Website, iOS, selected media and account privacy

Privacy

Effective 15 September 2026. This notice describes the data practices of the current What Made It? website and iOS app.

Privacy summary

What Made It? processes only the file or evidence unit you choose for an analysis. Choosing a file does not upload it by itself. Upload begins only after you confirm the scan. We use the upload to validate the file, inspect available metadata and provenance information, run the selected detection service, prevent abuse and produce your private report.

We do not sell personal data, use it for cross-app tracking or advertising, or use customer uploads to train a What Made It? public model. When external detection is enabled, the selected media is disclosed to Hive, a third-party AI service, as explained below. Hive's own processing terms differ from our first-party retention and model-training practices, so please read the Hive disclosure before submitting media.

Image and selected-evidence uploads

The web service accepts selected JPEG, PNG and WebP images. The iOS app accepts JPEG, PNG, WebP, HEIC and HEIF images. Files are transferred over HTTPS after confirmation, and the service validates file type, signature, dimensions and size before analysis.

On iOS, a compatible copy may be created before upload when a HEIC or HEIF image must be converted or when an image must be resized or recompressed to meet the service limit. The app identifies this preparation before submission. Conversion can change pixels, compression, embedded metadata and Content Credentials. When no conversion is needed, the selected original file is uploaded and may include embedded camera, device, date or location metadata. What Made It? does not display precise embedded location in the report.

Signed-in accounts can use the PDF page Beta. The original PDF is parsed locally in the browser and is not uploaded. You choose up to five pages; the browser renders only those pages as bounded images, and those rendered page images are transferred for separate image analyses. What Made It? does not extract or fact-check document text. Browser rendering can change pixels, compression, metadata and Content Credentials.

Signed-in accounts can use the Office embedded-image Beta for standard DOCX and PPTX files. The original Office package, XML, body text, layout, charts, links and unselected images stay in the browser and are not uploaded. You explicitly select up to five embedded JPEG, PNG or WebP images; only those selected image copies are transferred for separate image analyses. Macro-enabled, externally linked, encrypted, malformed and unsupported packages are rejected rather than repaired or uploaded.

Signed-in accounts can use the bounded Video frame Beta. The original video remains in the browser. You explicitly choose up to five candidate moments and confirm the derived JPEG frames before they are uploaded as separate image analyses. Unselected moments and the original video are not transferred or retained, and a selected-frame result is not a verdict about the complete video.

Signed-in accounts can also use the bounded Audio clip Beta. The original recording remains in the browser. You explicitly choose and confirm one clip of up to 30 seconds; the browser standardizes it as 16 kHz mono PCM WAV before upload. What Made It? does not create a transcript, identify a speaker or create a voiceprint, and a selected-clip result is not a verdict about the complete recording.

The original image is stored in a private temporary object while processing is active; the same temporary handling applies to a selected rendered PDF page, selected Office embedded image, selected video frame or standardized audio clip. What Made It? deletes that object when analysis completes or is cancelled. An interrupted upload becomes eligible for cleanup after 15 minutes and is removed by subsequent cleanup activity.

Face data and images containing faces

What we collect. A photo you select, capture or import may contain a person's face. If you submit it, we process the visible facial pixels as part of the selected image, including any embedded metadata in an unchanged original. Choosing or previewing an image does not itself upload it. The iOS app does not access Face ID or TrueDepth face data, create a facial identity template, match a face to a person, or infer demographic or sensitive traits. AI-content detection does not establish anyone's identity.

Purpose and sharing. We process the image to validate the file, inspect technical metadata and Content Credentials, run AI-generated-content detection and display your report. Images containing faces follow the same processing route as other selected images: our service infrastructure processes the image, and Hive (Castle Global, Inc.) receives it for external AI detection. Cloudflare supplies our network, compute, private temporary object storage and report database. Technical verification may also run on our privately connected processing service in Germany. We do not send your account email or payment details to Hive with the image. Hive's additional processing purposes and international processing are described in Hive third-party AI disclosure; our own model-training statement does not override Hive's terms.

Permission on iOS. Before your first upload, the image review screen identifies Hive and the data being shared and provides “Agree & analyze” and “Cancel.” Agreeing permits this processing for subsequent images you explicitly submit on that device under the same disclosure. You can withdraw that permission in Account → Privacy & data handling. Withdrawal blocks future submissions until you agree again; it does not undo processing already requested. Material changes to the recipient or processing terms require renewed permission.

Server and provider retention. Facial pixels in our primary temporary image object are deleted when analysis completes or is cancelled. Interrupted uploads become eligible for cleanup after 15 minutes and are removed by subsequent cleanup activity, rather than at a guaranteed 15-minute deadline. Where a delivery relay is used, its private image URL normally expires after 90 seconds; the service requests deletion of its temporary delivery copy after use, and expired residual copies are removed by later cleanup activity. Temporary files used for technical verification are removed when that operation exits normally. Hive's published default retention is 14 days, with different periods possible by arrangement. URL expiry and deletion of our copies do not delete a copy already received by Hive.

Device storage and report retention. The iOS app temporarily stores the image locally while preparing your submission and removes that staged file after the server accepts it or when you select Cancel on the review screen. Residual staged files older than 24 hours are removed when the app's startup cleanup next runs. A file waiting in the system-share inbox stays locally until the app imports it or the app is removed. A protected, downsampled report preview may still show a face and remains on that device until you delete the report, complete account deletion on that device or remove the app. Signing out does not erase these local previews. Server reports contain technical results and file information rather than the original image and remain until deleted. App data may be included in device backups according to your system settings; deleting a live copy does not remove an older device backup or the original photo in your photo library.

Deletion, protection and contact. You can cancel an active analysis, delete its report or delete your account using the app's controls. These actions cover the copies held by What Made It? as described above, not copies already disclosed to Hive or retained in your own backups. We use HTTPS, private object storage, restricted report access and iOS file protection for local report-preview files. For a request involving an image already disclosed to Hive, contact support@whatmadeit.com; Hive also lists privacy@thehive.ai for privacy inquiries. Do not submit an image containing another person's personal information unless you have the rights and permissions required for this processing.

Service providers and data sharing

We disclose data only as needed to operate the requested feature, secure the service, authenticate an account, deliver account email or process a purchase. We do not authorize a provider to sell your data, use it for advertising or combine it with data from other apps for tracking. Providers must protect data under their contractual obligations and applicable law, use appropriate security and confidentiality controls, and support applicable deletion and privacy rights. Processing-specific terms and exceptions are disclosed here rather than hidden behind a general promise.

  • Cloudflare provides network delivery, security, Worker compute, private object storage and database infrastructure. It processes the uploaded evidence, report records, account and session data, network information and operational logs needed to provide and protect the service.
  • Hive (Castle Global, Inc.) provides external AI-generated-media detection when that processing is enabled. The exact selected image, rendered page, selected Office image, selected frame or standardized audio clip is made available to Hive for the requested scan. We do not send your What Made It? name, email address or payment details with that media.
  • Apple and Google receive the information needed for their sign-in service only when you choose that provider. Their handling is governed by their respective privacy notices.
  • Our transactional email service receives the destination email address and delivery metadata needed to send verification, password-reset and account-security messages.
  • Dodo Payments is the Merchant of Record for website purchases. Apple processes iOS subscriptions through the App Store. They process the account, transaction, billing, tax and support information necessary for the purchase.
  • Google Analytics processes optional public-website analytics only after you accept optional cookies. It is not integrated into private report, account, login or checkout pages, or into the iOS app.

Hive third-party AI disclosure

When the external-detector Beta is enabled for an image, rendered PDF page, selected Office image, selected video frame or standardized audio clip, Hive receives a private, unguessable media URL that normally expires after 90 seconds. On iOS, “Agree & analyze” grants permission before the first upload; later scans use that saved, versioned permission until you withdraw it. Each scan still requires you to submit the selected image. On the website, confirming the scan directs What Made It? to disclose the selected media to Hive. You can decline by cancelling before submission. The URL expiry prevents later access to the What Made It? temporary object; it does not control or prove deletion of a copy already obtained by Hive.

Hive states that its default policy is to retain customer data for 14 days and that retention can be reduced, including to zero, by arrangement. Under Hive's currently published self-service terms, customer-provided content may be used to provide, develop and improve Hive services and underlying technologies, and may be subject to manual review unless the parties agree otherwise in writing. Review can therefore involve authorized Hive personnel or workers. Hive operates from the United States and states that information may be processed in the United States or other countries.

Hive's published materials describe SOC 2 Type II controls, TLS encryption in transit, encryption at rest and configurable retention. Its processing is governed by the Hive Terms of Use, Hive Privacy Policy and Hive data-retention FAQ. Only submit media you are authorized to disclose to Hive. Do not submit regulated, privileged, biometric-identification, intimate or otherwise highly sensitive material.

Report data and retention

After What Made It? deletes the temporary media object, it keeps the analysis status, safe filename, format, dimensions or bounded audio profile, file size, integrity hash, timestamps, technical evidence report and internal reliability diagnostics. A report may include directional scores, threshold states, provider or model versions and evidence scope. These fields are model signals, not proof of authorship or intent.

PDF page collections also retain the safe PDF filename, page count, selected page numbers, render profile and links to each independent page report. Office collection history retains the safe DOCX or PPTX filename, file kind, a user-facing image location such as “Image 01” or “Slide 2, image 1,” parser profile and links to each selected-image report. It does not retain document text, layout, unselected images, internal package paths or relationship URLs.

Video collection history retains safe display metadata, selected timestamps, frame profile and links to each selected-frame result. Audio collection history retains safe display metadata, bounded clip timing and profile, and directional provider evidence. It does not retain the original recording, a transcript or a voiceprint. Selected-evidence results are not extended to the whole document, video or recording.

PDF, Office, Video and Audio collections require a signed-in account. Reports remain private and are retained until you delete them or close the associated account. Guest image reports remain associated with the guest session rather than a public identity. Web guest sessions can remain valid for up to one year unless the cookie is cleared. iOS guest sessions use a revocable credential with a refresh lifetime of up to 30 days; the app may keep protected local report previews on the device so recent reports remain available after sign-out.

Daily usage records are removed after 32 days. A separate abuse-prevention counter uses an HMAC-pseudonymized Cloudflare network address, does not store the raw address in that counter and is removed after eight days. Authentication sessions are kept until they expire, are revoked or the account is deleted. Purchase providers may retain transaction, invoice, refund and tax records for the periods required by law and their own policies. Hive retention is described separately above.

Identity, guest access and subscriptions

Free use does not require an account. The website stores a signed, HttpOnly guest-session cookie. The iOS app stores its guest-session credential and free-usage identity in the Keychain so reinstalling, signing out or switching account state does not create a new free allowance. These credentials are used for session continuity, quota enforcement, report ownership, security and abuse prevention; they are not advertising identifiers.

If you create or use an account, the service stores the name and email you provide, a one-way password hash for email sign-in, account-provider identifiers, session records that may include network address and user-agent data, and subscription entitlement metadata. Email registration requires address verification; verification and password-reset links expire after 60 minutes, and a password reset revokes existing sessions. Apple or Google sign-in is used only when you select it.

Subscription entitlement is separate from sign-in state on iOS. Signing out does not cancel an App Store subscription. What Made It? receives App Store-signed transaction, renewal, product, status, account-link token and entitlement dates needed to verify and operate access; it does not receive App Store payment credentials. For website checkout, Dodo receives the account and transaction information needed for billing, tax, refunds and payment support. What Made It? does not receive or store complete card details.

Analytics and diagnostics

On public website pages, What Made It? offers optional Google Analytics 4 measurement to understand aggregate page usage. The Google tag is not requested and no analytics event is sent until you select “Accept optional cookies.” When allowed, Google Analytics may use first-party _ga cookies and receive the public page path, page title, browser and device information, approximate location derived from the network address, referral information and timestamps. Query strings, report identifiers, uploaded file details, account pages, login pages and checkout pages are excluded.

With the same optional choice, the website can keep first-party daily totals for a small approved campaign list and finite funnel events such as selecting a file, accepted analysis, result state, upgrade click and confirmed paid access. These totals contain only a date, campaign label, event label and count. They do not contain a file, filename, report identifier, user identifier, account identifier or object key.

Advertising storage, Google Signals and ad-personalization signals are disabled. Google processes permitted analytics data under its Privacy Policy. Declining leaves the Google tag unloaded. Withdrawing consent stops future analytics collection and removes accessible Google Analytics cookies for this site.

The iOS app does not contain Google Analytics, advertising SDKs or cross-app tracking. Apple MetricKit diagnostic payloads, when made available by iOS, are stored only in the app's local cache for troubleshooting and are not uploaded by What Made It?. Ordinary server requests still create limited security and operational logs such as time, route, response status, request identifier and network information.

Your choices and deletion controls

You may close the confirmation without uploading, cancel active analysis, delete a completed image report, delete a PDF page or Office embedded-image collection together with its child reports, or delete a video or audio collection with its child reports. Website users can clear the guest-session cookie through browser controls. iOS users can remove local report previews from the app; deleting the app removes its local files, although Keychain credentials can survive reinstall as an anti-abuse and continuity measure.

Signing out ends account access on that device but does not delete the account, cancel a subscription, erase reports or reset a free allowance. Signed-in users can request permanent account deletion from Account. You may delete immediately even while a paid subscription is active, or explicitly schedule deletion for the end of the current paid period.

Completed account deletion removes the account, sessions, reports, PDF page collections, Office embedded-image collections, video and audio collections, stored usage and local entitlement cache held by What Made It?. It also revokes What Made It? access to linked sign-in credentials where supported. Data already disclosed to a provider remains subject to that provider's retention and legal obligations. Account deletion does not cancel an App Store subscription, which must be managed separately in App Store settings.

You can withdraw optional website analytics consent at any time below. On iOS, withdraw future Hive-sharing permission in Account → Privacy & data handling; on the website, do not submit another scan. In either case, deleting a report removes the What Made It? report but cannot recall media during Hive's stated retention period. For access, correction, deletion or privacy support, email support@whatmadeit.com. We may need to verify control of the account before acting on a request.

Security, international processing and legal requests

What Made It? uses HTTPS, private object storage, signed and time-limited provider URLs, access-controlled report ownership, hashed passwords and tokens, and data-minimization checks. No internet service can guarantee absolute security. If we learn of a breach requiring notice, we will notify affected users and authorities as required by applicable law.

What Made It? and its providers may process data in the United States and other countries where they operate. Those countries may have different privacy laws. We use provider contracts, technical safeguards and applicable transfer mechanisms to protect data during such processing.

We may preserve or disclose limited data when reasonably necessary to comply with law, respond to valid legal process, protect users and the service, investigate fraud or security incidents, or establish and defend legal claims. We retain such data only for the period required for that purpose.

Service limits, children and contact

The service does not claim a universally valid accuracy percentage and should not be used as the sole basis for legal, employment, education, insurance, credit or other high-impact decisions. An assessment is not proof of authorship, identity, intent or truth.

What Made It? is not directed to children under 13, and we do not knowingly collect personal data from a child under 13. If you believe a child has provided personal data, contact us so we can investigate and delete it. Users must also comply with any higher minimum age or parental-consent rule that applies where they live.

We may update this notice when the product, provider terms or law changes. Material changes will be identified by a new effective date and, when appropriate, an in-product notice or renewed choice. Questions, privacy requests and security reports can be sent to support@whatmadeit.com.