Privacy Policy
Last updated: September 24, 2026
Our Commitment to Privacy
FactCheckAI is built on the principle of zero-knowledge fact-checking. We believe privacy is a fundamental right, not a premium feature. This policy explains what data we collect (spoiler: almost nothing), how we use it, and your rights under GDPR, CCPA, and other privacy regulations.
1. Data Collection
1.1 Extension Usage
When you use the FactCheckAI browser extension:
- Claim Text: The text you select for fact-checking is sent to our backend for analysis. We do NOT log or store this text.
- Anonymous Session IDs: A temporary, randomly-generated session identifier is used to group related checks within a browsing session. This ID cannot be linked to your identity and is discarded after 24 hours.
- No Browsing History: We never collect URLs, page titles, or browsing patterns.
- No User Accounts: The extension operates anonymously. We don't require registration or authentication for core features.
1.2 Website Analytics
This website uses privacy-respecting analytics to understand aggregate usage:
- Page views and navigation patterns (aggregated, no personal tracking)
- Referrer sources (e.g., search engines, social media)
- Device type and browser version (for compatibility testing)
- We use Plausible Analytics, a GDPR-compliant, cookie-free analytics provider
1.3 What We DON'T Collect
- IP addresses (anonymized immediately)
- Email addresses or contact information (unless you voluntarily submit feedback)
- Cookies or persistent identifiers
- Cross-site tracking or third-party advertising data
- Sensitive personal information (race, religion, political views, health data)
2. Data Usage
The minimal data we process is used exclusively for:
- Fact-Checking Analysis: Submitted claims are analyzed by our ML models and evidence retrieval systems to generate verdicts.
- Service Improvement: Aggregate, anonymous usage statistics help us optimize model performance and identify bugs.
- Research: De-identified, aggregated data may inform academic publications on misinformation detection (never individual claims).
We NEVER: Sell data, share data with advertisers, or use data for behavioral profiling or targeted advertising.
3. Data Storage & Security
3.1 Where Data is Stored
Our backend infrastructure is hosted on Render.com (US-based servers). Claims are processed in-memory and NOT persisted to disk or databases. Session IDs are stored temporarily in Redis with a 24-hour TTL.
3.2 Security Measures
- All data transmission uses TLS 1.3 encryption
- Backend APIs are protected by rate limiting and CORS policies
- No persistent storage of user-submitted content
- Regular security audits and dependency vulnerability scans
3.3 Data Retention
Since we don't log claims or personal data, there's nothing to retain. Temporary session IDs expire after 24 hours. Aggregate analytics are retained indefinitely for research purposes (fully anonymized).
4. Third-Party Services
We use the following third-party services:
- Render.com: Infrastructure hosting (Privacy Policy: render.com/privacy)
- Plausible Analytics: Privacy-first website analytics (Privacy Policy: plausible.io/privacy)
- GitHub: Open-source code hosting (no user data shared)
We do NOT use Google Analytics, Facebook Pixel, or any advertising/tracking networks.
5. Your Rights
5.1 GDPR Rights (EU Users)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access: Request a copy of any personal data we hold (we hold none)
- Rectification: Correct inaccurate data (not applicable—we don't store personal data)
- Erasure: Request deletion of your data (automatic after 24 hours for session IDs)
- Data Portability: Receive your data in a machine-readable format (not applicable)
- Objection: Object to data processing (you can stop using the service at any time)
5.2 CCPA Rights (California Users)
Under the California Consumer Privacy Act (CCPA), you have the right to:
- Know what personal information is collected
- Request deletion of personal information
- Opt-out of the "sale" of personal information (we never sell data)
- Non-discrimination for exercising your rights
To exercise any rights, contact us at: contact@gari.live
6. Cookies & Local Storage
We do NOT use cookies. The extension may use browser local storage to save user preferences (theme settings, filter options) locally on your device. This data never leaves your browser.
7. Children's Privacy
FactCheckAI does not knowingly collect data from children under 13. If you believe we've inadvertently collected such data, contact us immediately at contact@gari.live.
8. International Data Transfers
Our servers are located in the United States. If you access FactCheckAI from outside the US, your data may be transferred to US servers. We comply with EU-US Privacy Shield principles (where applicable) and implement appropriate safeguards.
9. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be announced via:
- A notice on this website
- A notification in the browser extension (if installed)
- GitHub repository announcements
10. Contact Us
For privacy inquiries, data requests, or security concerns:
- Email: contact@gari.live
- Website: gari.live