ZSURE / LEGAL

Privacy Policy

We analyze media, not people. Scanning requires an explicit action from you on every single piece of media — nothing is silently captured, stored, or shared.

Read the policyLAST UPDATED August 2026

ZSure is a browser extension that helps you judge whether an image or video on a web page is likely authentic or AI-generated. This Policy explains what data is involved, where it goes, how it is handled, and the choices you have — and how ZSure, operated from India under the Digital Personal Data Protection Act, 2023, complies with Indian law. We never silently scan everything you browse, and we never read your browsing history, messages, or account content beyond the specific photo or video you choose to verify.

By installing or using the extension you agree to the practices described here.

01 /

What We Collect

All collection is tied to your explicit scan action plus the minimal data needed to keep the service working and abuse-free.

  • Media you choose to scan. When you pick a photo or video and press scan, that image (or sampled frames of a video), together with its source URL, is transmitted to the configured backend and used solely to produce a detection result for you.
  • Authentication. The extension uses Google Sign-In (Chrome's identity API) so the backend can authenticate you and enforce a fair per-user scan quota. The backend verifies your access token against Google and receives your Google account identifier and verified email scope. No password is ever requested or stored.
  • Scan metadata. Basic technical details about each scan (media type, dimensions, timestamps, and whether an analysis failed) are used to route requests and reason about quality/errors.
  • Quota counters. The number of scans you have used within the quota window is recorded server-side, keyed to your Google account. This enables the free per-user allowance and prevents abuse.
  • Local settings & consent. Consent status, pre-approval choices, your selected backend URL, and any optional API key are stored locally in your browser using chrome.storage. These stay on your device and are not transmitted except as needed to make requests to the backend you configured.
  • Remote configuration. When you open the extension, it may retrieve small, non-personal configuration values (feature flags, banner text) from the default backend to keep the extension up to date.
02 /

What We Do NOT Collect

Nothing else. We do not collect, retain, or transmit:

  • Your browsing history or the contents of other pages you visit
  • Chat or private messages, comments, or direct messages
  • Passwords, credit cards, contacts, call logs, or keystrokes
  • Your name, phone number, or government-issued identifiers
  • Location data, advertising identifiers, or third-party tracking cookies
  • Any media you did not explicitly choose to scan
03 /

Scanning Is Always in Your Control

The extension operates exclusively on a pick-to-scan model. Simply browsing a page scans nothing. You open the extension, choose "Pick a photo / video to scan," then click the exact photo or video you want verified. Nothing is captured or transmitted until you take that final click, and you can exit at any time. There is no background scanning, no page surveillance, and no opt-out needed for something that never runs by default.

04 /

Where Your Data Is Sent

4.1 The inference backend

By default, the media you scan is sent to the ZSure inference service. Authentication, analysis, quota checks, and — if configured — BitMind's detection proxy operate through that service.

4.2 Custom backends

You may enter a custom backend URL in the extension's Options page. In that case the media you scan is sent to that server instead, over HTTPS, and is subject to that operator's policies. ZSure has no visibility into, or control over, third-party servers you configure, and you should review their privacy practices yourself before enabling a custom backend.

4.3 Fetching the image from its hosting site

To analyze an image, the extension may fetch that image from the same site that already serves it to the page you're viewing — it introduces no new parties to the request. These fetches happen with your browser's existing cookies for that image host, exactly as the page's own image load works (the browser attaches them; the extension never reads, stores, or transmits the contents of those cookies).

4.4 Token verification

The token used at sign-in is validated by asking Google to confirm it (Google's public tokeninfo endpoint). This exchanges data with Google solely to validate your login, consistent with using Sign in with Google on any other service.

05 /

Retention & Storage

Our principle is transient processing — media is processed to produce your result and not used for any other purpose.

  • Uploaded videos are written to temporary server storage, analyzed, and deleted immediately after the analysis finishes.
  • Scanned frames are held in memory for the duration of inference. Our reference deployment may additionally write a small set of the analyzed frames to a server-side "proof" directory for auditing and debugging purposes; operators can rotate or disable this directory, and it never serves as a dataset for training.
  • Analysis logs may record only the outcome — verdict, confidence, and model scores — for quality and error diagnosis. They do not contain the media itself.
  • Quota counters expire automatically after the quota window (default 30 days), after which the count is discarded.
  • Model training. We do not train detection models on your scanned media, and we offer no feature that retains your media for training. If we ever add optional, consent-based improvements, you will be asked separately before any of your content participates.

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), a Data Fiduciary must erase personal data once the specified purpose is served or consent is withdrawn, unless retention is required by law. Our 30-day quota window and transient media pipeline are designed to stay well inside that obligation.

06 /

Data Safety Commitments

We make the same three commitments we disclose on the Chrome Web Store:

  • We do not sell your data to third parties, and never will.
  • We do not use or transfer your data for purposes unrelated to the extension's core function of detecting manipulated media.
  • We do not use or transfer your data to determine your creditworthiness or for lending purposes.
07 /

Indian Legal Framework

ZSure is operated by Hypotenuse Analytics India Pvt. Ltd., a company based in Noida, India. This Policy is drafted to comply with the Indian laws that apply to synthetic-media detection and the data handled in its course, and is to be read consistently with them.

  • Digital Personal Data Protection Act, 2023 (DPDP Act). India's primary data protection statute. It governs how we — as a Data Fiduciary — collect, process, protect, and erase personal data, and secures your rights as a Data Principal before the Data Protection Board of India.
  • Information Technology Act, 2000 (IT Act). Creates the cyber offences used to prosecute deepfake misuse — identity theft (s. 66C), cheating by personation (s. 66D), violation of privacy (s. 66E), obscene and sexually explicit material (ss. 67–67A) — plus blocking powers (s. 69A) and the intermediary safe-harbour regime (s. 79).
  • IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended effective 20 February 2026. Introduces the regulatory definition of "synthetically generated information" (SGI), requires prominent labelling and permanent provenance metadata, prohibits harmful SGI categories, and compresses takedown timelines.
  • Bharatiya Nyaya Sanhita, 2023 (BNS). The general criminal code — covering cheating by personation (s. 319), forgery of false electronic records (ss. 335–336), public mischief through misinformation (s. 353), defamation (s. 356), and organised cybercrime including deepfake offences (s. 111).
  • Protection of Children from Sexual Offences Act, 2012 (POCSO) and related mandatory-reporting provisions — imposing reporting duties where child sexual abuse material is encountered.
  • Constitutional right to privacy (Justice K.S. Puttaswamy v. Union of India, 2017) — the fundamental-rights framework in which all of the above operate.
  • IndiaAI Governance Guidelines (November 2025) — the Government's risk-based framework encouraging safe and responsible use of AI, which our detection work supports.
09 /

Synthetic Media & Deepfake Regulation

India now regulates synthetically generated information (SGI): audio, visual or audio-visual content artificially or algorithmically created, generated, modified or altered so that it appears real and depicts a person or event in a manner likely to be perceived as authentic. Deepfakes, voice clones, and generated video frames all fall within this definition.

  • Where ZSure fits. The amended Rules place creation-and-dissemination duties on intermediaries that enable SGI. ZSure is a detection (classifier) service, not a generator: it does not create, modify, label, or distribute synthetic media. It helps you and platforms identify SGI so that responsible labelling, provenance, and moderation can follow.
  • Harmful categories the law targets. The Rules require intermediaries to prevent content that contains child sexual abuse material, non-consensual intimate imagery, forged documents or false electronic records, or that falsely depicts a natural person or real-world event in a manner likely to deceive.
  • Your obligations. You must not use ZSure to create, publish, or spread deceptive synthetic media, and detection output must never be used to deceive, defraud, or interfere with an election (matters that also engage the BNS and the Representation of the People Act, 1951).
  • Reporting. If, in the course of processing, we become aware — to a lawful standard — of unlawful SGI such as child sexual abuse material or non-consensual intimate imagery, applicable mandatory-reporting duties (for example under the Bharatiya Nagarik Suraksha Sanhita, 2023, and POCSO) may require us to act, consistent with confidentiality obligations.
We detect fakes. We never help make them.
10 /

Criminal Liability & Misuse

Deepfake misuse is a criminal matter in India, and investigation and prosecution are conducted by the States'/UTs' law-enforcement agencies. A single malicious piece of content can attract multiple provisions simultaneously:

OffenceLawWhat it coversMaximum penalty
Identity theftIT Act s. 66CFraudulent use of another's electronic signature, password, or unique identity feature (e.g. a cloned face or voice)Up to 3 years and fine up to ₹1 lakh
Cheating by personationIT Act s. 66DUsing a computer resource to cheat by personation — e.g. CEO-voice scams, fake KYCUp to 3 years and fine up to ₹1 lakh
Violation of privacyIT Act s. 66ECapturing, publishing or transmitting images of a person's private area without consent — primary section for intimate deepfakesUp to 3 years or fine up to ₹2 lakh or both
Obscene / sexually explicitIT Act ss. 67 / 67APublishing or transmitting obscene or sexually explicit material, including non-consensual intimate contentUp to 5 years (7 on repeat conviction) and fine up to ₹10 lakh
Cheating by personationBNS s. 319Cheating by pretending to be another person, real or imaginaryUp to 5 years or fine or both
ForgeryBNS ss. 335–336Making or using a false document or false electronic record — e.g. forged identity or financial documentsUp to 2–7 years and fine
Public mischiefBNS s. 353Knowing dissemination of false or misleading statements causing public mischief or fear — e.g. synthetic "news"Up to 3 years or fine or both
DefamationBNS s. 356Harming reputation through words imputed by any means, including synthetic mediaUp to 2 years (simple imprisonment) or fine or both
Organised cybercrimeBNS s. 111Systematic cyber activity involving synthetic media at scale, including deepfake campaignsImprisonment up to 7 years and fine up to ₹10 lakh

This is a summary for clarity, not legal advice. Penalties may also arise under other statutes, and actual liability depends on the specific facts and intent. ZSure does not immunise anyone from the law — detection does not authorise misuse of the things it surfaces.

11 /

Permissions Explained

Every permission the extension requests exists for a concrete reason and is used only when you act. Nothing runs in the background.

PermissionWhy we use it
identity + Google OAuth scopesSign in with Google so the backend can authenticate you and enforce the per-user scan quota.
storageSaves consent, your backend URL, and optional API key locally on your device.
activeTabTemporarily access the tab you're on only when you activate "Pick a photo / video to scan."
scriptingInjects — or refreshes — the small picker script into the page you are currently viewing when you invoke a scan.
host_permissions: <all_urls>Images and videos can live on any site, so the picker must be able to read the specific element you click and fetch it from its own host. Used exclusively for the media you choose; never for general page content.
12 /

Content That Shows Other People

The photos and videos you scan may depict other people who did not choose to be analyzed. Because scanning is initiated by you on content you have chosen to view, the analysis proceeds without that person's direct consent.

In India, that content constitutes third parties' personal data (facial and other biometric-feature data) under the DPDP Act. Where we process it, we do so on the lawful ground of your voluntary disclosure and for detection alone, in the same transient pipeline described in Retention & Storage. Please use the tool responsibly, respect the rights of people and content depicted, and conform to the applicable laws where you are.

Responsible-use notice: creating, sharing, or exploiting non-consensual synthetic depictions of real people is illegal and reportable under Indian law (see Criminal Liability & Misuse).
13 /

Children&apos;s Privacy

ZSure is not directed at children, and we do not knowingly collect personal information from them. This extends beyond a self-imposed rule: the DPDP Act (s. 9) imposes heightened obligations for processing children's personal data and mandates verifiable parental consent, and Indian law prohibits child sexual abuse material in any form (POCSO Act, 2012; IT Act s. 67B). ZSure must never be used to produce, scan for inappropriate purposes, or distribute any content involving children.

If you believe a child has provided us with personal information, contact us and we will delete it.

14 /

Cross-Border Data Transfers

The ZSure inference service is cloud-hosted and portions of processing may occur outside India. Under section 16 of the DPDP Act, transfers of personal data are permitted unless the Central Government notifies restrictions; we comply with any such notification as it takes effect.

All transfers are protected by encryption in transit (HTTPS), restricted access controls, and appropriate contractual safeguards, and remain subject to the retention limits in this Policy. Media you route to a custom backend is governed by that operator's practices and the laws of the place where the data lands.

15 /

Your Rights & Choices

As a Data Principal under the DPDP Act you have these rights, which you can exercise by contacting us:

  • Access (s. 11). Obtain a summary of the personal data we process, our processing activities, and the identities of the Data Fiduciaries/Processors with whom the data has been shared.
  • Correction & erasure (s. 12). Request correction of inaccurate or incomplete data, and erasure of your personal data where retention is no longer necessary for the specified purpose or required by law.
  • Grievance redressal (s. 13). Raise a grievance with our grievance officer, who will respond within the period prescribed by the DPDP Rules.
  • Nomination (s. 14). Nominate an individual to exercise your rights in the event of your death or incapacity.
  • Consent withdrawal (s. 6). Withdraw consent at any time and have downstream processing stopped and data erased.
  • Regulator remedy (s. 13). If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.

Also in your control

  • Uninstall. Removing the extension erases its local settings from your browser.
  • Stop signing in. The popup lets you sign out at any time; you can also revoke Google's access to the extension from your Google Account permissions page.
  • International rights. Where your local law gives additional rights over personal data (e.g. GDPR, PIPEDA, CCPA), you may request access to, correction of, or deletion of data we hold about you. Because we keep almost nothing beyond quota counters and logs, we can and will honour erasure requests promptly.
16 /

Security

All communication with backends happens over encrypted HTTPS. Media is processed in memory and kept only for the shortest time needed. We restrict server access to authorized operators, and we disclose retention above so you can audit the claim yourself. When you use a custom backend, transport security depends on that server's operator.

17 /

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or in applicable law — including Indian statutes and rules as they evolve. Material changes will be indicated by updating the "Last Updated" date at the top of this page and, where practical, by a notice inside the extension.

18 /

Contact Us

Questions about this Policy, your data, or privacy at ZSure? Write to our Data Protection / Grievance Officer:

info@hypotenuseanalytics.com
Hypotenuse Analytics India Pvt. Ltd., Noida, India

We acknowledge grievances promptly and respond within the period prescribed under the DPDP Rules; the Data Protection Board of India remains available if you are not satisfied.

WhatsApp
Ask ZSure AI