Privacy Policy

Last updated: 20 August 2026

Stipple ("Stipple", "we", "us") operates a document-verification service at www.stipple.sh. You submit a document (such as a PDF or image) and we check it for signs of tampering and internal inconsistency, then return an explainable result. This policy explains what we collect, why, who processes it, and how long we keep it. You can use the verifier without creating an account.

1. Information we collect

  • Documents you submit. The files you upload for verification and the figures and text our engine reads from them while analysing them.
  • Verification results and feedback. The result we produce for each document, and any thumbs-up / thumbs-down feedback you choose to give on a result.
  • Text you send with a rating. When you rate a text-analysis result — thumbs up or thumbs down — we keep the text you checked along with your rating, for 120 days, and use it only to measure and improve the accuracy of that check. Your rating tells us whether the result was right, and the text is what lets us reproduce it; a rating on its own tells us something was wrong but never what. Rating a result is entirely optional: if you do not rate it, nothing you checked is kept.
  • Account and API-key data. If you choose to sign in or create a free API key, we collect your email address, and we keep a history of your checks — the verdicts only, never the text or files you submitted. Website checks use a free account (Google or a sign-in link); the API and MCP work with a key or anonymously.
  • Payment data. If you buy credits, payment is handled by Stripe on Stripe-hosted pages — your card details never reach our servers. We keep a record of the purchase (the pack, the amount, the API key it credits, and the email Stripe verified with the payment) to maintain your balance and for accounting.
  • Technical and usage data. A one-way, salted hash of your IP address (we do not store your raw IP), your browser's or client's user-agent string, and basic request logs (the time of a request, which checks ran, what they cost in credits, and — for API callers — the key used and the client software's self-declared name). These are used to operate the service, enforce limits and credit charging, and prevent abuse.
  • Website analytics. Aggregate usage data collected through Google Analytics, and a small preference cookie that remembers your light/dark theme.

Over the API and MCP you do not need to provide a name, email address, or any account details to verify a document. On the website, running a check uses a free sign-in (Google or a sign-in link) — the email that comes with it, and an email for an API key or a purchase, is all we ask for. We do not knowingly store the content of your documents in our searchable index — that index holds only a minimal record of each check (its outcome and the hashed IP), never the document text or extracted personal data.

2. How we use your information

  • To run the verification you requested and return a result.
  • To prevent abuse, apply rate limits, and keep the service secure and reliable.
  • To detect, diagnose, and fix errors.
  • To understand aggregate usage and improve the service.
  • To improve detection quality. Documents submitted for verification on or after 14 August 2026, and their results, may be reviewed and used to test and improve our detection checks during their retention window. Documents submitted before that date are not used this way. Text you rate, and the rating you gave it, are used the same way: your rating is what tells us whether the check was right, so the two together are what let us measure and improve accuracy.

We do not use your documents to advertise to you, and we do not sell your personal information.

3. Cookies and analytics

We use a small functional cookie (stipple_theme) to remember your display preference, and Google Analytics, which sets its own cookies to measure how the site is used. You can block or delete cookies in your browser settings; the verifier itself works without them.

4. How we share information

We do not sell your information. We share it only with the service providers ("sub-processors") that help us run Stipple:

  • Google Cloud Platform — hosting, document and result storage, and our database, hosted in the Australia (Sydney) region.
  • OpenRouter — when AI analysis is used, the document (or images and text from it) is sent to our AI model provider, which runs the models that read and analyse it.
  • Stripe — payment processing for credit purchases, on Stripe-hosted checkout pages; card details go to Stripe, never to us.
  • Sentry — error and diagnostic reporting that helps us keep the service reliable.
  • Google Analytics — aggregate website usage measurement.

We may also disclose information if required by law, or to protect the rights, safety, and security of our users and our service.

5. Data retention

Documents uploaded for verification, their detailed results, and stored fact-check results are kept for 120 days and then automatically deleted. Storage is content-addressed, so if the identical file is submitted again the 120 days run from its first upload, not the latest one. (Documents submitted before 14 August 2026 remain under the earlier 30-day window.)

A minimal record of each check (its outcome and the hashed IP — never the document content) and our request logs are retained to operate the service, prevent abuse, and understand usage. You can ask us to delete a document or result you submitted at any time (see "Contact us"); deletion covers the stored document, its result, and any copy held for detection improvement.

6. Security

  • All data is encrypted in transit using HTTPS/TLS.
  • Documents and results are stored on Google Cloud Platform, protected by its security controls.
  • Your IP address is stored only as a one-way, salted hash — we cannot recover the original address from it.
  • No document content or extracted personal data is stored in our searchable index.
  • Accounts are passwordless (a sign-in link or Google sign-in) — there is no password for you to manage or for anyone to steal. The API and MCP work without an account. API keys are stored only as one-way hashes.

No method of transmission or storage is ever completely secure, but we work to protect your information using reasonable safeguards.

7. Where your data is processed

Your documents and results are stored in Australia (Google Cloud, Sydney region). Some of our sub-processors — our AI model provider, analytics, and error monitoring — may process data in other countries, including the United States. Where that happens, the data is handled under those providers' own terms and safeguards.

8. Your choices and rights

The API can be used without an account, so we hold very little information that identifies you. You can manage or block cookies in your browser, and you can email us to ask what data we hold about a verification you submitted or to request its deletion. Depending on where you live, you may have additional rights under local data-protection law; contact us and we will do our best to honour them.

9. Children's privacy

Stipple is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Significant changes will be made clear on this page.

11. Contact us

Questions about this policy or your data? Reach us through our contact page.