⛓ ClaimTrail — Privacy Policy
Last updated: July 9, 2026
ClaimTrail ("ClaimTrail," "we," "us") is a research tool — a website and a Chrome
extension — that helps people trace where claims come from and organize their evidence.
This policy explains what information we collect, how we use it, and who we share it with.
We keep it plain-English on purpose.
1. Information we collect
Account information
- Email address — used to sign in, identify your account, and send password-reset links.
- Password — stored only as a salted
scrypt hash. We never store or can see your actual password.
- Role — whether you signed up as a Student/Researcher or a Teacher.
- A short username handle automatically derived from your email, used to label your data and, for classroom features, to identify you to your teacher.
Content you create
- Evidence you save — the claims, quotes, or text you highlight; images you capture; the source URLs; and any analysis notes you write.
- Projects, case files, classes, assignments, and groups you create or join.
- A research activity log — timestamps of actions like saving or removing evidence, so you (and, for assignments, your teacher) can see your research trail.
Automatically collected
- Session tokens — a random token issued when you sign in, so you stay logged in. Stored in your browser (and, for the extension, in
chrome.storage.local).
- Usage counters — a count of analyses you've run, to enforce free-tier limits.
- Preferences — such as your chosen color theme.
We do not use advertising trackers, and we do not build advertising profiles.
2. The browser extension
The ClaimTrail Chrome extension only acts when you ask it to:
- When you click the ClaimTrail icon (or use the optional selection popup / region-capture), it reads the text you have highlighted and the URL of the current page, and sends them to ClaimTrail to reconstruct the claim's provenance.
- It injects a sidebar panel into the page to show you the results.
- It does not continuously monitor, log, or transmit your browsing history. It reads page content only for the tab and moment you trigger it.
3. How we use your information
- To provide the service: store and organize your research, trace claims, and power classroom features.
- To authenticate you and keep you signed in.
- To send transactional email (password-reset links). We do not send marketing email.
- To enforce free-tier usage limits.
4. How your information is processed and shared
We do not sell your personal information. To run the service, your data is
processed by the following service providers ("sub-processors"), only as needed to provide
ClaimTrail:
- Supabase — database hosting (stores your account and content).
- Render — backend/server hosting.
- Vercel — website hosting.
- Tavily — web search. When you trace a claim, the claim text is sent to Tavily to find candidate sources.
- Groq (and, as a fallback, Google Gemini) — AI analysis. The claim text and the search results are sent to reconstruct the provenance trail. Your account details are not sent.
- SendGrid — sending password-reset emails.
We may also disclose information if required by law, or to protect the rights, safety, or
security of ClaimTrail and its users.
5. AI processing
Claim tracing uses AI models via the providers above. The content sent for analysis is the
claim text and web-search results — not your email, password, or private
account data. ClaimTrail reports how clearly a claim can be traced to its sources; it does
not determine whether a claim is "true."
6. Data security
- Passwords are hashed with a per-password salt (
scrypt) and never stored in plaintext.
- All traffic is served over HTTPS.
- API access requires your session token; you can only access your own data (and shared group/class data you belong to).
No method of transmission or storage is 100% secure, but we take reasonable measures to protect your information.
7. Data retention & your choices
- You can delete individual pieces of evidence, projects, and (for teachers) classes at any time in the app.
- You can request deletion of your entire account and associated data by emailing us (below).
- Signing out invalidates your session token.
8. Students and classrooms
ClaimTrail includes classroom features intended for use under the direction of a teacher or
school. It is not directed at children under 13, and we do not knowingly collect personal
information from children under 13 without appropriate consent. If you are a teacher or
school using ClaimTrail with students, you are responsible for obtaining any consent required
by your institution and applicable law (e.g., FERPA/COPPA). If you believe a child has
provided us personal information without consent, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating
the "Last updated" date above.
10. Contact
Questions, or want your account deleted? Email
claimtrailapp@gmail.com.
ClaimTrail — provenance, not truth scores.