FACT & ANCHOR/Privacy Policy

Privacy Policy

Last updated: June 2025

Overview

Fact & Anchor (“we”, “us”) is a pre-alpha personal document vault. This policy describes how we handle data you provide while using the service. By using Fact & Anchor you agree to this policy.

What we collect

  • Account information — your Google email address and display name, obtained via Google Sign-In.
  • Uploaded documents — files you upload are stored in Supabase Storage associated with your account (tenant).
  • Extracted record fields — key/value data extracted from your documents (e.g. names, dates, policy numbers) stored in our database.
  • Chat messages — questions and AI responses are persisted so the thread survives page refreshes.
  • Audit logs — reveal events for sensitive/secret fields are logged for security purposes.

How we use your data

  • To provide the vault service — storing, retrieving, and answering questions about your documents.
  • To improve the prototype — we may review aggregate usage patterns to guide development.
  • We do not sell, rent, or share your personal data with third parties for marketing.

Anthropic API

Document text is sent to the Anthropic API (Claude) for field extraction and chat responses. Anthropic does not store or train on API request data by default under their standard API terms. Secret field values (marked sensitive by you) are never sent to any external AI API.

You should not upload documents containing real sensitive personal information during the pre-alpha period. The service is for validation and testing purposes only.

Data storage and security

Data is stored in Supabase (PostgreSQL database and object storage) hosted in the United States. Fields you mark as “secret” are encrypted at rest using AES-256-GCM before being written to the database.

Your rights

  • Access — you can view all your stored records and documents within the app.
  • Deletion — to request deletion of your account and all associated data, email factandanchor@gmail.com. We will process deletion requests within 30 days.
  • Portability — contact us to request an export of your data in JSON format.

Cookies and tracking

We do not use advertising cookies or third-party trackers. Firebase Authentication uses a session token stored in browser local storage to keep you signed in.

Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated via email to registered users. Continued use after changes constitutes acceptance.

Contact

Questions about this policy? Email us at factandanchor@gmail.com.

Effective Date

This policy is effective as of June 2, 2026.