How does GenDetect currently handle content and access data?
No account is required. Local checks do not upload content. Full analysis sends text or media to the detection service only after explicit selection and consent to the disclosed processing. Google Analytics 4 measures page visits and usage without sending detection input as analytics parameters.
Current version
No account · Local by default · GA4 usage statistics
Last updated
01 · Detection content
Local checks stay in the browser; full analysis requires upload consent.
Local checks use page memory, browser media capabilities and provenance verification. Full analysis uploads only after explicit selection and consent. Detection input is not written to persistent browser storage.
Text stays in the page by default
Pasted text remains in the input and page memory while repetition, sentence length, punctuation, and character heuristics are calculated. Local mode does not upload text. Full analysis sends text to our API and, when needed, the disclosed Copyleaks service. We do not retain the original text; only results and task fingerprints are stored temporarily. Text is not written to localStorage or cookies. Refreshing or closing the page clears the page state.
Images are local by default and remote only by selection
The local heuristic uses the File API to inspect known generator metadata and a temporary object URL, image element, and Canvas for pixel signals without uploading the image. Full analysis uploads the original to our API and private inference service. When specialist review is needed and authorized, the image is forwarded to Sightengine. Legacy Gemini/Verify endpoints retain their own provider disclosures.
Video analysis samples frames and reads metadata locally
A browser media element, temporary object URL, and Canvas sample static frames near 20%, 50%, and 80% while reading duration, resolution, file size, MIME type, and extension. Local mode does not upload the video. Full analysis uploads the original video, potentially including audio, to our storage and private processing service. Only extracted frames may be forwarded to Sightengine; audio is not analyzed or sent to that provider. File removal, replacement, or the end of the page session invalidates the temporary browser reference.
02 · Browser and network
Preferences, usage statistics, and page requests exclude detection input.
GenDetect itself stores only a theme preference. Google Analytics 4 may use cookies or local identifiers for usage statistics. Analytics events exclude detection input; text or media is uploaded only after full analysis is selected and consented to.
GenDetect persists only the theme; GA4 may set analytics cookies
GenDetect stores only gendetect-theme in localStorage and does not persist the image mode, detection content, filename, or score. Google Analytics 4 may use cookies or local identifiers to distinguish browsers and sessions. These values can be removed through browser site-data settings.
Cloudflare handles ordinary request metadata
To return HTML, CSS, scripts, fonts, and icons, Cloudflare may process an IP address, User-Agent, requested URL, timestamp, response status, and security diagnostics. Infrastructure-log retention is controlled by the Cloudflare service. These page requests do not carry detection input.
Google Analytics 4 measures visits without reading detection input
The site uses Google Analytics 4 (measurement ID G-2M0XZ9X6Y1) to measure page URLs, referrers, browser and device information, approximate geography, and usage events enabled by the GA4 property. Google may receive request data such as an IP address and use cookies or local identifiers. GenDetect does not send pasted text or selected images and videos as analytics event parameters. Remote checks still load Cloudflare Turnstile on demand.
Local content has no backend copy; remote media and results have defined retention.
Local processing reduces the paths by which content leaves the device. Remote media is deleted after completion, with a one-day lifecycle backstop for interrupted uploads. Full-analysis results become inaccessible after 24 hours and their content is cleared within the following hour. Budget records and task fingerprints without original text remain for at most 30 days.
Remote content is processed only for the selected job
The same-origin API stores media privately under a high-entropy task ID and deletes it after completion. Necessary metadata, results, input fingerprints and budget reservations follow the retention schedule above. Original text is not written to logs or result caches. GenDetect does not use them for training, sales, advertising, or account history.
Specialist detection is handled by disclosed providers
Full analysis may send text to Copyleaks and images or sampled video frames to Sightengine. Provider names and privacy links are shown before submission. Legacy Gemini/Verify disclosures still apply to their legacy tasks. Each provider handles its copy, logs, and retention under its own policy, outside GenDetect’s deletion schedule. Review the policies shown in the interface before using sensitive images.
Page state ends with the browser session
Text, results, and selected-file references primarily exist in current page memory. Clearing the input, removing a file, refreshing, or closing the page ends the corresponding state. Browser history, cache, crash recovery, or form restoration remain subject to your browser settings.
Sensitive material still needs device-level protection
Before opening unpublished work, personal media, or confidential material on a shared or managed device, review screen sharing, extension permissions, download locations, and local-account isolation. No local web page can prevent software with device access from reading the screen or memory.
04 · Future changes
Disclosure must change before adding a provider, account, or cloud history.
Configurable full analysis is implemented. A new provider, account, or cloud-history feature would change the data flow again and must state purpose, recipients, retention, security, and user controls before launch.
Any new processor must name its purpose and recipients
Before adding a first-party processing path or third-party provider, the interface must explain which fields or files leave the device, what recognition or processing purpose applies, who provides the service, whether data supports training, and what happens after failure or cancellation.
Account features must define identity and retention rules
If login, history, or long-lived cloud tasks are introduced, the notice must list account identifiers, stored content, result history, access controls, deletion methods, and a defined retention period. The current no-account and local-default statement cannot automatically cover capabilities that do not yet exist.
Use the page date and implemented code as the reference
This notice describes the current front-end implementation on the displayed last-updated date; it is not a retroactive promise about every browser, Cloudflare, or future service. Supplier or capability changes require updated copy, methodology, interface notices, and verification against actual network requests.