SourceTrace Privacy Policy
Last updated: 21 July 2026
The short version. When you analyze a page, SourceTrace sends that photo to its server so an AI model can read the text on it and search the web for the sources behind its claims. The photo isn't saved to any database, and it isn't used to train any AI model.
Your analysis history stays on your device. There are no accounts, no advertising, no analytics trackers, and nothing is sold or shared for marketing.
Who this covers
This policy applies to the SourceTrace iOS app and the SourceTrace web app. Throughout, "we" means the individual developer who operates SourceTrace, and "the service" means the app together with the backend server it talks to.
What happens to a page you photograph
Analyzing a page is the only action that sends anything off your device. When you tap analyze, the following happens in order:
- The photo is uploaded over HTTPS to the SourceTrace backend, hosted on Railway.
- The backend passes the image to the Anthropic API, where a Claude model reads the text and identifies the factual claims on the page. Anthropic does not use API inputs to train its models; it retains inputs for a limited period for safety and abuse monitoring, under its own privacy terms.
- For each claim, the backend sends a short text search query to the Brave Search API to find candidate sources. Your photo is never sent to Brave — only the query text derived from the claim.
- The candidate results are sent back to Claude to be scored for relevance, and the finished analysis is returned to your device.
- If you share highlighted text from a browser, your device may also pass along the address of the page it came from. The backend fetches that page once, purely to check that the passage really appears on it and to read the page's own title, so the analysis can name the article instead of guessing at it. The address is used for that one request and is never written to our logs and never stored. You can see which site it is before you tap, and decline it, on the preview screen.
The image is not stored. SourceTrace has no database. The photo exists in the backend's memory only for the length of the request and is discarded when the analysis is returned. It is never written to disk, never attached to a profile, and never used to train an AI model.
What stays on your device
Your analysis history lives in your browser's or the app's local storage, on your device only. It is never uploaded. It holds up to 25 recent analyses, and for each one:
- a small thumbnail (roughly 160 pixels) of the page you photographed;
- the claims found and the sources returned;
- the time of the analysis.
Star ratings you give an analysis are also stored locally. You can erase all of it at any time by clearing your history in the app, or by deleting the app.
What our server records
The backend keeps operational logs. They contain no page images and no page text. Specifically:
- Cost and usage records — an analysis identifier, the AI model used, token counts and the resulting cost, so the service's running costs can be monitored.
- Quality ratings — if you rate a result, the 1–5 score is recorded so the analysis quality can be improved.
- Feature interest — if you tap an option indicating interest in a paid feature, that tap is recorded as a count.
- A request identifier — to apply rate limits and prevent abuse, each request is attributed to a caller, derived from the app's shared access key or your IP address. Signed out — which is how the app runs today — this is not linked to any personal profile or account.
- Standard server logs — our hosting provider (Railway) keeps routine request logs, which include IP addresses, for a limited period as part of operating the service.
Camera and photo library
The app asks for camera access so you can photograph a page, and for photo library access so you can choose an existing photo instead. iOS will ask your permission before either is used, and you can withdraw it at any time in Settings → SourceTrace. SourceTrace does not browse, scan, or upload your photo library — only the single image you pick for an analysis is used.
Accounts
SourceTrace currently has no accounts, and the app works fully signed out. If optional sign-in is introduced in a future version, it will be handled by Supabase and would involve storing your email address to identify your account. This policy will be updated before that happens.
What we don't do
- No advertising, and no advertising or attribution SDKs in the app.
- No third-party analytics or behavioural tracking.
- No tracking across other companies' apps or websites, so the app does not ask for tracking permission.
- We do not sell or rent your data, and we do not share it for marketing.
- We do not use your pages to train AI models.
Service providers
The service depends on a small number of providers, each handling data only to make SourceTrace work: Anthropic (reading the page and scoring sources), Brave Search (web search queries), Railway (backend hosting), and Vercel (web app hosting). Each is linked above or operates under its own published privacy terms.
Children
SourceTrace is not directed to children under 13, and we do not knowingly collect information from them.
Your choices
Because the service holds no account and no stored copy of your pages, there is no profile to export or delete. To remove everything SourceTrace holds about you, clear your history in the app or delete the app; you can also revoke camera and photo access in iOS Settings at any time. If you have a question about the operational logs described above, or want to request their deletion, contact us below and we'll help.
Changes to this policy
If how the service handles data changes, this page and the App Store privacy details will be updated together, and the date at the top will change.
Contact
Questions about this policy or about your data: armen.changelian@gmail.com