To check handling of uploaded voice, image and video data, start by defining the exact information or account action in scope. Then use the current provider notice and control rather than a memory of how the service worked before.
What this check covers
Treat biometric-style media and intimate uploads as higher-exposure inputs. The purpose is to turn a broad privacy concern into a bounded task you can document. A dated policy can show what a provider states. A visible setting can show that a control is offered. Neither alone proves every internal system, backup, processor or future change.
Keep the question narrow: what category of information, which account, which feature, which requested outcome and which date? That makes it easier to select the right control and to explain the issue if you contact support or a regulator.
A three-step action plan
- 1
Check upload, generation, moderation and removal policies before sending media.
- 2
Avoid real-person media without clear permission.
- 3
Keep the original file and request details if you later need to document a removal request.
Record only what helps you complete the task. Store confirmations securely. Do not publish account identifiers, request references, intimate conversations or another person’s information as “proof.”
How to read the evidence
The sources below play different roles. Provider pages describe the service’s own statements and available routes. Regulator and standards sources offer broader principles for minimisation, rights, accountability and sensitive-information risk. We label vendor material instead of treating it as independent verification.
Check dates and the actual page you plan to rely on. Product controls, legal terms and support routes can change. If a statement is important to your decision, save the page date and ask the provider to clarify anything vague. A successful web request only proves that a page was reachable when checked; it does not certify compliance or test an account.
Claims this guide does not make
We do not claim access to private systems, first-hand account testing, complete deletion, guaranteed confidentiality, guaranteed security, legal eligibility or regulatory approval. We also do not assume that a control has the same effect in every country or for every data category.
For a personal legal question, use an appropriate professional or regulator. For an account incident, secure the account and preserve a minimal record before taking irreversible steps. For real-person media, confirm adult status and specific consent; do not upload deceptive, non-consensual or ambiguous-age material.
Frequently asked questions
Does this prove an app is private?
No. Public policies and controls can be reviewed, but they do not prove every system behavior or future change.
Is this legal advice?
No. Rights and exceptions vary by place and circumstance. Use the provider’s current route and a relevant regulator for individual guidance.
Does deleting a screen guarantee complete erasure?
No. A visible action may have a narrower scope, and retention or backup exceptions may apply. Read the current notice and request confirmation.
Sources checked for this guide
- Candy AI privacy policyvendor policy · checked August 21, 2026
- Candy AI content removal policyvendor policy · checked August 21, 2026
- OWASP guidance on sensitive information disclosureindependent standard · checked August 21, 2026