Privacy policy for Phan0s — Deepfake Detector
Phan0s — Deepfake Detector by CADMUS Cyber Solutions
Phan0s Browser Extension Privacy Policy
Effective Date: July 17, 2026
CADMUS Cyber Solutions Limited ("CADMUS", "we", "us", or "our") operates the Phan0s browser extension, an advanced media forensics and deepfake detection engine. This Privacy Policy details our operational data handling methodologies, infrastructure security protocols, and strict retention limits designed to safeguard user privacy while executing biometric and cryptographic analysis via our browser extension.
By installing and interacting with the Phan0s browser extension (the "Extension"), you explicitly consent to the collection, processing, and strict automated disposal of data as described herein.
The Extension requires specific browser permissions to function securely. We operate under a principle of least privilege and do not passively track your browsing history or monitor background tabs.
- ActiveTab & Scripting: The Extension only accesses the webpage you are currently viewing when you explicitly click the extension icon and initiate a scan. It reads the active URL (for supported platforms like TikTok, X, Facebook, and LinkedIn) or uses local scripting to extract raw
<video>binary data on unsupported pages. - Storage: We utilize local browser storage (
chrome.storage.local) exclusively to maintain temporary UI state data (e.g., tracking an active analysis job ID) so the extension can recover gracefully if closed or if the background worker sleeps. - Notifications & Offscreen: These permissions are used strictly to deliver local desktop alerts and audio cues when an analysis is completed.
The fundamental core of the Phan0s data framework is privacy-by-design. We maintain a strict Zero-Retention Policy for any media routed through the Extension.
- Processing Isolation: When the Extension dispatches a URL or uploads an extracted video payload (the "Payload"), it is ingested securely and transferred to a volatile, temporarily isolated storage container on our secure cloud backend.
- Automated Deletion: The Payload is held exclusively for the brief duration required for the ensemble model pipeline to execute its diagnostic passes. Immediately upon completing feature extraction, standard deviation computation, and late-fusion analysis, the entire Payload is automatically and permanently purged from our file servers.
- Persistent Exclusions: We do not permanently log, store, or warehouse raw user video frames, face-crop graphics, or raw audio waveforms.
To maintain system security, enforce architectural rate-limiting, and return processing logs to your Extension interface, we handle specific operational metadata:
- Cryptographic Hashes: We compute an automated SHA-256 hash of every submitted Payload. This hash is cross-referenced against a temporary 24-hour database cache to allow near-instantaneous query matching for duplicate identical files.
- Diagnostic Metrics: We log the resulting mathematical output metrics, including final confidence percentage scores, model variance indexes, elapsed processing times, file naming strings, and detected file dimensions/modalities.
- Network Ingestion Data: Our server nodes automatically capture basic network handshake metadata, including your Internet Protocol (IP) address, operating browser user-agent string, and timestamps of request initialization.
We implement robust, defense-in-depth technical safeguards to secure the data channel between your browser Extension and our API:
* Enforcing global Transport Layer Security (TLS 1.3) encryption on all inbound and outbound API payload streams.
* Utilizing a decoupled, queue-driven worker architecture to ensure inference computing nodes are fully isolated from direct public web exposure.
* Enforcing strict role-based access tokens (RBAC) governing administrative backends and database infrastructure.
- Cloud Processing: Phan0s infrastructure utilizes secure, high-assurance distributed cloud datacenters (including localized nodes on Microsoft Azure). Payloads are processed in transient pipelines that may route requests internationally depending on computing pool availability, executed strictly under robust security protections.
- Law Enforcement Compliance: Because we maintain a zero-retention policy for standard media payloads, we do not possess historical user upload archives to share with external parties. We will cooperate fully with valid judicial warrants issued by competent courts in Nairobi, Kenya, regarding operational metadata or active user accounts, provided the request adheres to legal requirements.
In compliance with the Kenya Data Protection Act (2019) and corresponding global data protection standards, users whose metadata or account records are managed by CADMUS possess the right to:
* Request confirmation of any personal identifier data or account histories we maintain.
* Request the immediate correction or total erasure of your user profile, account billing metadata, or active liaison emails.
* Withdraw your operational consent at any time by uninstalling the Extension and deleting your account.
CADMUS reserves the right to update this Privacy Policy to reflect changing security paradigms, new multi-modal model integrations, or evolving legislative frameworks. We will alert users to major revisions by advancing the "Effective Date" at the top of this document or via an Extension update notification.
Contact Us
For personal data inquiries, metadata erasure requests, or to contact our data protection officer, email: privacy@cadmuscyber.com