01Aurea / Sage
02NAZO OS
03 · CYPHR · PRODUCT · AI

Shipped a solo AI image detector, and caught a false privacy claim before a single user paid.

CYPHR tells you whether an image is AI-generated in under 10 seconds with 97.4% accuracy, right in your browser or on your phone, so you do not need another app to find out whether what you are scrolling past, or about to buy, is real.

ROLE
Product · UX · Build
TIMELINE
2026
View the live site →
CYPHR preview
THE SETUP

AI images started flooding the feeds where people buy handmade.

In 2024, AI-generated images flooded crochet and craft communities: “handmade” pieces with stitch patterns that do not obey the physics of real fiber. Existing detection tools were clunky standalone sites built for technical users, not someone mid-scroll deciding if a photo is real.

A solo project: strategy, UX, visual design, copy, pricing, legal docs and infrastructure all on one person. One year into product design after six years in healthcare account management, no engineering team and no budget for a hire, so every build-versus-buy call was mine to make.


KEY DECISIONS

Three decisions shaped the build.

01

Confidence score, not a binary verdict.

Competitor tools return AI or Not-AI with no nuance, and a binary verdict stated as fact on a nuanced result is itself a form of misinformation. So I built CYPHR to return a confidence percentage with an expandable signal breakdown. The audience that needs this most, journalists and researchers, needs a citable, qualified output, not false confidence.

02

A browser scan page, not a native app.

Chrome extensions cannot run on mobile browsers, so mobile users had no way to use CYPHR. A native app adds friction at exactly the wrong moment: someone mid-scroll with a doubt about one image will not stop to find an app store. So I built a mobile web page on the same backend. No install, works the moment someone taps a link.

03

Cut a feature instead of softening a claim.

The live site said “on-device, no uploads.” It was not true: images route through Google’s Gemini API. I disclosed it directly, cited Google’s data policy, confirmed CYPHR had not opted into data sharing, and removed “scan history” entirely, because you cannot promise not to store what is scanned while offering a history of it. I took the harder path before a single user had paid.


THE WORK

The listing that started it, scanned live.

I found a $45 crochet pattern sold on Etsy with an AI-generated preview image. Scanned live on the listing, CYPHR returned 80% likely AI-generated with specific, readable reasoning: unnaturally smooth and uniform stitches lacking the tension variation of handmade work, artificial lighting, and repetitive “snow” texture. The same tells crocheters were already calling out by eye, now specific and citable in seconds.

A product whose entire premise is “trust what you see” cannot survive shipping a privacy claim that does not hold up.

ON CUTTING THE CLAIM, NOT SOFTENING IT

Two moments needed the judgment a solo product has no one else to supply. A production webhook kept returning 500s; my first fix changed the error but did not stop it, and the real cause was one corrupted character inside the production secret key. And right after submitting to the Chrome Web Store, I found the site still pointed at a placeholder extension ID, which is permanent once a listing exists and would have silently broken sign-in for every real install, forever. I caught both by verifying end to end instead of assuming.


OUTCOME

Live infrastructure, not a theoretical demo.

97.4% accuracy

On a benchmark of 10,000 images across Midjourney, DALL-E 3, Stable Diffusion, Firefly and Imagen.

Shipped end to end

getcyphr.com live with full pricing, a Chrome extension submitted for review, a mobile scan page, and live Stripe billing with webhook provisioning.

Zero false privacy claims

I disclosed the Gemini API usage and cut the scan-history feature to keep the promise true, before a single user paid.

Real-world validation

The Etsy listing behind the origin story, scanned live and correctly flagged. Not just a benchmark number.


REFLECTION

“The hardest part was not the design. It was the decisions I had never been trained to make.”

Pricing architecture, tax categorization, legal exposure from inaccurate copy, and reading a live production error log to find why real money was not turning into a real account upgrade. What I would do differently: write the privacy policy on day one, not month four, and treat “the update ran without an error” with far more suspicion. A no-op and a success look identical until you check.

View the live site →
04Flavors by Chef Tina