Trust, Privacy & Responsible Use
How we handle your content, your data, and the responsibilities that come with running a moderation API.
Content handling
- Nothing is retained. Images live only in request memory. Video frames exist only for the minutes it takes to reach a verdict, then are deleted.
- We store verdicts, quota counters, and non-reversible content fingerprints — never your content.
- Verdict cache entries contain hashes and outcomes only; they cannot be reversed into imagery.
Data & infrastructure
- All traffic is encrypted in transit (TLS). API keys are stored as SHA-256 hashes; full keys are shown once at creation and never recoverable by us.
- Processing runs on GPU infrastructure we operate, plus European cloud for extraction. Video is fetched from your URL over HTTPS wherever offered.
- Your media is never shared with any third party, and never used to train or improve any model.
- Regional and single-tenant processing is available under Private deployment.
Subprocessors
We use the following vendors to operate the service. None of them stores your media content.
- Hetzner Online GmbH (Germany) — API hosting, job queue, and video extraction; EU data centers. Video bytes pass through here transiently during analysis and are deleted within minutes of the verdict.
- Cloudflare, Inc. (US) — DNS, DDoS protection, and the TLS-terminating edge proxy in front of the API; request traffic (including uploaded image bytes) transits Cloudflare but is not stored by them.
- Resend — transactional email (verification links, API key delivery). Receives your email address only.
- Polar — billing and subscriptions. Receives billing details and usage counters (image counts, video-minutes), never content.
This list is updated when vendors change; material changes are announced to affected customers by email.
Responsible use
- SafeReel flags pornographic content. It does not offer CSAM detection and makes no age determinations.
- Using the API to find explicit content rather than filter it violates our terms and gets keys revoked.
- We operate hash-matching against known-illegal-content lists. A match triggers our escalation procedure, including reports to the appropriate hotlines where the law requires.
- We do not sell, rent, or analyze your usage beyond operating quotas and abuse prevention.
Security & availability
- Public status page: /status.html; availability incidents get a postmortem within 48 hours of resolution.
- Report vulnerabilities or abuse to [email protected] — see Security for our disclosure policy, infrastructure practices, and incident-response commitments. General support: [email protected].
- Formal DPA available on request for paid plans. SOC 2 is on the roadmap and not claimed today.