Privacy Policy
The short version
GAIC is designed to minimize collection. Text checks and the bundled image model run on your device, and the on-device result appears first. Image, video-frame, and screen-frame content stays on-device by default. On the web, an image up to 3 MiB is uploaded only when an active, server-verified GAIC Pro subscriber enables the separate cloud option for that check. Native media checks stay on-device in this release.
What we process
- Text checks and writing assist — analyzed and edited locally on your device. The writing workspace uses deterministic wording rules, stores no draft library, and does not send your original or suggested text to our servers.
- Image checks — the three bundled GAIC Image Forensics v3 pixel classifiers, camera metadata, and supported embedded Content Credentials are read locally. Photos and sampled video frames use a locked high-confidence rule: the primary and verifier must pass the base gate, then either one must reach its stronger cutoff or the web-robustness arbiter must independently confirm the ambiguous case. Screen checks use seven full-precision views and require the same strong primary-or-verifier evidence on a matching crop, or extreme broad agreement across the fixed views. The official Content Authenticity Initiative SDK checks the credential's manifest, signature, asset binding, validation state, and signer trust against a bundled checksum-pinned official trust-list snapshot. Remote-manifest fetching is disabled, and GAIC displays only controlled status categories rather than arbitrary manifest text. If the validator, local runtime, or trust list cannot complete a check, the result is unavailable rather than invalid. Optional cloud analysis is available only to a server-verified GAIC Pro web subscription after you tick its separate consent box for an image no larger than 3 MiB. Your local result is displayed before this work starts. Our API stores the temporary image payload only as AES-GCM-encrypted ciphertext accessible to the background job for up to 15 minutes. QStash receives an opaque job ID and limited orchestration metadata, not the image or the decryption key. The worker decrypts the payload only to send the image to our configured inference provider, which processes it to return the second model signal and may handle request data under its applicable service and retention terms. GAIC deletes the encrypted image payload promptly when the job completes or fails; bounded cleanup removes expired payload and owner-scoped, image-free status records. Deleting the owning account purges its remaining GAIC-controlled status, encrypted-payload, and lease records immediately.
- Video and screen checks — supported embedded video Content Credentials are checked locally before GAIC requests up to eight still frames spread across the video's full timeline. Only confirmed seeks are scored; audio and motion over time are not analyzed. A screen check watches a screen or window you explicitly choose for about four seconds, samples up to eight still frames from it, and stops sharing as soon as that window ends. No recording is written to a file — only transient frames exist, and they are discarded after scoring. These frames cannot enter the native cloud path and are not intentionally stored.
- Browser extension — if you install the GAIC Chrome extension, nothing is inspected until you open its popup and choose Scan this page. It then reads only the current tab’s hostname, title, and visible image, video, and canvas rectangles, captures the visible screenshot and an optional media crop, and scores them on your device with the same bundled image models. The screenshot, crop, page context, and result stay in the popup’s temporary memory and are discarded when the popup closes. The extension has no host permissions, background scanning, browsing-history access, storage, analytics, or network requests, and website content it reviews is never uploaded.
- Native shortcuts and sharing — iOS App Intents can open the scanner or accept one image or text value that you explicitly pass from Siri or Shortcuts. A content action opens GAIC and runs that one local check. Image input is capped at 8 MB, signature-checked, copied once into protected app cache, and deleted after handoff. A single-image HEIC/HEIF input is converted locally to a bounded JPEG derivative for the visual model; GAIC does not treat the derivative's missing Content Credentials or metadata as evidence about the original. Text is capped at 100,000 UTF-16 units and 256 KB and removed from the handoff cache immediately after reading. If you deliberately choose GAIC from Android's share sheet, the app accepts either plain text or one supported image and stages it for review without automatically checking it. Android shared images receive the same bounded signature check, one-shot private-cache copy, and deletion. Neither platform uses an accessibility service, overlay, or background screen observer.
- Usage counts — the free-tier counter enforces three checks per calendar week; every text, image, video, or screen check counts as one. You can use GAIC without an account, in which case the counter stays on your device. If you are signed in, the count is also kept against your account so it follows you across devices and is not reset by reinstalling. Only a number and the week it belongs to are stored — never what you checked or what the result was.
- Account — checking content does not require an account. A free GAIC account is required to buy or restore a subscription in the iOS or Android app so the store transaction can be validated for the correct account and restored on another client. If you create one we process your email address, and a password that is hashed and stored by our authentication provider — we never see or store your password ourselves. Choosing "Continue with Google" shares your email address with us from that provider. Accounts live in GAIC's own dedicated Supabase project, separate from our other apps, so a GAIC account is not linked to any other NIRO product. We use it only to sign you in, tie your allowance and any subscription to you, and contact you about your account. You can delete the account and its data at any time from Delete account in the account panel.
- Product analytics — The web, iOS, and Android checker can send privacy-minimal first-party product analytics to NIRO's service, but analytics stays off until you choose Allow in Privacy choices. Global Privacy Control or Do Not Track always overrides the local choice. Each product event contains only a one-time random event ID, a fixed event name and fixed broad mode or outcome, web/iOS/Android surface, major.minor app release, coarse operating-system family and major version, and broad device class. The service adds a country code derived from the hosting platform's connection header so the owner report can show country-level activity. This is approximate location; no precise location is collected, and the raw network address is not stored in the analytics event. A secret-keyed pseudonymous digest of the source address is used only for abuse limits; it stops being used after ten minutes, and bounded daily cleanup removes expired digest rows. The one-time event ID is retained for duplicate prevention for 24 hours and then removed by the same bounded cleanup. Daily aggregate event, country, operating-system, and broad-device counters are retained for 13 months. Up to three fixed JavaScript-or-promise error counts can be sent per use using those same coarse fields; no error name, message, stack, or raw error object is sent. The collector never receives submitted text or media, filenames, metadata, screen frames, model scores, results, receipts, account details, email, a page address or referrer, precise location, or a stable person, account, device, installation, or session identifier. These event records are not linked to a GAIC account and are used only to understand product use, reliability, protect the service from abuse, and identify which features need attention. The separate Mac desktop build keeps general analytics off. The clearly labelled web-only Also try rail also counts fixed aggregate referrals among GAIC, DeNiro Card, PicPlots, and SkyWrite; it never runs inside the iOS or Android apps.
Subscriptions & payments
- In the iOS app, GAIC Pro is billed by Apple through your Apple ID for unlimited on-device checks. A free GAIC account is required to buy or restore. Its account UUID is supplied to StoreKit as the purchase's account token; our validation service stores a one-way account reference and current lifecycle state so the entitlement is tied to the correct GAIC account. Eligible new subscribers can start with a 7-day free trial; after 7 days it renews monthly at the localized App Store price unless canceled before the trial ends. Apple collects and manages the payment account or card information required to start. We do not receive your full payment-card details. Manage or cancel in App Store account settings.
- In the macOS app, GAIC Pro is billed by Apple through your Apple ID. Eligible new subscribers can start with a 7-day free trial; after 7 days it renews monthly at the localized App Store price unless canceled before the trial ends. Apple collects and manages the payment account or card information required to start. The Mac App Store build does not offer or link to Stripe checkout. We do not receive your full payment-card details. Store transaction data is sent to our validation service to confirm the product and entitlement. Purchase, restore, manage, or cancel through the app and App Store account settings.
- In the Android app, GAIC Pro is billed by Google through your Google Play account for unlimited on-device checks. A free GAIC account is required to buy or restore. Its account UUID is supplied to Google Play as the obfuscated external account identifier; our validation service stores a one-way account reference and current lifecycle state so the entitlement is tied to the correct GAIC account. Eligible new subscribers can start with a 7-day free trial; after 7 days it renews monthly at the localized Google Play price unless canceled before the trial ends. Google collects and manages the payment account or card information required to start. We do not receive your full payment-card details. Manage or cancel in Google Play subscriptions.
- On the web, GAIC Pro is billed by Stripe. Creating a free account does not require a card, but Stripe collects card information before an eligible new subscriber starts the 7-day trial. After 7 days, Stripe charges $3.99 per month unless the subscriber cancels before the trial ends. Your full card details go to Stripe, not to us. We receive the Stripe customer, subscription, payment status, and transaction identifiers needed to activate, restore, secure, and manage access. While Pro is active, choose Manage Pro in the checker to update your card or cancel.
The native receipt-validation SDK is configured to send the store-signed transaction without its optional analytics, support, fraud-device, or tracking metadata. It does not attach an advertising ID, persistent device ID, device fingerprint, model, manufacturer, or operating-system details to NIRO's validation request.
Service logs, retention, and deletion
Hosting, security, queue, inference, billing, and app-store providers may create operational records such as request time, route, response status, IP address, device or user-agent information, opaque job identifiers, and transaction identifiers. They retain these records under their own security, fraud-prevention, accounting, service, and legal policies. QStash receives only opaque orchestration data for a cloud job; the configured inference provider receives the separately consented image.
- Clear GAIC site/app data or uninstall the app to remove the local usage counter and cached entitlement data. Android and iOS delete each temporary native-entry image after handoff and clear stale copies when the native bridge next starts.
- Use Privacy choices in the checker to change the locally saved analytics preference. Choosing No thanks stops future analytics even if storage is enabled in a later disclosed release.
- Leave the optional cloud box off to withhold consent for future uploads. A request already delivered to an inference provider cannot be recalled, although GAIC still applies the encrypted-payload deletion schedule above.
- Delete your account and its data — if you created a GAIC account, open the account panel and choose Delete account. Confirming permanently removes your account record, including your email address, stored weekly usage count, native iOS/Android entitlement state, and remaining GAIC-controlled cloud job and encrypted-payload records, from our systems. For a web subscription, deletion first cancels the Stripe subscription, expires any open GAIC Checkout Session, and removes the associated Stripe customer and payment details from GAIC's active billing account. Deletion does not cancel a subscription billed by Apple or Google, and mobile paid access cannot be restored to a deleted GAIC account. Cancel the native subscription in App Store or Google Play settings before deleting the account. Queue, inference, hosting, and billing providers may retain limited operational, transaction, accounting, fraud-prevention, security, service, or legal records under their own policies. This cannot be undone, and it does not require emailing us.
- GAIC has no saved-content library. For billing identifiers, an operational-log inquiry, or deletion of data we control where legally and technically possible, email support@gaicheck.com.
What we don't do
We don't sell submitted content, use it for advertising or cross-app tracking, or intentionally use it to train models. GAIC does not store cloud-uploaded images in plaintext: it keeps only the temporary encrypted payload described above, makes it accessible to the job for up to 15 minutes, deletes it on completion or failure, removes expired records through bounded cleanup, and keeps no saved-content library.
Children
GAIC is not directed to children under 13. Children under 13 should not use the service or submit personal information, text, images, video frames, or screen frames to its optional cloud feature. If you believe a child under 13 provided personal information to GAIC, email support@gaicheck.com so we can investigate and delete information we control where required, subject to identity verification and any legal retention obligation.
Contact
Questions? See Support or email support@gaicheck.com.
Last updated: August 24, 2026.