Legal

Data Use

How workspace content, prompts, files, integrations, and derived metadata may be processed to provide product features.

01

Product processing

FactNot uses workspace content, prompts, uploads, source documents, citations, messages, search terms, embeddings, and derived metadata to provide search, AI assistance, collaboration, verification, notifications, and export features.

  • Account export includes account-level data and a manifest; source-specific exports remain in their source surfaces.
  • Derived search and embedding records are rebuilt or purged from source records rather than treated as permanent primary records.
  • Shared workspace content is retained with anonymized attribution by default after account erasure.
02

Save to FactNot browser extension

Save to FactNot processes a page only after you open the extension, select a writable FactNot library, and choose Save. The save request contains exactly the selected page URL and library ID; the server uses the existing public-content ingestion and private reader flow.

  • The local title and hostname preview is not included in the save request.
  • FactNot fetches public HTML pages and public PDFs. The extension does not transmit rendered page DOM or paywalled content.
  • There is no offline save queue. A network failure requires you to retry while the page is active.
  • Session credentials and PKCE state are not persisted across a browser restart; the only local preference is the last selected library ID.
  • Operational telemetry is limited to aggregate outcomes and latency and excludes article URLs and bearer tokens.
03

AI and vendors

AI processing may involve configured model, embedding, search, and infrastructure providers. Exact providers, regions, DPA status, retention settings, and transfer mechanisms are tracked in the vendor inventory and launch evidence.

  • No-training, zero-data-retention, EU-only processing, or fixed provider-retention claims apply only where vendor evidence supports them.
  • During beta, configured providers include Fly.io, Tigris Data, Resend, OpenRouter routing DeepSeek, Cloudflare Turnstile, and Namescheap.
  • Model selection may change the provider path. Use sensitive, confidential, legal, medical, financial, or copyrighted material only with models and settings you are comfortable using.
  • Prompts and outputs follow source/workspace retention where they contain personal data.
  • Administrative audit logs should record events, not raw exported payloads or unnecessary sensitive request details.