← Back to Pikaan

Privacy Policy

Last updated: August 5, 2026 · Policy version 2026-08-05

1. Introduction

Pikaan ("we", "our", or "us") is an AI-powered real-time fact-checking platform. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

2. Data processing and retention

The registry below is Pikaan's authoritative description of the personal data used by each launch capability. We do not sell personal data. A configured provider receives only the data needed for its role in the requested service.

Account and authentication

Data
Name, email address, account role and profile settings; Password hashes, sign-in sessions and security audit metadata; IP address and device or browser metadata used for security.
Purposes
Create and secure the account; Authenticate requests and prevent abuse; Provide account support and security notices.
Provider roles
Pikaan application and database hosting; Authentication and optional social sign-in providers.
Retention
Kept while the account is open. Security and audit records may remain for the period needed to protect the service or meet legal obligations after account cleanup.
User controls
Profile correction and account-rights requests are handled through account settings or [email protected].

Verification content and results

Data
Submitted text, URLs, documents, audio and transcripts; Extracted claims, sources, analysis results and session activity; Private object-storage references and processing diagnostics.
Purposes
Run the requested fact-checking workflow; Save sessions and results for the account owner; Secure, diagnose and support the verification service.
Provider roles
Configured AI model and web-search providers; Configured speech-to-text providers; Private file storage and application hosting providers.
Retention
Submitted text, transcripts and results remain with a saved session until the user deletes that session or account cleanup completes. Temporary uploaded objects use their object-specific expiry and cleanup schedule.
User controls
Session owners can delete saved sessions. Provider processing depends on the capability and model selected for that request.

Billing and credits

Data
Subscription, invoice and payment-provider identifiers; Credit transactions, usage totals and reconciliation records; Pikaan does not store full payment-card details.
Purposes
Provide paid plans, receipts and credit accounting; Prevent duplicate charges and reconcile provider events; Meet tax, accounting and dispute obligations.
Provider roles
Payment processor; Pikaan billing database.
Retention
Commercial and accounting records are kept for the period required for billing, dispute handling and applicable legal obligations.
User controls
Subscription and payment-method controls are provided through the billing surface and payment processor.

Product analytics

Data
Privacy-filtered product events, route templates and aggregate counts; An account identifier after sign-in when analytics is configured; Submitted claim text, transcripts and source text are excluded by policy.
Purposes
Understand feature reliability and aggregate product usage; Improve navigation and launch operations.
Provider roles
Configured product-analytics provider.
Retention
Pikaan policy limits product-analytics events to 90 days. The analytics owner must keep provider-side retention at or below this limit before enabling analytics.
User controls
Analytics availability and any required notice or choice are owned by the analytics policy for the launch jurisdiction.

Transactional email

Data
Recipient email address and message content while delivery is pending; A keyed recipient digest, delivery state, provider receipt and safe error code after delivery.
Purposes
Send verification, recovery, security, billing and access messages; Retry transient delivery failures and diagnose non-delivery.
Provider roles
Configured SMTP or transactional-email provider.
Retention
Pending message content expires after 24 hours and is removed after successful or terminal delivery. Privacy-filtered delivery receipts are retained for 90 days.
User controls
Transactional messages are limited to service, security, billing and requested account operations.

Error diagnostics

Data
Error type, approved error code, route template and runtime surface; Release identifier and random correlation identifier; Raw messages, request bodies, URLs, claim text and stack values are excluded.
Purposes
Detect and diagnose application failures; Connect a user-visible reference to privacy-filtered operational logs.
Provider roles
Pikaan runtime logging; An external error sink only after explicit configuration approval.
Retention
The built-in sink writes only privacy-filtered metadata to runtime logs, which are retained for no more than 90 days under the launch policy.
User controls
A correlation identifier can be shared with support without sending submitted content.

Access requests and support

Data
Waitlist or support email, name and message; Signed-in feedback message, feedback type, account association, reference identifier and workflow status; A redacted route and broad viewport-size hint submitted with feedback; never page content, query strings, browser fingerprint or fact-checking results; Decision, delivery and support-handling metadata.
Purposes
Review access requests and answer support questions; Acknowledge, triage and resolve feedback; Maintain abuse-prevention and request audit records.
Provider roles
Pikaan access administration; Support email provider.
Retention
Kept while the request is active and for the follow-up or security period required by the owning access or feedback workflow. Stored feedback stays associated with the account and is removed when the account is permanently deleted.
User controls
Contact [email protected] to correct or remove an access or support request. Deleting your account removes stored feedback with it.

3. Providers and international processing

Depending on the selected capability, Pikaan uses configured hosting, storage, authentication, payment, AI model, web-search, speech-to-text, analytics, email, and runtime-logging providers. Providers may process data outside your country. Pikaan limits each provider to its documented role. Where a transfer safeguard is required, Pikaan's launch policy requires the appropriate contract and configuration before that provider is enabled. Contact us for the current provider list that applies to your request.

4. Security

We implement industry-standard security measures including encrypted connections (TLS), secure password hashing, and token-based authentication to protect your data.

7. Optional Usage Analytics

Pikaan may send a small set of structured usage events through our same-site analytics proxy to PostHog's European service. These events help us understand broad product funnels. The analytics SDK runs without analytics cookies or persistent browser identifiers, and session replay, automatic element capture, surveys, console capture, network capture, and exception capture are disabled. Fact-checking inputs, verification content, source URLs, media, transcripts, reports, and exports are not analytics properties.

You can turn optional usage analytics off quietly at any time. Pikaan stores only this on/off preference in your browser and, when you are signed in, on your account. We also honor Global Privacy Control and Do Not Track browser signals.

Privacy-safe usage analytics

Help Pikaan improve with cookieless usage events. Verification text, media, reports, and source content are never included.

Analytics are on. No analytics cookies or browser identifiers are stored.

5. Your rights

Depending on your location, you may have rights to access, correct, obtain a copy of, restrict, object to, or delete personal data, and to withdraw consent where consent is the processing basis. Account settings are not the only request path: contact us to exercise a right or raise a privacy complaint.

6. Contact

If you have questions about this Privacy Policy, please contact us at [email protected].