Privacy Policy
Ministry of Truth — Digital Authenticity Verification
1. Overview
Ministry of Truth ("MOT", "we", "us", "our") is a mobile application that helps you verify the authenticity of digital media — photos, videos, and content from social-media links — by running them through a multi-layer forensic analysis pipeline. This Privacy Policy explains what information the app collects when you use it, how that information is used, with whom it is shared, and how long it is retained.
By installing or using Ministry of Truth, you agree to the practices described in this Policy. If you do not agree, please do not use the app.
2. Information We Collect
2.1 Media you submit for analysis
When you choose a photo or video from your gallery, capture an image with your camera, paste a URL, or share content into Ministry of Truth from another app via the iOS Share Sheet, the following information is sent to our analysis backend:
- The image file, video file, or extracted video frames you submitted.
- The URL string you pasted or shared (e.g. an Instagram Reel link, YouTube link).
- Technical metadata embedded in the media file (e.g. EXIF data, codec information). This metadata is required for forensic analysis.
2.2 Information collected automatically
When the app communicates with our backend, the following limited technical information is transmitted:
- Approximate file size of the upload, for routing and timeout configuration.
- HTTP request headers required for transport, including a generic User-Agent string identifying the app.
2.3 Information we do NOT collect
- We do not require you to create an account.
- We do not collect your name, email address, phone number, or any persistent identifier.
- We do not track you across other apps or websites.
- We do not collect precise location data.
- We do not use advertising identifiers (IDFA) and we display no advertising.
- We do not access your contacts, calendar, microphone, or health data.
2.4 Media containing faces
Media files you submit for analysis may incidentally contain human faces. Ministry of Truth does not perform facial recognition, does not extract or store face embeddings or any biometric template, and does not build any identity profile. Because the app has no user accounts and collects no personal identifiers, submitted media is never linked to any individual. The app's purpose is to determine whether submitted media is AI-generated or digitally manipulated (including "deepfake" manipulation). When media is submitted, it is forwarded to our third-party analysis providers (see Section 4) solely to produce that authenticity verdict. The media file is deleted immediately from our servers after the result is returned to your device; our providers' retention is described in Section 4 and Section 6. We do not use submitted media to train any model.
3. How We Use Your Information
The media and URLs you submit are used solely to perform the forensic analysis you requested and to return that result to your device. Specifically:
- The file is temporarily uploaded to our analysis backend.
- Our backend runs the 5-layer forensic pipeline (cryptographic provenance check, deep-learning fingerprint scan, spectral analysis, physics/ELA analysis, and chrominance analysis).
- The resulting verdict and per-layer details are returned to your device.
- The uploaded file is then deleted from our processing servers — see Section 6 — Data Retention.
We do not use your submitted media to train AI models, build profiles about you, or for any marketing purpose.
4. Third-Party Services
To perform certain forensic checks, our backend forwards your media (or a copy of it) to a small number of trusted third-party services. By using Ministry of Truth, you consent to this transmission. The third parties currently used are:
- Sightengine — used for AI-generation fingerprint detection (Layer 2 of our pipeline). Sightengine receives the image bytes only; it does not receive any identifier tying the image to you. Their privacy policy: sightengine.com/privacy.
- Hive AI — used for AI-generation and deepfake-manipulation detection. Hive receives the media bytes only; it does not receive any identifier tying the media to you. By its standard policy, Hive may retain submitted media for up to 14 days for operational purposes before deletion. Their privacy policy: thehive.ai/privacy.
- Google Cloud Run — hosts our backend infrastructure. Google Cloud may log standard request metadata (timestamps, IP address) for service operation and security. See: cloud.google.com/terms/cloud-privacy-notice.
- Public social-media content (Instagram, YouTube, etc.) — when you submit a URL, our backend fetches publicly available content from that URL using standard download tools. Only the URL you provide is requested; no credentials of yours are sent.
We do not sell, rent, or otherwise share your submitted media with any party for purposes unrelated to providing the analysis you requested.
5. Data Security
All communication between the app and our backend uses encrypted HTTPS (TLS). Uploads are stored in volatile, sandboxed working directories on Cloud Run and are deleted after processing. Access to our backend infrastructure is restricted to authorized maintainers using Google Cloud identity controls.
While we apply industry-standard safeguards, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but we work to follow best practices.
6. Data Retention
- Submitted media files: deleted from our processing servers automatically after the analysis completes, typically within minutes of upload. In rare cases of server reboot, files may persist for up to 24 hours before automatic cleanup.
- Third-party analysis providers: when media is forwarded to our detection providers (see Section 4), Sightengine supports deletion immediately upon processing, while Hive AI may retain the media for up to 14 days before deletion, under their respective data-retention policies. No user identifier is ever sent with the media, so this data cannot be linked to an individual.
- Analysis results: not stored on our servers after they are returned to your device. The result remains only on your device.
- Server logs: standard operational logs (timestamps, request paths, response codes, IP addresses) are retained by Google Cloud for up to 30 days for debugging and abuse-prevention purposes, then automatically purged.
7. Children's Privacy
Ministry of Truth is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, please contact us at the address below and we will delete it.
8. Your Rights
Because we do not retain submitted media after processing and do not associate submissions with any identifier, we generally have no personal information about you to access, correct, export, or delete. If you are based in a jurisdiction that grants you specific rights (e.g. GDPR, CCPA) and you wish to make an inquiry, please contact us at the email below.
9. Changes to This Policy
We may update this Privacy Policy from time to time as the app evolves. The "Effective date" at the top of this page reflects the most recent revision. We encourage you to review this page periodically. Continued use of the app after changes constitutes acceptance of the revised Policy.
10. Contact
Questions, comments, or requests regarding this Privacy Policy can be sent to:
- Email: utkarshk98@gmail.com
- App: Ministry of Truth (iOS)