Skip to content

truuimage · Legal

Privacy Policy

Last updated: 2026-08-14

1. Who we are

truuimage is operated by Resonix Labs Corporation, of 71 Fort Street, 3rd Floor, Grand Cayman, Cayman Islands KY1-9009 ("we", "us"). This policy describes what personal data we collect through the truuimage account console and API, why, and what you can do about it. For privacy or data-subject requests, contact privacy@resonixlabs.io.

2. What we collect

Account information. The name and email address you register with. Your password is never stored in plain text, it is hashed with Argon2id before being written to the database, and is not recoverable by us even in principle. If you enable two-factor authentication, we store the associated secret and backup codes.

Session and security information. A session cookie (HTTP-only, not readable by page scripts), and, for security and abuse prevention, the IP address and user-agent string of requests we receive, including those recorded in a security audit log for account and API-key events.

Images you submit for scanning. When you submit an image, we receive the original file to analyze it. In the ordinary case the original is deleted within seconds of the scan finishing (completed, failed, or expired) and is not retained past that. Two honest edge cases: a scan that gets stuck can take longer to reach that point (up to roughly ten minutes, while an automated job expires it); and if that automated job's credit-refund step keeps failing, the scan never reaches a final state at all, and its original is retained until that failure is fixed. A small, downscaled thumbnail is kept afterward, with all embedded metadata (EXIF, GPS, ICC, IPTC, XMP) stripped, so a scan can be reviewed later in your account console; the thumbnail is not the original file. We also keep the scan's metadata (filename, size, a content hash, timestamps), the verdict and confidence score, and the detection model's full raw output. See /legal/retention for exactly how long each of these is kept, and the exact mechanism behind both edge cases above.

Feedback you give us about a scan. On a scan's report page you can tell us whether the verdict was right. If you do, we store the verdict you say is correct, an optional generator you named, and any free-text notes you choose to type, that text is stored exactly as you wrote it; we do not redact or review it first. It is kept for as long as the scan record it belongs to exists (see /legal/retention , today, that is indefinitely), and used to help us understand where the detector gets it wrong.

Payment information. Stripe processes your payment directly; we never receive or store your full card number. We keep a record of each purchase (the pack, the amount, its status, and Stripe's own identifiers for it) and every movement of your credit balance.

API usage information. If you create an API key, we store a SHA-256 hash of it (never the plaintext secret, which is shown to you once and not retained by us), a short non-secret prefix so you can tell your keys apart, and when it was last used. We also keep rate-limit counters that record how many requests a key or address has made recently.

3. Lawful basis

Where the GDPR or UK GDPR applies to you, we rely on the following bases:

  • Performance of a contract for creating and running your account, accepting an image and returning a result, and managing your credit balance.
  • Legitimate interests for keeping the service secure and available, preventing abuse and fraud, enforcing rate limits, and keeping the audit records described above. Our interest is in operating a service that is not abused, balanced against your interest in not being over-monitored, which is why the audit log records actions rather than the content of your images.
  • Legal obligation for keeping billing and tax records for as long as applicable law requires.

We do not rely on consent for anything today, because the only cookies we set are strictly necessary to sign you in, and we run no analytics, advertising or third-party tracking. If that ever changes, we will ask first.

4. Who we share it with

We share data with the service providers that make truuimage work, and no one else:

  • Stripe, processes payments and stores your payment method on our behalf; we never see your full card number.
  • Resend, delivers transactional email (sign-in codes, verification, and account notices). We send no marketing email today.
  • Our hosting provider (Vercel) , hosts the application and, when configured, the object storage that holds your retained thumbnail.
  • Our database provider (Neon) , hosts the Postgres database that stores the account, scan, and billing records described above.
  • Our detection compute provider (Modal) , runs the image-analysis model your original image is sent to. Every request tells this backend not to retain a copy of the image, and it makes a best-effort attempt to delete the file from its own disk immediately after analysis, not a guaranteed one; a failed delete is logged there, not silently retried. Regardless of whether that file delete succeeds, this backend keeps its own separate submission-log record, a content hash of the image, the verdict, confidence, and processing timings, but not the file itself or its filename.

We disclose data beyond this list only if required by law, or to protect the rights, property, or safety of truuimage, our users, or the public.

5. International data transfer

The operator is established in the Cayman Islands, and the processors listed above operate in the United States. Your data will therefore be stored and processed outside your own country, and outside the EEA and the UK.

Where data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, and on the UK International Data Transfer Addendum where the UK GDPR applies. Each processor above offers these as part of its published data processing terms. Ask us at privacy@resonixlabs.io for the mechanism that applies to a particular processor.

6. Data retention

We keep different categories of data for different lengths of time, driven by why each one exists, a security audit record needs longer than a rate-limit counter, and your original upload needs none at all once analysis finishes. The full, category-by-category breakdown, with the exact retention windows the code enforces, is published separately at /legal/retention.

7. Your rights

You can access or correct your account information from the account console. You can also delete your account yourself, from the account settings page, type your account email address to confirm, and deletion begins immediately. Your password and two-factor secret, every API key, and every signed-in session are revoked immediately, before anything else runs; your email address is replaced with a placeholder and freed for reuse right away too. Your uploaded images and thumbnails, and your Stripe customer record, are purged next, if a scan you submitted is still being analyzed at that moment, its cleanup (and the account's move to fully deleted) waits for that scan to reach a final state first, rather than skipping it. Your scan history is retained with the filename and content hash removed, and your purchases, credit ledger, and balance are retained as financial records, linked to your account identifier, not to your name or email. See /legal/retention for the full, category-by-category breakdown, including the exact mechanism and the honest edge cases (a scan still being analyzed, or a slow or failing storage/Stripe delete, is retried automatically until it succeeds, rather than silently abandoned).

For anything the console does not yet expose, contact privacy@resonixlabs.io. We will act on a verified request by hand.

8. Children's privacy

truuimage is not directed at children. You must be at least 18 to hold an account, which matches the capacity requirement in our Terms of Service. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, contact privacy@resonixlabs.io and we will delete it.

9. Security

Passwords are hashed with Argon2id, never stored in plain text. API key secrets are stored only as a SHA-256 hash. Session cookies are HTTP-only and same-site. Requests are rate-limited, and every write endpoint that can move credits or change account state is checked against cross-origin forgery before anything else runs, except endpoints that authenticate themselves by signature or bearer token instead (Stripe's webhook, verified against its own signing secret; the reconciliation cron, which can itself move credits via automatic refunds; and the API's own detect endpoint), each of which is exempt from that specific check only because it independently verifies who is calling it before doing anything else. No system is perfectly secure, and we cannot guarantee absolute security.

10. Changes to this policy

We may update this policy from time to time. The date at the top of this page reflects the last time the text changed.

11. Contact

Privacy questions or data-subject requests: privacy@resonixlabs.io. General questions: hello@resonixlabs.io.