TruthLens
  • EN · English
  • RU · Русский
  • 简体中文
  • FR · Français
  • हिन्दी
  • DE · Deutsch
  • ES · Español
  • PT-BR · Português (Brasil)
  • 日本語
  • 한국어
  • IT · Italiano
  • NL · Nederlands
  • PL · Polski
  • TR · Türkçe
  • UK · Українська
  • SV · Svenska
  • DA · Dansk
  • NB · Norsk bokmål
  • FI · Suomi
  • CS · Čeština
  • SK · Slovenčina
  • HU · Magyar
  • RO · Română
  • Ελληνικά
  • CA · Català
  • HR · Hrvatski
  • FR-CA · Français (Canada)
  • ES-419 · Español (Latinoamérica)
  • PT · Português
  • 繁體中文
  • 繁體中文(香港)
  • ไทย
  • VI · Tiếng Việt
  • ID · Bahasa Indonesia
  • MS · Bahasa Melayu
  • SL · Slovenščina
← Back

Privacy Policy

Effective date: 22 July 2026

This Privacy Policy explains what data the TruthLens Service (mobile application, browser extensions, and the truthlens.wiki website) collects, why, how it is protected, and what rights you have. The data controller is Nazerke Saktapbergenova, an individual carrying out activities under the legislation of the Republic of Kazakhstan (the "Operator", "we"). Contact: support@truthlens.wiki.

This Policy has been developed taking into account the legislation of the Republic of Kazakhstan on personal data, the EU General Data Protection Regulation (GDPR), the PRC PIPL, and the data protection legislation of the states whose languages are supported in the application.

1. What data we collect and why

1.1. Account data. When you sign in with Apple, Google, or email, we receive and store: an internal user identifier, your email address (or its anonymized relay provided by Apple), and your name if the provider shares it. Purpose: creating and maintaining the account, counting the free-check quota, providing Premium access. Legal basis: performance of a contract.

1.2. Submitted content and results. Content you submit for checking (text, links, images, video, audio, documents), transcripts created from it, and analysis results (claims, verdicts, explanations, sources, manipulation findings) are stored in your check history. Purpose: providing the core function of the Service and showing your history. Legal basis: performance of a contract.

1.3. Uploaded files. Media files uploaded for analysis (images, video, audio, documents) are stored temporarily and automatically deleted from the server after processing or upon expiry of a short technical retention window (hours, not days). Voice recordings transcribed on your device are not sent to the server at all when on-device recognition succeeds.

1.4. Subscription data. When you purchase Premium we receive from Apple or Google a cryptographically signed confirmation of the transaction (product, validity period, transaction identifier) and store the subscription status linked to your account. We never receive your card or bank details — payments are handled entirely by Apple or Google. Legal basis: performance of a contract.

1.5. Technical data. For security, abuse prevention, and rate limiting we process IP addresses and technical request logs; legal basis: our legitimate interest in the security and stability of the Service (you may object — see Section 7). If you enable push notifications ("check is ready"), the device push token is transmitted together with the check request and stored with the check record; legal basis: your consent expressed via the in-app toggle. When the toggle is off, the token is not transmitted; tokens stored with earlier records are removed together with those records. Application settings (theme, language, push toggle) are stored on your device.

1.5.1. Website analytics and cookies. The website stores a functional language preference in your browser. With your prior consent, it also uses Google Analytics 4 to measure visits, traffic sources, page interactions, and outbound clicks. Google Analytics may store _ga cookies and receive technical data such as your IP address, browser and device information, approximate location, visited pages, and campaign parameters. We disable Google Signals and advertising personalization and do not send submitted check content to Google Analytics. Analytics is not loaded if you decline. You can change your choice at any time using “Cookie settings” in the footer. Google explains its processing at How Google uses information from sites or apps that use our services. Legal basis: your consent.

1.6. Anonymous modes. The browser extension operates using a technical (anonymous) authentication session, and the public check on the website is available without an account and is limited per network address. On iOS, the mobile application additionally offers a limited number of text and link checks (currently 5, one-time) before you create an account. To prevent repeated use of this limit by reinstalling the application, these checks are counted per physical device using Apple's DeviceCheck service: the application sends Apple an opaque, device-generated token, and Apple's servers return and store one persistent flag indicating whether this physical device has already used this limit. Apple does not receive the content you check; we do not receive any device identifier from Apple beyond this flag. In these modes we process the submitted content and technical data described above without linking them to a personal account.

1.7. Advertising install attribution. When we run paid advertising campaigns for the application, we need to know which campaign an installation came from — otherwise we would be paying for advertising blindly. For this purpose the application transmits to a mobile measurement provider (AppsFlyer): an installation identifier generated by that provider, technical characteristics of the device and the application (model, operating system version, application version, interface language, IP address and the approximate country derived from it), the fact of installation and first launch, and the fact of a Premium purchase without any payment details. On Android the Google advertising identifier (GAID) is transmitted as well — it is what makes attribution accurate on that platform; you can reset or delete it in the operating system settings. On iOS we do not use the advertising identifier (IDFA) and do not display the App Tracking Transparency prompt; there, attribution relies on Apple's SKAdNetwork framework, which reports campaign performance to the advertising platform in aggregated form. If an installation comes from an Apple Ads campaign, on iOS the application additionally passes to the provider Apple's attribution token (the AdServices framework): it contains no device identifiers and only indicates which campaign the installation came from.

This data is not combined with the content you submit for checking, is not used to build a profile about you, and is not used to show you advertising inside the Service.

This mechanism is not activated for users in the European Economic Area, Switzerland, and the United Kingdom: in those regions the measurement component does not start and transmits nothing. Elsewhere, the legal basis is our legitimate interest in measuring the effectiveness of our own advertising expenditure; you may object — see Section 7.

1.8. What we do not collect. We do not collect precise geolocation or contact lists, and we do not use analytics SDKs that record your behaviour inside the Service. Apart from the install attribution described in Section 1.7, we do not track you across other applications and websites. Google Firebase processes device and instance identifiers strictly for authentication and push delivery (see Section 2). We do not sell personal data.

2. Third-party processors

To provide the Service, the following categories of processors receive the minimum data necessary:

  • Google Firebase (authentication, push notifications) — account identifiers and push tokens;
  • AI providers (including Google Gemini and Groq) — the content of the check, to extract claims and generate assessments;
  • evidence search providers (including Tavily) — the text of extracted claims, as search queries;
  • public sources (including YouTube) — when a link you submit is ingested;
  • a network provider that routes our requests to YouTube — the video link and its subtitles;
  • Apple (DeviceCheck) — an opaque per-device token, to enforce the one-time pre-account free-check limit on iOS (Section 1.6);
  • mobile measurement provider (AppsFlyer) — the installation, first launch, and purchase events and the technical device data listed in Section 1.7, to attribute installations to our advertising campaigns; not activated for users in the European Economic Area, Switzerland, and the United Kingdom;
  • hosting provider of our server infrastructure — where all server data is stored.

These providers process data under their own terms and only for the purposes of providing the Service. We do not transfer your data to third parties for their marketing purposes.

We select these processors on the condition that their business terms afford the transferred data a level of protection equal to or comparable with the one described in this Policy: processing limited to providing their service to us, confidentiality, and appropriate technical and organisational security measures. Where a provider is located outside your country, the transfer takes place on the safeguards described in Section 4.

Before your content is sent to these providers for the first time, the mobile app asks for your explicit permission and names the recipients and the data being sent. You can decline; in that case the check is not performed. You can withdraw your permission at any time in the app settings; further checks then require it to be given again.

3. Personal data of third parties in checked content

Content submitted for checking may contain personal data of third parties (for example, names of public figures in a news article). We process such data solely as part of providing the check to you: it passes through the analysis pipeline (Section 2) and remains in your check history. We instruct you not to submit content containing special categories of third-party personal data (health, biometrics, and similar) without a lawful basis. Legal basis for this processing: our and your legitimate interest in verifying publicly disseminated information. Informing each mentioned person individually would involve disproportionate effort (GDPR Article 14(5)(b)); instead, this Policy serves as public information, and any person may exercise their rights (Section 7) or dispute a result concerning them (Terms of Use, clause 6.6) by contacting support@truthlens.wiki.

4. Cross-border transfer

Our server infrastructure and the processors listed in Section 2 may be located outside your country, including in the United States and the European Union. Where GDPR applies, transfers are carried out on the basis of adequacy decisions or standard contractual clauses of the respective providers; information about the applicable safeguards can be requested at support@truthlens.wiki.

EU representative. The Operator is established outside the European Union and has not appointed a representative in the Union under Article 27 GDPR. Requests from data subjects in the EU are handled directly by the Operator at support@truthlens.wiki, under the same terms and timelines described in Section 7.

5. Data security

All data in transit is protected by TLS encryption. Access to server data is restricted and granted only for the operation of the Service. Payment data does not pass through our infrastructure at all. Premium status is verified by cryptographic validation of store-signed transactions.

6. Retention periods

  • Check history, transcripts, and results (including push tokens stored with check records) — until deleted by you or until account deletion.
  • Uploaded media files — deleted automatically after processing (a technical window of several hours).
  • Account data and subscription status — for the lifetime of the account.
  • Technical logs — up to 90 days, unless a longer period is required to investigate a specific security incident.
  • Attribution data (Section 1.7) — stored by the measurement provider for the period set out in our contract with it; on our side we keep only aggregated campaign reports that contain no device identifiers.
  • The per-device flag and check counter used for the iOS pre-account free tier (Section 1.6) are tied to the physical device, not to your account: deleting your account does not reset or delete them, and the application provides no control to reset them (this is the anti-abuse mechanism the limit relies on, not an oversight). They are cleared only by a factory reset of the device or expiry of Apple's own DeviceCheck record.

After account deletion, associated data is removed from active systems within 30 days; residual copies in backups are destroyed within 90 days.

7. Your rights

You have the right to: access your data; correct it; delete it; receive it in a machine-readable format; object to or restrict processing based on legitimate interest; withdraw consent where processing is based on consent (for example, push notifications); and lodge a complaint with a data protection supervisory authority. For users in the EU these rights are guaranteed by Articles 15–21 GDPR. To exercise your rights, contact support@truthlens.wiki; requests from EU data subjects are handled directly by the controller. We respond within the time limits established by applicable law (as a rule, within 30 days).

Automated processing. Analysis results are generated automatically, but they assess the checked content, not you, and do not produce legal or similarly significant effects concerning you. The Service does not carry out automated decision-making within the meaning of Article 22 GDPR.

8. Deleting data yourself

  • Check history: Settings → Clear history (deletes all your checks on the server, including push tokens stored with them).
  • Account: use the account deletion function in the application settings (where available) or send a request to support@truthlens.wiki from the email associated with the account; deletion of the account removes account data, history, and subscription linkage from active systems.
  • Push notifications: can be disabled in the application settings; the push token stops being transmitted.

9. Children

The Service is not directed at children under 13. We do not knowingly collect data of children under 13. If you believe a child has provided us with personal data, contact support@truthlens.wiki and we will delete it. In the EU, the use of the Service by persons under 16 may require parental consent.

10. Data breach notification

In the event of a personal data breach, we will notify the competent supervisory authority within the time limits established by applicable law (under GDPR — within 72 hours of becoming aware, where feasible). If the breach is likely to result in a high risk to your rights, we will also notify you without undue delay.

11. Changes to this Policy

We may update this Policy. The current version is always available in the application (Settings → Privacy Policy) and at truthlens.wiki. We will announce material changes in the application in advance. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

12. Language

This Policy is drawn up in English; versions in other languages are provided for convenience. In the event of a discrepancy, the English version prevails to the extent permitted by the mandatory rules of your jurisdiction.

13. Contact

Data controller: Nazerke Saktapbergenova

Email: support@truthlens.wiki

Website: truthlens.wiki