Privacy Policy

SourceLedger Privacy Notice

Last updated: September 22, 2026.

Who We Are and What This Notice Covers

SourceLedger is a web application for investigating factual claims in web pages and pasted articles. This notice explains how the operator of this SourceLedger installation handles information when you visit, sign in, submit material, and use its research and AI features. Privacy questions and requests can be sent to bcbasshead@gmail.com.

Google Sign-In and Account Information

We use Google Sign-In with the openid, email and profile permissions. Google supplies an identity token and basic identity information. We verify that token and store your Google account identifier, verified email address and display name to create and identify your SourceLedger account. We also store an internal account identifier, account creation time, recent activity time, language and theme preferences, and account access or moderation status.

We do not receive your Google password, request access to Gmail, Drive, contacts or calendars, or store a Google profile photograph. Google identity information is used for authentication, account administration and security, not as input to investigation models, for advertising targeting, or for sale to advertisers. The sign-in integration does not retain Google access or refresh tokens for ongoing access to your Google account.

Documents, Research and Analysis We Store

When you investigate a URL or paste an article, we store the submitted URL where applicable, article title and captured or pasted text, retrieval and submission timestamps, resolved URLs and retrieval identifiers. These records are associated with your SourceLedger account. We also store the generated title and summary, extracted claims and context, keyword queries, search and fact-check results, selected evidence documents, separate evidence and fact-check assessments, citations, final judgments, model names and prompt-version identifiers. The final report preserves the title, summary, full verdict list and a snapshot of the assessments used. Retrieval progress records allow the browser to replay retrieval milestones; model work runs in the open browser tab.

Every completed report is automatically published. Anyone can read its title, summary, claims, judgments and limitations through its public report link without signing in. This applies to reports based on pasted articles as well as URLs. The public report page does not display your Google identity, email address, API credentials, full submitted article text or raw retrieval records. Report summaries and claims can nevertheless reveal information from the submitted material. Public reports may be shared, indexed by search engines or copied by others; deleting a report here cannot remove copies held elsewhere.

We use this information to perform the investigation, retain the evidence behind an assessment, troubleshoot failures and provide results associated with your account. Do not submit passwords, API keys, private access links, confidential documents, or personal information you are not authorized to share. A pasted article skips retrieval of the original page but is still stored and processed by the research and AI stages.

Retrieval and Search Providers

SourceLedger uses DuskRail, a separate crawler and document store, to retrieve submitted URLs and selected evidence pages. DuskRail stores its own page captures and retrieval metadata. Pages retrieved there may also be available through DuskRail independently of your SourceLedger investigation. The destination website receives the crawler's request, including the requested URL and the crawler server's network information; SourceLedger does not supply your Google identity as part of that request.

Claim-related research queries are sent through our SearXNG search service to the selected external search engines. Those engines receive the query and the search server's request information. A query may reveal information contained in your submitted material. Search engine privacy practices apply to their handling of those requests.

After evidence assessment, SourceLedger sends claim-related research queries to Google's Fact Check Tools API to find published fact-check results. Google receives those queries and our server's request information, but not your Google sign-in identity or OpenRouter key. We store the returned publisher reviews, original ratings, dates, URLs, provider response data and lookup outcomes linked to your investigation's claims. A matching review is a candidate for comparison, not automatically a verdict on your claim. Google's privacy policy applies to its processing of these requests: https://policies.google.com/privacy.

OpenRouter, AI Providers and Your API Key

AI requests are made directly by your browser to OpenRouter using your own API key. The first request includes the supplied document text and title to produce a summary and extract claims. Research calls include claims with search results and available evidence documents; fact-check assessment includes claims with returned publisher reviews. The final judgment call includes each claim and its two saved assessments, rather than the underlying results or article bodies. OpenRouter routes requests to the selected model provider. OpenRouter receives your browser's network information and API credential; the model provider receives the content required for the request. Model output returns to your browser, which sends the investigation results to SourceLedger for storage.

SourceLedger's backend does not intentionally receive or store your OpenRouter API key. Your AI settings offer browser session storage or persistent browser storage; the application also holds the key in page memory while in use. Persistent storage exposes it to anyone or any software with sufficient access to your browser profile, extensions, backups or site session. Use Clear Key to remove the key from the application's browser storage; revoke the key at OpenRouter if you believe it has been exposed.

OpenRouter and model providers have their own retention and data-use policies, which can differ by provider, model and your OpenRouter privacy settings. Some providers may retain content or use it for training where their terms and your settings permit. SourceLedger does not guarantee zero retention or no training by these third parties. Review https://openrouter.ai/privacy and https://openrouter.ai/providers before submitting sensitive material.

Cookies, Browser Storage and Advertising

We use cookies for your signed-in session, request-forgery protection and abuse prevention. The sign-in cookie is configured for long-lived sessions, with a maximum lifetime of approximately ten years; signing out or clearing the site's cookies ends that browser session. Browser storage also holds AI settings, model preferences and, only according to your chosen storage mode, your OpenRouter key.

The idle investigation sidebar loads a third-party advertisement from a.magsrv.com. Loading the advertisement sends a request from your browser to the advertising service, which can receive your IP address, browser information and permitted referrer information, and may use cookies or similar identifiers under its own policies and your browser settings. We do not intentionally attach your Google account information, investigation text or OpenRouter key to ad requests. Blocking third-party content or cookies may prevent advertisements from loading; it does not delete your SourceLedger records.

Operational Logs and Security

Our web server and application process technical information needed to operate and protect the service, including IP addresses, request URLs, browser or user-agent information, timestamps, response statuses and errors. Browser error reports sent to our backend can include your internal user identifier, error message, script source, stack trace and investigation-stage context. These diagnostics may contain URLs or fragments of submitted or provider-returned content. The error-reporting path attempts to redact recognizable OpenRouter keys and bearer credentials.

Access controls, HTTPS, request validation and restrictions on serving source files and logs help protect stored information. Authorized operators and infrastructure administrators may access records for maintenance, security, support and handling privacy requests. No storage or transmission system can be guaranteed completely secure.

Sharing and Processing Locations

Information is disclosed through the retrieval, search, AI and advertising operations described above and to infrastructure providers as necessary to run the service. The operator may also disclose information when legally required or necessary to investigate abuse and protect the service or its users. These third parties may process information in countries different from yours. Your SourceLedger account credentials are not required by the model or search providers and are not intentionally included in their research requests.

Retention, Deletion and Your Choices

There is currently no automatic expiry schedule for SourceLedger accounts, submitted articles or investigation records. They can remain stored until the operator deletes them. Logs and backups are managed separately and may retain information after a record is removed from the active database; we do not currently promise a fixed deletion interval for those copies. DuskRail captures and copies held by external providers are separate from SourceLedger's account records.

Contact bcbasshead@gmail.com to request access to, correction of, or deletion of your account and associated investigation records, or to ask about other privacy rights available to you. We may need to verify account ownership before acting. There is not currently a self-service account-deletion control. Please do not send passwords or API keys with your request. We will explain any information that cannot be removed, and any separate action needed for DuskRail or third-party copies.

You can sign out, clear the site's cookies and browser storage, remove the OpenRouter key with Clear Key, and revoke SourceLedger's Google connection at https://myaccount.google.com/connections. Revoking Google access or clearing browser storage does not itself delete server-side account or investigation records.

Changes to This Notice

We will update this page and its revision date when the application's data practices change. Check this notice before using newly introduced features or providers. Contact bcbasshead@gmail.com if anything here is unclear.