FactLens processes the page, audio, images, posts, or API inputs you deliberately ask it to check. Third-party provider API keys used by the extension stay on your device. Direct FactLens API keys are server-issued credentials and are stored by FactLens as a prefix and one-way hash, together with the usage and billing records described below.
This policy explains how FactLens processes information through the Chrome extension, factlens.pro, api.factlens.pro, console.factlens.pro, support, billing, referrals, administrator services, and direct FactLens API access. Questions, access requests, or deletion requests may be submitted through FactLens Support.
Depending on the features you use, FactLens may process:
FactLens does not intentionally read passwords, form entries, cookies, keystrokes, general browsing history, private files, or content from unrelated tabs.
Third-party provider API keys used by the extension are encrypted before being written to Chrome local storage. They are not uploaded to FactLens Cloud or displayed in Console or administrator tools. A key is sent only to the AI, transcription, search, or custom provider you selected when a request requires that provider.
Local extension storage may also contain settings, current-session state, up to the extension's local history limit, locally bound credential IDs, cached entitlement information, and synchronization checkpoints. Removing the extension or clearing its storage removes this extension-managed local data.
A direct request to the FactLens API sends the content required for the selected checking mode to FactLens so the service can perform retrieval, transcription or media processing when applicable, evidence evaluation, and return the requested result. Direct API request content is processed to fulfill the request and may pass through infrastructure or evidence providers selected by FactLens for that operation.
FactLens stores the issued API credential as a key prefix and one-way hash rather than storing the full secret in readable form. The API usage ledger records operational and accounting metadata such as the API-key identifier, request ID, mode, status, duration, error code, creation time, and completion time. The current API usage table does not store the claim, transcript, image, audio, or other request body.
API-key records also maintain the customer email, budget, request limit, requests used, enabled state, expiry, and last-used timestamp. These records are used to authenticate requests, enforce allowances, calculate usage, investigate abuse, support idempotent operations, resolve billing disputes, and determine API refund eligibility under the Refund Policy.
Audio is captured only while you run an audio/video session. A custom transcription option connects to an endpoint you configure, which may be self-hosted, while managed transcription sends audio to the provider you select. FactLens does not store captured audio in FactLens Cloud as part of extension session synchronization.
Image/post mode scans the active page for visible images, removes duplicates locally, and shows a selection before checking. Only selected image data is sent to the AI provider you configure. FactLens Cloud may store derived session records such as claims, verdicts, prompts, responses, source links, and safe metadata about the original page image, but not the selected image pixels or local preview data.
For extension workflows, FactLens sends the minimum request content required for the selected stage to the provider you configure. This can include a claim, limited page/media or speaker context, selected images, your prompt customization, retrieved source text, and expected response format. Search sends a short retrieval query to Browser Search, Brave Search, Serper, SerpApi, or a custom endpoint. Preferred sources may be prioritized; blocked domains are excluded and filtered from returned evidence.
Custom endpoints are controlled by you. Their operator may log or retain requests under its own terms. Direct FactLens API requests use the FactLens service and may be processed by infrastructure or evidence providers selected by FactLens. Provider processing is limited to what is reasonably required to perform the requested operation.
Safe account configuration synchronizes separately from complete session content. This includes profile, appearance, credential names and non-secret provider settings, routing, prompts, verdict cards, source preferences, and device metadata.
For a signed-in Trial account, complete session/history synchronization is enabled by policy while the Trial is active and cannot be turned off. This is part of providing the signed-in Trial experience. A new paid FactLens Pro account begins with complete-session synchronization enabled and may stop future session uploads at any time from the extension or Console. Turning off future Pro uploads does not disable safe configuration or device synchronization.
When a Pro user asks FactLens to generate a speaker report, the request is queued privately to the account. The signed-in extension asks for confirmation before sending that speaker's synchronized claims and evidence summary to the locally bound AI provider selected by the user's routing. FactLens stores the returned evidence-scoped summary, eleven ratings and rationales, uncertainty, sources, and report history. HTML report downloads are assembled in the browser and inherit the user's current appearance settings.
Console and the extension may register as separate product surfaces of the same browser installation so they appear as one connected device. Installation identifiers are scoped to each signed-in account for authorization and synchronization; they are not used to prevent a browser from signing in to another FactLens account.
Account notifications may be created from stored activity, failed requests, profile or configuration changes, and completed report requests. Realtime delivery reduces delay between the extension and Console, but every private read and change remains subject to server authorization.
If synchronization is temporarily unavailable, the extension may continue operating locally and retry eligible queued data. It does not fabricate Console records.
Profile images are converted to WebP, stored in a private owner-specific location, and displayed through time-limited signed URLs. Administrator-uploaded images for public What's new and Blog posts are converted to WebP and intentionally made public with the article. Video is embedded from an administrator-supplied external URL rather than uploaded to FactLens storage.
Images, screenshots, posts, and other material selected by a user for checking do not become FactLens property. The user or original rights holder retains the applicable rights. FactLens processes that material only to perform the requested check and maintain the derived records described in this policy. FactLens-owned branding, interface artwork, editorial graphics, and original site images are owned by or licensed to FactLens; third-party evidence images, trademarks, and linked media remain the property of their respective owners.
Referral records include the unique code, referring and referred account identifiers, qualification status, reward claims, and relevant timestamps. A referral qualifies only after the referred person follows the eligible flow, installs FactLens, signs in, and completes the required first use. Billing and checkout for FactLens Pro are handled by Paddle; FactLens stores the customer, subscription, transaction, billing-period, renewal, cancellation, entitlement, refund, and fraud-status references needed to operate and support Pro. FactLens does not receive or store full payment-card details.
For direct FactLens API access, FactLens stores the API customer email, key metadata, purchased budget or request allowance, usage counts, last-used time, and per-request operational ledger described above. These records may be consulted to enforce limits, prevent abuse, investigate fraud, support customers, calculate remaining access, and verify whether the seven-day no-usage condition for an API refund is satisfied.
FactLens applies server and device rate limits to protect profiles, referrals, publishing, support, API access, and synchronized resources from abuse. Limited request/device metadata may be used to enforce those controls and investigate fraud or service misuse.
FactLens relies on Google and Supabase for authentication and account storage, Netlify for public-site hosting and delivery, Paddle for payment processing, and Cloudflare Turnstile for support/uninstall abuse prevention. The AI, transcription, search, or custom providers you select receive only requests directed to them. Direct FactLens API operations may use infrastructure and evidence providers selected by FactLens to perform the requested check. Each provider processes information under its own terms and privacy policy.
The public Blog may display advertising supplied by Google AdSense. Third-party vendors, including Google, may use cookies, web beacons, IP addresses, device or browser information, and the page URL to deliver services, measure ad effectiveness, prevent fraud and abuse, and, when permitted, personalize advertising based on visits to this and other sites. Learn more about how Google uses information from sites that use its services.
Configured advertising placements and the Google AdSense tag load when a Blog page opens. Advertising remains part of Blog pages regardless of the optional-cookie choice; rejecting optional cookies does not hide or disable ads. FactLens initializes Google consent signals with optional analytics, advertising storage, user-data use, and ad personalization denied until the browser-level choice is updated. When personalization consent is unavailable, Google may serve limited or non-personalized advertising according to the publisher's AdSense and consent-platform settings. Essential storage remains available for security, sign-in, saved privacy choices, and core operation. Choices can be changed at any time through Cookie preferences in the footer. Google Ads controls are also available through Google Ads Settings, and industry opt-out choices may be available through AboutAds.
FactLens does not provide an account email, display name, profile image, private session content, provider key, or FactLens API secret to Google AdSense for ad personalization. In regions where law or Google policy requires a certified consent platform, personalized advertising is not enabled unless the required Google-certified consent mechanism is active and the user has made the necessary choice. Contextual or non-personalized advertising may still use limited storage where permitted for security, frequency control, aggregated reporting, and fraud prevention.
Information is processed to provide requested checks and API operations, maintain accounts and entitlements, authenticate API access, synchronize settings/history under the applicable Trial or Pro policy, meter purchased usage, prevent abuse, provide support, process refund eligibility, publish updates, improve reliability, meet legal obligations, and protect FactLens and its users. Depending on your location and the activity, the legal basis may be performance of the service agreement, consent where specifically requested, legitimate interests in security and reliability, or compliance with law.
Support and uninstall feedback contain the category, message, optional reply email, date, and source. Cloudflare Turnstile processes the technical request data needed to distinguish legitimate submissions from automated abuse. The short-lived verification token is checked on the server and is not stored as feedback content. FactLens does not store an IP address or IP hash with support or uninstall feedback.
Console allows Pro users to set supported session/activity retention periods, export synchronized data, stop future Pro session uploads, and clear synchronized history. Clearing synchronized history removes sessions, activity events, speaker claims, and generated reports while preserving account configuration such as credential names, workflows, prompts, verdict cards, appearance, source preferences, devices, and authentication. Extension history can be cleared locally. Uninstalling removes extension-managed local storage.
API-key and API-usage records may be retained as reasonably necessary to authenticate access, enforce purchased limits, support idempotency and reliability, determine refund eligibility, investigate abuse, resolve billing or legal disputes, and meet accounting or legal obligations. The current API usage ledger contains operational metadata rather than the API request body.
A verified account-deletion request removes the authentication account and associated FactLens account resources, subject to records that may lawfully be retained for billing, API usage, security, fraud prevention, disputes, or legal obligations. Public release articles remain until an administrator unpublishes or deletes them.
External providers may retain requests under their own policies. Deleting FactLens data does not delete a request already sent to a selected third-party provider or infrastructure provider used to complete a direct FactLens API request.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data. The European Commission explains GDPR rights for people in the EU. Submit a request through Support; identity may be verified before a request is completed. Some records may be retained where legally permitted or required.
FactLens uses encrypted local secret storage, one-way hashing for direct FactLens API secrets, strict extension content-security rules, validated cross-context messages, source-URL validation, redacted error handling, private owner-scoped profile media, server-side authorization, row-level database controls, request validation, and rate limits. No online service can guarantee absolute security; report suspected problems through Support.
FactLens is not directed to children under 13 and they may not create an account. Where local law requires a higher minimum age for an online service, that higher age applies unless a parent or guardian provides legally valid authorization. The FTC provides information about children's online privacy.
FactLens and its providers may process information in countries other than yours. Those countries may have different data-protection rules. Where required, appropriate transfer mechanisms and provider safeguards are used.
Material changes will update the effective date above and may also be announced in What's new or another appropriate product notice. Continued use after an effective update is governed by the revised policy to the extent permitted by law.