Information we process
We process account details needed for Supabase authentication, content you deliberately submit for assessment, Proof Request workflow data, and the technical information required to secure and operate the service.
- Account and profile information
- Submitted images, text, URLs, and proof responses
- Assessment results and history allowed by your plan
- Security, device, and diagnostic events
- Web subscription identifiers and status supplied by Stripe
How we use information
We use information to authenticate you, perform requested assessments, operate Proof Requests, enforce plan limits, protect the service, provide support, and meet legal obligations. InvisiProof does not treat an AI assessment as verified identity.
BYOK provider keys
When you choose a bring-your-own-key provider, your API key is transmitted to the analysis backend only for the duration of that request. The web application does not store provider keys in local storage, cookies, analytics, or the InvisiProof database unless a future implementation is separately disclosed and consented to.
Service providers
Supabase provides authentication and backend infrastructure. Stripe processes web subscription billing. RevenueCat and Google Play continue to manage mobile purchases. Each provider processes data under its own terms and privacy commitments.
Retention and deletion
Assessment history retention depends on your subscription. Some records may be retained where required for fraud prevention, dispute handling, security, or law. Account deletion requests are processed through the verified backend deletion workflow.
Security and choices
We use access controls, encrypted transport, row-level authorization, and least-privilege credentials. No system is perfectly secure. You can review profile settings, limit what you submit, request account deletion, and contact support about privacy questions.