← Back to Home

Privacy Policy

Last updated: September 27, 2026

1. Information We Collect

When you use deetech™, we collect information you provide directly (such as account details and uploaded media for analysis), usage data (how you interact with our platform), and technical data (device type, browser, IP address) to provide and improve our services.

2. How We Use Your Information

We use collected information to operate our deepfake detection and forensic analysis services, improve detection accuracy, maintain platform security, communicate service updates, and comply with legal obligations.

3. Data Retention & Security

Uploaded media is processed for analysis and retained according to your subscription plan. All data is encrypted at rest and in transit. We implement industry-standard security measures including role-based access control, audit logging, and regular security assessments.

4. Browser Extension

The optional DeeTech browser extension acts only when you select one media item or paste a public HTTPS media URL and confirm the transfer. It does not read your browsing history, cookies, private-page content, or surrounding page. The selected URL is sent to DeeTech for server-side analysis and may consume an analysis credit even when the media cannot be fetched.

A scoped API token is held only in extension session memory and is removed when the browser session ends or you log out; it is not stored in extension local storage. Selection and result references can be cleared in the extension. Server-side media follows your subscription retention settings and can be managed or removed from Library. Extension submissions are not used for model training by default; a separate, explicit ground-truth permission is required for governed learning use.

5. Zoom Connection

If an organization administrator installs the optional Zoom connection, we store opaque Zoom account and authorizing-user identifiers, the granted permission, encrypted OAuth credentials, and limited lifecycle records needed to secure and support the connection. The connection does not import Zoom recordings, transcripts, chat, participant lists, or meeting content, and it does not start monitoring automatically.

Disconnecting revokes OAuth access and schedules removal of Zoom identifiers and credentials. Revoking the app in Zoom triggers the same removal after a signed provider notice. Sanitized security and operation records, and any separate DeeTech meeting evidence or reports, remain subject to their applicable retention policy. The Zoom connection is not used for model training.

6. Third-Party Services and Subprocessors

We use the service providers below to run DeeTech. Each entry says what the provider does, what it receives and when. These providers have their own privacy policies governing data handling.

  • Google Cloud — Hosts the DeeTech platform: servers, database, file storage, encryption keys and logs. The platform runs in Google Cloud's us-central1 region in the United States. Receives: Account details, the files you upload, analysis results, and service logs that include IP addresses. When: Always.
  • Google Cloud Vertex AI — Writes the one-sentence AI descriptions of images and documents. It runs inside our Google Cloud project, in the same region. Receives: Images analyzed with a Deep Scan, the first page of each PDF document, and document scans uploaded as images. When: On by default, while the “AI descriptions and transcription” setting is on. For documents, an organization owner or admin can also turn descriptions off for the whole organization, and document pages are not sent for organizations that delete files after analysis.
  • Google Firebase and Identity Platform — Sign-in and account security, and hosting for our website. Receives: Your name, email address and password when you sign up or sign in, your sign-in activity, your phone number if you turn on text-message verification, and the IP address and browser details of website visitors. When: Always.
  • RunPod — Runs our detection models on GPU servers. Receives: The images, video frames and audio you submit for analysis, and scanned document pages. When: Every time one of these is analyzed.
  • OpenAI — Turns speech into text (transcription). Receives: Audio files, and the audio track of video files. When: On by default. It runs when you open an audio or video file in the media dashboard while the “AI descriptions and transcription” setting is on, and when you request a transcript through the API.
  • SerpApi — Runs reverse image searches. SerpApi passes the image link to Google's image search (Google Lens), which uses the link to fetch the image. Receives: A link to the image: either a temporary link to your file that expires after one hour, or the web address you gave us. When: On by default for images analyzed with a Deep Scan, while the “Reverse image search” setting is on, and whenever you start a reverse image search yourself.
  • Resend — Sends our emails. Receives: Recipients' names and email addresses, and the content of our emails, such as team invitations, account notices, and the details you send through our contact or demo-request forms. When: Whenever we send an email.
  • Stripe — Processes payments and subscriptions. Receives: Billing contact details, payment card details (which you enter directly with Stripe), and records of your purchases. When: When you buy or manage a paid plan or credits.

The “Reverse image search” and “AI descriptions and transcription” settings are on by default. Each user can switch them off for their own account under Settings → Analysis options.

Live meeting monitoring and phone-call monitoring are not currently available, so no meeting-bot or telephony provider receives your data.

Our public web pages also show a security-rating badge from SecurityScorecard. When your browser loads the badge, SecurityScorecard receives your IP address and browser details.

Our public web pages (deetech.ai, deetech.au, dee.tech, and our blog, but not the signed-in app) use Google Analytics to count visits and basic interactions, such as BotBlock section views, pilot-button clicks, and successful form submissions. We send the form type, not its contents. When you load one of these pages, Google receives the page address, the page you came from, your browser and device details, and your IP address, which Google uses to estimate your country and city and does not store. Google Analytics sets cookies to recognize a returning browser, except for visitors in the European Economic Area, the United Kingdom, and Switzerland, whose visits are counted without analytics cookies. We do not use it for advertising, and its data is kept for up to 14 months. You can opt out with Google's opt-out browser add-on.

7. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at admin@deetech.ai. We will respond within 30 days.

8. Contact

For privacy-related inquiries, contact us at admin@deetech.ai.