Privacy Policy

Last updated: 3 August 2026

This Privacy Policy explains how DotCheck processes personal data for the Chrome extension, the website at dotcheck.ai, and related APIs (together, the “Services”). It is written for the EU GDPR and aligned Czech law. The summary below is for convenience. The numbered sections that follow are controlling.

Summary

DotCheck scores how AI-like images, video frames, text, and audio look or sound. Processing is limited to what the Services need to provide that score, run accounts and billing, prevent abuse, and avoid re-scoring identical content.

The numbered sections set out categories of data, purposes and legal bases, recipients, retention, security, and your rights.

DotCheck estimates how AI-like images, video frames, text, and audio look or sound. Scores are probabilistic estimates, not guarantees of authenticity and not a substitute for human judgment. Text scoring supports English, Chinese, Spanish, French, Portuguese, German, Italian, and Dutch. Other languages are not scored yet.

Privacy contact / DSARs: contact@dotcheck.ai (subject line: Privacy Request). We aim to respond within one month.

1. Who is the controller

The controller of personal data processed through the Services is:

Petr Jaroch (trading as DotCheck)
IČO: 03330389
Registered place of business: Jeníkovice 2, 535 01 Přelouč, Czech Republic
Legal form: Natural person entrepreneur under the Czech Trade Licensing Act (živnostenský zákon)
Trade licensing authority: Městský úřad Přelouč
Public registers: ARES / živnostenský rejstřík (IČO 03330389)
Email: contact@dotcheck.ai

Petr Jaroch is a natural person entrepreneur registered in the Czech Republic (first trade authorisation dated 25 August 2014).

Lead supervisory authority: Úřad pro ochranu osobních údajů (ÚOOÚ), Czech Republic, uoou.gov.cz. You may also complain to the supervisory authority in your EU/EEA Member State of habitual residence, place of work, or place of the alleged infringement.

2. What this policy covers

This policy applies to personal data we process as controller when you:

It does not govern third-party websites you visit while browsing with the extension installed, except for the limited content you send us for scoring.

3. What personal data we process

Depending on how you use the Services, we may process the following categories:

Short version: we process what is needed to score content submitted for analysis, run accounts and billing, prevent abuse, and avoid re-scoring identical content with a hash cache. We do not process browsing for advertising.

CategoryExamplesSource
Account & identity Firebase Auth UID; email and basic profile fields from your sign-in provider (e.g. Google); subscription tier You / identity provider
Billing identifiers Stripe customer and subscription IDs; plan and billing interval (we do not store full card numbers) You / Stripe
Content for analysis Image bytes; video frames or MP4 uploads (within product limits); text snippets; PDF/DOCX/TXT/PPTX you submit for scoring; standalone audio files you upload; short (~4 s) tab-audio windows captured in the extension only on click or play (never continuous microphone listening) You
Derived scores & cache keys AI-likelihood probability; content hash + engine id used to avoid re-scoring; optional Share job metadata Generated by us
Score feedback (optional) Thumbs up/down on a score you were shown, keyed to a content hash (not a browsing history) You
Usage & abuse controls Daily analysis counts; Share counts; Pro confirm counts; one-way hash of IP (with a secret salt) when you are not signed in Generated by us / network
Public site page opens Counts of which DotCheck pages were opened; a one-way salted hash of IP used only to estimate unique visitors per day (not a lasting identity) Generated by us / network
History (Premium+) Metadata rows (kind, score label, date) from intentional Check or popup drops, not a permanent media gallery and not automatic browse logging Generated after your scores
Device / extension settings Local preferences and local cache keys in Chrome storage (primarily on your device) You / device
Support messages Name, email, message content you send via contact form or email You
Technical logs Limited server logs needed for security and reliability (e.g. timestamps, error codes, approximate request metadata) Generated by us

What we do not collect as a product: full browsing history, full page HTML dumps, continuous microphone capture, advertising profiles, or sale of personal data to data brokers. On Premium and Pro, when live tab soundtrack is on, tab audio is captured only in a short window after you click or play. Free never captures tab audio. Automatic browsing does not capture tab audio.

Sensitive content: Please do not upload special-category data (for example health records, biometric templates for identification, or children’s data) unless you have a lawful reason and accept that scoring may process those bytes transiently. We do not ask for such data.

4. Purposes and legal bases (GDPR Art. 6)

PurposeLegal basis
Provide scoring you request (extension, Check, documents, optional score feedback) Art. 6(1)(b): performance of a contract / steps at your request
Account, Premium/Pro subscription, billing portal Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for tax/accounting records where applicable
Fair-use limits, Pro confirm caps, rate limiting, abuse prevention Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (secure, fair service)
Hash-based analysis cache (avoid re-scoring identical content) Art. 6(1)(f) legitimate interests (efficiency and cost control; not a personal browsing diary)
Pro explicit confirm (Sightengine / Winston) when you click confirm Art. 6(1)(b) contract for Pro features
Share photo or clip render when you request it Art. 6(1)(b) contract
Respond to support / privacy requests Art. 6(1)(b) or (f); Art. 6(1)(c) when complying with data-protection law
Service security, debugging, availability Art. 6(1)(f) legitimate interests
Count public-site page opens so we can run the website Art. 6(1)(f) legitimate interests
Non-essential cookies or marketing trackers (if we add them later) Art. 6(1)(a) consent: we will ask first; none are required today for core use

Where we rely on legitimate interests, you may object under Art. 21 (see §11). For essential security and abuse prevention, we may not be able to stop that processing while you continue using the Services.

5. How scoring and Pro confirm work

6. Recipients and processors

We use selected processors and service providers. They process data on our instructions, or as independent controllers for their own billing/auth layers where that is how the product is designed (notably Stripe and Google/Firebase Auth).

We do not sell your personal data. The table below lists who helps run the product.

PartyRoleTypical location / notes
Heroku (Salesforce) Hosts the Express API (current production) Often US / non-EEA; we prefer migrating toward EU hosting where practical
DotCheck inference host In-house image, video-frame, text, and audio scoring; Share render where configured Netherlands (EU); operator-controlled
MongoDB Atlas Analysis cache, usage counters, History Cluster region as configured; we prefer EU regions
Google Firebase / Google Cloud Authentication, Firestore tier/billing ids; client SDKs May involve transfers outside EEA; Google SCCs / frameworks apply
Stripe Payments, subscriptions, customer portal Payment processor; card data handled by Stripe
Sightengine Pro explicit media confirm only Content sent only on your confirm action
Winston AI Pro explicit text/document confirm only Content sent only on your confirm action
GoDaddy Static marketing website hosting Hosting provider for site files
Web3Forms Contact form delivery Message relay for support mail
Google Fonts / gstatic (technical) Font and Firebase script delivery if loaded from Google CDNs May involve IP transfer to Google when pages load

We may disclose data if required by EU/Czech law or to establish, exercise, or defend legal claims.

7. International transfers

Because some providers are headquartered or process outside the EEA (for example the United States), personal data may be transferred internationally.

Where GDPR Chapter V applies, we rely on appropriate safeguards used by those providers: typically the European Commission’s Standard Contractual Clauses (SCCs), and where applicable an adequacy decision (including the EU: US Data Privacy Framework for certified organisations). You may ask us at contact@dotcheck.ai for pointers to the relevant provider documentation.

Our product direction is to keep primary scoring infrastructure in the EU. Until every layer is EU-resident, this section remains accurate and will be updated when hosting changes.

8. Retention

9. Cookies and similar technologies

The Chrome extension does not use advertising cookies.

The website uses technologies needed to run the service (for example session/auth persistence for Firebase when you sign in). We do not run marketing or advertising trackers. Counting opens of our own pages uses a first-party request and does not use a cookie; we honor Global Privacy Control and Do Not Track when the browser sends them.

If we introduce non-essential cookies or similar tracking, we will provide a clear notice and obtain consent where required by the ePrivacy rules and GDPR.

Loading fonts or scripts from third-party CDNs may expose your IP address to those providers (see §6).

10. Security

We apply technical and organisational measures matched to the data we handle. In practice that includes:

No method is perfectly secure. Please use a strong account with your identity provider, and do not upload content you are not allowed to process.

11. Your rights

If GDPR applies to you, you may have the right to:

Signed-in users can erase the account from Check (Delete my account). That cancels an active subscription immediately and removes account-tied data as described in §8. You may also email contact@dotcheck.ai with subject Privacy Request for access, correction, or other rights. We may need to verify your identity. We aim to respond within one month (extendable by two further months for complex requests, with notice).

Some data (for example Stripe invoices, shared content-hash score cache, operator mail, or security logs) may be retained where law requires, where the cache is not tied to your account, or where erasure would impair security of the Services.

12. Children

The Services are not directed at children. We do not knowingly collect personal data from children under 13. Where EU rules on digital consent for information-society services apply, Member States set ages between 13 and 16 (Czechia: generally 15 for that specific consent context). Our Terms also set higher contractual age rules for creating paid accounts. If you believe a child has provided us data, contact us and we will delete it where required.

13. Automated processing

DotCheck uses automated models to produce AI-likelihood scores. Those scores help you interpret content; they are not intended as solely automated decisions that produce legal effects or similarly significantly affect you within the meaning of GDPR Art. 22. Do not use DotCheck scores as the only basis for employment, credit, law-enforcement, or similar high-stakes decisions.

14. Changes

We will update this page when our processing, hosting, or legal details change. The “Last updated” date at the top will change. For material changes, we will take reasonable steps to inform you (for example a notice on the website or by email if we have your address). Where consent is required, we will ask again.

15. Contact and complaints

Petr Jaroch, trading as DotCheck
IČO: 03330389
Registered place of business: Jeníkovice 2, 535 01 Přelouč, Czech Republic
Email: contact@dotcheck.ai

You have the right to lodge a complaint with the Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, uoou.gov.cz, or with your local EU/EEA supervisory authority.