WUSIR|← Back to WUSIR

Privacy Policy

Last updated: 25 August 2026

This policy describes, as accurately as we can, what WUSIR actually does with your data. It is provided in good faith and is not a substitute for legal advice; if you rely on this page for compliance purposes, have it reviewed by a qualified lawyer in your jurisdiction.

1. Who we are

WUSIR ("we", "us") operates the website at wusir.tech, the WUSIR mobile app, and the underlying detection API. The data controller responsible for the processing described below is:

[CONTROLLER NAME] · [ADDRESS] · [COUNTRY]
Contact: info@wusir.tech

2. What we collect, and why

a) Image detection (website & API)

When you upload a file or paste a URL to be analysed, the image is held in memory only for the duration of the analysis and is never written to disk or stored by us. We do not keep a copy of your images and do not use them to train any model. We do keep a lightweight usage log of each analysis — timestamp, which endpoint was used, and the result (prediction, confidence score) — with no image content and no identifier that lets us link a log entry back to a specific person.

b) Provenance Registry (WUSIR app & website lookup)

The WUSIR app lets you cryptographically register a photo at the moment it is captured, using your device's Secure Enclave and Apple App Attest. Doing so submits: a SHA-256 hash and a perceptual hash of the file, a device signature and device-identity keys, a capture timestamp, and — only if you choose to include it — GPS coordinates and a self-chosen user ID. This data is stored so that anyone (via the website or API) can later look up that exact file hash and see whether it was registered, when, and with what device-signed and self-reported details. Because this is a provenance/authenticity record, entries are designed to be tamper-evident and are not silently editable — see "Your rights" below for how erasure requests are handled.

c) Website analytics

We run our own self-hosted analytics (Umami) on infrastructure we control. It does not use cookies, does not use any persistent identifier, and cannot follow you across other websites. It gives us aggregate, non-identifying figures such as page views, referrers, and approximate country of visitors. No data is shared with Google, Meta, or any other third-party analytics or advertising network.

d) Correspondence

If you email info@wusir.tech, we keep that correspondence (hosted on our own mail server) for as long as needed to handle your request and any follow-up.

3. Legal bases (GDPR Art. 6)

  • Detection service and usage logs: performance of a contract / legitimate interest in operating and improving the service.
  • Provenance Registry: consent — registering a photo, and especially including GPS data, is an explicit, opt-in action you take in the app.
  • Analytics: legitimate interest in understanding aggregate, non-identifying usage of the site.
  • Correspondence: legitimate interest in responding to you, or performance of a contract if your request relates to one.

4. Retention

  • Uploaded images: not retained — discarded immediately after analysis.
  • Detection usage logs: contain no personal identifiers; kept in aggregate for product analytics.
  • Registry entries: kept for the working life of the registry, as its purpose is to provide a durable provenance record. You can request removal of the self-reported fields (GPS, user ID) associated with your device — see Section 6.
  • Correspondence: kept only as long as reasonably needed to resolve your request.

5. Where your data is processed

Our servers are hosted with Contabo GmbH in Germany (European Union). For visitors inside the EU/EEA, your data does not leave the EU. For visitors outside the EU/EEA, using WUSIR means your data is transferred to and processed in the EU, which — unlike the reverse direction — is not something GDPR restricts. We do not use any third-party AI or cloud API to analyse your images: all detection models run on our own servers.

6. Your rights

Wherever you are in the world, you can ask us — at info@wusir.tech — to: tell you what data we hold about you, correct it, delete the self-reported fields you supplied (GPS, user ID), export what we hold in a portable format, or object to a particular use of it. If you are in the EEA, UK, or Switzerland, these are your rights under the GDPR/UK GDPR, and you may also lodge a complaint with your local data protection authority. If you are in another jurisdiction with its own privacy law (for example the CCPA in California), we extend the same rights to you as a matter of policy, not just where legally required.

7. Children

WUSIR is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will remove it.

8. Security

All traffic to wusir.tech and our API is encrypted in transit (TLS/HTTPS). Registry entries are protected by device-level cryptographic attestation (Secure Enclave signatures, Apple App Attest) so that entries can't be forged by a compromised client. We don't store uploaded images at all, which limits what there is to protect in the first place.

9. Changes to this policy

If we materially change how we handle your data, we'll update the date at the top of this page and, where the change is significant, note it on the site.

10. Contact

Questions or requests about this policy: info@wusir.tech