Legal
The short version: When you scan an image, it is sent to Google's Gemini API for analysis and immediately discarded, by both Google and CYPHR. We never store, view, or share your images, their URLs, or the results. The only activity data CYPHR keeps is a running count of how many scans you've run, used to enforce your plan's limit, never a record of what you scanned.
CYPHR is a Chrome extension and web service operated by NAZO Collective LLC, a Texas single-member LLC. When this policy says "CYPHR," "we," "us," or "our," it refers to NAZO Collective LLC.
Contact: hello@getcyphr.com
When you hover an image and trigger a scan, CYPHR sends that image to Google's Gemini API (a third-party AI service) to perform the detection analysis. The result (a confidence score and verdict) is returned to your browser and displayed in the extension popup.
CYPHR does not process images on your device. The image travels from your browser to Google's Gemini API servers and back. No image data is stored, logged, or retained by CYPHR at any point in this process.
Google's role: Google's Gemini API may retain prompts and responses for up to 55 days for abuse monitoring and safety purposes. This data is disconnected from your Google Account and API key before any review. Google does not use CYPHR API requests to train its models. Logging is strictly opt-in, and CYPHR has not opted in. See Google's Gemini API data logging policy for full details.
| Data type | Purpose | Retained by CYPHR? |
|---|---|---|
| Scan count per billing period | Enforcing your plan's scan limit (see Pricing) | Yes: a count only, never linked to what you scanned |
| Email address (or Google / Apple sign-in) | Account creation, billing, support, and product communications (see below) | Yes |
| Anonymous device ID | Counting free scans on the no-account tier (3/month) before sign-in | Yes: a random ID and a count only, not linked to your identity |
| Subscription status | Determining your tier (Free / Pro / Ultra) | Yes, via Stripe |
| Image content | Detection (processed by Gemini API) | No: never stored by CYPHR |
| Image URL | Sent to the Gemini API to retrieve the image for detection | No: never stored by CYPHR |
| Scan verdict + confidence score | Returned to your browser for display | No: shown to you, never stored |
When you create an account (by providing an email address or signing in with Google or Apple), you agree that CYPHR may contact you about product updates, new features, exclusive access and offers, and important information about your account. We send these to the email associated with your account. You can opt out of non-essential marketing emails at any time via the unsubscribe link in any such email, or by emailing hello@getcyphr.com. You will still receive essential account and billing messages. We never share or sell your email address.
Every scan is processed by Google's Gemini 2.5 Flash model via the Gemini API. By using CYPHR, you acknowledge that image data you submit for scanning is transmitted to Google's servers under Google's terms.
Reference: ai.google.dev/gemini-api/docs/logs-policy
Payment processing is handled by Stripe, Inc. CYPHR does not store credit card numbers or payment details. Stripe's privacy policy applies to payment data: stripe.com/privacy.
Account authentication is handled by Clerk. Your email and session credentials are managed by Clerk under their privacy policy: clerk.com/privacy.
CYPHR's website, API, and database (Vercel Postgres) are hosted on Vercel. The database stores account data: your email, tier, scan count, and the anonymous device ID/count for the free tier. No image content is stored in this database. vercel.com/legal/privacy-policy.
CYPHR retains your account data (email, tier, scan count) for as long as your account is active. Your scan count is a running number used only to enforce your plan's limit, and it is never linked to the images, URLs, or results of what you scanned. If you delete your account, your data is removed from CYPHR's systems within 30 days. Stripe and Clerk may retain billing and authentication records subject to their own retention policies and legal requirements.
You may request access to, correction of, or deletion of your account data at any time by emailing hello@getcyphr.com. We will respond within 30 days.
If you are located in the European Economic Area, you have additional rights under the GDPR, including the right to data portability and the right to lodge a complaint with your local supervisory authority.
All data in transit is encrypted via TLS. Database contents are encrypted at rest. We apply the principle of least privilege: CYPHR stores only what it needs to function, nothing more.
CYPHR is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us at hello@getcyphr.com.
By using CYPHR, you agree to this Privacy Policy. You will be asked to review and accept it before your first scan on the free tier, and again when you create an account. If you do not agree, please do not use CYPHR.
Continued use of CYPHR after any update to this policy constitutes acceptance of the revised policy.
We may update this policy as CYPHR's features evolve. Material changes will be communicated via email to registered users. The effective date at the top of this page reflects the most recent revision.
NAZO Collective LLC
Dallas, Texas
hello@getcyphr.com