Privacy Policy
Last updated: 2026-08-29
according to is a Chrome extension that checks claims you select on the web against real search results, weighted by a list of domains you personally curate. This policy describes exactly what data the extension and its backend collect, why, and where it's stored — nothing more.
What we collect
Email address. Collected when you create an account, via Supabase Auth. Used only for sign-in. An account is required to use the extension at all, since every check is scored against your own trust list.
Your trusted-domains list. Each domain you add on the Sources tab, plus the trust score you assign it. You fully control this list — add, edit, or remove entries at any time.
Search history, including the sources behind each result. Each time you check a claim, we store the claim text, the resulting verdict, the confidence score, and a timestamp — plus, for every source used to reach that result, its domain, your trust score for it, the LLM's supports / refutes / unrelated judgment, the snippet text, and the source URL. This is what powers the Searches tab, including its "see sources" evidence view. We do not store the raw text you originally selected on the page — only the claim(s) extracted from it (see "How your data is processed" below).
Billing and subscription state, if you subscribe. Your Stripe customer ID, current plan, and subscription status. We never see or store your card details — those go directly to Stripe's own hosted checkout page.
Your own Anthropic API key, only if you choose the "bring your own key" (BYOK) plan. Stored encrypted at rest. Used to make Anthropic API calls on your behalf so that usage bills to your own Anthropic account instead of ours.
On your device, via Chrome's storage
API. Your sign-in session (access and refresh tokens, plus
your user id/email), so you stay signed in between browser restarts;
two small display preferences (confidence-mode and trust-score
scale); and a short-lived cache of your most recent check
result, so reopening the popup shows it instantly. None of this
leaves your device except your session token, which is sent to
authenticate your own calls to our backend.
How your data is processed
Checking a claim involves a few third-party services along the way:
- Claim extraction. The raw text you selected is sent to Anthropic's Claude API to narrow it down to up to 3 specific, checkable claims, and to judge whether the text reads as a checkable factual claim at all (as opposed to an opinion or anecdote). This raw selection is not stored by us — only the extracted claim(s) that result from it, once you confirm and run a check. If the text didn't read as a checkable claim, the steps below (search and stance classification) are skipped entirely and the result is recorded as "not assessable" with no sources.
- Search. Finding sources for a claim means sending the claim text as a search query to Serper.dev, plus your browser's country/language so results are geo-targeted to you rather than to our server's location. If Serper is unavailable, we fall back to Brave Search with the same claim text and locale.
- Stance classification. The claim text and each retrieved result snippet are sent to Anthropic's Claude API, which judges whether the snippet supports, refutes, or is unrelated to the claim.
- Billing. If you subscribe, checkout and payment happen entirely on Stripe's own hosted pages. We only receive your Stripe customer ID and subscription status back via Stripe's webhooks.
If you're on the BYOK plan, claim extraction and stance classification are billed to your own Anthropic account (using your stored key) instead of ours; otherwise they run on our shared Anthropic account. Anthropic's, Serper's, Brave's, and Stripe's handling of the data sent to them is governed by their own respective privacy policies, not this one.
Where your data is stored
Your email, trusted-domains list, search history (including per-source snippets and links), subscription/billing state, and — if you're on the BYOK plan — your encrypted Anthropic API key are stored in Supabase, a third-party backend-as-a-service provider we use for our database and authentication. Row Level Security scopes every row to your own account, so only you (and, operationally, us as the service operator) can access your data — never other users.
Supabase, Anthropic, Serper, Brave, and Stripe all operate infrastructure in the United States. Using according to means your data may be processed and stored outside your own country, including the US, regardless of where you are.
How we secure your data
- All traffic between the extension, our backend, and every third-party service above travels over HTTPS.
- Your BYOK Anthropic API key, if you provide one, is encrypted at rest (Fernet/AES) before it's stored, and only decrypted in memory at the moment it's used to make an API call on your behalf.
- We never see or store your card details — Stripe's own hosted checkout handles those directly.
- Supabase Row Level Security enforces account-scoping at the database level, not just in application code.
How long we keep your data, and how to delete it
We keep your account data — email, trusted-domains list, search history, and billing state — for as long as your account is active. You can remove individual trusted-domain entries yourself at any time from the Sources tab, and export your full search history at any time from the Searches tab. To delete your account and all associated data, email us at the address below; we don't yet have a self-serve "delete my account" button, so this is handled manually on request.
Your rights
Depending on where you live, you may have rights under laws like the EU/UK GDPR or the California CCPA/CPRA to access, correct, export, or delete your personal data, or to object to how it's processed. You can already do most of this yourself in the extension (see above); for anything else, email us at the address below and we'll honor applicable requests.
Children's privacy
according to is not directed to children under 13, and we do not knowingly collect data from them.
Changes to this policy
If we materially change what data we collect or how we use it, we'll update this page and its "Last updated" date, and adjust the extension's in-product disclosures to match. Continuing to use according to after a change means you accept the update.
What we don't do
We do not sell your data to third parties, and we do not use your search history, source data, or trusted-domains list for advertising.
Contact
Questions about this policy: jonathan.kammering@gmail.com