What happens to the media you send us, and who can technically read it — written to be accurate rather than reassuring.
The short version. Media you send is sealed on your device — TLS plus our envelope — so no proxy, CDN, edge or load balancer on the path sees it or the reply. The detector opens it in memory, runs the model and discards it: nothing from it is written to persistent storage, nothing about it is logged, and it is never used for training. Tayanch and its hosting provider (Modal, USA) hold the key the envelope is sealed to and can therefore technically read the media during the seconds of analysis; a link check necessarily shows us the link, and the platform sees our fetch. We keep your email only if you create an API key or ask us to call you back.
Tayanch is an AI-generated content detection service operated by Jamoliddinbek Yodgorov from the United Arab Emirates. For anything in this policy, including a request to access or delete your data, contact jamoliddinbekyodgorov@gmail.com or +971 50 726 4406.
Tayanch is not yet incorporated. When it is, the registered entity will assume the role of data controller described here and this policy will be updated with its details.
| Data | Why | How long we keep it |
|---|---|---|
| Media you submit — images, video, audio, or a public link you ask us to fetch | To produce the verdict you requested. Nothing else. | Not retained. Discarded as soon as the verdict is returned, whether the analysis succeeded or failed. A random token tied to the verdict lives in memory for 30 minutes so a follow-up noise-map request can reuse it; it contains no media and cannot be looked up by content. |
| Email address — if you create an API key | To issue the key, apply your quota, and contact you about the service | While the key is active, and a reasonable period after for billing records. We do not currently verify the address at signup; if someone used yours, tell us and we delete it. |
| API key | Authentication and quota | We store only a cryptographic hash of the key, never the key itself |
| Usage counts — per key, per endpoint, per day | Quota and billing | With the key's record. This is a named record of how many calls your key made, not anonymous metadata. |
| Account, if you create one — email, a hash of your password, the name and company you typed | To sign you in and show you the keys and usage of that address | Until you delete the account. Deleting it erases the profile, its sessions and its API keys in one action. An account is optional — the demo and the free key work without one. |
| Sign-in sessions — a hash of the session token, its dates, and a coarse client label such as "Firefox on Linux" | To keep you signed in, and to let you see and end your own sessions | Until you sign out, change your password or the session expires after 30 days. We store no IP address and no full browser fingerprint with it. |
| Callback request — name, phone, email, company, your note | Only to call you back, because you asked us to | Until the enquiry is closed, or until you ask us to delete it. We do not store the IP address the form was sent from. |
| Operational counters — request and error counts per endpoint | To keep the service running | Short-lived aggregates. They contain no media, no verdict per request, and no identity. |
This is the part that matters most, so it is stated precisely.
When you paste a link, the URL is a request to us: we receive it, we fetch the post's media on your behalf, and the platform (Instagram, YouTube, TikTok) sees our request — from our account, when a login is configured for sites that require one. No encryption changes who learns the link. Link checks are not offered on the attested tier described below.
On the web, the code that fetches our key, checks any attestation and seals your file is JavaScript served by Tayanch. If we, or someone controlling our hosting, served different code to you, you could not tell — every browser-based end-to-end-encrypted product has this limit. The web demo can show you which tier you are on; only a native client with the server's measurement compiled into a signed release (the app-store build, a versioned SDK) can carry the sentence "we cannot read it".
Two tiers exist in the code. The standard tier is what runs today. The attested tier — the detector inside hardware whose software measurement your client checks before sending — is written and tested but not yet provisioned: our current host offers no such hardware, so it will run on a confidential-computing cloud once set up. We will update this page when it is live.
| Tier | Client | Feature | Who can technically read the media | What we retain | What you are trusting |
|---|---|---|---|---|---|
| standard | web demo | image | Tayanch and Modal, during analysis. Not the network path. | Nothing from the media; a 30-minute token in memory; hourly counters | The page's JavaScript (served by Tayanch); Modal; the TLS certificate authority |
| standard | app / SDK | image | Same | Same | The client's own code; Modal; TLS CA |
| standard | any | link check | Tayanch and Modal, plus the platform that serves the post (it sees our fetch) | Nothing from the media; counters | As above, plus the platform |
| standard | any | video, audio, noise map | Tayanch and Modal, during analysis (video features live in a per-request RAM directory) | Nothing from the media; counters | As above |
| attested · pending | app / SDK with the pinned measurement | image only | Only the process inside the attested hardware — not Tayanch, not the cloud operator's staff, not the network | Nothing from the media; hourly counters with no finer timestamp | The chip vendor (Intel or AMD; or AWS's Nitro hypervisor — isolation, not memory encryption); the cloud's launcher and attestation signer; Tayanch's published measurement; the client's code |
| attested · pending | web demo | image only | Technically as above, but the page's code is served by Tayanch and could differ per visitor | Same | Tayanch (the page), then the row above |
| attested · pending | any | link check, video, audio, noise map | Not offered on this tier. | ||
"Technically read" means: has the key or the memory. It does not mean we do; the code paths that would store, log or export media do not exist. "Attested" is not "provable": that word would require a third party to rebuild our image, obtain the same measurement, and find it in a public log we do not control. We will not use it before that has happened.
If you require that your content never reaches us at all, Tayanch can be deployed inside your own environment, where the analysis runs on your infrastructure and nothing is sent to us. Contact us about on-premise deployment.
Content you submit may contain personal data — a photograph of a person is personal data, and a face may be treated as biometric or sensitive data under some laws. You are responsible for having the right to submit the content you send us. Because we retain nothing, we cannot later search for, retrieve or delete a specific file you submitted: it no longer exists.
Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and under the GDPR where it applies to you, you may request access to the personal data we hold about you, ask us to correct it, ask us to delete it, object to processing, or ask for a copy in a portable format. Write to jamoliddinbekyodgorov@gmail.com and we will respond within 30 days.
In practice the personal data we hold about you is the email address on your API key, the usage counts attached to it, your account row and its sessions if you created one, and anything you typed into the callback form. The account page can erase all of it yourself, at any time. We can access, correct and delete all of it on request, and we will ask our hosting provider about log lines that carry your identifier. The media itself cannot be returned because it does not exist after the verdict. Being unable to read your media does not change our responsibilities as the controller of this processing: we keep a data-protection impact assessment on file and processing terms with each provider below.
We use these infrastructure providers, and no others:
Modal and Vercel operate from data centres outside the UAE, principally in the United States, so submitting content to the hosted service involves an international transfer (Articles 22–23 of the UAE data protection law; Chapter V of the GDPR where it applies). We do not sell, rent or share your data with advertisers, data brokers or any other third party. On-premise deployment removes the transfer entirely; the attested tier can be placed in a UAE region once provisioned.
We do not use advertising or tracking cookies. The site stores one preference in your
browser's local storage — whether you chose light or dark mode — and your API key if you ask
the browser to remember it. When you sign in, your session token is kept in the tab's session
storage, so closing the tab signs that tab out; it is sent to us only as an
Authorization header on account requests, never as a cookie. Neither is sent to us as a cookie or used to track you. The mobile
app keeps its history — verdict and file name; the rendered noise map is no longer stored — on
your device under the operating system's app-storage protections; it is yours to clear and is
not sent to us. Operating-system crash reports, where you have enabled them, go to Apple or
Google under their terms.
Visit statistics. We count page views with Vercel Web Analytics, run by our
website host. It sets no cookies. For each page view it records the time, the page address
including a campaign tag such as ?ref=, the site you came from, an approximate
location (country, region and city), and your device type, operating system and browser.
Vercel identifies a visit with a hash of the incoming request that it discards after 24 hours;
page views are not tied to a person or an IP address, and we see aggregate counts only. It
never sees the files you check or their verdicts, which go to the detection service directly.
Vercel describes it at
vercel.com/docs/analytics/privacy-policy.
To stop being counted on a device, open tayanch.com/?analytics=off
once: the browser then keeps a single “off” flag in local storage and the site sends no page
views from it; ?analytics=on removes the flag.
Tayanch is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18.
We use TLS, the sealed envelope in both directions, hashed API keys, per-key quotas and rate limits. No system is perfectly secure; if a breach affects your personal data — the account and contact records above, even where media is unreadable — we will notify you and the relevant authority as required by law.
If this policy changes materially we will update the date at the top and, where we hold your email address, tell you. Turning on the attested tier will be such a change.
Jamoliddinbek Yodgorov · Tayanch · United Arab Emirates
jamoliddinbekyodgorov@gmail.com ·
+971 50 726 4406