring and logging, and a written incident response plan with breach notification commitments. A more detailed description is available on our Security page. No system can be guaranteed to be perfectly secure, and we encourage you to use strong, unique passwords and to be cautious about the information you submit through any online form.
١٢. اتخاذ القرار الآلي
The Platform uses machine-learning models to analyze media for indicators of synthetic generation or manipulation, and to produce a confidence score, an agreement metric, and a recommended verdict. The Platform is designed to support, not replace, human review. We do not use automated decision-making to make decisions about Website visitors that produce legal or similarly significant effects. For Platform deployments where a customer chooses to integrate FalsiFind output into automated decisioning, the customer is responsible for ensuring appropriate human oversight, contestability, and disclosure under applicable law (including the EU AI Act, where applicable).
١٣. التغييرات على هذه السياسة
We may update this policy from time to time. When we do, we will post the updated policy here, update the “Last Updated” date, and, for material changes, provide notice through the Website or by email where we have your contact information. Your continued use of the Website or the Platform after the effective date of an update constitutes acceptance of the updated policy.
١٤. اتصل بنا
For privacy questions, requests, or complaints:
Email: privacy@falsifind.com
Mail:
Obscurae Intelligence Inc.
Attn: Privacy
522 West Riverside Ave., #8054
Spokane, WA 99201
United States
For security-related concerns, please contact security@falsifind.com. For all other legal notices, please contact legal@falsifind.com.
FalsiFind is a product of Obscurae Intelligence Inc., a Delaware corporation.
