1. Who we are
Wular Ltd ("Wular", "we", "us" or "our") provides AI Radar and is responsible for deciding how information described in this policy is processed. Contact us at contact@wularstudio.com.
2. Information we collect
Media and content you choose
We process only the photo or video you select for a check, or a public link you submit. For supported links we may also process the resolved public media, platform, title, thumbnail and duration returned by the link provider. AI Radar may read the clipboard only after you ask it to preview a link while the link field is empty.
Analysis and history
We store the media type and source, processing status, duration and analysed duration, credit charge, verdict, AI, deepfake and AI-audio scores, audio-detection status, consistency, sampled frame results, timestamps, error categories and creation/completion times. For link checks, the submitted source URL is stored with the analysis until deletion.
Account and app information
We process the anonymous Firebase identifier, preferred language, country where supplied by the app, platform and app version. Firebase and the operating system may process technical information needed to authenticate the installation and secure requests.
Credits and purchases
We process credit balances, daily-credit claims, idempotent debit/refund records, purchased pack size and fixed purchase outcomes. Apple or Google processes payment details. RevenueCat processes the app customer identifier, store transaction information and virtual-currency balance. We do not receive full card details.
Support messages
If you contact us, we receive the contact details and information you choose to include. Please do not send private media, submitted URLs, authentication tokens, receipts or account identifiers through ordinary email unless we provide a secure method.
3. Your AI-processing choice
Before the first upload or public-link preview, AI Radar asks whether you allow the photo, video or public link you selected to be processed, as needed, using the third-party AI services Sightengine and Undetectable AI. Choosing Not now sends no selected content, starts no link-preview request or analysis, and charges no credits. Your choice is stored only on your device.
You can review or withdraw this permission in AI Radar Settings. Withdrawal prevents future selected content from being transmitted until you allow processing again. It does not undo processing that already finished or delete completed checks; use the check-deletion or account-deletion controls for that.
4. How media is processed
- The app uploads the selected item directly to private Cloudflare R2 storage using an expiring upload URL, or the server resolves a supported public link.
- The server normalises the file. It removes EXIF, XMP, ICC and other embedded image metadata. Videos are limited to the first 60 seconds, re-encoded, stripped of metadata and chapters, and sampled into up to six frames. If a video has audio, a temporary mono audio file covering only that analysed portion is extracted; the retained sanitised video has its audio removed.
- The sanitised media is sent to SightEngine for visual detection. The temporary extracted audio is uploaded privately to UndetectableAI for AI-audio detection. MediaApi receives a submitted supported link to locate its public media.
- The raw staging upload and local temporary working files, including extracted audio, are deleted after the job finishes. The sanitised media and sampled frames are retained privately for history until you delete the check or account.
Detector results are probabilistic. We do not use your media to identify you, infer sensitive characteristics, train our own model, publish content or build advertising profiles. A selected image or video may nevertheless contain personal or sensitive information, so submit only content you are entitled to process.
5. Anonymous product analytics
We use PostHog to understand whether core features work and where people leave a workflow. AI Radar sends only explicitly defined events for onboarding, daily credit claims, analysis progress and completion, result sharing or saving, paywall views, purchases and purchase synchronisation.
Depending on the event, properties may include platform, app version, selected locale, image or video, upload or link source, a broad duration range, credits charged, a broad verdict category, pack size and a fixed outcome such as completed, cancelled or failed. Events use a random analytics identifier created for the installation.
Autocapture, session recording/replay, person profiles, push-event capture and IP-based geolocation are disabled. We do not use PostHog for advertising or cross-app tracking. Account deletion resets the local PostHog identity; aggregate statistics and events already processed under the previous random identifier may remain for the configured analytics-retention period.
6. Why we use information
- Provide authentication, uploads, link previews, analysis, history, sharing and deletion.
- Calculate, reserve, grant and refund credits and synchronise store purchases.
- Secure the service, reject unsafe links, prevent duplicate charges and investigate failures.
- Measure reliability, onboarding, check completion, retention and purchase-flow quality using limited analytics.
- Respond to support requests and comply with legal obligations.
Where applicable, our legal bases include performing the service you request, our legitimate interests in securing and improving it, consent where required for device permissions, and compliance with law. You control photo-library permissions through your device settings.
7. Service providers and disclosures
We do not sell personal information and do not share it for cross-context behavioural advertising. We disclose the minimum relevant information to providers acting for the purposes below:
- Google Firebase: anonymous authentication.
- Cloudflare R2: private staging and retained media storage.
- Sightengine: AI-generation and manipulation signal analysis.
- Undetectable AI: AI-generated audio signal analysis for the analysed portion of videos that contain audio.
- MediaApi: extraction of media from supported public links.
- RevenueCat, Apple and Google: purchases, credit grants, store transactions and purchase synchronisation.
- PostHog: limited anonymous product analytics described above.
Selected-content processors
Sightengine receives the selected image or the normalized, metadata-stripped portion of a selected video under a random working filename. It uses that content only to return AI-generation and manipulation signals. AI Radar stores normalized scores needed for the result and history, not the provider’s raw response.
Undetectable AI receives a private, randomly named temporary audio file only when the selected video contains audio. The file is limited to the analysed portion and is used only to return an AI-audio signal. AI Radar deletes its temporary local and object-storage audio copies when processing ends and retains the normalized score and status; a provider job identifier is retained only while needed to complete or resume the check.
MediaApi receives a supported public URL to locate the public image or video and return limited preview details. It is not used for private or login-only content. Direct supported media links do not require social-platform extraction.
We require every service provider that receives personal data from AI Radar to protect it to the same or an equivalent standard as this policy, use it only to provide the contracted service, apply appropriate security and confidentiality controls, and delete or return it in accordance with our instructions and the applicable service agreement, except where law requires retention. Provider-side transient copies are governed by those contractual retention and deletion commitments; AI Radar does not authorise providers to train models on selected content or use it for advertising.
Supported social platforms are independent services and are not affiliated with AI Radar. Their own policies apply when you use or submit their links. Providers may process information in countries outside yours. Where required, we use contractual and organisational safeguards for international transfers.
8. Retention and deletion
Raw staging uploads and local server working files, including temporary extracted audio, are designed to be removed after a check reaches a terminal state. Failed checks do not retain sanitised result media. Completed checks retain sanitised media without video audio, sampled frames, analysis records and any submitted source URL until you delete that check or the account. Processing performed by Sightengine and Undetectable AI is also subject to their applicable retention and service terms.
Deleting a history item removes its associated retained R2 objects and database record. Deleting the account removes the RevenueCat customer, all associated R2 objects, AI Radar analysis and credit records, and the app-scoped SQL user before the client removes its Firebase identity and resets the analytics identity.
Some limited records may remain where required for security, legal compliance, dispute handling, store accounting or backup integrity. Backups age out under our backup schedule. Aggregated information that no longer identifies an account or installation may be retained.
9. Security
We use authenticated app-scoped APIs, ownership checks, private object storage, expiring signed URLs, encrypted transport, URL safety checks and restricted provider credentials. No service can guarantee absolute security. Keep your device secure and avoid submitting content you do not need checked.
10. Your choices and rights
You can limit photo access, withdraw third-party AI-processing permission, delete individual checks and delete the entire account in the app. Depending on your location, you may also have rights to access, correct, erase, restrict or object to processing, request portability, or complain to a data-protection authority.
Because AI Radar accounts are anonymous, we may need a secure way to verify that a request relates to your installation without exposing another person's data. Contact contact@wularstudio.com for assistance.
11. Children
AI Radar is not directed to children under 13 and we do not knowingly collect their personal information. Where local law requires a higher age for independent consent, a parent or guardian must authorise use. Contact us if you believe a child has provided information so we can investigate and delete it.
12. Changes to this policy
We may update this policy when features, providers or legal requirements change. We will post the updated date here and provide additional notice where required.
13. Contact us
Questions, privacy requests or complaints can be sent to contact@wularstudio.com. You can also read our Terms of Service or visit AI Radar Support.