Privacy Policy
Last updated: 3 August 2026
This Privacy Policy explains how DotCheck processes personal data for the Chrome extension, the website at dotcheck.ai, and related APIs (together, the “Services”). It is written for the EU GDPR and aligned Czech law. The summary below is for convenience. The numbered sections that follow are controlling.
Summary
DotCheck scores how AI-like images, video frames, text, and audio look or sound. Processing is limited to what the Services need to provide that score, run accounts and billing, prevent abuse, and avoid re-scoring identical content.
- The score belongs to the content. Scoring uses the media or text you submit or that the extension sends for analysis. Reuse relies mainly on a content hash and the score. We do not store what you browsed.
- No browsing log. DotCheck does not collect full browsing history or full page HTML as a product. The extension scores media, frames, or supported-language text in view.
- Temporary uploads. Files submitted for scoring are deleted after processing or shortly thereafter. Share renders are short-lived download jobs, not a permanent gallery.
- In-house by default. Free and Premium everyday scoring stays on DotCheck’s own models. Sightengine and Winston are used only for Pro Confirm, and only when you request that retest.
- We do not sell what you check; no ad trackers. We do not sell a profile of pages you opened. The public site does not run marketing or advertising trackers. We may count opens of our own pages so we can run the Services, and that count does not use a cookie. The Chrome extension does not use advertising cookies.
- EU operator; mixed processors. The controller is in the Czech Republic. Primary in-house analysis runs in the Netherlands. Account, billing, and API layers may use processors outside the EEA (including Google/Firebase, Stripe, and current API hosting), listed in the sections below.
- Tab audio: Premium and Pro only. When the live tab soundtrack setting is on, the extension may capture a short window (about four seconds) of that tab’s audio on click or play. Free accounts never capture tab audio. It does not use the microphone and does not listen continuously. Automatic browsing does not capture tab audio. Audio and video files you upload on Check or in the popup are scored on every plan.
- History only when you use it. Premium and Pro History stores metadata from analyses you run in Check or the extension popup (type, score label, date). It is not automatic browse logging and does not keep the original files.
The numbered sections set out categories of data, purposes and legal bases, recipients, retention, security, and your rights.
DotCheck estimates how AI-like images, video frames, text, and audio look or sound. Scores are probabilistic estimates, not guarantees of authenticity and not a substitute for human judgment. Text scoring supports English, Chinese, Spanish, French, Portuguese, German, Italian, and Dutch. Other languages are not scored yet.
Privacy contact / DSARs: contact@dotcheck.ai (subject line: Privacy Request). We aim to respond within one month.
1. Who is the controller
The controller of personal data processed through the Services is:
Petr Jaroch (trading as DotCheck)
IČO: 03330389
Registered place of business: Jeníkovice 2, 535 01 Přelouč, Czech Republic
Legal form: Natural person entrepreneur under the Czech Trade Licensing Act (živnostenský zákon)
Trade licensing authority: Městský úřad Přelouč
Public registers: ARES / živnostenský rejstřík (IČO 03330389)
Email: contact@dotcheck.ai
Petr Jaroch is a natural person entrepreneur registered in the Czech Republic (first trade authorisation dated 25 August 2014).
Lead supervisory authority: Úřad pro ochranu osobních údajů (ÚOOÚ), Czech Republic, uoou.gov.cz. You may also complain to the supervisory authority in your EU/EEA Member State of habitual residence, place of work, or place of the alleged infringement.
2. What this policy covers
This policy applies to personal data we process as controller when you:
- browse or use the marketing site and tools (including Check), or call the Pro API with a key you created;
- install or use the Chrome extension;
- create or use a Firebase account (for example Google sign-in);
- subscribe via Stripe (Premium / Pro);
- contact us (for example via the contact form or email);
- request a Pro “confirm” retest or create a Share photo or clip.
It does not govern third-party websites you visit while browsing with the extension installed, except for the limited content you send us for scoring.
3. What personal data we process
Depending on how you use the Services, we may process the following categories:
Short version: we process what is needed to score content submitted for analysis, run accounts and billing, prevent abuse, and avoid re-scoring identical content with a hash cache. We do not process browsing for advertising.
| Category | Examples | Source |
|---|---|---|
| Account & identity | Firebase Auth UID; email and basic profile fields from your sign-in provider (e.g. Google); subscription tier | You / identity provider |
| Billing identifiers | Stripe customer and subscription IDs; plan and billing interval (we do not store full card numbers) | You / Stripe |
| Content for analysis | Image bytes; video frames or MP4 uploads (within product limits); text snippets; PDF/DOCX/TXT/PPTX you submit for scoring; standalone audio files you upload; short (~4 s) tab-audio windows captured in the extension only on click or play (never continuous microphone listening) | You |
| Derived scores & cache keys | AI-likelihood probability; content hash + engine id used to avoid re-scoring; optional Share job metadata | Generated by us |
| Score feedback (optional) | Thumbs up/down on a score you were shown, keyed to a content hash (not a browsing history) | You |
| Usage & abuse controls | Daily analysis counts; Share counts; Pro confirm counts; one-way hash of IP (with a secret salt) when you are not signed in | Generated by us / network |
| Public site page opens | Counts of which DotCheck pages were opened; a one-way salted hash of IP used only to estimate unique visitors per day (not a lasting identity) | Generated by us / network |
| History (Premium+) | Metadata rows (kind, score label, date) from intentional Check or popup drops, not a permanent media gallery and not automatic browse logging | Generated after your scores |
| Device / extension settings | Local preferences and local cache keys in Chrome storage (primarily on your device) | You / device |
| Support messages | Name, email, message content you send via contact form or email | You |
| Technical logs | Limited server logs needed for security and reliability (e.g. timestamps, error codes, approximate request metadata) | Generated by us |
What we do not collect as a product: full browsing history, full page HTML dumps, continuous microphone capture, advertising profiles, or sale of personal data to data brokers. On Premium and Pro, when live tab soundtrack is on, tab audio is captured only in a short window after you click or play. Free never captures tab audio. Automatic browsing does not capture tab audio.
Sensitive content: Please do not upload special-category data (for example health records, biometric templates for identification, or children’s data) unless you have a lawful reason and accept that scoring may process those bytes transiently. We do not ask for such data.
4. Purposes and legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide scoring you request (extension, Check, documents, optional score feedback) | Art. 6(1)(b): performance of a contract / steps at your request |
| Account, Premium/Pro subscription, billing portal | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for tax/accounting records where applicable |
| Fair-use limits, Pro confirm caps, rate limiting, abuse prevention | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (secure, fair service) |
| Hash-based analysis cache (avoid re-scoring identical content) | Art. 6(1)(f) legitimate interests (efficiency and cost control; not a personal browsing diary) |
| Pro explicit confirm (Sightengine / Winston) when you click confirm | Art. 6(1)(b) contract for Pro features |
| Share photo or clip render when you request it | Art. 6(1)(b) contract |
| Respond to support / privacy requests | Art. 6(1)(b) or (f); Art. 6(1)(c) when complying with data-protection law |
| Service security, debugging, availability | Art. 6(1)(f) legitimate interests |
| Count public-site page opens so we can run the website | Art. 6(1)(f) legitimate interests |
| Non-essential cookies or marketing trackers (if we add them later) | Art. 6(1)(a) consent: we will ask first; none are required today for core use |
Where we rely on legitimate interests, you may object under Art. 21 (see §11). For essential security and abuse prevention, we may not be able to stop that processing while you continue using the Services.
5. How scoring and Pro confirm work
- Free and Premium: Everyday scoring uses DotCheck’s in-house image, video-frame, text, and audio models on infrastructure we operate or contract. Free and Premium never call Sightengine or Winston.
- Pro confirm: Only when you explicitly request a retest. Media confirms may use Sightengine; text/document confirms may use Winston AI. Document confirms may re-upload qualifying embedded images to Sightengine and qualifying text to Winston when you ask. Confirm is capped (see product plans) and does not replace the in-house score path for Free/Premium.
- Documents: When you score a PDF, DOCX, PPTX, or TXT, we process the upload then delete the temporary file. We do not keep the full document text in our database, only a short preview, score fields, and a flag that Confirm is available. Optional Save marked copy runs in your browser from the local file you still have; the server may return score geometry (
markSignal) with the score (and cache it by content hash), not a marked file. Marked downloads may show a short Checked by DotCheck.ai footer on the local copy. Pro Confirm re-uploads the file when you ask. - Models: Scoring runs on servers we operate or contract. The product path does not download model weights into your browser or install a local scorer on your machine.
- Hosting: Primary in-house analysis is intended to run in the Netherlands (EU). The controller is based in the Czech Republic. Some processors for API hosting, auth, and payments are still outside the EEA: see §6: §7. We will update this section when that map changes.
6. Recipients and processors
We use selected processors and service providers. They process data on our instructions, or as independent controllers for their own billing/auth layers where that is how the product is designed (notably Stripe and Google/Firebase Auth).
We do not sell your personal data. The table below lists who helps run the product.
| Party | Role | Typical location / notes |
|---|---|---|
| Heroku (Salesforce) | Hosts the Express API (current production) | Often US / non-EEA; we prefer migrating toward EU hosting where practical |
| DotCheck inference host | In-house image, video-frame, text, and audio scoring; Share render where configured | Netherlands (EU); operator-controlled |
| MongoDB Atlas | Analysis cache, usage counters, History | Cluster region as configured; we prefer EU regions |
| Google Firebase / Google Cloud | Authentication, Firestore tier/billing ids; client SDKs | May involve transfers outside EEA; Google SCCs / frameworks apply |
| Stripe | Payments, subscriptions, customer portal | Payment processor; card data handled by Stripe |
| Sightengine | Pro explicit media confirm only | Content sent only on your confirm action |
| Winston AI | Pro explicit text/document confirm only | Content sent only on your confirm action |
| GoDaddy | Static marketing website hosting | Hosting provider for site files |
| Web3Forms | Contact form delivery | Message relay for support mail |
| Google Fonts / gstatic (technical) | Font and Firebase script delivery if loaded from Google CDNs | May involve IP transfer to Google when pages load |
We may disclose data if required by EU/Czech law or to establish, exercise, or defend legal claims.
7. International transfers
Because some providers are headquartered or process outside the EEA (for example the United States), personal data may be transferred internationally.
Where GDPR Chapter V applies, we rely on appropriate safeguards used by those providers: typically the European Commission’s Standard Contractual Clauses (SCCs), and where applicable an adequacy decision (including the EU: US Data Privacy Framework for certified organisations). You may ask us at contact@dotcheck.ai for pointers to the relevant provider documentation.
Our product direction is to keep primary scoring infrastructure in the EU. Until every layer is EU-resident, this section remains accurate and will be updated when hosting changes.
8. Retention
- Upload temps: Deleted after scoring or shortly thereafter (fail-closed cleanup).
- Share jobs / clips: Short-lived storage for render and download; not a permanent personal gallery.
- Analysis cache: Rows keyed by content hash + engine may be kept (typically on the order of about 30 days for successful scores) to avoid re-scoring identical content. When the Chrome extension scores result content on a known AI studio page, the shared cache may store a lasting AI-environment product score (100% AI) plus the underlying model reading for audit. Image rows may also keep a cleaned media URL for lookup. This is not a personal history of everything you browse, and it can outlive account deletion. We do not use your media to train models.
- Usage counters: Daily / monthly aggregates for plan limits, Shares, and Pro confirms (UTC periods).
- History (Premium+): Metadata until you delete entries or close the account, subject to backup/legal limits.
- Idle Free accounts: Free accounts that stay inactive for about 30 days may be removed so we do not keep dormant Free profiles. Paid Premium and Pro accounts are not removed for inactivity under this rule. After removal, signing in with Google again creates a new Free account.
- Account & Firestore fields: While the account/subscription is active. Signed-in users can delete the account from Check; that cancels an active Stripe subscription immediately, then removes Auth, Firestore profile data, and account-tied usage/history/keys. Shared analysis-cache rows stay (see above).
- Billing: Stripe and we may retain invoices and payment records as required by tax and accounting law (often several years).
- Support / operator mail: Kept as business correspondence as long as needed to resolve your request, then ordinary email retention / deletion practice.
- Security logs: Short to medium term, then rotated.
- Public site page opens: Daily aggregates kept for operator statistics. Per-day visitor hashes are short-lived and then discarded.
9. Cookies and similar technologies
The Chrome extension does not use advertising cookies.
The website uses technologies needed to run the service (for example session/auth persistence for Firebase when you sign in). We do not run marketing or advertising trackers. Counting opens of our own pages uses a first-party request and does not use a cookie; we honor Global Privacy Control and Do Not Track when the browser sends them.
If we introduce non-essential cookies or similar tracking, we will provide a clear notice and obtain consent where required by the ePrivacy rules and GDPR.
Loading fonts or scripts from third-party CDNs may expose your IP address to those providers (see §6).
10. Security
We apply technical and organisational measures matched to the data we handle. In practice that includes:
- HTTPS/TLS for product traffic where the Services use HTTPS;
- access-controlled cloud accounts and least-privilege credentials;
- preferring content hashes and cache keys over full payloads in operational logs;
- one-way hashes of IP addresses (with a secret salt) for signed-out daily limits and for estimating unique public-site visitors per day (not a public identity);
- deletion of temporary upload files after processing (fail-closed cleanup);
- keeping Free/Premium everyday scoring on in-house paths so third-party detectors are not a silent default.
No method is perfectly secure. Please use a strong account with your identity provider, and do not upload content you are not allowed to process.
11. Your rights
If GDPR applies to you, you may have the right to:
- Access: confirmation and a copy of personal data we hold about you;
- Rectification: correct inaccurate data;
- Erasure: request deletion (“right to be forgotten”) where a ground in Art. 17 applies;
- Restriction: limit processing in cases set out in Art. 18;
- Portability: receive data you provided in a structured, commonly used, machine-readable format where Art. 20 applies;
- Object: object to processing based on legitimate interests (Art. 21);
- Withdraw consent: where processing is consent-based, without affecting prior lawful processing;
- Complain: to a supervisory authority (see §15).
Signed-in users can erase the account from Check (Delete my account). That cancels an active subscription immediately and removes account-tied data as described in §8. You may also email contact@dotcheck.ai with subject Privacy Request for access, correction, or other rights. We may need to verify your identity. We aim to respond within one month (extendable by two further months for complex requests, with notice).
Some data (for example Stripe invoices, shared content-hash score cache, operator mail, or security logs) may be retained where law requires, where the cache is not tied to your account, or where erasure would impair security of the Services.
12. Children
The Services are not directed at children. We do not knowingly collect personal data from children under 13. Where EU rules on digital consent for information-society services apply, Member States set ages between 13 and 16 (Czechia: generally 15 for that specific consent context). Our Terms also set higher contractual age rules for creating paid accounts. If you believe a child has provided us data, contact us and we will delete it where required.
13. Automated processing
DotCheck uses automated models to produce AI-likelihood scores. Those scores help you interpret content; they are not intended as solely automated decisions that produce legal effects or similarly significantly affect you within the meaning of GDPR Art. 22. Do not use DotCheck scores as the only basis for employment, credit, law-enforcement, or similar high-stakes decisions.
14. Changes
We will update this page when our processing, hosting, or legal details change. The “Last updated” date at the top will change. For material changes, we will take reasonable steps to inform you (for example a notice on the website or by email if we have your address). Where consent is required, we will ask again.
15. Contact and complaints
Petr Jaroch, trading as DotCheck
IČO: 03330389
Registered place of business: Jeníkovice 2, 535 01 Přelouč, Czech Republic
Email: contact@dotcheck.ai
You have the right to lodge a complaint with the Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, uoou.gov.cz, or with your local EU/EEA supervisory authority.