Privacy Policy

Last updated: April 2026

1. Who We Are

itsnotai is a digital art platform powered by itsnotai.org AI detection technology. "We", "us", or "itsnotai" refers to the platform operator.

2. What Data We Collect

  • Account data: username, email address, hashed password, display name, bio, website URL.
  • Uploaded content: artwork files and metadata (title, description, tags, category).
  • Interaction data: likes, comments, follows, direct messages.
  • Technical data: IP address (for rate-limiting only, not stored long-term).
  • Session data: an authentication cookie (HttpOnly, not readable by JavaScript) used to keep you signed in.

3. Legal Basis for Processing (GDPR)

  • Contractual necessity: account creation, authentication, content delivery.
  • Legitimate interests: platform security, spam prevention, abuse detection.
  • Consent: you explicitly accept these terms at registration.

4. How We Use Your Data

  • To provide and operate the platform.
  • To run AI detection on uploaded artwork via itsnotai.org detection engines.
  • To send transactional emails (verification, password reset). No marketing emails.
  • To enforce our Terms of Service.

5. Data Sharing

We do not sell your data. We share data only with:

  • AI detection endpoints (Hugging Face): uploaded images/videos are sent for analysis. No data is retained beyond the request.
  • Email provider (SMTP): to deliver transactional emails.

6. Data Retention

Your data is retained for as long as your account exists. On account deletion, all personal data is removed within 30 days. Anonymised aggregate statistics may be retained indefinitely.

7. Your Rights (GDPR)

  • Access: download a copy of your data at Settings → Export My Data.
  • Rectification: update your profile at any time.
  • Erasure: permanently delete your account at Settings → Delete Account.
  • Portability: export your data as JSON at Settings → Export My Data.
  • Objection / restriction: contact us at privacy@itsnotai.org.

8. Cookies

We use a single essential authentication cookie (refresh_token). It is HttpOnly, Strict SameSite, and expires after 7 days. No tracking or analytics cookies are used.

9. Children

The platform is not directed at children under 16. By registering, you confirm you are at least 16 years old.

10. Contact

For privacy questions: privacy@itsnotai.org