Privacy
ClaimCircle Privacy Policy
Effective date: June 22, 2026
Overview
ClaimCircle is a Chrome extension that helps users fact-check online content after the user deliberately circles a post, paragraph, image, or other visible page area. The extension is designed to process only the selected region needed for the requested check. ClaimCircle has a zero data retention policy for selected website content: circled page text, image content, URLs, and nearby context are used to return the requested check and are not saved as a user history or stored for later review. ClaimCircle does not sell user data, does not use user data for advertising, and does not run continuous full-page fact checks in the background.
Information We Collect or Process
ClaimCircle may collect or process the following categories of data:
- Account information: email address, user ID, sign-in provider, authentication session state, and password reset or email confirmation state when you create or use an account. If you use email and password sign-in, your password is sent to Supabase Auth for authentication; ClaimCircle does not store your plain-text password.
- Quota and plan information: installation identifier, free checks used, free checks remaining, plan status, Paddle customer and subscription identifiers, subscription status, and billing-period dates.
- Payment information: Paddle processes payment details, billing address, tax information, and transaction records. ClaimCircle receives subscription status and identifiers needed to grant paid quota, but does not receive or store your full payment card number.
- Selected website content: the visible text, page title, page URL, image metadata, image URLs, image data, and nearby context from the specific area you intentionally circle. For YouTube checks, ClaimCircle may process a short recent caption window around the video timestamp when available. This selected website content is processed under ClaimCircle's zero data retention policy and is not saved as a fact-check history.
- Local gesture information: recent mouse coordinates and circle-detection data used locally by the extension to determine whether you intentionally circled a region. This local gesture stream is not sent to ClaimCircle unless it becomes part of a user-triggered check request.
- Diagnostics and request metadata: extension version, request stage, provider name, timing, error type, HTTP status, Cloudflare request ID, approximate country or data center derived by Cloudflare, and similar reliability information. ClaimCircle may also receive standard server metadata such as IP address, user agent, origin, request URL, and request time through Cloudflare logs.
- Website analytics: visits to the ClaimCircle website may be measured with Google Analytics, including pages viewed, approximate location, device/browser information, and referral information.
Information We Do Not Intentionally Collect
ClaimCircle does not intentionally collect full browsing history, full-page HTML, keystrokes, passwords from webpages, payment card numbers, government IDs, or health records. The extension includes safeguards designed to prevent checks from capturing sensitive form areas, including password fields, email fields, phone fields, card fields, OTP fields, textareas, and editable form content. ClaimCircle reads visible page text rather than raw form values; masked fields such as passwords are not available to ClaimCircle as raw text and appear only as browser-masked characters such as dots or asterisks.
How We Use Information
We use the information described above to:
- authenticate users and keep accounts signed in;
- provide the requested fact-check result, including verdict, confidence, explanation, and source links;
- manage installation and account quotas, subscription access, billing support, and abuse prevention;
- debug failures, measure latency, improve reliability, and protect the service from misuse;
- understand aggregate website traffic and product usage.
Service Providers and Data Sharing
ClaimCircle shares data only when needed to operate the extension, provide the requested feature, secure the service, comply with law, or handle a business transfer. Current service providers include:
- Cloudflare: hosts the ClaimCircle backend API and may process request metadata, logs, diagnostics, and fact-check requests.
- Supabase: provides authentication, email/password account flows, Google OAuth session handling, password reset, user IDs, email addresses, and quota storage.
- Paddle: provides checkout, payment processing, tax handling, receipts, subscription billing, customer billing portals, and refund processing for ClaimCircle Plus.
- Mistral AI: provides the fact-checking assessment with search grounding. It processes the selected circled context, image content when included, grounded source snippets, and instructions needed to return a verdict, confidence, explanation, and source links.
- Google: provides Google OAuth sign-in when you choose it and Google Analytics for the ClaimCircle website.
ClaimCircle does not sell personal data and does not transfer user data to serve personalized, retargeted, or interest-based advertising.
Storage and Retention
Account, authentication, quota, and subscription status information may be stored in Supabase while your account remains active or while needed to operate ClaimCircle. An installation identifier and anonymous usage count may be stored locally in the extension and in Cloudflare KV. Local extension storage may also contain session tokens and cached remote configuration until you sign out, clear extension storage, or uninstall the extension. Paddle retains transaction and subscription records under its legal and operational requirements. Cloudflare logs and diagnostics may be retained for operational debugging and security. Selected website content submitted for a fact check is handled under zero data retention: it is processed to produce the requested result and is not stored by ClaimCircle as a user history, training dataset, or archive. ClaimCircle uses API providers for transient processing on zero data retention or no-training terms for selected website content.
Security
Production network requests use HTTPS. Provider API keys are kept on the hosted backend and are not included in the Chrome extension package. Authentication is handled through Supabase, and ClaimCircle verifies signed user sessions on the backend before applying quota. Access to operational systems is limited to people and services that need it to operate and secure ClaimCircle.
User Choices and Controls
ClaimCircle sends selected page content only when you intentionally trigger a check by circling content. You can sign out from the extension popup. You can uninstall the extension at any time to remove its local browser storage. You can use browser settings or extensions to limit cookies, analytics, and site storage on the ClaimCircle website.
Access, Deletion, and Support Requests
To request account deletion, quota data deletion, or privacy support, contact the publisher using the contact email listed on the ClaimCircle Chrome Web Store listing. We may need enough information to identify the account, such as the email address used to sign in.
Children
ClaimCircle is not directed to children under 13 and is not intended to knowingly collect personal information from children.
Changes
We may update this policy as ClaimCircle changes. When we make material changes, we will update the effective date on this page.
Limited Use Statement
ClaimCircle's use and transfer of information received from Chrome extension permissions is limited to providing and improving the user-facing fact-checking feature, account/quota functionality, security, debugging, and compliance. ClaimCircle does not use or transfer this information for personalized advertising, retargeting, interest-based advertising, or sale.