IAMF Validator

PRIVACY · 6 OCTOBER 2026

Your file, in your browser.

The application processes selected file ranges locally and keeps the report in the current page session.

What happens when you select a file

A browser Worker reads the ranges needed for supported metadata inspection. The application does not send your file, excerpts, filename, path, report, or file fingerprint to a server. It does not modify the source file.

Application code and the bundled example load from the website’s own origin. Choosing “Load example” downloads that example before sending it through the same local analysis path as a selected file.

Reports and filenames

The filename is shown in your current session so you know what you selected. JSON and TXT exports omit the filename and embedded text labels by default. You can explicitly include both with the export checkbox. A copied summary does not include either.

Downloads are created locally in your browser. Once you share a report, its recipient can read the technical metadata and evidence it contains. Results do not receive public or indexable report URLs.

Clear and cancel

Cancel terminates the active Worker or example request. Clear also releases the application’s file reference, report, and selection state. Refreshing or leaving the page ends the session. The application does not save reports or file handles to localStorage or IndexedDB.

Accounts, plans, and credits

Registration and sign-in use a one-time email code. Your email, any name supplied, and the code you enter go to the account service over the website connection. The configured SMTP provider delivers the code to your email; that provider processes the recipient address and email contents. Codes expire after five minutes and are stored hashed by the account service. The service also stores resend and rate-limit records to control repeated requests.

The service stores your verified account, session records, assigned plans, and credit activity. No password is requested by the current sign-in flow. Existing account and billing records are retained when you switch to code sign-in. An HTTP-only session cookie keeps you signed in; signing out invalidates the session.

Starting a file analysis sends the product identifier, an opaque request identifier, and the displayed credit price to the server for authorization. This request contains no file content, filename, metadata, fingerprint, or report. Administrators can configure credits and plans and manage account entitlements. The bundled example is free.

PayPal payments

Choosing a paid plan sends its identifier, an opaque request identifier, and the displayed payment amount and currency to our server. Checkout redirects you to PayPal, where PayPal processes your payment information under its own privacy policy. Our server sends PayPal the order amount, currency, plan description, and an opaque order reference; it does not send media, filenames, or reports.

We store order references, amounts, payment status, purchased entitlements, and refund or reversal review flags linked to your account. We do not collect or store card numbers. Payment notifications are verified with PayPal before processing. The browser uses sessionStorage to retain your pending checkout reference and quoted amount for retries in the current tab.

Website statistics

We use self-hosted Plausible at stats.actify.cc to measure page views, engagement, outbound link clicks, downloads of public website files, and form submission counts. These statistics do not include form field values, email addresses, verification codes, media files, or report contents.

Page URLs, referrers, and outbound link URLs have query strings and fragments removed before statistics are sent. This analytics setup does not use cookies or cross-site identifiers. The statistics service may process IP addresses and other connection metadata to generate aggregate statistics.

The application does not use advertising scripts, session replay, or a remote media analysis service. Its parsing path does not use an LLM. Like any website, ordinary requests may expose connection information such as an IP address to the host; authentication sessions may also retain connection information for security. Following a source link opens that source’s website and its privacy policy applies there.

Local processing has limits

The parser applies boundaries and budgets to untrusted binary data and can stop when coverage is insufficient. Local processing does not establish that a media file is safe for every other application. See the implemented scope and limitations.