Scanon.ai and the GDPR.
The short version
- We do not store uploaded media — files are processed in memory and discarded.
- We do not require an email, phone number, or real identity to use the redaction tool.
- EXIF metadata (including GPS) is stripped from outputs by default.
- All AI inference runs on our own infrastructure — your media is never sent to a third-party model API.
Why redaction is a GDPR-relevant tool
Under the GDPR, a recognizable face, a license plate, or a unique tattoo can constitute personal data — and in some contexts, biometric data — even when the person isn't named. Publishing or storing that content without a lawful basis can expose your organization to compliance risk. Scanon.ai helps journalists, NGOs, insurers, public bodies, and product teams apply data minimization at source by removing identifying features before media is shared, archived, or processed downstream.
Lawful basis and the controller / processor relationship
When you upload media to Scanon.ai, you act as the data controller for any personal data contained in those files. Scanon.ai acts as a processor for the brief moment your file is in memory, strictly to perform the redaction service you requested. Because no copy of your input or output is retained, our processing is bounded to a single in-memory operation.
Data subject rights
If you are in the EU, UK, or EEA, the GDPR grants you a number of rights over your personal data, including:
- The right to access, correct, or delete your personal data
- The right to restrict or object to processing
- The right to data portability
- The right to withdraw consent
- The right to lodge a complaint with a supervisory authority
Because Scanon.ai does not retain uploaded media or processed outputs, most of these rights apply only to limited account data (such as your anonymous account ID and Usage Data described in our Privacy Policy). To exercise any of these rights, email info@scanon.ai.
International transfers
Scanon.ai is operated by Unlimited Coverage Cybersecurity LLC in Delaware, United States. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards in line with Chapter V of the GDPR.
Data Processing Agreements (DPAs)
Business customers using Scanon.ai or the Scanon.ai API at scale can request a Data Processing Agreement. Contact us and we'll send the latest version.
Not legal advice
This page describes how Scanon.ai is designed and operated. It is not legal advice and does not substitute for an assessment by your own counsel or Data Protection Officer.
