Privacy policy.
Last updated 26 July 2026. We keep the questions, not the questioner.
Trust Me Bro finds real sources for claims. To do that it has to send the claim somewhere. Here is exactly what moves, what stays, what we never touch, and the rights you have over all of it. We make money from subscriptions, not from selling you: we never sell or share your personal information, and we never sell user data to anyone. Who we are. The data controller is Edward Ashdown, sole proprietor, trading as Trust Me Bro, reachable at receipts@trustmebro.to. This policy covers the browser extension, the trustmebro website, and our public pages (Receipts, the Trust Feed, and the Trust Wiki).
What we receive
- The text you check. When you run a lookup, check a claim or quote, or review an essay, that text is sent to our server so we can search the academic literature and return sources. Nothing is sent until you act; highlighting alone sends nothing.
- Page title and address, sometimes. When you check a claim from a page, the page's title and URL ride along to improve the search. That is the only page data we see.
- An anonymous device ID. A random identifier stored in your browser, used to count your checks and remember your tier. It is not linked to your name, email, or browsing.
- Account details, if you have an account. Email address and a password (stored only as a salted hash). You can use the free extension without an account. An account is required for a Bro or Pro subscription, and to submit disputes or contributions.
- Votes, disputes, and contributions you submit on Receipts.
- Payment metadata. Payments run through Stripe. Your card details go to Stripe, never to us; we hold only a Stripe customer reference and your subscription status.
- Waitlist emails, if you join a waitlist.
What stays on your device, and what does not
Two different things live in two different places, and we want to be straight about it.
- Your history is yours. The "Recent lookups" drawer, and your citation format preference, live in local extension storage. We never see that list, and we hold no per-person history of what you have looked up.
- The claims themselves enter our database. Every claim the engine judges is stored on our servers with its verdict and sources, so repeat lookups are instant, so Receipts have an honest history, and so the public library grows. That record is stored as a claim, not as your claim: it carries no device ID, no account, and nothing that ties it back to you.
So: we keep the questions, not the questioner.
What we never collect
- Browsing history. The extension does not track the pages you visit.
- Page content you didn't explicitly check.
- Your name, unless you email it to us.
Why we use it, and our legal bases
Where GDPR or UK GDPR applies, each use has a legal basis:
| What | Why | Legal basis |
|---|
| Text you check, page title/URL | Search the literature and return sources, the service you asked for | Performance of a contract |
| Device ID, usage counts | Meter quotas, enforce tiers, prevent abuse | Legitimate interests |
| Account email + password hash | Sign-in, disputes, subscription management | Performance of a contract |
| Payment metadata | Billing via Stripe, tax | Contract and legal obligation |
| Anonymized claims in the Trust Feed and Wiki | Public record of what the engine judged | Legitimate interests (published without identity) |
| Feedback (thumbs up or down) | Improve accuracy of the engine | Legitimate interests |
Referral tokens and the tmb_ref cookie | Credit referrals | Legitimate interests, or consent where required |
We do not make automated decisions about you that have legal or similarly significant effects.
Your content, and what we may do with the claim corpus
This is the part most privacy policies fudge, so here it is plainly.
- Your personal data is not for sale. Not now, not later, not to anyone. We do not sell or share it for advertising, and we do not hand it to data brokers.
- We do not use your content to train AI models, and our AI providers are not permitted to train on what we send them.
- The claim corpus is a different thing, and we may license it. Claims, verdicts, evidence, and Receipts, stripped of any connection to the people who submitted them, make up a public and growing body of work. We may license access to that corpus, or to an API built on it, to businesses including AI companies. What would be licensed is the claim-verdict-source record, the same material anyone can already read on our public pages, never your identity, your account, your device ID, or a history of who asked what.
- Because a claim box accepts free text, please do not type personal details about yourself or anyone else into one. Treat it as a public question, because that is what it becomes.
Chrome Web Store
Trust Me Bro's use and transfer of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements: data the extension handles is used only to provide and improve its single purpose, finding sources for claims, and never for advertising, creditworthiness, or sale to data brokers. The extension also tells you this up front, on first run, before anything is sent.
Public pages: Receipts, the Trust Feed, and the Trust Wiki
Receipts are permanent and public. None of them are connected to you.
- Every Receipt is anonymous by construction. When the engine judges a claim, the Receipt it produces carries the claim, the verdict, the confidence, and the sources. It never carries your device ID, your account, your email, or your name, whether or not you ever press Share.
- Fresh claims may appear on our public pages. The Trust Feed and Trust Wiki publish claims the engine has judged, anonymized in exactly that way. Don't type anything into a claim box you wouldn't want on that wall, because the claim can appear there even if you never share it.
- Sharing publishes your connection to a Receipt, not your data. Pressing Share gives you a link and makes that Receipt discoverable. The page still says nothing about you. What changes is that you are now the person handing it around, and anyone you send it to knows you checked that claim. That link is permanent and search engines can index it, so share what you are happy to be seen sharing.
- Receipts can quote and cite third-party published sources. If you are an author, publisher, or person referenced on a Receipt, you can dispute it via the link on the page; we review disputes within 7 days and publish dated corrections (see the Terms of Service, Sections 10 and 11).
- To request removal of a shared Receipt, use the dispute link or email us and we'll sort it, normally within 7 days.
Receipt dividends and attribution
- When you share a Receipt, we mint an anonymous attribution code tied to your device: a random code, never your name or email. Each share gets its own per-share token, so no stable identifier follows you or anyone else around the web.
- If someone opens a Receipt through your link, we set a first-party cookie (
tmb_ref) in their browser for 30 days so a later subscription can be credited to your wallet. It is a single opaque token, readable only by us, holding no personal data. - The map from token to wallet lives only on our server and is never exposed.
Cookies
We set only first-party cookies: tmb_session (sign-in, HttpOnly, up to 90 days) and tmb_ref (referral attribution, 30 days). We run no third-party analytics, ad pixels, or trackers on the extension, the site, or Receipt pages.
Third parties we use
These providers receive only what's listed, never your identity alongside it:
- Google Vertex AI (Gemini) receives the text being checked and retrieved paper abstracts, to judge how well a source supports a claim and to write the summary. Google's terms do not permit training on this data.
- Academic databases (Europe PMC and OpenAlex, with Semantic Scholar and Crossref as fallbacks) receive search queries derived from your claim.
- Google Fact Check Tools API (Pro features) receives the claim text.
- Stripe handles payment processing; Stripe's privacy policy applies to that step.
- Google Cloud Run hosts our application servers (United States, us-central1).
- Neon hosts our Postgres database (United States).
International transfers
Our servers and most providers above are in the United States, so your data is processed there, and wherever Google and Stripe operate, regardless of where you live. For users in the EEA, UK, and Switzerland, we rely on Standard Contractual Clauses and, where providers hold them, EU-US Data Privacy Framework certifications, as the safeguards for these transfers.
Retention
- Checked claims and results are kept indefinitely, cached so repeat lookups are instant, with an append-only log of claim events so a Receipt can show its history honestly. These contain no identity, only the claim text and the engine's output.
- Essay text submitted for review is deleted within 30 days of the review completing.
- Draft hand-offs (the stash used to move an essay into the side panel) are deleted on first read or within 1 hour, whichever comes first.
- Accounts are kept until you delete them. Disputes and contributions are kept as part of the public record of the Receipt they concern.
- Payment records are kept as long as tax and accounting law requires.
Your rights
Wherever you live, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Email receipts@trustmebro.to from your account address, or include your device ID (shown in the extension's settings) for extension-only data. We answer within 30 days. If you are in the EEA, UK, or Switzerland, you additionally have the rights to restrict or object to processing, to data portability, and to withdraw consent at any time where consent is the basis, and you may lodge a complaint with your local data protection authority. If you are a California resident, you have the right to know, delete, and correct, and the right to opt out of sale or sharing of personal information. **We do not sell or share personal information as the CCPA defines those terms**, and we do not use sensitive personal information beyond providing the service. We will not discriminate against you for exercising any right. Deleting your account or data does not unpublish Receipts. Receipts were never connected to you in the first place, so there is nothing personal in them to remove; if you want a specific Receipt taken down, use the dispute or removal process above.
Security
Everything moves over HTTPS. Passwords are stored only as salted scrypt hashes. Payment webhooks are signature-verified. Access to production data is limited to the operator. If a breach ever affects your personal data, we will notify you and the relevant authorities as the law requires, within 72 hours to authorities where GDPR applies.
Children
The Service is not directed at children under 13, and we do not knowingly collect personal data from them. If we learn we have, we will delete it. If you are 13 to 17, use the Service with a parent or guardian's consent.
Changes to this policy
We date every version. If we change our data practices materially, we will give notice in the extension and on the site before the change takes effect, including the notice the Chrome Web Store requires when an extension's data practices change after install. Questions? receipts@trustmebro.to. We read everything.