X-RAY
  • Home
  • Try Demo
  • Features
  • How it works
  • Pricing
  • API
Home / Privacy Policy

Privacy Policy

Effective date: April 11, 2026

Contents

  1. 1. Who We Are
  2. 2. Information We Collect
  3. 3. How We Use Your Data
  4. 4. Third-Party Services
  5. 5. Data Retention
  6. 6. Cookies & Local Storage
  7. 7. Your Rights
  8. 8. Security
  9. 9. Age Requirement
  10. 10. Changes to This Policy
  11. 11. Contact

1. Who We Are

X-RAY ("we", "us", "our") is an AI image detection service available at xray-ai.xyz, operated by an individual.

Questions about this Privacy Policy may be directed to [email protected].

2. Information We Collect

Account data: When you register, we collect your email address and chosen username.

Usage data: We store hashed IP addresses for rate-limiting and fraud prevention. Raw IPs are never stored in plain text.

Uploaded images: Images you submit for analysis are stored temporarily on our servers for up to 30 days to allow PDF report generation, then permanently deleted.

Payment data: Payments are processed by Stripe, Inc. We never see or store your credit card numbers. Stripe collects and handles payment data under its own Privacy Policy (stripe.com/privacy) in accordance with PCI DSS.

OAuth data: If you sign in via Google, Facebook, or GitHub, we receive your name and email address from that provider as permitted by their terms.

3. How We Use Your Data

To provide and improve the service — including running AI analysis, generating PDF reports, and maintaining your analysis history.

To process payments through Stripe and manage your subscription status.

To send transactional emails: email verification, password resets, billing receipts.

To enforce usage limits and prevent abuse.

To comply with applicable laws and legal requests.

4. Third-Party Services

Stripe — payment processing. Stripe processes and stores all payment card data. Privacy policy: stripe.com/privacy.

Google / Facebook / GitHub — optional OAuth sign-in. Their respective privacy policies apply to data they provide.

Cloudflare Turnstile — CAPTCHA-based bot protection on registration forms. No advertising data is collected.

We do not use advertising trackers, third-party analytics, or sell any user data to third parties.

5. Data Retention

Uploaded images: stored for a maximum of 30 days, then permanently and automatically deleted.

Account data (email, username, analysis history): retained while your account is active.

To delete your account and all associated data, email [email protected]. We will process the request within 14 days.

6. Cookies & Local Storage

We do not use advertising cookies or third-party tracking cookies.

We use browser localStorage to store your authentication token and preferred language. These are strictly necessary for the service to function.

7. Your Rights

You have the right to access the personal data we hold about you.

You have the right to correct inaccurate data.

You have the right to request deletion of your data.

To exercise any of these rights, contact [email protected]. We will respond within 30 days.

8. Security

We use HTTPS for all data transmission, bcrypt for password hashing, and JWT tokens for session authentication.

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but take commercially reasonable steps to protect your data.

9. Age Requirement

The service is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has registered, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the site at least 14 days before taking effect.

Continued use of the service after changes become effective constitutes acceptance of the updated policy.

11. Contact

For any privacy-related questions or requests, contact us at [email protected].

Terms · [email protected]