Designed around private work
Your FauxProof work stays private to your account. FauxProof does not sell it or use it for ads. It shares work only when you choose a feature that needs another service.
Read full privacy details
Effective August 24, 2026.
FauxProof stores the content you explicitly protect, selected pictures and supported project files, working drafts, revision proposals, protection rules, restore points, and audit records so the service can protect approved work, compare proposed changes, and restore earlier versions. Each signed-in account is kept in a separate private storage namespace. Project-file bytes and the media store's detailed record are encrypted at rest; the protected project state retains the file name, type, size, opaque ID, creation time, and SHA-256 integrity fingerprint needed to display, verify, version, export, and delete that file. The authentication identity used to sign in is handled by Auth0 and is separate from protected project content. We do not sell personal data or use protected content for advertising.
Service providers and data flow. Auth0 provides authentication. Railway hosts the production application and storage. AI clients you connect, including ChatGPT, Codex, and Claude Code, receive only the content needed for the FauxProof action you ask that client to perform. FauxProof acts only on content you explicitly provide or select for an action; it does not extract unrelated conversation history, AI memory, or unrelated uploaded content. When a supported host supplies a user-selected file, FauxProof retrieves only that exact short-lived host-authorized URL after hostname, redirect, DNS, network-address, byte-size, and content checks. A device upload may also be saved in the host's file Library; FauxProof keeps a separate encrypted project copy. Deleting the FauxProof copy does not delete a separate host-Library original, and deleting a host-Library original does not delete the FauxProof project copy. If you specifically ask FauxProof support to investigate a problem, support may access only the affected record or history needed to handle that request. Access tokens and short-lived file-link bearer tokens are verified for access control and are not stored as project content. FauxProof may process transient network/request metadata needed for authentication, abuse prevention, and rate limiting. FauxProof security-event telemetry records only an event type, timestamp, and a short process-local one-way correlation value; it does not record protected content, access tokens, email addresses, raw account identifiers, or raw IP addresses. Routine FauxProof request logging is disabled by default; when enabled, private picture and backup URL tokens are redacted. Data is encrypted in transit.
Local comparison, DriftStop Pro, and Source-Backed Fact Check. FauxProof's deterministic comparison stays within FauxProof. Quick Fact Scan also stays within FauxProof. Optional Pro checks send content to the OpenAI API only after you see the disclosure for that one run and explicitly consent. Selectable AI checks, including Voice Guard, AI Fact Check, Character / Story Consistency Check, and Brand Voice Profile, send the exact protected text, candidate text, selected check mode, applicable project rules, deterministic findings, and a one-way app-specific safety identifier. AI Fact Check uses AI general knowledge to flag possible factual issues; it does not search sources or prove truth. Source-Backed Fact Check sends the exact editable copy, searches public outside sources, and returns a plain-language review with clickable source links. These checks do not edit, approve, apply, or save wording, investigate people, or run background checks. FauxProof does not send this material autonomously or in the background. The requests use the OpenAI Responses API with store: false and explicit prompt-cache mode with no cache breakpoints, which disables retrievable Response storage and prompt-cache writes for that run. This is not a zero-retention claim: by default, OpenAI API abuse-monitoring logs may contain prompts and responses and may retain that content for up to 30 days unless the account has different data-retention controls. OpenAI states that longer retention may apply when required by law or reasonably necessary to protect its services or third parties from harm.
Retention. Protected project data is retained while your FauxProof application account remains active or until you permanently delete a file or project or a verified application-data deletion request is completed. Permanent project-file deletion removes that file from current project state, saved-version manifests, rolling metadata backups, and encrypted object storage; it does not affect a separate source stored by the host. FauxProof-created application backup files are operational safety copies; the current storage system keeps a rotating set of the 50 newest per-user backup files and does not claim an automatic age-based deletion period for an inactive account. FauxProof does not silently delete protected work merely because it is old. Authentication identity data remains with Auth0 while the corresponding sign-in account remains active. Railway currently retains platform logs for 7 days on Hobby, 30 days on Pro, and up to 90 days on Enterprise; FauxProof does not independently extend that platform-log retention.
Portable project backups. A complete .fpak export contains the project state plus every current or historical project file referenced by it, with per-file and whole-archive integrity checks. The downloaded archive is portable plaintext, not an encrypted vault; store it somewhere you trust. Its five-minute download link is bound to one account, project, and exact state version, and becomes invalid after expiry, project change, file deletion, or project/account deletion.
Timestamp content records. If you choose to create a timestamp content record, you must separately acknowledge that FauxProof will retain that record and its original PDF after the related project or account is deleted. The retained record contains the name you enter, project and protected-item titles, item types, dates, opaque identifiers, SHA-256 content fingerprints, and the record PDF, but not the protected text itself. Anyone holding the full unpredictable record number can check whether the record exists and whether current saved work matches, changed, or is unavailable; a changed result may name items listed in the record but never names items added later. PDF download is limited to the account that created the record, so download and keep the PDF when you create it; self-service PDF access ends if that account is deleted.
Your controls. You can export complete .fpak project backups at any time, open individual project files with a short-lived private link, and permanently delete an individual FauxProof file or an entire project from the review board. Email fauxproof.support@gmail.com to request deletion of your FauxProof application data, ask about a timestamp content record, or raise a privacy question. Deleting ordinary project or account data does not automatically remove a content record you explicitly chose to retain. Requests concerning a content record are verified and handled subject to applicable law; if a record must be removed, its online lookup will become unavailable.
Restricted data. Do not submit payment-card data, protected health information, government identifiers, passwords, API keys, MFA or OTP codes, or other authentication secrets to FauxProof.
FauxProof does not intentionally write protected document text, file content, or access tokens to routine application logs.