Last updated: August 23, 2026
Privacy Policy
TamperCheck AI is the trade name of Guni Innovations Pte. Ltd. (collectively, “TamperCheck AI,” “we,” “us,” or “our”). We provide document fraud-detection and analysis services. Because our customers upload highly sensitive documents and authenticate with API keys, we are designed around minimal collection, strong security, and clear boundaries. This policy explains what we process, why, and your choices.
1. Introduction
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you interact with our websites, APIs, dashboard, and related services (collectively, the “Services”).
This Privacy Policy is intended to comply with applicable privacy and data protection laws, including the Personal Data Protection Act 2012 of Singapore (“PDPA”), the General Data Protection Regulation (“GDPR”) and UK GDPR (where applicable to individuals in the EEA or United Kingdom), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other applicable data protection legislation.
By accessing our websites or using the Services, you are informed of the practices described in this Privacy Policy. This Privacy Policy does not constitute consent to the processing of your personal data; where consent is required, it will be obtained separately in accordance with applicable law.
2. Who we are
Guni Innovations Pte. Ltd. is a technology company providing automated document fraud-detection and analysis services under the trade name TamperCheck AI. Our full contact details are in Section 18 below.
3. Our role in processing personal data
Depending on the context, TamperCheck AI may act as either a Data Controller or a Data Processor.
- Controller. We act as a controller for account, billing, website analytics, marketing, and support data that we collect and determine the purposes of processing.
- Processor. When you submit documents via the API or dashboard for analysis, we act as a processor on your behalf. You (or your organization) remain the controller/data fiduciary for that document content and must have a lawful basis to submit it for processing. TamperCheck AI processes such content solely for the purpose of performing the requested analysis and delivering results, in accordance with your instructions.
If you require a Data Processing Agreement for your compliance needs, please contact us.
4. Categories of personal data we process
| Category | Examples |
|---|---|
| Account & identity | Name, email address, profile details received via sign-in provider |
| Organization | Organization name, domain, industry, team membership |
| API keys | Key identifiers, secure hashes/prefixes, creation and revocation timestamps |
| Usage & billing | Request timestamps, job IDs, verdict summaries, wallet balance changes, error codes |
| Payment | Processed by our payment processor (e.g. Stripe); we do not store full card numbers on our systems |
| Support & communications | Emails, contact form submissions, feedback |
| Document content & analysis artifacts | Uploaded document bytes, extracted text, analysis results - retained only for the minimum period necessary to process and deliver results (see Section 7) |
| Website & technical | IP address, browser/device information, cookies, log files, analytics identifiers |
5. How we collect personal data
We may collect personal data:
- Directly from you, when you create an account, submit documents, or contact us;
- From identity and sign-in providers (e.g. Google OAuth), when you choose to authenticate through them;
- From our payment processor, to facilitate billing and transactions;
- Automatically through our websites and APIs, including via cookies and similar technologies; and
- From AI inference and OCR providers, solely as part of producing analysis results on your behalf.
6. How we use personal data
We process personal data to:
- Provide, operate, secure, and improve the Services;
- Process documents you submit and deliver analysis results;
- Authenticate API requests and prevent abuse;
- Process payments and maintain billing records;
- Respond to enquiries and support requests;
- Comply with legal and regulatory obligations;
- Communicate with you about the Services, incidents, or policy updates; and
- Improve and develop our products (without using your submitted documents to train AI models).
7. Document processing and retention
Purpose-limited processing. Document content you submit is processed solely to produce and deliver the requested analysis result. We do not use your documents to train AI models, for marketing, for resale, or for any purpose unrelated to providing the Services.
No document archive. We do not operate a customer document archive for re-download, batch analytics, or any secondary purpose. Document content is retained only for the minimum period necessary to process the job and deliver results, after which it is discarded from operational processing paths.
Operational reality. Like any file-processing service, transient infrastructure storage, logs, backups, or diagnostics may retain fragments for a short period beyond delivery. We apply technical and organizational measures to keep this window as short as practicable and to restrict access.
Job metadata. Metadata associated with analysis jobs (e.g. verdict, risk score, timestamps, job identifiers, error codes) may be retained for audit, billing, reliability, and abuse-prevention purposes. This is distinct from the document content itself.
If you require specific contractual commitments regarding data handling for your regulatory environment, please contact us to discuss a Data Processing Agreement.
8. Legal bases for processing
We rely on the following legal bases, depending on the nature of the processing and applicable law:
| Processing activity | PDPA / GDPR basis |
|---|---|
| Operating your account and providing the Services | Contract performance; legitimate purposes |
| Processing document content on your instructions | Customer's instructions (processor role); contract |
| Security, fraud prevention, abuse detection | Legitimate interests / legitimate purposes |
| Non-essential cookies and analytics | Consent (where required) |
| Tax, accounting, and regulatory record-keeping | Legal obligation |
| Marketing communications | Consent; legitimate interests (where permitted) |
9. Who we share personal data with
We may share personal data with the following categories of recipients, each engaged under appropriate contractual safeguards:
- Payment processors - to handle billing and transactions;
- Identity and authentication providers - to facilitate sign-in;
- Cloud hosting, storage, and CDN providers - to operate and deliver the Services;
- AI inference and OCR providers - solely to process analysis requests on your behalf;
- Email and messaging providers - for transactional and support communications;
- Bot and fraud protection providers - to prevent abuse;
- Analytics providers - to understand website usage and improve the Services;
- Professional advisors - including legal counsel and auditors, under confidentiality obligations; and
- Regulators and law enforcement - where required by applicable law or valid legal process.
All third parties that process personal data on our behalf do so under contract and are required to implement appropriate security measures. We do not sell personal data. A current list of subprocessors is available on request for security reviews and enterprise Data Processing Agreements.
10. International data transfers
We may process personal data in Singapore and in other countries where we or our subprocessors operate. Where cross-border transfers are required, we use appropriate safeguards consistent with applicable law, including:
- Contractual protections consistent with the PDPA transfer obligations;
- Standard Contractual Clauses approved by the European Commission (where GDPR applies); and
- Other safeguards as required by applicable data protection legislation.
Regardless of where data is processed, we implement appropriate technical safeguards including encryption in transit and at rest.
11. Data retention schedule
We retain personal data only for as long as necessary for the purposes for which it was collected:
| Data category | Retention period |
|---|---|
| Document content & processing artifacts | Minimum period necessary to complete processing and deliver results |
| Account & organization data | While your account is active, plus any period required by law |
| Billing and tax records | As required by applicable law |
| Job metadata (verdicts, timestamps) | While your account is active, for audit and service reliability |
| Support communications | As needed to resolve the request plus a reasonable follow-up period |
| Marketing & newsletter | Until you unsubscribe |
12. Your privacy rights
Depending on where you are located and applicable law, you may have rights in relation to your personal data, including:
- Access - to obtain a copy of your personal data;
- Correction - to have inaccurate or incomplete data corrected;
- Erasure / deletion - to request deletion of your personal data in certain circumstances;
- Portability - to receive your data in a structured, machine-readable format where applicable;
- Objection / restriction - to object to processing based on legitimate interests or to request restriction;
- Withdrawal of consent - where processing is based on consent, you may withdraw it at any time without affecting lawfulness of prior processing; and
- Complaint - to lodge a complaint with the relevant data protection authority (e.g. PDPC in Singapore, or your national authority under GDPR).
To exercise your rights, submit a Data Subject Access Request. We will respond within 30 days (or such shorter period as required by applicable law). We may need to verify your identity before processing a request. You can also revoke API keys and close your account from the dashboard where available.
California residents (CCPA/CPRA). If you are a California resident, you may have additional rights under the CCPA, including the right to know what personal information we collect and how it is used, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell or share (as defined by the CCPA) your personal information. To exercise your CCPA rights, submit a Data Subject Access Request. We will not discriminate against you for exercising your rights.
Document content processed as Processor. Where we process document content on behalf of an organization (as Processor), individuals should direct data rights requests to the organization that submitted the data. We will assist that organization in responding to such requests in accordance with applicable law.
13. Automated analysis
TamperCheck AI uses automated processes, including AI models, to analyze documents and produce outputs such as risk scores, verdict labels, and explanatory findings. These outputs are assistive tools designed to help you make informed decisions - they are not legal determinations, compliance certifications, or investigative conclusions.
You (or your organization) remain responsible for any decision made on the basis of TamperCheck AI outputs. No adverse decision affecting an individual should be made solely on the basis of automated outputs without appropriate human review.
If you believe an automated assessment has affected you and you wish to request human review, contact us at tina@tampercheck.ai with the subject line “Human Review Request” and include the job ID and the document concerned.
14. Security
We maintain appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. These measures include:
- Encryption of data in transit (TLS) and at rest;
- Role-based access controls and least-privilege principles;
- Secure handling of API keys (hashed storage; keys are not retrievable after creation);
- Monitoring, logging, and alerting for anomalous access patterns;
- Employee confidentiality obligations and security awareness; and
- Incident response procedures, including notification as required by applicable law.
No method of transmission or storage is 100% secure. We work continuously to reduce risk and to respond promptly if an incident occurs.
15. Cookies and similar technologies
Our websites and Services may use cookies, analytics scripts, and similar technologies. We use the following types:
- Strictly necessary - required to operate the Services (e.g. session authentication cookies). These cannot be disabled.
- Analytics - used to understand how visitors use our website and to improve the Services. These are set in accordance with applicable consent requirements.
- Preferences - used to remember settings and improve your experience.
You may manage cookie preferences through your browser settings. Disabling non-essential cookies will not affect your ability to use the core Services.
16. Children's privacy
The Services are intended for professional and business use and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take appropriate steps to delete it without undue delay.
17. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal obligations, or privacy practices. We will post the revised version on this page and update the “Last updated” date. Material changes will be communicated through appropriate channels (e.g. email or in-product notice) before taking effect.
18. Contact
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or raise a concern regarding the processing of your personal data, please contact us:
- Email: tina@tampercheck.ai
- Organization: Guni Innovations Pte. Ltd. (trading as TamperCheck AI)
- Registered address: 68 Circular Road #02-01, 049422, Singapore
See also our Terms of Service.