Privacy Policy
Last updated: August 6, 2026
FactScope is a verification assistant. It processes content only after you choose a page scan or image verification. This policy describes the extension, FactScope backend, configured providers, local storage, telemetry, and deletion controls.
What we handle
FactScope handles the following data when you use a related feature:
- Page scans — The page URL, title, extracted text, author and publication metadata, limited outgoing links, and basic media information are sent only after you start a page scan and accept the first-scan disclosure.
- Image verification — The selected image URL, page URL, nearby caption or post text, platform, and public account name may be sent after you choose “Verify image with FactScope” and accept the disclosure. The backend fetches the selected image for analysis.
- Anonymous installation session — The server creates a random installation identifier and signed bearer token. The token is stored in Chrome local extension storage; only a one-way hash of the token and the random server identifier are stored in the database.
- Scan-access metadata — To count distinct anonymous installations that access an analysis, the server stores the analysis fingerprint, anonymous installation identifier, result type, timestamps, and access count. These records contain no page text, title, full URL, image URL, or claim.
- Community contributions — Flags, justifications, source links, and votes are associated with the anonymous installation identifier.
- Operational data — Request ID, route, response status, latency, quota usage, and provider failure type are logged without scanned content or URLs. A keyed hash of the network address is used in memory for burst limiting.
- Optional telemetry — If enabled in the extension, FactScope stores only an allowlisted event name such as “page scan completed” or “history cleared,” plus the anonymous installation identifier and timestamp.
- Local history — The extension stores up to 15 recent entries locally, including full page URL, title, domain, result score, verdict, scan type, and timestamp.
What we do not collect
- No account profile, name, email address, phone number, or postal address
- No passwords, page login credentials, cookies, or cross-site tracking identifiers
- No content from pages you merely visit; scripts and styles are injected only after a scan or image-verification action
- No page text, titles, claims, full URLs, or image URLs in optional telemetry
- No sale of data or use of scanned content for advertising
How scans are processed
- The selected content is sent through the FactScope backend hosted by Render.
- Page text, image content, and relevant context are sent to the configured Google Gemini API model for analysis. Google processes this data under its Gemini API terms.
- Extracted claims may be queried through Google News RSS and the Google Fact Check Tools API. These queries contain claim terms needed for corroboration, not your installation token.
- Results are cached in the FactScope database so identical content can reuse an existing result during the retention period.
Storage and security
Production data is stored in Turso, a SQLite-compatible database. FactScope stores anonymous installation identifiers rather than account identities. Bearer tokens are signed, and only token hashes are stored server-side. Access controls, request limits, private-network URL blocking, and response-size limits are used to reduce misuse. No security measure can guarantee absolute protection.
Third-party services
- Google Gemini API — AI analysis of selected page content and images
- Google News RSS and Fact Check Tools API — Claim corroboration
- Render — Backend hosting and operational logs
- Turso — Production database storage
- Chrome local extension storage — Session token, consent version, telemetry preference, and recent scan history on your device
Retention
- Raw page and image scan records are automatically deleted after 30 days by a scheduled cleanup process.
- Scan-access metadata is automatically deleted 30 days after its last access.
- Optional telemetry events are automatically deleted after 30 days.
- Installation sessions expire after 180 days by default. Scheduled cleanup removes the expired session and records linked to that installation so data is not orphaned.
- Local scan history remains on your device until you clear it, delete server data through the extension, clear extension storage, or uninstall FactScope.
- Community flags, votes, and public share pages remain until you use “Delete my server data” or they are removed for operational or moderation reasons.
- Minimal abuse-prevention records — the hashed installation session and current quota counter are retained after a deletion request until their normal expiry. They contain no page text, titles, claims, full URLs, or image URLs and prevent repeated deletion from resetting free usage limits.
- Aggregated domain statistics and de-identified knowledge-base entries may remain because they are not linked to an installation identifier.
Your controls
- You can decline the first-scan disclosure. Declining prevents that page or image content from being transmitted.
- Optional telemetry is off by default and can be enabled or disabled under Privacy & data in the extension popup.
- You can clear recent local history from the extension popup.
- You can select Delete my server data to delete scans, image scans, scan-access metadata, flags, votes, telemetry events, tier assignment, and owned share pages linked to the current installation. A minimal hashed session record and the current quota counter remain temporarily for security and abuse prevention, then expire automatically.
- You can uninstall the extension at any time to stop future transmission.
Children's privacy
FactScope is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as FactScope changes. Material changes will be shown here with a revised date.
Contact
Questions or deletion problems? Contact factscope@gmail.com.