BACK TO TRUESTREAM
LEGAL · LAST UPDATED JANUARY 2026

Privacy Policy

TrueStream is a fact-checking tool for social-media videos. This Privacy Policy explains what information we collect when you use the web app, our Android overlay bubble, or the shared fact-check pages — and what we do with it.

What we collect

Video URLs you submit. When you paste or share a URL, we send it to our backend to fetch the video's captions and run our multi-agent verification pipeline. We cache the resulting verdict, tied to a hash of the URL, so we can serve subsequent requests instantly.

Account data (only if you sign in). Sign-in is via Google (Emergent-managed OAuth). If you sign in we store your email, display name, profile picture URL, and a session token. We never store your Google password — Google handles authentication.

Anonymous usage counters. Anonymous browsers get up to three free fact-checks per session, tracked in your browser's localStorage only. Clearing your site data resets the counter.

Server logs. Our backend receives your IP address in HTTP request headers so it can enforce rate-limits (30 requests / minute per IP) and diagnose abuse. IPs are not linked to your account.

Android app permissions. The TrueStream Android app uses an Accessibility Service restricted at the OS level to a hard-coded list of video / audio apps (YouTube, TikTok, Instagram, X, Facebook, Spotify, YouTube Music, Netflix). It reads the currently-visible video title or URL from those apps only, and uses it to fact-check the video. It cannot read from any other app on your device.

What we do NOT collect

  • Your Google password (Google auth handles this).
  • Browsing history or content from any app outside the video-app allow-list on Android.
  • Payment information — TrueStream is currently free.
  • Precise device location.
  • Sensitive categories (health data, sexual orientation, religion, etc.).

How we use your data

  • To run the fact-check pipeline you asked for.
  • To keep a shared cache of verdicts so repeated checks are instant (video URL hash + verdict, no user identifier).
  • To rate-limit abuse.
  • To let signed-in users skip the anonymous 3-checks-per-browser cap.

Third-party services

  • Google Fact Check Tools API — used to look up IFCN-verified fact-checker reviews for each claim. Only the claim text is sent, never your identity.
  • OpenAI (GPT-5.2 & Whisper) via Emergent — used for claim detection, evidence synthesis, and (fallback) audio transcription. Only the relevant transcript / claim text is sent.
  • Wikipedia REST API — used for background evidence lookups.
  • yt-dlp — used server-side to fetch public video captions.
  • Google OAuth — handles sign-in.

Retention

Cached verdicts follow a variable time-to-live (12 h for breaking news, 72 h for scientific claims, up to 30 days for historical claims), after which MongoDB deletes them automatically. User sessions expire after seven days. Signed-in user records persist until you request deletion (see below).

Your rights

You can request access to, correction of, or deletion of your account data at any time by emailing us. If you're in the EU / UK / California, you have additional rights under GDPR / CCPA — same email works. We reply within 30 days.

Children

TrueStream is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

We'll update the “last updated” date at the top when we make material changes. Continuing to use TrueStream after changes means you accept them.

Contact

Questions or requests: hello@truestream.app.

ONE-TAP FROM ANY VIDEO APP
Install TrueStream

Add to your home screen so “Share → TrueStream” works from YouTube, TikTok, Instagram, X, and Facebook.