Transparency
This page says what SIMA does, what it does not do, and exactly what its record proves. It is written to be read by someone who is not an engineer.
SIMA does not detect AI
This is the core rule, so it goes first. SIMA does not examine an image to decide whether it was made with AI. There is no such check inside the product, hidden or otherwise.
A person declares; the tool records. You look at each image and say what it is: not AI, AI-generated, or AI-edited. SIMA takes that declaration, signs it into the chain, and applies the official EU label to the copy.
No detection tool is reliable enough to carry a legal declaration. So SIMA does not pretend to have one.
What a declaration holds — and what it does not
Each declaration holds: which image it is about, what was declared, which account declared it, exactly when, an optional note, and two signatures — its own and the previous declaration's, which is what binds them into a chain.
It holds no analysis of the image, no probability score, and no opinion from the system. There is no such field.
Declarations are append-only. They are never deleted or edited — not even by us. If you change your mind, a new declaration is written and the record shows both. That is deliberate: a record that can be altered afterwards proves nothing.
For your sign-in we keep an IP address and browser identifier, as any login system does. Those belong to the session, not to the declaration.
The chain and the timestamp: what they prove
Each declaration is signed together with the one before it. Altering an old declaration breaks every signature after it, so it shows immediately.
But the chain runs on our own machines, so on its own it cannot prove when something was written. That is why the head of the chain is sent to an independent time-stamping authority, which signs it with its own clock. The date is not our assertion.
You can download the raw proof and check it with openssl, without us. If checking it required us to still exist — and to still be honest — it would not be doing its job.
What it does NOT prove: it does not prove the declaration is correct. It does not prove an image is or is not AI. It says nothing about what happened before the declaration. It proves that you declared this, then, and that nobody has changed it since.
The record also shows how many declarations the latest timestamp covers. Any written after it are shown as not yet timestamped, rather than implying the whole record is covered.
Where SIMA uses AI
Nowhere. There is no AI model inside SIMA, ours or anyone else's. No image, no text and no customer data is sent to an AI service.
SIMA does four things, all deterministic: it reads your pages to find images, it computes signatures, it composites the official label onto a copy, and it writes the record.
Because there is no conversational or generative element, there is no Article 50 disclosure owed to you. The transparency duty SIMA serves is yours, towards your audience.
What scanning your site does
Scanning reads what a browser reads. It identifies itself as SIMA/1.0 with a link to a page explaining what it does, and it respects robots.txt: if you disallow it, it stops.
For each image it finds we keep details, not the file itself: its address, the pages it appears on, its dimensions, its type, and a signature of its content.
A copy of the image itself is kept only when you declare it as AI — then we store both the original and the labelled copy, as evidence of exactly what was declared and how the label looked, even if you later remove the image from your site.
Scanning never reaches internal addresses. Every outbound request is checked at the moment the connection opens, and internal addresses are refused.
Who can read your records, and for how long
Every database query is restricted to the signed-in user's organisation, inside the query itself. A request for another customer's record answers "not found" — it does not even confirm the record exists.
Stored copies are kept under a path that begins with your organisation's identifier.
Duration: declarations and timestamps are permanent — that is the point of them as an evidence record. Email verification codes are stored hashed and expire after 30 minutes.
SIMA does not sell, rent or share customer data. There is no code that sends it anywhere else.
What this service is not
SIMA does not give legal advice. It does not decide whether you are compliant, and it does not shield you before a regulator or a court.
You decide what is AI. SIMA applies the European Commission's official label — verbatim, never redrawn by us — and keeps the record of your decision.
For what the law requires and of whom, see the "What applies" page, where every claim carries its source.