Privacy Policy for FactsOnly
Last Updated: June 30, 2026
Overview
FactsOnly is an automated fact-checking service that performs metadata-first fact analysis and may request direct media upload when metadata confidence is low. Currently available on Instagram, with more platforms planned. This policy explains how we handle your data.
What Data We Collect
Automatically Collected
- Platform User ID: To enforce rate limits (20 fact-checks per day)
- Message Content: Text and captions you send to the bot
- Permalink Metadata: If you share a post link, we may resolve metadata (for example caption/title and author name) through official APIs
- Media Content: Images/videos you send for fact-checking when deep analysis is required
- Message Metadata: Timestamps, message IDs (from platform webhooks)
- Verdict reports: If you flag a verdict as wrong ("report wrong verdict"), the disputed verdict text is logged so we can review and correct it
Persisted Intelligence (Structured, Not Raw Media)
- Claim records: normalized claim text, claim hash, verdict, search content (source snippets), topic, language
- Source records: URLs of sources used to verify each claim
- Post linkage: external post IDs and claim-to-post links
- Verdict log: verdict response text and extracted claims for quality review — stored anonymously, with no user identifier attached. We keep no per-user fact-check history in our database
- Cache records: short-lived Redis entries (about 24 hours) for rate limiting, deduplication, and follow-up conversation context
- First-use notice flag: a single flag in Redis noting we've shown you the one-time welcome/terms notice, kept up to 1 year so the bot doesn't repeat it on every message
Not Collected / Not Retained Permanently
- We only act on content you actively send or share with the bot — we do NOT crawl, monitor, or collect from Instagram on our own. To fact-check a reel or post you share, we may retrieve its media through a third-party retrieval service (see Third-Party Services)
- We do NOT permanently store raw uploaded media files
- We do NOT track your activity outside of direct interactions with the bot
How We Use Your Data
Ephemeral Processing (Temporary)
- Media Analysis: Your image/video is temporarily processed to extract factual claims
- AI Processing: Content is sent to Google Gemini AI for claim extraction; claims are verified via Tavily Search API and, as a fallback, Google Search grounding
- Automatic Deletion: Media is deleted immediately after analysis completes (cleared in a
finallyblock), with a short safety-net cleanup that removes anything left within minutes
Persistent Intelligence (Core Database)
- Structured claim intelligence is stored in Supabase (Postgres) as the system of record
- This includes claim normalization, verdicts, search content, and post linkage
- This does not include permanent storage of raw uploaded images/videos
Caching & Rate Limiting (Redis)
- Platform user IDs are used as short-lived keys (about 24 hours) to enforce daily usage limits (20 checks/day) and to hold brief follow-up conversation context
- Duplicate message IDs are cached for up to an hour to prevent double-processing
- A first-use flag is kept up to 1 year so the one-time welcome/terms notice is shown once, not on every message
Third-Party Services
We share data with the following services only during active fact-checking:
Google Gemini AI (Gemini 3 Flash)
- Purpose: Extract factual claims from media
- Data Shared: Your image/video content temporarily
- Privacy: Subject to Google's Generative AI Terms
Tavily Search API
- Purpose: Per-claim web search to find authoritative sources for verification
- Data Shared: Rewritten search queries derived from claims (no images/videos)
- Privacy: Subject to Tavily Privacy Policy
Google Search (Grounding Fallback)
- Purpose: Fallback verification when primary search returns no results
- Data Shared: Text claims only (no images/videos)
Messaging Platforms (currently Instagram/Meta)
- Purpose: Deliver responses to you via DM
- Data Shared: Message content (fact-check results only)
- Privacy: Subject to the platform's own privacy policy (e.g. Meta's Privacy Policy)
Supabase (Database Hosting)
- Purpose: Persistent storage of structured claim intelligence and lifecycle history
- Data Shared: Claim text, verdicts, search content snippets, source metadata, post linkage
- Privacy: Subject to your Supabase project configuration and regional setup
Reel/Post Media Retrieval (third-party)
- Purpose: When you share a reel or post link, recover its publicly-available media so it can be fact-checked
- Data Shared: The public reel/post URL only — no messages, no user IDs, no media
Sentry (Error Monitoring)
- Purpose: Catch and diagnose service errors so the bot stays reliable
- Data Shared: Operational diagnostics only. Message content (captions, claims, search queries, verdict text) is stripped before sending, and the platform user ID is hashed (pseudonymized) — it is not sent in the clear
- Privacy: Subject to Sentry's Privacy Policy
Data Retention
| Data Type | Retention Period | Purpose |
|---|---|---|
| Media content (images/videos) | Until analysis completes (cleared within minutes) | Analysis only |
| Structured claim records (normalized text, verdict, sources) | Persistent (anonymous) | Reuse, deduplication, consistency |
| Verdict log (response text + claims) | Persistent (anonymous — no user identifier) | Quality review |
| Platform User ID (rate-limit & session keys, Redis) | ~24 hours | Rate limiting, follow-up context |
| First-use notice flag (Redis) | ~1 year | Show the welcome/terms notice once |
| Server logs / error monitoring | 7 days | Error debugging |
Your Rights
Can the developer see my messages?
As the service operator, we technically have access to message content through the Instagram API and server logs. We do not read, review, or monitor individual conversations. Messages are processed automatically by AI and are not reviewed by humans unless required for abuse investigation or legal compliance.
Access & Deletion
Raw media is ephemeral and auto-deleted right after analysis. Verdict and claim records are stored anonymously (no user identifier), and we keep no per-user fact-check history. The only data tied to you is short-lived Redis state (rate-limit counters and recent conversation context) that expires on its own.
You can still erase that state at any time, three ways:
- In the DM: send "delete my data" (or "forget me") and the bot immediately clears your saved conversation state, then confirms.
- By email: contact us at the address below and we'll erase it for you.
- By removing the app: if you remove FactsOnly from your Instagram settings — or Meta sends us a data-deletion request on your behalf — we automatically clear your state.
Either way, the shared, anonymous fact-check records are unaffected — there's nothing in them that identifies you.
Opt-Out
Stop using the bot at any time by:
- Blocking or unfollowing FactsOnly on your platform
- Deleting your conversation with the bot
Data Security
- All communication uses HTTPS/TLS encryption
- Media is processed in-memory when possible
- Temporary files are deleted with best-effort cleanup (finally blocks + timeout cleanup)
- Rate limit data is stored in Redis according to your hosting/deployment configuration
- Supabase service-role credentials are intended for backend-only use
Children's Privacy
FactsOnly is not intended for users under 13. We don't knowingly collect data from children. Instagram requires users to be 13+.
Changes to This Policy
We may update this policy. Changes will be posted here with an updated "Last Updated" date. Continued use after changes constitutes acceptance.
Legal Basis
If applicable in your jurisdiction (for example GDPR/UK GDPR), processing may rely on:
- Legitimate Interest: Providing fact-checking services you request
- Consent: By sending content to the bot — after the one-time notice that points you to these terms — you consent to the processing needed to fact-check it
This section is informational only and is not legal advice.
Limitations & Disclaimers
Not Professional Advice
- Results are for informational purposes only
- Not medical, legal, financial, or professional advice
- Verify important claims with qualified professionals
Accuracy
- We use AI and automated sources which may contain errors
- Always verify critical information independently
- Sources are provided for your own verification
Fair Use
- Content analysis is designed for transformative fact-checking use
- We don't republish or redistribute your content
- Permanent storage is limited to structured intelligence, not raw media
Contact
For privacy questions, data deletion requests, or concerns:
Compliance
This service is designed to align with:
- Instagram Platform Terms
- Meta Developer Policies
- Google Generative AI Terms
- General data protection best practices
Actual compliance depends on your deployment configuration, jurisdiction, and operational controls.
Note: This is an independent bot and is not affiliated with Instagram, Meta, or Google.
