Privacy

GPTTrace was built so that checking a file never means giving it away. Everything happens in your browser tab.

What happens when you check a file

When you drop an image, audio file or video, your browser reads it from your disk into memory inside the tab. GPTTrace’s JavaScript parses the metadata, decodes the pixels or audio, and runs the forensic checks and neural models in Web Workers on your own processor. The result is drawn on the page. When you close the tab, it’s gone. Text works the same way: it is analysed where you pasted it.

There is no upload step, no server-side processing and no account. GPTTrace’s servers deliver static files — HTML, CSS, JavaScript, WebAssembly and model weights — and nothing else.

How you can verify that

Open your browser’s developer tools, switch to the Network tab and check a file. You will see requests that download GPTTrace’s scripts and, the first time, the model files. You will not see any request that sends your file or text. The site also sets a Content Security Policy that restricts the page’s connections to GPTTrace itself and the model mirrors, so even a bug or a compromised script could not post your data elsewhere. The exceptions are the analytics services described below, which receive page-view information, never file contents.

Because everything runs locally, GPTTrace keeps working with the network switched off once the page and models have loaded.

What we do collect

Nothing about the content you check. The hosting provider keeps standard request logs for security and reliability. We use two analytics services to understand how the site is used. Cloudflare Web Analytics is cookie-free and records page views, referring sites, browser type, country and page-load timings. Google Analytics 4 records similar page-view information and sets first-party cookies to recognise returning visitors; Google’s handling of that data is described in its own privacy policy. Neither service receives anything you analyse — no file, text, result or file name is ever sent. You can block both with any standard content blocker without affecting the detectors.

Third parties

GPTTrace loads no third-party fonts or widgets. The only third-party scripts are the two analytics tags described above. The optional text model may be downloaded from Hugging Face, which sees an ordinary file request from your browser.

Questions about privacy can be raised through the contact details on our home page.

Frequently asked questions

Do you keep logs of what I check?
We have no way to: the file or text is never sent to us. Like any website, the hosting provider records ordinary request logs (which pages and scripts were requested), but not the content you analyse.
Do you use cookies or trackers?
We use Google Analytics, which sets first-party cookies to count visits and see which pages people find useful, and Cloudflare Web Analytics, which is cookie-free. Neither ever receives the files or text you check. GPTTrace has no advertising trackers. Your browser’s local storage also remembers whether the neural models are switched on.
What about the neural models?
They are downloaded to your browser and cached, like an image or a font. Model files only travel from the server to you. The image model is served from GPTTrace itself; the larger optional text model comes from our model mirror or Hugging Face.
Can I use GPTTrace for confidential material?
Yes — that is what it was designed for. Journalists, investigators and teachers can check sensitive files without exposing them to a third-party service. For the strongest assurance, load the page, disconnect from the network, and run your checks offline once the models are cached.