Privacy
Privacy information
Version 2026-08-07-v2. Complete the controller identity, processor locations and retention schedule before production and obtain legal review.
1. Controller
Controller: FORENLYX, DEINE STRASSE 1, 86150 AUGSBURG, DEUTSCHLAND. Privacy contact: privacy@forenlyx.com.
2. Account and authentication data
We process email address, display name, authentication status, security factors, consent records and security events to create and protect the account and provide the service.
3. Media analysis
Supported image files are processed server-side for the requested authenticity analysis. The original file is not written to FORENLYX persistent storage by default. A reduced copy may be transmitted to the configured visual-analysis provider for visual observations relevant to AI-generation and editing assessment.
Stored authenticity reports can include file name, size, SHA-256 hash, technical properties, metadata/provenance, observations, assessments, limitations, module status and analysis timestamps.
4. Billing
For paid subscriptions we process plan, subscription status, billing period, customer and subscription identifiers. Payment-card data is handled by the payment provider and is not stored by FORENLYX.
5. Purposes and legal bases
Processing is carried out to perform the contract and pre-contractual measures, comply with legal duties, protect the service against abuse and, where required, on the basis of consent. Optional marketing consent is separate and can be withdrawn.
6. Processors and transfers
Configured providers can include Supabase for authentication and database services, OpenAI for visual analysis, Stripe for billing, an SMTP provider for transactional email and Cloudflare Turnstile for bot protection.
The final production notice must identify the actual providers, processing locations, safeguards and international-transfer mechanisms used by the deployed service.
7. Retention and deletion
Stored analysis reports are technically limited by plan: Trial 7 days, Core 90 days and Professional 365 days; Team retention is not time-limited while that plan configuration applies. A server-side maintenance routine physically removes expired reports and must be scheduled in production.
When an account is deleted, the Supabase Auth user and account-bound profile, report, usage, legal-acceptance and subscription mappings are removed. FORENLYX keeps only bounded, pseudonymised audit or unresolved consumer-request records where the documented retention schedule requires them. Local Stripe identifiers are redacted and, once no open subscription exists, FORENLYX requests deletion of the Stripe Customer object. Stripe can retain or redact payment-related data where its legal, fraud or operational duties require this.
8. Rights
Depending on applicable law, data subjects may request access, correction, deletion, restriction, portability and objection, withdraw consent and lodge a complaint with a supervisory authority.
9. Cookies and device storage
FORENLYX uses technically necessary authentication cookies to maintain secure sessions. The application does not currently persist optional analytics, advertising or marketing identifiers in browser storage. If non-essential technologies are introduced later, they must remain disabled until the required consent mechanism is in place.
10. Security
FORENLYX uses access controls, row-level security, encryption in transit, server-side quota checks, bot protection and optional multi-factor authentication. No online service can guarantee absolute security.