Skip to content

Transparency Report

Q4 2025 (October - December 2025)

Published: December 31, 2025 | Next Report: March 31, 2026


Executive Summary

This is qwip's first quarterly transparency report. We publish these reports to maintain accountability and demonstrate our commitment to user privacy.

Key Highlights:

  • ✅ Zero government data requests
  • ✅ Zero data breaches
  • ✅ Zero user privacy complaints
  • ✅ Zero data sold or shared with third parties

1. Government Requests for Data

Summary

Request TypeCountData ProvidedUsers Affected
Law Enforcement Requests0N/A0
National Security Letters0N/A0
Court Orders/Subpoenas0N/A0
Foreign Government Requests0N/A0

Total: 0 requests in Q4 2025

Our Policy

If we receive a data request:

  1. Evaluate legality - Ensure request has proper legal basis
  2. Minimize disclosure - Only provide what's legally required
  3. Notify users - Unless legally prohibited (gag order)
  4. Challenge if necessary - Push back on overly broad requests
  5. Report publicly - Include in next transparency report

What data could we provide?

  • Anonymous session IDs (not useful for identification)
  • Image hashes (cannot reverse to images)
  • Aggregate statistics (no individual data)

What we CANNOT provide:

  • User identities (we don't have this)
  • Images (never stored)
  • Browsing history (never tracked)
  • Personal information (never collected)

Commitment

We have never:

  • Built backdoors into our service
  • Weakened security at government request
  • Provided bulk access to data
  • Participated in mass surveillance programs

We will always:

  • Require proper legal process
  • Notify users unless gagged
  • Report requests publicly
  • Fight overly broad requests

2. Data Breaches

Summary

Q4 2025: 0 breaches

All Time: 0 breaches

What Counts as a Breach

We consider a breach any:

  • Unauthorized access to our systems
  • Data exfiltration (even anonymous data)
  • Security vulnerability exploited
  • Accidental data exposure

If a Breach Occurs

Our response plan:

Within 24 hours:

  1. Contain the breach
  2. Assess scope and impact
  3. Begin forensic investigation

Within 72 hours:

  1. Notify affected users (if any)
  2. Notify supervisory authorities (GDPR requirement)
  3. Publish public disclosure

Within 30 days:

  1. Complete investigation
  2. Publish detailed post-mortem
  3. Implement preventive measures
  4. Third-party security audit

What Would Be Compromised

In a worst-case server breach:

Attacker could get:

  • Anonymous session IDs (random UUIDs)
  • Image hashes (cryptographic, can't reverse to images)
  • Detection results (AI/Real labels)
  • Aggregate statistics

Attacker could NOT get:

  • ❌ User identities (we don't have them)
  • ❌ Images (never stored)
  • ❌ Personal information (never collected)
  • ❌ Anything that identifies specific users

Impact assessment: Very low (no personal data to leak)


3. User Rights Requests

Summary

Request TypeCountAverage Response Time
Access Requests (GDPR Art. 15)0N/A
Deletion Requests (GDPR Art. 17)0N/A
Portability Requests (GDPR Art. 20)0N/A
Objection Requests (GDPR Art. 21)0N/A
CCPA Access Requests0N/A
CCPA Deletion Requests0N/A
General Privacy Inquiries0N/A

Total: 0 requests in Q4 2025

Note: This is our launch quarter. Most users clear session data directly in settings (immediate, no request needed).

Our Commitment

Response times:

  • GDPR requests: Maximum 30 days (target: 7 days)
  • CCPA requests: Maximum 45 days (target: 15 days)
  • General inquiries: Maximum 5 business days

We will:

  • Honor all legitimate requests
  • Provide clear explanations
  • Never charge fees for basic requests
  • Verify identity without collecting additional data

4. Third-Party Data Sharing

Summary

Q4 2025: Zero data shared

Service Providers:

ProviderPurposeData SharedJustification
NoneN/AN/AN/A

Our Policy

We do not:

  • ❌ Sell data to anyone
  • ❌ Share data with advertisers
  • ❌ Provide data to data brokers
  • ❌ Use third-party analytics (Google Analytics, etc.)

Future third-party services: If we add service providers (e.g., cloud hosting, CDN), we will:

  • List them in this report
  • Ensure strong data processing agreements
  • Limit data access to minimum necessary
  • Require GDPR/CCPA compliance

5. Privacy Complaints

Summary

Q4 2025: 0 formal complaints

Categories:

Complaint TypeCountResolution
Data collection concerns0N/A
Tracking concerns0N/A
Deletion requests not honored0N/A
Other0N/A

How to File a Complaint

Contact us: privacy@qwip.io

Or file with:

  • EU: Your national Data Protection Authority
  • UK: Information Commissioner's Office (ICO)
  • California: Attorney General's office

6. Platform Statistics (Anonymous)

These statistics help demonstrate our platform's growth while protecting user privacy.

Usage Statistics

MetricQ4 2025Notes
Total Installations[To be added]Chrome Web Store data
Active Users (DAU avg)[To be added]Anonymous session count
Images Analyzed[To be added]Aggregate count
AI Detection Rate[To be added]% flagged as AI

Note: First quarter launch data. Will populate in future reports.

Geographic Distribution

We do NOT track:

  • IP addresses
  • Location data
  • Country of origin

We CAN estimate (from aggregate data):

  • Approximate region (if users enable server queries)
  • Time zone distribution (from query timestamps)

Q4 2025: Data not yet available (initial launch period)


7. Security Incidents

Summary

Q4 2025: 0 security incidents

What Counts

We report:

  • Security vulnerability discoveries
  • Attempted intrusions (even if unsuccessful)
  • DDoS attacks
  • Service outages due to security issues

Vulnerability Disclosures

Responsible disclosure policy:

If you discover a vulnerability:

  1. Email: security@qwip.io
  2. We'll acknowledge within 48 hours
  3. We'll fix critical issues within 7 days
  4. We'll credit researchers (with permission)

Q4 2025: No vulnerabilities reported


8. Policy Updates

Changes to Privacy Practices

Q4 2025: No changes

Initial documentation published:

  • Privacy Overview
  • Data Collection Practices
  • Security Practices
  • Compliance (GDPR/CCPA/COPPA)
  • User Rights
  • This Transparency Report

Notification of Changes

We will notify users if we change:

  • What data we collect
  • How we use data
  • Data retention periods
  • Third-party sharing

Notification methods:

  • Extension update notification
  • Updated documentation (with changelog)
  • This transparency report

9. Regulatory Compliance

Compliance Status

RegulationStatusLast Reviewed
GDPR (EU)✅ CompliantDecember 2025
UK GDPR✅ CompliantDecember 2025
CCPA (California)✅ CompliantDecember 2025
COPPA (USA)✅ CompliantDecember 2025
PIPEDA (Canada)✅ CompliantDecember 2025
LGPD (Brazil)✅ CompliantDecember 2025

Regulatory Inquiries

Q4 2025: 0 inquiries from regulators

If we receive inquiries:

  • We'll respond within required timeframes
  • We'll cooperate fully
  • We'll report outcomes publicly (unless prohibited)

10. Open Source & Audits

Code Transparency

GitHub Repository: https://github.com/yourorg/qwip

Q4 2025 Activity:

  • ✅ Full codebase published
  • ✅ Privacy documentation added
  • ✅ Security audit (internal)
  • 🚧 Third-party audit (planned Q1 2026)

Community contributions welcome:

  • Security reviews
  • Privacy audits
  • Code improvements

Security Audits

Planned:

  • Q1 2026: Professional third-party audit
  • Q2 2026: Penetration testing
  • 2026: SOC 2 Type II preparation

11. Metrics & Accountability

Privacy-First Metrics

We measure success by privacy protection, not data collection:

MetricTargetQ4 2025
Data breaches0✅ 0
Government requests0✅ 0
User complaints<10✅ 0
Response time (requests)<7 daysN/A
Code audit frequencyQuarterly✅ Q4

Improvement Goals

Q1 2026:

  • Complete third-party security audit
  • Implement certificate pinning
  • Add per-install API keys
  • Launch bug bounty program

12. Contact Information

Questions about this report: privacy@qwip.io

Security concerns: security@qwip.io

General inquiries: hello@qwip.io

Supervisory authority complaints:

  • EU/EEA: Your national DPA
  • UK: ICO
  • California: Attorney General

Commitment to Transparency

We publish these reports quarterly to maintain accountability.

Next Report: Q1 2026 (January - March 2026)

  • Publication date: March 31, 2026
  • Will include comparison to Q4 2025

Historical Reports:

  • Q4 2025 (this report)
  • Q1 2026 (March 2026)
  • Q2 2026 (June 2026)
  • Q3 2026 (September 2026)

Certification

This transparency report accurately reflects qwip's data practices for Q4 2025 to the best of our knowledge.

Signed:

[Signature space for team lead/CEO when applicable]

Date: December 31, 2025


Published under: Creative Commons Attribution 4.0 (CC BY 4.0) Archived at: https://github.com/yourorg/qwip/transparency-reports/


Transparency is not just disclosure - it's accountability.

Open source and privacy-first