SourceTrace uses submitted images only to perform the search you requested. It does not train models on your work or add uploads to generative-art datasets.
Uploaded images are validated, decoded, and re-encoded into metadata-stripped PNG working copies. The original upload bytes are not written to storage. Working copies and derived variants are retained with the search so its public evidence record stays inspectable. Do not submit private, confidential, or unpublished work.
Retention can be configured by an operator. The default keeps search records indefinitely; setting a positive retention period enables scheduled cleanup of both files and database records.
SourceTrace does not use uploaded artwork to train or fine-tune models, imitate an artist's style, build image-generation datasets, or sell or license submitted images. Your upload is processed only to find public matches, inspect attribution evidence, and produce the report you requested.
Live searches use external API services for visual lookup, visible-text extraction, and bounded evidence review. Only the information needed for the requested operation is sent. These API calls are server-side and are not a contribution to a SourceTrace training dataset.
A completed search with a cautious creator attribution can contribute the artist name, public handles, source links, confidence label, and a submitted-image thumbnail to the public artist index. Weak Match and failed searches do not create public profiles.
Repeated uploads are collapsed by file or visual fingerprint when counting distinct images. Public profile connections are evidence leads, not legal authorship records, and can be challenged through the correction process. Do not submit private, confidential, or unpublished work.
Community-supplied source and direct-image URLs are checked against the same public-network safety rules. A direct Reddit image fallback must use Reddit's media hosts and is disclosed separately from page-exposed metadata.
SourceTrace extracts a constrained set of metadata for attribution analysis before creating the stripped working copy. GPS fields, maker notes, and other sensitive or unbounded EXIF structures are deliberately excluded. Stored paths never appear in public API responses.
In live mode, SourceTrace sends the metadata-stripped working image to external search and text-reading APIs. Those services return indexed matching-page leads and visible text needed for the search. SourceTrace may then fetch a public candidate image into bounded server memory to compare its pixels and structure with the submitted working image before inspecting public page metadata.
API credentials remain on the server and are never sent to the browser. External API services process requests under their own privacy and retention terms, so private, confidential, or unpublished work should not be submitted.
Only HTTP and HTTPS resources are accepted. Localhost, private networks, link-local ranges, cloud metadata endpoints, embedded credentials, and non-public DNS results are blocked. Redirects, time, and response size are limited.
SourceTrace does not bypass authentication, CAPTCHAs, paywalls, robots restrictions, or platform access controls, and it never executes scripts from inspected pages.