Privacy Policy
Also referred to as the Privacy Statement · Last updated July 28, 2026
This document is also referred to in the Platform as the "Privacy Statement." References to "Privacy Policy" and "Privacy Statement" mean this document.
1. Who we are and scope
1.1 What The Fact?! ("WTF", "we", "us") is operated by Bridge Business Support Solutions LLC, 2389 Main St. STE 100, Glastonbury, CT 06033. We are the data controller for personal data processed as described in this Privacy Statement, except where we act solely as a processor on documented instructions of another controller under a separate agreement.
1.2 WTF is an AI-assisted verification service. It helps users assess whether online content appears accurate, whether attached media appears authentic, and observable information about the source or account behind the content. It provides an evidence-based assessment — not a legal ruling or guarantee of truth.
1.3 This Privacy Statement applies to: visitors to our website; users of the iOS and Android applications; account holders; people who contact support; and people whose publicly available posts, media, or accounts are analysed in connection with a verification — even if they are not WTF users (see Section 8).
1.4 Privacy contact: help@whatthefact.app.
2. What WTF does with data (plain summary)
Input. A user may submit a link, claim, article, image, screenshot or video; optional comments or context; and basic account/technical information needed to run the service. The user must have a lawful basis to submit the material.
Process. WTF may extract text, media and account details; identify the main claim; search public sources and existing fact checks; analyse whether the claim is supported; examine whether media appears genuine, altered or AI-generated; assess the source or account using observable public information; and store results so the same claim can be recognised, reused and updated later. Processing may use AI providers, media-detection tools, hosting providers and other processors.
Output. WTF may provide a report including a verdict on the main claim; a media-authenticity assessment; information about the source or account (including an account-authenticity assessment where applicable); supporting evidence and links; uncertainty, limitations and context; and corrections or updates where new evidence appears. Reports reflect evidence available at the time and may be incomplete, wrong or later changed. They are informational only and are not legal, medical, financial or other professional advice.
Public reports. Public report pages should not identify the person who submitted the check unless that person chooses to share it. We do not sell personal data.
3. Data we collect from users
3.1 Account and identity
- Email address; display name if provided
- Apple or Google sign-in identifiers (and relay email if used)
- Password only as a secure hash for manual sign-up (we never store plain-text passwords), or passwordless login tokens
- Session and login records; short-lived email verification and password-reset tokens
- Age confirmation that you are 17 or older (we do not collect birth dates as a core requirement)
- Subscription / entitlement status from the App Store or Google Play
- Account preferences and notification settings (e.g. push tokens if enabled)
3.2 Content you submit for verification
- URLs / public links, claims, articles, screenshots, images, videos and related context
- Metadata associated with submitted links or files (where available)
- Verification history associated with your account
- Shared outputs you choose to export or share
Submitted content may contain personal data about third parties. By submitting content, you represent that you have a lawful basis to submit it for verification processing.
3.3 Verification outputs we generate
- Claim analyses, explanations, findings and source links
- Media-authenticity assessments
- Account-authenticity assessments (likelihood-based; see Sections 7–8)
- Technical processing/status records needed to run and debug the pipeline
- Claim/media fingerprints or hashes used to recognise repeat checks (not a substitute for keeping original files indefinitely)
3.4 Technical and support data
- IP address, device/app/OS information, language/region, session activity, crash/diagnostic logs as needed for security and reliability
- Support messages, attachments and correspondence if you contact us
We do not intentionally collect contacts, precise location, payment card numbers, or browsing history outside the Platform. Card payments are handled by Apple/Google (or another designated processor). We do not sell personal data and we do not show personalised ads as part of the core V1 product.
4. Why we use personal data and lawful bases
| Purpose | Examples | Typical lawful basis |
|---|---|---|
| Provide the service | Accounts, verification pipeline, History, entitlements | Contract |
| AI-assisted verification | Claim, media and source analysis; report generation | Contract; legitimate interests |
| Cache, reuse and update checks | Recognise prior claims; refresh assessments | Legitimate interests |
| Public-account authenticity assessments | Observable public profile signals; challenge handling | Legitimate interests (see Section 8 and LIA) |
| Security, abuse prevention, fair use | Rate limits, fraud, incident response | Legitimate interests; legal obligation |
| Support and service notices | Help desk; critical account messages | Contract; legitimate interests |
| Legal compliance | Respond to lawful requests; defend claims | Legal obligation; legitimate interests |
Where we decide why and how publicly available personal data is analysed for verification or account-authenticity purposes, we act as controller for that processing.
6. International transfers
Personal data may be transferred to, stored in, or accessed from countries other than your country of residence (including where subprocessors operate, such as the United States). Where required, we use appropriate safeguards (for example standard contractual clauses and/or participation in an applicable data-privacy framework), and supplementary measures as appropriate. Our API arrangements with model providers are intended to exclude use of customer content for model training where the provider offers that tier.
7. AI, automated processing and profiling
7.1 The Platform uses automated systems and AI to analyse submitted content and generate verification outputs. Outputs are probabilistic and informational. They are not guaranteed to be accurate, complete, fair or up to date, and they are not legal determinations, law-enforcement findings or certified professional conclusions.
7.2 Account-authenticity assessments evaluate observable public signals about an account (for example profile information and publicly visible behaviour indicators) to produce a likelihood-based authenticity assessment. That processing may constitute profiling under UK GDPR / GDPR because it evaluates characteristics using automated processing. It does not automatically make the processing unlawful. We do not present raw "bot probability" figures or false precision. Assessments use clear, non-precision language, evidence standards, expiry periods, and a challenge process (Section 8).
7.3 We do not use Platform outputs as the sole basis for decisions that produce legal or similarly significant effects about you within the meaning of applicable automated-decision laws, except where such laws do not apply or exemptions exist. Contested assessments are subject to human review on request.
8. People whose posts or accounts are analysed (including non-users)
This Section is for individuals whose publicly available posts, media, or accounts may be analysed when a WTF user submits a verification — including people who have never created a WTF account.
8.1 What may be collected and from where
- Public post text, media, metadata and permalinks from the submitted URL or public page
- Publicly visible account/profile information (e.g. handle, display name, bio, follower/following counts, account creation indicators where publicly shown)
- Publicly available corroborating sources located during the check
- Derived assessments: claim analyses, media-authenticity assessments, and account-authenticity assessments
- Fingerprints/hashes of claims or media used to recognise repeats — not indefinite storage of original private files
We analyse information that is publicly available or that a user lawfully submits for verification. We do not ask non-users to create an account as a condition of being analysed.
8.2 Why and lawful basis
Purpose: to operate an evidence-based verification service that assesses claims, media authenticity, and observable source/account authenticity in the public information environment; to cache and update assessments; and to reduce misuse of the Platform.
Lawful basis: legitimate interests (and, where applicable, related bases for security and legal compliance). We document a Legitimate Interests Assessment for account-authenticity processing and a DPIA covering high-risk aspects before launch. See the companion internal documents in this counsel package.
8.3 Publication of assessments
A verification report or account-authenticity assessment may be stored and, where the product design provides, made available as part of the Platform's cache or public correction/history features. Public pages are designed not to identify the submitting user. Assessments describe public content and observable account signals; they are informational likelihood-based outputs, not findings of wrongdoing.
8.4 How to object, correct or challenge
If you believe an account-authenticity assessment or related report about you is inaccurate, incomplete, outdated, or unfairly presented, email help@whatthefact.app with the subject "WTF Assessment Challenge," and include: the URL or handle concerned; the report/assessment reference if you have it; and why you say it is wrong, with supporting evidence where possible.
We will review challenges with human involvement. Outcomes may include correction, clarification, update, earlier expiry, or removal of the contested assessment where appropriate. Statutory data-subject rights under UK GDPR / GDPR (access, erasure, restriction, objection, etc.) also apply where those laws cover you — contact the same email.
8.5 How long assessments remain; expiry
Account-authenticity assessments are refreshed on cache timers (typically between 1 and 30 days depending on assessment category and product rules) and are removed or updated when superseded, when a substantiated objection succeeds, or when retention rules require deletion. Older assessments may expire automatically so they do not present stale profiling. Claim verification caches may be retained longer as anonymised or content-keyed records describing public material (see Section 9). Exact operational periods are set out in Section 9 and the Data Retention Policy.
9. Retention
We retain personal data only as long as needed for the purposes in this Privacy Statement, or as required by law. Where a period below conflicts with a live legal duty, the legal duty wins and the exception is logged. Summary:
| Category | Retention |
|---|---|
| Account record (user ID, email, display name) | Life of account; deleted within 30 days of a verified deletion request |
| Manual credentials (password hash / login token) | Life of account; deleted with account |
| Email verification / reset tokens | Minutes to hours; auto-expire |
| Session / login metadata | 90 days rolling |
| Subscription entitlement | Life of account, plus aggregate records tax/accounting law requires |
| Verification results (content-keyed cache) | Retained as cache/public record of public content; user link removed on account deletion; failed jobs purged at 90 days |
| Raw model responses | 90 days, then deleted |
| Media hashes / metadata | Retained for deduplication (hashes, not original files) |
| Original media bytes | Deleted once analysed; 90 days maximum |
| Account-authenticity assessments | Cache timers typically 1–30 days; removed/updated on successful challenge or expiry |
| Server / cost logs | 30 days |
| Support tickets | Up to 24 months after closure (longer if dispute-related) |
| Backups | Encrypted rolling backups (about 35 days); deleted data falls out of backups within 90 days |
| Deletion compliance log | Salted hash of user ID + completion date only |
Full operational detail is in the companion Data Retention Policy (Schedule for engineering and counsel).
10. Security
We implement technical and organisational measures designed to protect personal data, which may include TLS in transit, encryption at rest where appropriate, hashed passwords, access controls, monitoring, and staff confidentiality obligations. No method is completely secure. You must keep credentials and device access confidential. If a personal data breach affects you, we will take appropriate steps and notify as required by law.
11. Your rights (users and affected individuals)
Subject to applicable law (including UK GDPR / GDPR where it applies), you may have rights to access, correct, delete, restrict or object to certain processing, and to data portability, and to withdraw consent where processing is based on consent. You may lodge a complaint with the ICO (UK) or your local supervisory authority.
How to exercise rights: email help@whatthefact.app with subject "WTF Privacy Request," with enough information to verify identity and locate relevant records. In-app: where available, Profile → Delete my profile / Privacy & Data. Account deletion: on confirmation we revoke sessions, hard-delete the account record, unlink or delete user-linked history, complete deletion within 30 days, and purge backups within 90 days, subject to legal exceptions.
12. Children — 17+
The Platform is only available to users aged 17 or older. It is not directed to children. We do not knowingly collect personal data from anyone under 17. If we learn we have collected such data, we will take reasonable steps to delete it. There is no parental-consent pathway for under-17 use.
14. Third-party services
The Platform interacts with third-party services (social platforms, news sources, authentication providers, app stores, AI vendors). Their practices are governed by their own policies. We are not responsible for privacy practices of third-party sites accessed through submitted links or corroboration sources.
15. Changes
We may update this Privacy Statement from time to time. The Last Updated date will change. Material changes will be notified by in-app notice, email, website banner or other reasonable means. We will update this policy before launching features that materially change collection (for example any future follow-up chat).
16. Jurisdiction notes
16.1 EEA / UK. If GDPR / UK GDPR applies to you, email help@whatthefact.app to exercise any of the rights in Section 11 or to raise a concern about how we handle your personal data, and we will respond. To delete your account and personal data yourself, use our account-deletion page: deletion takes effect as soon as you confirm it and is complete within 30 days at the latest, with backups purged within 90 days (see Section 9).
16.2 California (CCPA/CPRA). We do not "sell" personal information for money. You may have rights to know, delete, correct, and opt out of certain sharing for cross-context behavioural advertising. Submit requests to help@whatthefact.app.