Privacy policy.

Last updated 26 July 2026. We keep the questions, not the questioner.

Trust Me Bro finds real sources for claims. To do that it has to send the claim somewhere. Here is exactly what moves, what stays, what we never touch, and the rights you have over all of it. We make money from subscriptions, not from selling you: we never sell or share your personal information, and we never sell user data to anyone. Who we are. The data controller is Edward Ashdown, sole proprietor, trading as Trust Me Bro, reachable at receipts@trustmebro.to. This policy covers the browser extension, the trustmebro website, and our public pages (Receipts, the Trust Feed, and the Trust Wiki).

What we receive

What stays on your device, and what does not

Two different things live in two different places, and we want to be straight about it.

So: we keep the questions, not the questioner.

What we never collect

Why we use it, and our legal bases

Where GDPR or UK GDPR applies, each use has a legal basis:

WhatWhyLegal basis
Text you check, page title/URLSearch the literature and return sources, the service you asked forPerformance of a contract
Device ID, usage countsMeter quotas, enforce tiers, prevent abuseLegitimate interests
Account email + password hashSign-in, disputes, subscription managementPerformance of a contract
Payment metadataBilling via Stripe, taxContract and legal obligation
Anonymized claims in the Trust Feed and WikiPublic record of what the engine judgedLegitimate interests (published without identity)
Feedback (thumbs up or down)Improve accuracy of the engineLegitimate interests
Referral tokens and the tmb_ref cookieCredit referralsLegitimate interests, or consent where required

We do not make automated decisions about you that have legal or similarly significant effects.

Your content, and what we may do with the claim corpus

This is the part most privacy policies fudge, so here it is plainly.

Chrome Web Store

Trust Me Bro's use and transfer of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements: data the extension handles is used only to provide and improve its single purpose, finding sources for claims, and never for advertising, creditworthiness, or sale to data brokers. The extension also tells you this up front, on first run, before anything is sent.

Public pages: Receipts, the Trust Feed, and the Trust Wiki

Receipts are permanent and public. None of them are connected to you.

Receipt dividends and attribution

Cookies

We set only first-party cookies: tmb_session (sign-in, HttpOnly, up to 90 days) and tmb_ref (referral attribution, 30 days). We run no third-party analytics, ad pixels, or trackers on the extension, the site, or Receipt pages.

Third parties we use

These providers receive only what's listed, never your identity alongside it:

International transfers

Our servers and most providers above are in the United States, so your data is processed there, and wherever Google and Stripe operate, regardless of where you live. For users in the EEA, UK, and Switzerland, we rely on Standard Contractual Clauses and, where providers hold them, EU-US Data Privacy Framework certifications, as the safeguards for these transfers.

Retention

Your rights

Wherever you live, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Email receipts@trustmebro.to from your account address, or include your device ID (shown in the extension's settings) for extension-only data. We answer within 30 days. If you are in the EEA, UK, or Switzerland, you additionally have the rights to restrict or object to processing, to data portability, and to withdraw consent at any time where consent is the basis, and you may lodge a complaint with your local data protection authority. If you are a California resident, you have the right to know, delete, and correct, and the right to opt out of sale or sharing of personal information. **We do not sell or share personal information as the CCPA defines those terms**, and we do not use sensitive personal information beyond providing the service. We will not discriminate against you for exercising any right. Deleting your account or data does not unpublish Receipts. Receipts were never connected to you in the first place, so there is nothing personal in them to remove; if you want a specific Receipt taken down, use the dispute or removal process above.

Security

Everything moves over HTTPS. Passwords are stored only as salted scrypt hashes. Payment webhooks are signature-verified. Access to production data is limited to the operator. If a breach ever affects your personal data, we will notify you and the relevant authorities as the law requires, within 72 hours to authorities where GDPR applies.

Children

The Service is not directed at children under 13, and we do not knowingly collect personal data from them. If we learn we have, we will delete it. If you are 13 to 17, use the Service with a parent or guardian's consent.

Changes to this policy

We date every version. If we change our data practices materially, we will give notice in the extension and on the site before the change takes effect, including the notice the Chrome Web Store requires when an extension's data practices change after install. Questions? receipts@trustmebro.to. We read everything.