Uploads and server copies
You upload a photo and its filename so EvidPic can perform the operation you choose, produce a result and enable the available follow-up actions. The server's temporary working copy, including the checker source and its job data, is kept for follow-up actions for no longer than 30 minutes; a watchdog removes expired jobs. A processed response file is deleted after it is streamed to you. This deletion does not apply to the separate copy sent to a secure operational service.
Anti-abuse and browser/device signals
To protect the service from abuse and apply request limits, we process a limited set of technical browser and device parameters, including GPU characteristics and time zone. A normalized set of these parameters is hashed to form a pseudonymous identifier. The identifier is used across requests to apply limits and protect sessions; a derived rate-limit key is retained only in dedicated in-memory storage for up to 24 hours. The identifier may also be included in the operational logs described below.
OpenAI provenance check
OpenAI receives an eligible image only when you press the separate OpenAI SynthID/C2PA check button, so it can perform that requested provenance check. OpenAI processes and retains the image under its API data controls.
Android app diagnostics and local history
The Android app uses the Tracer SDK to detect crashes, ANRs and non-fatal errors. When such an event occurs, a diagnostic report is sent to Apptracer through sdk-api.apptracer.ru. A report may contain its date and time, stack trace and thread information, app version, technical logs recorded before the event, and device characteristics: board, brand, manufacturer, model and system device name, processor architecture and core count, Android and SDK versions, carrier and installer package when available. The network request also exposes the IP address to the service. Tracer is not used to transmit images processed with EvidPic. According to Apptracer's documentation, diagnostic events from the latest 90 days are retained. Separately, Android keeps report history and thumbnails locally on the device; you can delete them through “History”.
Recipients and their roles
EvidPic operates the service and processes the upload, filename, report and browser/device signals to provide the requested feature and protect the service. Apptracer receives Android diagnostic reports to detect and diagnose app failures. The operational service receives the first source upload and the associated operational information described below so EvidPic can operate, monitor and investigate the service. OpenAI receives an eligible image only for the optional provenance check you initiate.
Operational notifications
In production during stealth beta, the first source upload is sent to a secure operational service together with its original filename, a bounded source-metadata snapshot, client and proxy IP fields, request headers, selected tool, format, size bucket, output size, duration and result. This service copy is stored separately from the temporary working copy and is not automatically deleted; it remains there until the operational-service account administrators delete it. Capability and download tokens are not included.
Logs and abuse prevention
Technical abuse-monitoring logs may be retained for up to 30 days for rate limiting, security review and failure investigation.