Privacy Policy
Bear in Mind Fact Check
Effective and last updated: September 8, 2026
Bear in Mind Fact Check ("FactCheck," "we," or "us") is operated by Infomancers Ltd. This policy explains how the FactCheck app, Safari and share extensions, and secure service handle information.
In brief: FactCheck runs only when you ask it to check an article, submitted text, or screenshots, or create a news brief. We do not sell personal information, use an advertising identifier, or track you across apps and websites. The OpenAI API key stays on our server and is never placed in the app.
Information processed for a fact-check
When you request a check, the app sends the following over HTTPS:
- the selected article or submission's title, source URL when supplied, language, and a Markdown document created on your device (older app versions may send a locally rendered PDF);
- the report language you selected;
- a random job identifier and short-lived access secret;
- Apple-signed app, subscription, and consumable-purchase information used to verify the app and deliver allowances; and
- service data needed to enforce allowances, including a one-way HMAC hash associated with the Apple app-transaction identity.
For a news brief, the app contacts only the HTTPS homepages you enter and the article links it finds there. Those publishers receive an ordinary web request from your device and handle it under their own privacy terms. The app extracts readable article text and creates a combined Markdown document in which every article title links back to its original page.
When you import screenshots, Apple’s Vision framework recognizes text on your device. You can review and edit that text before submitting it. Screenshot images stay on your device and are not uploaded by this feature. Pasted text, reviewed screenshot text, its selected scope, capture time, and any source link you supply are sent only after you tap Check. Reading an article link makes a web request from your device to that publisher.
Our secure service sends the article, submitted-content, or news-brief Markdown (or a PDF from an older app version), source URL, selected language, and fact-checking instructions to OpenAI to generate the requested report and search for independent evidence. OpenAI receives our server credential; you do not provide an OpenAI API key.
For shared checks, a protected local upload file temporarily holds the request and signed app identity so iOS can finish sending it after the share sheet closes. It is removed when the transfer completes. Pending or failed submissions retain their reviewed text and recovery reference locally until saved into Library or dismissed. Library stores the submitted text with its report, within the existing limit of 100 completed reports. Screenshot previews are held only for the current review session.
Service records and retention
We do not keep the PDF or Markdown attachment as a separate backend file. A temporary service-job record may contain the request, URL, progress events, partial or completed report text, evidence-source links, assigned analysis configuration, token counts, latency and cost estimates, continuation status, and coarse error status. These records expire within 24 hours. An automated cleanup runs every 15 minutes.
Hashed weekly-allowance records are retained for no longer than 90 days. Technical and error logs are retained for no longer than 30 days.
To preserve purchased extra checks and prevent duplicate redemption, we retain a pseudonymous account hash, unused balance, and a one-way HMAC hash of each Apple transaction identifier, together with its product, environment, purchase date, and credited runs. We do not store the raw transaction identifier in the database. These purchase records are kept as needed to deliver unused paid runs, prevent replay, and meet accounting or legal obligations.
Feedback you choose to send
When you send a bug report, feature suggestion, or report of an inaccurate fact-check, we receive your category, description, optional reply email, app and OS versions, and whether it came from the app or extension. The article link and fact-check report are included only when you select their checkboxes; you can preview them before sending. We do not automatically attach article text, screenshots, or logs.
Feedback is stored privately on our DigitalOcean backend, together with a submission reference and a pseudonymous account hash used to prevent abuse and duplicate submissions. Signed Apple credentials are verified but are not stored in feedback records. Feedback is not sent to OpenAI or TelemetryDeck. Feedback records are removed by the scheduled cleanup after 180 days. We use an email address you provide only to follow up on your feedback. Unsent drafts stay in memory and are lost when you reload the page or close the app.
OpenAI processing
We request stateless Responses API processing by setting store to false. OpenAI states that API data is not used to train its models unless the API customer opts in. Unless a stricter approved retention control applies, OpenAI may retain abuse-monitoring logs containing customer content for up to 30 days by default, and may retain information longer where legally required or necessary to protect its services or third parties. This processor retention is separate from our 24-hour service-record limit. See OpenAI's API data-controls documentation.
Information stored on your device
The app keeps up to 100 completed reports in its private shared app container so you can inspect them later or reuse a completed check for the same canonical URL and report language. A saved entry includes the article URL and title, completion date, report, source links, language, and text direction. The oldest entries are replaced as the limit is reached. The app also caches the latest allowance state and displayed StoreKit price so settings can load promptly.
This local history is not sent to TelemetryDeck. It remains until replaced or until the app's data is removed by you or the operating system.
Privacy-preserving analytics
We use TelemetryDeck to understand usage and reliability. Analytics may include:
- a pseudonymous one-way account or installation identifier;
- events such as starting or completing a check, sharing, cache use, and failures by coarse category;
- app version and build, device type, operating-system version, and similar technical metadata;
- the article URL's top-level domain and a namespaced SHA-256 hash of the normalized full URL, but never the raw URL; and
- the assigned model, reasoning level, and caching experiment variant, plus whether a cache hit or automatic continuation occurred;
- input, cached-input, cache-write, output, reasoning, and total token counts;
- analysis latency, web-search call count, success or failure by coarse category, and a versioned estimated service cost.
We do not send article titles, article text, report text, evidence text, raw URLs, Apple transactions, or API credentials to TelemetryDeck. TelemetryDeck states that it does not store IP addresses and does not use analytics for cross-app or advertising tracking. See TelemetryDeck's privacy FAQ.
Purchases
Apple processes purchases through StoreKit. FactCheck receives signed transaction and entitlement information to provide FactCheck Plus and consumable extra checks. Purchased extra checks are held separately and do not reset with the weekly allowance. We do not receive your payment-card number. Apple's handling of purchase information is governed by Apple's privacy policy.
Sharing
Sharing occurs only when you choose it. The extension can export a page as Markdown or create a findings-only PDF. The app can share a combined news-brief Markdown file or a PDF of its report. Shared files can include article text, findings, original links, evidence links, and an app-download link. The destination you select handles that content under its own privacy terms.
How we use information
We use information to provide the report you request, search for evidence, verify purchases, enforce allowances, preserve reports on your device, secure and diagnose the service, prevent abuse and duplicate redemption, improve reliability, and comply with legal obligations.
We do not sell personal information, use Apple's advertising identifier, or use information for cross-app advertising tracking.
Service providers and international processing
Our current service providers include Apple (distribution and purchases), DigitalOcean (service and database infrastructure), OpenAI (report generation and evidence search), and TelemetryDeck (privacy-preserving analytics). They may process information in countries other than your own, subject to their applicable safeguards, terms, and privacy commitments.
Security
We use HTTPS, short-lived job credentials, one-way HMAC hashing for account and purchase identifiers, SHA-256 hashing for URL analytics, Apple-signed transaction verification, private on-device storage, and access controls intended to protect information. No system can be guaranteed completely secure.
Children
FactCheck is a general-audience media-literacy tool and is not directed to children below the minimum age required in their country. We do not knowingly request a child's name, email address, or precise location.
Your choices and requests
You decide which articles to check and whether to share a report. You can stop future processing by no longer using the extension, remove local app data by deleting the app (subject to operating-system behavior), and manage FactCheck Plus in your Apple Account subscription settings.
For access, correction, deletion, objection, or other privacy questions, email aviad [at] dovladaat.com or use our contact page. We may need enough information to verify and fulfill a request, and some purchase records may need to be retained for legal, accounting, security, or service-delivery reasons.
Changes
We may update this policy when the product, providers, or legal requirements change. The effective date at the top identifies the current version.