NEWS
Verax AI Risk Assessment is live. See what's exposed
fotor
fotor
 
Risk Overview
Significant Risk
7.3
/10
Image Generation
·
Image Editing
·
Top Risks

Chinese company subject to PRC intelligence laws requiring government data cooperation; 2020 breach of 13M users with possible lack of user notification; disputes must be litigated in Chinese courts (Chengdu) making recourse impossible for most users; no SOC 2/ISO certifications; NowSecure flagged mobile app risks; data sovereignty risk is maximum for a non-China-classified company.

Mitigations

AIGC data stored on AWS US servers (not Chinese servers); explicit prohibition on face data use for training or identification; face data deletion available after use; company states it does not sell personal data to third parties; users can delete AIGC inputs; face data specifically protected from marketing use.

Get started
Is your team using 
fotor
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Legal Terms

Terms of Service governed by laws of the People's Republic of China. Disputes under jurisdiction of People's Court in Chengdu City, Sichuan Province. Users waive right to class-action lawsuits. Arbitration appears replaced by Chinese court jurisdiction which is far less favorable to international users. Extremely limited ability for non-Chinese users to seek legal recourse. No US/EU arbitration option — disputes must be litigated in Chinese courts, presenting a nearly insurmountable barrier for most users.
9
/10

Data Sovereignty

Chengdu Everimaging Science & Technology Co., Ltd. is a Chinese company headquartered in Chengdu, Sichuan, China. Subject to PRC's National Intelligence Law, Cybersecurity Law, and Data Security Law — all of which require data cooperation with Chinese state authorities. While AIGC data stored on AWS US servers, Chinese company must comply with PRC government data demands. Highest sovereignty risk category alongside other Chinese AI companies (similar to TikTok/ByteDance concerns).
9
/10

Security Posture

Critical security failures: 2020 breach exposed 13 million users' names, email addresses, and geolocation data in a publicly accessible database with no authentication required. It is unclear if users were ever notified of this breach. NowSecure mobile app security assessment flagged risks. No SOC 2 or ISO 27001 certifications found. No bug bounty program identified. Data stored partly on Chinese infrastructure. Chinese legal jurisdiction means security standards may not meet Western regulatory expectations. Most concerning security profile in this batch.
9
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.