Standard image check
The original stays in browser memory. Metadata, visible text, faces and privacy-relevant devices are inspected on-device. Face detection locates people but never identifies them. The export is created locally.
This is the complete data path for every hide workflow, including the parts that leave your device.
The original stays in browser memory. Metadata, visible text, faces and privacy-relevant devices are inspected on-device. Face detection locates people but never identifies them. The export is created locally.
An installed hide app keeps the shared image in a one-time device cache. It is deleted on first open or after ten minutes.
This is off by default. After explicit opt-in, each web check sends one reduced copy to the configured recognition provider and discards it after the response.
The identifiers you submit are sent to the named public services and connected search provider. Results and your review decisions are saved to your account.
Findings, verdicts and check summaries are stored. Evaluation contribution is separate and off by default; when enabled it keeps only category, source type, score and Correct or Wrong.
A campaign link stores the first content campaign connected to an account, its arrival time and completed-check counts. It never stores findings, submitted identifiers or image content.
Joining a team never shares images, identifiers, findings or source links. A creator can separately allow managers to see only check dates, aggregate activity counts and the number of items awaiting that creator’s review.
After an authorised external check, hide records only the service, outcome, operation counts, latency and time. It never records the image, query, identifier or response body. Records older than 90 days are purged when the next provider-health event is written.
Saved exposure records use Cloudflare D1. D1 automatically encrypts live databases, inactive databases and metadata at rest using AES-256 with GCM, while traffic between the application and database is protected with TLS.
Read the platform security specificationHide’s private evaluation runner measures identity-match precision, known-exposure recall, localization overlap, confidence calibration and time to result. It separates faces, text, documents, landmarks and direct or multi-source matching.
Report a reproducible security issue affecting hide. Test only with accounts and content you own or are authorised to use. Do not access other people’s data, degrade availability, or include passwords, API keys or unrelated personal information.
Each accepted submission receives a reference and is recorded for operator review. This intake is not an emergency channel and does not replace professional security review before public launch.
Sign in before submitting so the report has an accountable contact and private reference.
Sign in to report an issue