Privacy Policy
The short version
AICheck is designed to minimize collection. Text checks and the bundled image model run on your device, and the on-device result appears first. Image, video-frame, and screen-frame content stays on-device by default. On the web, an image up to 3 MiB is uploaded only when an active, server-verified AICheck Pro subscriber enables the separate cloud option for that check. Native media checks stay on-device in this release.
What we process
- Text checks and writing assist — analyzed and edited locally on your device. The writing workspace uses deterministic wording rules, stores no draft library, and does not send your original or suggested text to our servers.
- Image checks — AICheck Image Model v2, camera metadata, and supported embedded Content Credentials are read locally. The official Content Authenticity Initiative SDK checks the credential's manifest, signature, asset binding, validation state, and signer trust against a bundled checksum-pinned official trust-list snapshot. Remote-manifest fetching is disabled, and AICheck displays only controlled status categories rather than arbitrary manifest text. If the validator, local runtime, or trust list cannot complete a check, the result is unavailable rather than invalid. Optional cloud analysis is available only to a server-verified AICheck Pro web subscription after you tick its separate consent box for an image no larger than 3 MiB. Your local result is displayed before this work starts. Our API stores the temporary image payload only as AES-GCM-encrypted ciphertext accessible to the background job for up to 15 minutes. QStash receives an opaque job ID and limited orchestration metadata, not the image or the decryption key. The worker decrypts the payload only to send the image to our configured inference provider, which processes it to return the second model signal and may handle request data under its applicable service and retention terms. AICheck deletes the encrypted image payload promptly when the job completes or fails; bounded cleanup removes expired payload and owner-scoped, image-free status records. Deleting the owning account purges its remaining AICheck-controlled status, encrypted-payload, and lease records immediately.
- Video and screen checks — supported embedded video Content Credentials are checked locally before AICheck requests up to eight still frames from the first ten minutes. Only confirmed seeks are scored; audio and motion over time are not analyzed. A screen check watches a screen or window you explicitly choose for about four seconds, samples up to eight still frames from it, and stops sharing as soon as that window ends. No recording is written to a file — only transient frames exist, and they are discarded after scoring. These frames cannot enter the native cloud path and are not intentionally stored.
- Native shortcuts and sharing — iOS App Intents can open the scanner or accept one image or text value that you explicitly pass from Siri or Shortcuts. A content action opens AICheck and runs that one local check. Image input is capped at 8 MB, signature-checked, copied once into protected app cache, and deleted after handoff. A single-image HEIC/HEIF input is converted locally to a bounded JPEG derivative for the visual model; AICheck does not treat the derivative's missing Content Credentials or metadata as evidence about the original. Text is capped at 100,000 UTF-16 units and 256 KB and removed from the handoff cache immediately after reading. If you deliberately choose AICheck from Android's share sheet, the app accepts either plain text or one supported image and stages it for review without automatically checking it. Android shared images receive the same bounded signature check, one-shot private-cache copy, and deletion. Neither platform uses an accessibility service, overlay, or background screen observer.
- Usage counts — the free-tier counter enforces three checks per calendar week; every text, image, video, or screen check counts as one. You can use AICheck without an account, in which case the counter stays on your device. If you are signed in, the count is also kept against your account so it follows you across devices and is not reset by reinstalling. Only a number and the week it belongs to are stored — never what you checked or what the result was.
- Account (optional) — you can create an AICheck account to keep Pro access and your weekly allowance across devices. Checking content does not require one. If you create one we process your email address, and a password that is hashed and stored by our authentication provider — we never see or store your password ourselves. Choosing "Continue with Google" shares your email address with us from that provider. Accounts live in AICheck's own dedicated Supabase project, separate from our other apps, so an AICheck account is not linked to any other NIRO product. We use it only to sign you in, tie your allowance and any subscription to you, and contact you about your account. You can delete the account and its data at any time from Delete account in the account panel.
- Product analytics — Analytics transmission and storage are disabled in this release, including when an older saved preference says Allow. The checker keeps an equal Allow analytics / No thanks choice and reusable Privacy choices setting so a future disclosed release can honor consent without silently opting anyone in. Global Privacy Control or Do Not Track always overrides the local preference and keeps it off. A future analytics release would require an updated disclosure and would be limited to fixed, coarse, anonymous product events; it would never include submitted content, results, account details, email, stable device or session identifiers, URLs, referrers, full user-agent strings, or location.
Subscriptions & payments
- In the iOS app, AICheck Unlimited is billed by Apple through your Apple ID for unlimited on-device checks. Eligible new subscribers can start with a 7-day free trial; after 7 days it renews monthly at the localized App Store price unless canceled before the trial ends. Apple collects and manages the payment account or card information required to start. We do not receive your full payment-card details. Store transaction data may be sent to our validation service to confirm the product and entitlement. Manage or cancel in App Store account settings.
- In the macOS app, AICheck Unlimited is billed by Apple through your Apple ID. Eligible new subscribers can start with a 7-day free trial; after 7 days it renews monthly at the localized App Store price unless canceled before the trial ends. Apple collects and manages the payment account or card information required to start. The Mac App Store build does not offer or link to Stripe checkout. We do not receive your full payment-card details. Store transaction data is sent to our validation service to confirm the product and entitlement. Purchase, restore, manage, or cancel through the app and App Store account settings.
- In the Android app, AICheck Unlimited is billed by Google through your Google Play account for unlimited on-device checks. Eligible new subscribers can start with a 7-day free trial; after 7 days it renews monthly at the localized Google Play price unless canceled before the trial ends. Google collects and manages the payment account or card information required to start. We do not receive your full payment-card details. Store purchase data may be sent to our validation service to confirm the product and entitlement. Manage or cancel in Google Play subscriptions.
- On the web, AICheck Pro is billed by Stripe. Creating a free account does not require a card, but Stripe collects card information before an eligible new subscriber starts the 7-day trial. After 7 days, Stripe charges $3.99 per month unless the subscriber cancels before the trial ends. Your full card details go to Stripe, not to us. We receive the Stripe customer, subscription, payment status, and transaction identifiers needed to activate, restore, secure, and manage access. While Pro is active, choose Manage Pro in the checker to update your card or cancel.
The native receipt-validation SDK is configured to send the store-signed transaction without its optional analytics, support, fraud-device, or tracking metadata. It does not attach an advertising ID, persistent device ID, device fingerprint, model, manufacturer, or operating-system details to NIRO's validation request.
Service logs, retention, and deletion
Hosting, security, queue, inference, billing, and app-store providers may create operational records such as request time, route, response status, IP address, device or user-agent information, opaque job identifiers, and transaction identifiers. They retain these records under their own security, fraud-prevention, accounting, service, and legal policies. QStash receives only opaque orchestration data for a cloud job; the configured inference provider receives the separately consented image.
- Clear AICheck site/app data or uninstall the app to remove the local usage counter and cached entitlement data. Android and iOS delete each temporary native-entry image after handoff and clear stale copies when the native bridge next starts.
- Use Privacy choices in the checker to change the locally saved analytics preference. Choosing No thanks stops future analytics even if storage is enabled in a later disclosed release.
- Leave the optional cloud box off to withhold consent for future uploads. A request already delivered to an inference provider cannot be recalled, although AICheck still applies the encrypted-payload deletion schedule above.
- Delete your account and its data — if you created an AICheck account, open the account panel and choose Delete account. Confirming permanently removes your account record, including your email address, stored weekly usage count, and remaining AICheck-controlled cloud job and encrypted-payload records, from our systems. For a web subscription, deletion first cancels the Stripe subscription, expires any open AICheck Checkout Session, and removes the associated Stripe customer and payment details from AICheck's active billing account. Deletion does not cancel a subscription billed by Apple or Google; cancel it in App Store or Google Play subscription settings before deleting the account if you do not want it to renew. Queue, inference, hosting, and billing providers may retain limited operational, transaction, accounting, fraud-prevention, security, service, or legal records under their own policies. This cannot be undone, and it does not require emailing us.
- AICheck has no saved-content library. For billing identifiers, an operational-log inquiry, or deletion of data we control where legally and technically possible, email support@niroaerial.com.
What we don't do
We don't sell submitted content, use it for advertising or cross-app tracking, or intentionally use it to train models. AICheck does not store cloud-uploaded images in plaintext: it keeps only the temporary encrypted payload described above, makes it accessible to the job for up to 15 minutes, deletes it on completion or failure, removes expired records through bounded cleanup, and keeps no saved-content library.
Children
AICheck is not directed to children under 13. Children under 13 should not use the service or submit personal information, text, images, video frames, or screen frames to its optional cloud feature. If you believe a child under 13 provided personal information to AICheck, email support@niroaerial.com so we can investigate and delete information we control where required, subject to identity verification and any legal retention obligation.
Contact
Questions? See Support or email support@niroaerial.com.
Last updated: July 2026.