ZSure is a browser extension that helps you judge whether an image or video on a web page is likely authentic or AI-generated. This Policy explains what data is involved, where it goes, how it is handled, and the choices you have — and how ZSure, operated from India under the Digital Personal Data Protection Act, 2023, complies with Indian law. We never silently scan everything you browse, and we never read your browsing history, messages, or account content beyond the specific photo or video you choose to verify.
What We Collect
All collection is tied to your explicit scan action plus the minimal data needed to keep the service working and abuse-free.
- Media you choose to scan. When you pick a photo or video and press scan, that image (or sampled frames of a video), together with its source URL, is transmitted to the configured backend and used solely to produce a detection result for you.
- Authentication. The extension uses Google Sign-In (Chrome's
identityAPI) so the backend can authenticate you and enforce a fair per-user scan quota. The backend verifies your access token against Google and receives your Google account identifier and verified email scope. No password is ever requested or stored. - Scan metadata. Basic technical details about each scan (media type, dimensions, timestamps, and whether an analysis failed) are used to route requests and reason about quality/errors.
- Quota counters. The number of scans you have used within the quota window is recorded server-side, keyed to your Google account. This enables the free per-user allowance and prevents abuse.
- Local settings & consent. Consent status, pre-approval choices, your selected backend URL, and any optional API key are stored locally in your browser using
chrome.storage. These stay on your device and are not transmitted except as needed to make requests to the backend you configured. - Remote configuration. When you open the extension, it may retrieve small, non-personal configuration values (feature flags, banner text) from the default backend to keep the extension up to date.
What We Do NOT Collect
Nothing else. We do not collect, retain, or transmit:
- Your browsing history or the contents of other pages you visit
- Chat or private messages, comments, or direct messages
- Passwords, credit cards, contacts, call logs, or keystrokes
- Your name, phone number, or government-issued identifiers
- Location data, advertising identifiers, or third-party tracking cookies
- Any media you did not explicitly choose to scan
Scanning Is Always in Your Control
The extension operates exclusively on a pick-to-scan model. Simply browsing a page scans nothing. You open the extension, choose "Pick a photo / video to scan," then click the exact photo or video you want verified. Nothing is captured or transmitted until you take that final click, and you can exit at any time. There is no background scanning, no page surveillance, and no opt-out needed for something that never runs by default.
Where Your Data Is Sent
4.1 The inference backend
By default, the media you scan is sent to the ZSure inference service. Authentication, analysis, quota checks, and — if configured — BitMind's detection proxy operate through that service.
4.2 Custom backends
You may enter a custom backend URL in the extension's Options page. In that case the media you scan is sent to that server instead, over HTTPS, and is subject to that operator's policies. ZSure has no visibility into, or control over, third-party servers you configure, and you should review their privacy practices yourself before enabling a custom backend.
4.3 Fetching the image from its hosting site
To analyze an image, the extension may fetch that image from the same site that already serves it to the page you're viewing — it introduces no new parties to the request. These fetches happen with your browser's existing cookies for that image host, exactly as the page's own image load works (the browser attaches them; the extension never reads, stores, or transmits the contents of those cookies).
4.4 Token verification
The token used at sign-in is validated by asking Google to confirm it (Google's public tokeninfo endpoint). This exchanges data with Google solely to validate your login, consistent with using Sign in with Google on any other service.
Retention & Storage
Our principle is transient processing — media is processed to produce your result and not used for any other purpose.
- Uploaded videos are written to temporary server storage, analyzed, and deleted immediately after the analysis finishes.
- Scanned frames are held in memory for the duration of inference. Our reference deployment may additionally write a small set of the analyzed frames to a server-side "proof" directory for auditing and debugging purposes; operators can rotate or disable this directory, and it never serves as a dataset for training.
- Analysis logs may record only the outcome — verdict, confidence, and model scores — for quality and error diagnosis. They do not contain the media itself.
- Quota counters expire automatically after the quota window (default 30 days), after which the count is discarded.
- Model training. We do not train detection models on your scanned media, and we offer no feature that retains your media for training. If we ever add optional, consent-based improvements, you will be asked separately before any of your content participates.
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), a Data Fiduciary must erase personal data once the specified purpose is served or consent is withdrawn, unless retention is required by law. Our 30-day quota window and transient media pipeline are designed to stay well inside that obligation.
Data Safety Commitments
We make the same three commitments we disclose on the Chrome Web Store:
- We do not sell your data to third parties, and never will.
- We do not use or transfer your data for purposes unrelated to the extension's core function of detecting manipulated media.
- We do not use or transfer your data to determine your creditworthiness or for lending purposes.
Indian Legal Framework
ZSure is operated by Hypotenuse Analytics India Pvt. Ltd., a company based in Noida, India. This Policy is drafted to comply with the Indian laws that apply to synthetic-media detection and the data handled in its course, and is to be read consistently with them.
- Digital Personal Data Protection Act, 2023 (DPDP Act). India's primary data protection statute. It governs how we — as a Data Fiduciary — collect, process, protect, and erase personal data, and secures your rights as a Data Principal before the Data Protection Board of India.
- Information Technology Act, 2000 (IT Act). Creates the cyber offences used to prosecute deepfake misuse — identity theft (s. 66C), cheating by personation (s. 66D), violation of privacy (s. 66E), obscene and sexually explicit material (ss. 67–67A) — plus blocking powers (s. 69A) and the intermediary safe-harbour regime (s. 79).
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended effective 20 February 2026. Introduces the regulatory definition of "synthetically generated information" (SGI), requires prominent labelling and permanent provenance metadata, prohibits harmful SGI categories, and compresses takedown timelines.
- Bharatiya Nyaya Sanhita, 2023 (BNS). The general criminal code — covering cheating by personation (s. 319), forgery of false electronic records (ss. 335–336), public mischief through misinformation (s. 353), defamation (s. 356), and organised cybercrime including deepfake offences (s. 111).
- Protection of Children from Sexual Offences Act, 2012 (POCSO) and related mandatory-reporting provisions — imposing reporting duties where child sexual abuse material is encountered.
- Constitutional right to privacy (Justice K.S. Puttaswamy v. Union of India, 2017) — the fundamental-rights framework in which all of the above operate.
- IndiaAI Governance Guidelines (November 2025) — the Government's risk-based framework encouraging safe and responsible use of AI, which our detection work supports.
Legal Basis for Processing (India)
Under the DPDP Act, ZSure is the Data Fiduciary and you are the Data Principal. Every element of processing described in this Policy is anchored to a specific lawful ground.
- Consent (s. 6). The pick-to-scan step is a free, specific, informed, unconditional and unambiguous act of consent with a clear affirmative action. By selecting media and pressing "Scan," you consent to the processing of that media, and no more than is necessary, for the purpose of producing a detection result.
- Notice (s. 5). Before or at the time of consent you are given this notice in clear, plain language describing the data collected and the purpose of its processing. Consent is never bundled or hidden.
- Purpose limitation (ss. 4 & 6). Data is processed only for the specific, stated purpose and is not used for secondary or unrelated purposes. If a new purpose ever arises, fresh consent will be sought.
- Legitimate uses (s. 7). Limited processing without consent may occur where the DPDP Act expressly permits it — for example, responding to a lawful court order or a written request from a legally authorised authority.
- Withdrawal (s. 6). You may withdraw consent at any time with the same ease with which you gave it. Withdrawal does not affect the lawfulness of processing before withdrawal; thereafter, we will — within a reasonable time — cease and cause our processors to cease processing and erase the data, unless retention is required or authorised by law.
- Data Principal's duties (s. 15). You undertake not to use ZSure to impersonate another person, suppress material information, or register false or frivolous grievances. Misuse of detection results may be addressed under the criminal provisions described below.
Synthetic Media & Deepfake Regulation
India now regulates synthetically generated information (SGI): audio, visual or audio-visual content artificially or algorithmically created, generated, modified or altered so that it appears real and depicts a person or event in a manner likely to be perceived as authentic. Deepfakes, voice clones, and generated video frames all fall within this definition.
- Where ZSure fits. The amended Rules place creation-and-dissemination duties on intermediaries that enable SGI. ZSure is a detection (classifier) service, not a generator: it does not create, modify, label, or distribute synthetic media. It helps you and platforms identify SGI so that responsible labelling, provenance, and moderation can follow.
- Harmful categories the law targets. The Rules require intermediaries to prevent content that contains child sexual abuse material, non-consensual intimate imagery, forged documents or false electronic records, or that falsely depicts a natural person or real-world event in a manner likely to deceive.
- Your obligations. You must not use ZSure to create, publish, or spread deceptive synthetic media, and detection output must never be used to deceive, defraud, or interfere with an election (matters that also engage the BNS and the Representation of the People Act, 1951).
- Reporting. If, in the course of processing, we become aware — to a lawful standard — of unlawful SGI such as child sexual abuse material or non-consensual intimate imagery, applicable mandatory-reporting duties (for example under the Bharatiya Nagarik Suraksha Sanhita, 2023, and POCSO) may require us to act, consistent with confidentiality obligations.
Criminal Liability & Misuse
Deepfake misuse is a criminal matter in India, and investigation and prosecution are conducted by the States'/UTs' law-enforcement agencies. A single malicious piece of content can attract multiple provisions simultaneously:
| Offence | Law | What it covers | Maximum penalty |
|---|---|---|---|
| Identity theft | IT Act s. 66C | Fraudulent use of another's electronic signature, password, or unique identity feature (e.g. a cloned face or voice) | Up to 3 years and fine up to ₹1 lakh |
| Cheating by personation | IT Act s. 66D | Using a computer resource to cheat by personation — e.g. CEO-voice scams, fake KYC | Up to 3 years and fine up to ₹1 lakh |
| Violation of privacy | IT Act s. 66E | Capturing, publishing or transmitting images of a person's private area without consent — primary section for intimate deepfakes | Up to 3 years or fine up to ₹2 lakh or both |
| Obscene / sexually explicit | IT Act ss. 67 / 67A | Publishing or transmitting obscene or sexually explicit material, including non-consensual intimate content | Up to 5 years (7 on repeat conviction) and fine up to ₹10 lakh |
| Cheating by personation | BNS s. 319 | Cheating by pretending to be another person, real or imaginary | Up to 5 years or fine or both |
| Forgery | BNS ss. 335–336 | Making or using a false document or false electronic record — e.g. forged identity or financial documents | Up to 2–7 years and fine |
| Public mischief | BNS s. 353 | Knowing dissemination of false or misleading statements causing public mischief or fear — e.g. synthetic "news" | Up to 3 years or fine or both |
| Defamation | BNS s. 356 | Harming reputation through words imputed by any means, including synthetic media | Up to 2 years (simple imprisonment) or fine or both |
| Organised cybercrime | BNS s. 111 | Systematic cyber activity involving synthetic media at scale, including deepfake campaigns | Imprisonment up to 7 years and fine up to ₹10 lakh |
This is a summary for clarity, not legal advice. Penalties may also arise under other statutes, and actual liability depends on the specific facts and intent. ZSure does not immunise anyone from the law — detection does not authorise misuse of the things it surfaces.
Permissions Explained
Every permission the extension requests exists for a concrete reason and is used only when you act. Nothing runs in the background.
| Permission | Why we use it |
|---|---|
identity + Google OAuth scopes | Sign in with Google so the backend can authenticate you and enforce the per-user scan quota. |
storage | Saves consent, your backend URL, and optional API key locally on your device. |
activeTab | Temporarily access the tab you're on only when you activate "Pick a photo / video to scan." |
scripting | Injects — or refreshes — the small picker script into the page you are currently viewing when you invoke a scan. |
host_permissions: <all_urls> | Images and videos can live on any site, so the picker must be able to read the specific element you click and fetch it from its own host. Used exclusively for the media you choose; never for general page content. |
Content That Shows Other People
The photos and videos you scan may depict other people who did not choose to be analyzed. Because scanning is initiated by you on content you have chosen to view, the analysis proceeds without that person's direct consent.
In India, that content constitutes third parties' personal data (facial and other biometric-feature data) under the DPDP Act. Where we process it, we do so on the lawful ground of your voluntary disclosure and for detection alone, in the same transient pipeline described in Retention & Storage. Please use the tool responsibly, respect the rights of people and content depicted, and conform to the applicable laws where you are.
Children's Privacy
ZSure is not directed at children, and we do not knowingly collect personal information from them. This extends beyond a self-imposed rule: the DPDP Act (s. 9) imposes heightened obligations for processing children's personal data and mandates verifiable parental consent, and Indian law prohibits child sexual abuse material in any form (POCSO Act, 2012; IT Act s. 67B). ZSure must never be used to produce, scan for inappropriate purposes, or distribute any content involving children.
If you believe a child has provided us with personal information, contact us and we will delete it.
Cross-Border Data Transfers
The ZSure inference service is cloud-hosted and portions of processing may occur outside India. Under section 16 of the DPDP Act, transfers of personal data are permitted unless the Central Government notifies restrictions; we comply with any such notification as it takes effect.
All transfers are protected by encryption in transit (HTTPS), restricted access controls, and appropriate contractual safeguards, and remain subject to the retention limits in this Policy. Media you route to a custom backend is governed by that operator's practices and the laws of the place where the data lands.
Your Rights & Choices
As a Data Principal under the DPDP Act you have these rights, which you can exercise by contacting us:
- Access (s. 11). Obtain a summary of the personal data we process, our processing activities, and the identities of the Data Fiduciaries/Processors with whom the data has been shared.
- Correction & erasure (s. 12). Request correction of inaccurate or incomplete data, and erasure of your personal data where retention is no longer necessary for the specified purpose or required by law.
- Grievance redressal (s. 13). Raise a grievance with our grievance officer, who will respond within the period prescribed by the DPDP Rules.
- Nomination (s. 14). Nominate an individual to exercise your rights in the event of your death or incapacity.
- Consent withdrawal (s. 6). Withdraw consent at any time and have downstream processing stopped and data erased.
- Regulator remedy (s. 13). If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.
Also in your control
- Uninstall. Removing the extension erases its local settings from your browser.
- Stop signing in. The popup lets you sign out at any time; you can also revoke Google's access to the extension from your Google Account permissions page.
- International rights. Where your local law gives additional rights over personal data (e.g. GDPR, PIPEDA, CCPA), you may request access to, correction of, or deletion of data we hold about you. Because we keep almost nothing beyond quota counters and logs, we can and will honour erasure requests promptly.
Security
All communication with backends happens over encrypted HTTPS. Media is processed in memory and kept only for the shortest time needed. We restrict server access to authorized operators, and we disclose retention above so you can audit the claim yourself. When you use a custom backend, transport security depends on that server's operator.
Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or in applicable law — including Indian statutes and rules as they evolve. Material changes will be indicated by updating the "Last Updated" date at the top of this page and, where practical, by a notice inside the extension.
Contact Us
Questions about this Policy, your data, or privacy at ZSure? Write to our Data Protection / Grievance Officer:
info@hypotenuseanalytics.com
Hypotenuse Analytics India Pvt. Ltd., Noida, India
We acknowledge grievances promptly and respond within the period prescribed under the DPDP Rules; the Data Protection Board of India remains available if you are not satisfied.

