Last updated: March 24, 2026
IFP (Image Fingerprint Protection) is an independent research initiative by Jevgeni Striganov, based in Estonia, EU. This policy explains how IFP handles your data.
Jevgeni Striganov
Estonia, European Union
[email protected]
This email also serves as the contact point for all GDPR-related requests.
IFP processes your data on the following grounds under GDPR Article 6:
When you register, IFP stores your email address and display name. If you sign in with Google, IFP receives only your email and profile name — no other Google data is accessed. Google Sign-In is subject to Google's Privacy Policy and the Google API Services User Data Policy.
When you register an image through "Create Fingerprint," the original image is uploaded to IFP servers. The original is stored securely and used solely as a source for generating structural fingerprints and licenses.
IFP generates structural fingerprint data from your uploaded images. This data is used to identify matches when images are checked against the database.
When someone uses "Check Image," the uploaded query image is processed to search the database. Query images are deleted automatically within 24 hours after processing.
IFP records processing logs for each operation (registration, check, dispute) for debugging and quality assurance. Logs are retained for 90 days, then permanently deleted.
Only you have access to your original uploaded images through your account. Other users and visitors never see or download your originals.
When a match is found through "Check Image," other users see only a small thumbnail of the matched image along with the registered owner's display name. The original file is never exposed.
If you assign a license (LIC code) to an image, the license status and code are visible when a match is detected. This is by design — it allows others to verify licensing.
If a dispute is initiated, both parties see the dispute analysis (metadata comparison, scoring). Dispute records are stored as part of the ownership chain.
Images and fingerprint data are stored on dedicated servers located within the European Union. Data is not transferred outside the EU. Data is not shared with third parties, not used for AI/ML training, and not sold.
You can delete any registered image through the IFP interface. When you delete an image:
When images are deleted, anonymized chain metadata (timestamps, match records, license events) is retained as part of the forensic record. This data is stripped of personal identifiers and is designed to prevent re-identification. It exists solely to preserve the integrity of the historical chain.
To delete your entire account, contact [email protected]. Upon account deletion, all your images and fingerprint data are removed, licenses and protection cease, and remaining chain metadata is anonymized as described above.
As a user, you have the right to:
To exercise any of these rights, contact [email protected]. IFP will respond within 30 days.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee.
IFP currently operates in test mode. Fingerprint registrations are active for 3 days, after which they expire automatically. This limitation exists to prevent abuse — without identity verification (KYC), unrestricted permanent registration could allow bad actors to claim ownership of content they do not own. Permanent registration will require identity verification in future versions.
IFP uses essential cookies for authentication (session management) only. No advertising cookies, marketing trackers, or third-party analytics are used.
IFP is not intended for use by individuals under the age of 16. IFP does not knowingly collect personal data from anyone under 16. If you believe a minor has created an account, contact [email protected] and the account will be deleted.
In the event of a data breach that poses a risk to your rights and freedoms, IFP will notify affected users without undue delay and no later than 72 hours after becoming aware of the breach, in accordance with GDPR Article 33.
If this policy changes substantially, IFP will notify registered users by email at least 14 days before the changes take effect. The updated version will be posted here with a new date. For questions, contact [email protected]