Skip to content

Last updated July 7, 2026

Privacy Policy

This policy explains what personal data Fact Engineering collects, why, and the rights you have over it. The data controller is Fact Engineering Inc., a Delaware corporation. For anything privacy-related, contact us at support@fact.engineering.

1. Data we collect

  • Account data — your name and email address, collected through our authentication provider (WorkOS) when you sign up.
  • Content you submit — the documents and text you upload for checking, your Knowledge Bank material, and the resulting fact-check reports. If you configure Connectors, the API keys you supply are stored encrypted.
  • Billing data — credit purchases and transaction history. Card payments are handled by Stripe; we never see or store your card number.
  • Usage and log data — IP address, API request logs, and check metadata (timestamps, tiers, credit usage), used for security, debugging, and billing accuracy.
  • Anonymized analytics — we use Plausible Analytics, a privacy-first, cookieless analytics service, to measure website traffic in aggregate (pages visited, referrer, browser, country). It sets no cookies and stores no persistent identifiers or personal data; your IP address is processed transiently to derive anonymous aggregate statistics and is never stored.
  • Cookies — we use only essential cookies, to keep you signed in. We use no advertising or analytics cookies and no cross-site trackers.

2. How we use your data

We use your data to:

  • provide the Service — run the checks you request, maintain your credit balance, and deliver results and webhooks;
  • process payments and maintain required financial records;
  • secure the Service and prevent abuse;
  • communicate with you about your account, purchases, and material changes to the Service;
  • comply with legal obligations.

We do not sell your personal data, and we do not use your documents to train AI models.

3. Legal bases (GDPR)

Where the GDPR applies, we process your data on these legal bases: performance of a contract (providing the Service you signed up for), legitimate interests (securing the Service, preventing fraud and abuse), legal obligation (tax and accounting records), and consent where we ask for it specifically.

4. How your content is processed

To fact-check a document, we send the relevant text to a panel of AI models via OpenRouter (which routes to model providers such as Anthropic, OpenAI, and Google). For live-research checks, claim text is also sent to web-search providers (Tavily, Exa). These providers process the data solely to return results for your check and are engaged under terms that restrict any other use.

5. Who we share data with

We share data only with the service providers that make the Service work, each acting on our instructions:

  • Amazon Web Services — hosting, document storage, and databases;
  • WorkOS — authentication;
  • Stripe — payment processing;
  • OpenRouter and the underlying AI model providers — running the fact-check analysis;
  • Tavily and Exa — web research for live-research checks;
  • Plausible Analytics — anonymized, cookieless website analytics, hosted in the EU.

Beyond that, we disclose data only if required by law or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to your data).

6. International transfers

We are a US company and process data in the United States. Where we transfer personal data of EU/EEA, UK, or Swiss residents, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or providers' certification under the EU–US Data Privacy Framework.

7. Retention

We keep your account data for as long as your account exists. Your documents and fact-check reports are kept until you delete them or your account, after which they are removed from our systems within a reasonable period. Billing records are retained as long as tax and accounting law requires. Server and API logs are kept for a limited period and then deleted.

8. Your rights

Depending on where you live — and always if the GDPR applies to you — you have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to our processing of it, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data-protection supervisory authority.

Deleting your account and data, or exporting your data: email support@fact.engineering from the email address on your account, with a subject line starting with “[Urgent]” (for example “[Urgent] Account and data deletion request” or “[Urgent] Data export request”), and include your account email and account ID. The Account page in the app has buttons that open a correctly prefilled request for you. These requests are currently processed manually: we verify each request against the account it concerns and respond within 30 days, as the GDPR requires. Deletion is permanent and covers your documents, reports, Knowledge Bank, API keys, and remaining credit balance.

9. Security

We protect your data with encryption in transit and at rest, encrypted storage of connector API keys, network isolation of our processing infrastructure, and least-privilege access controls. No system is perfectly secure, but if a breach affects your data we will notify you as required by law.

10. Children

The Service is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. For material changes we will give notice — for example by email or an in-product notice — before the change takes effect. The “Last updated” date above always reflects the current version.

12. Contact

Fact Engineering Inc. · support@fact.engineering. See also our Terms of Service.