Image, document, selected media and account privacy

Privacy

Effective 5 September 2026. This page describes the processing behavior implemented in the current What Made It? service configuration.

Image and selected-evidence uploads

Selected JPEG, PNG and WebP files are transferred to the What Made It? application over HTTPS. The service validates file type, signature, dimensions and size before analysis.

Signed-in accounts can use the PDF page Beta. The original PDF is parsed locally in your browser and is not uploaded. You choose up to five pages; the browser renders only those pages as bounded images, and those rendered page images are transferred for separate image analyses. What Made It? does not extract or fact-check document text. Browser rendering can change pixels, compression, metadata and Content Credentials.

Signed-in accounts can use the Office embedded-image Beta for standard DOCX and PPTX files. The original Office package, XML, body text, layout, charts, links and unselected images stay in the browser and are not uploaded. You explicitly select up to five embedded JPEG, PNG or WebP images; only those selected image copies are transferred for separate image analyses. Macro-enabled, externally linked, encrypted, malformed and unsupported packages are rejected rather than repaired or uploaded.

Signed-in accounts can use the bounded Video frame Beta. The original video remains in the browser. You explicitly choose up to five candidate moments and confirm the derived JPEG frames before they are uploaded as separate image analyses. Unselected moments and the original video are not transferred or retained, and a selected-frame result is not a verdict about the complete video.

Signed-in accounts can also use the bounded Audio clip Beta. The original recording remains in the browser. You explicitly choose and confirm one clip of up to 30 seconds; the browser standardizes it as 16 kHz mono PCM WAV before upload. The derived WAV is kept temporarily in private object storage and made available to Hive through a short-lived signed URL for analysis. What Made It? does not create a transcript, identify a speaker or create a voiceprint, and a selected-clip result is not a verdict about the complete recording.

The original image is stored in a private temporary object while processing is active; the same temporary handling applies to a selected rendered PDF page, selected Office embedded image, selected video frame or standardized audio clip. It is deleted when analysis completes or is cancelled. Interrupted uploads are marked for deletion after 15 minutes and are also checked during later API activity.

When the external-detector Beta is enabled for an image, rendered PDF page, selected Office image, selected video frame or standardized audio clip, Hive receives a private, unguessable media URL that normally expires after 90 seconds. When the external-processing controls are disabled, Hive is skipped. Provider processing is subject to its own service and data-processing controls. Do not upload regulated, privileged, biometric, intimate or otherwise sensitive material.

Report data

After the original image, rendered page image, selected Office image, selected video frame or standardized audio clip is deleted, What Made It? keeps the analysis status, safe filename, format, dimensions or bounded audio profile, file size, integrity hash, timestamps, technical evidence report and internal Shadow Mode diagnostics. A report may include deterministic explanation fields for each available channel: a directional 0–100 signal strength, threshold state, model version and evidence scope. These fields are not a probability of AI authorship. PDF page collections also retain the safe PDF filename, page count, selected page numbers, render profile and links to each independent page report.

Office collection history retains the safe DOCX or PPTX filename, file kind, stable user-facing image location such as “Image 01” or “Slide 2, image 1,” parser profile and links to each independent selected-image report. It does not retain the original package, document text, layout, unselected images, internal package paths or relationship URLs.

Video collection history retains safe display metadata, selected timestamps, the frame profile version and links to each independent selected-frame result. It does not retain the original video or unselected moments. Audio collection history retains safe display metadata, the bounded clip timing and profile, and directional provider evidence for the selected clip; it does not retain the original recording, a transcript or a voiceprint. PDF page, Office embedded-image, Video frame and Audio clip explanations stay scoped to the selected evidence unit. What Made It? does not create a whole-document, whole-video or whole-recording authenticity score.

Guest image reports are associated with the signed browser session and are not public. PDF, Office, Video and Audio collections require a signed-in account and are private to that account. You can delete an image report or an entire PDF, Office, video or audio collection from Recent reports.

Identity and accounts

Free use does not require an account. What Made It? stores a signed, HttpOnly guest-session cookie so the server can enforce the three-scans-per-UTC-day allowance and keep reports separated between browser sessions. Daily usage records are removed after 32 days. A separate abuse-prevention counter uses an HMAC-pseudonymized Cloudflare network address; that counter does not store the raw address and is removed after eight days.

If you create a paid account, the service stores the name and email you provide, a one-way password hash for email sign-in, account-provider identifiers, session records (which may include network address and user-agent data) and subscription entitlement metadata. Email registration requires address verification; verification and password-reset links expire after 60 minutes, and a password reset revokes existing sessions. The configured transactional email service receives the destination address and delivery metadata needed to send those security messages. Google sign-in is used only when you select it.

Dodo Payments is the hosted payment provider and Merchant of Record for paid plans. It receives the account and transaction information needed for checkout, billing, tax, refunds and payment support, including name, email, billing details and payment credentials. What Made It? does not receive or store complete card details; it stores provider customer and subscription identifiers, subscription status, plan, billing period and entitlement dates needed to operate the account.

Optional website analytics

On public pages, What Made It? offers optional Google Analytics 4 measurement to understand aggregate page usage. The Google tag is not requested and no analytics event is sent until you select “Accept optional cookies.” When allowed, Google Analytics may use first-party _ga cookies and receive the public page path, page title, browser and device information, approximate location derived from the network address, referral information and timestamps. Query strings, report identifiers, uploaded file details, account pages, login pages and checkout pages are excluded from this integration.

Advertising storage, Google Signals and ad-personalization signals are disabled in the site configuration. Google processes permitted analytics data under its own Privacy Policy. Your choice is stored in this browser and can be changed at any time. Declining leaves the Google tag unloaded; withdrawing consent disables future analytics collection and removes accessible Google Analytics cookies for this site.

Your controls

You may cancel active analysis, delete completed image report records, delete a PDF page or Office embedded-image collection together with its child reports, delete a video collection together with its selected-frame reports, delete an audio collection, clear the guest-session cookie through browser controls, or avoid processing sensitive material. Completed temporary image, rendered-page, selected-Office-image, selected-frame and standardized audio objects have already been deleted.

Signed-in users can request permanent account deletion from Account. If a subscription is active, the request waits until the hosted billing portal and a signed provider update confirm that the subscription has ended. Completion removes the account, sessions, reports, PDF page collections, Office embedded-image collections, video and audio collections, stored usage and local entitlement cache held by What Made It?. Dodo continues to retain hosted transaction, invoice, refund and tax records as required for financial, legal and support obligations; the account-deletion control does not alter those records.

To request access to paid-account data, obtain deletion support, or report a privacy or security concern, email support@whatmadeit.com. What Made It? may need to verify control of the account before acting on a request.

Current limits

The service does not claim an independently validated public accuracy percentage and should not be used for regulated, privileged, biometric or highly sensitive material. An assessment is not proof of authorship or intent.

What Made It? does not use uploaded files to train public models and does not sell report data. What Made It? cannot make an independent promise about a third-party detector’s retention, training or review practices beyond the provider controls applicable to the configured account.