Privacy Policy

Effective date: to be set at launch · Last updated August 9, 2026

In short: Debunked runs on your computer, not on ours. Audio is transcribed on your device by default, your data is stored on your device, and we operate no servers that see any of it. When a claim is fact-checked, its text goes directly from your computer to Anthropic under your own API key. We collect no analytics and require no account.

Two things do leave your device if you choose them, and both are off until you turn them on: cloud transcription, which sends live audio to Deepgram, and speaker naming, which depends on it. If you use Debunked to listen to a room rather than to your own speakers, please read section 5 — recording other people is regulated, and in some places it is a crime.
  1. 1. Who we are and what this covers
  2. 2. Information processed on your device
  3. 3. Information that reaches service providers
  4. 4. Information we collect ourselves
  5. 5. Recording other people
  6. 6. Voice and biometric law
  7. 7. Your controls
  8. 8. The website and waitlist
  9. 9. Data retention
  10. 10. Security
  11. 11. Your rights
  12. 12. International transfers
  13. 13. Children
  14. 14. Changes to this policy
  15. 15. Contact

1. Who we are and what this covers

This policy covers the Debunked desktop application for Windows ("the app") and the website at de-bunked.com ("the site"). "We" refers to the developer of Debunked ("Debunked", "we", "us"). It describes what information the app processes, where that information goes, and the choices you have. It is written to be read; if anything in it is unclear, ask us at the address in section 15.

2. Information processed on your device

Debunked's design principle is local processing. The following is created and handled on your computer and, except as described in section 3, does not leave it:

3. Information that reaches service providers

Debunked has no servers of its own. When data leaves your device it goes directly from your computer to one of the providers below, only for the purpose stated, and in most cases only after you act.

ProviderWhat is sentWhenWhy
Anthropic (Claude API) The text of a claim being checked, together with a short excerpt of surrounding transcript for context; for screen checks where on-device reading is unavailable, the captured image Whenever a claim is checked while fact-checking is on Fact-checking. Requests are made with your own API key under Anthropic's commercial terms, so this traffic is between you and Anthropic — we are not a party to it and cannot access it. Under those terms, inputs and outputs from the API are not used to train models.
Deepgram Live audio from your selected source Only while listening and only if you have switched speech recognition to the Cloud option, which requires your explicit confirmation first Cloud transcription, and the speaker separation that depends on it. Off by default; stops when you pause or switch back to local. See section 6.
Hugging Face A standard download request, including your IP address as any web download carries On first run, and if you change speech models Downloading the speech-recognition model that then runs locally.
de-bunked.com
(private beta builds only)
A beta key and a hashed identifier for your computer; the request itself carries your IP address Once, when you activate a beta key Enforcing one-computer-per-key during the private beta. Described in section 4.

Each provider processes data under its own privacy policy. The app is built so that no provider receives more than this table states.

4. Information we collect ourselves

Nothing from the released app. No account, no sign-in, no telemetry, no analytics, no crash reporting. We do not receive your audio, your transcripts, your claims, your verdicts, your keys, or any record that you use the app at all.

One exception, in private beta builds only. A beta key has to work on one computer, and nothing on your machine can enforce that, so activating a beta key makes a single request to de-bunked.com containing the key and a hashed identifier derived from your computer's name, architecture and processor description. We store the tester number, that hash, and the dates it was used.

We are being specific about this because a hash is not anonymous. It cannot be read back to recover your computer's name, and we hold nothing linking it to your identity beyond the tester number we issued you — but under the GDPR and several US state privacy laws it is still personal data, and calling it otherwise would be wrong. It is deleted when the beta ends, or sooner on request. None of this applies to the public release, which contains no beta key mechanism at all.

The update check. On start-up, a released direct-download build requests a single static file from de-bunked.com to see whether a newer version has been published. It is an ordinary web request for a file: it sends no account, no identifier, no query string and no body — nothing beyond what your browser sends fetching any page (your IP address, as with any request, which we do not log against you). We learn nothing about who made the request or what version they run. Nothing is downloaded or installed automatically; the app only shows you a notice with a link. Beta builds and Microsoft Store builds do not make this request at all.

5. Recording other people is your responsibility

Debunked listens to your computer's audio by default, which is normally your own media. It can also listen to a microphone, and that is where the law changes.

Recording or transcribing a conversation is regulated, and the rules depend on where everyone is. Most US states require only one participant to consent — but California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania and Washington generally require every participant to consent, and violations can be criminal as well as civil. Other countries have their own rules, often stricter.

We cannot know who is in your room, so we cannot make this judgement for you. If you point Debunked at a microphone during a conversation, you are responsible for having whatever consent the law where you are requires. We recommend simply telling people. If you are unsure, use the system-audio source, which hears only what your computer is playing.

Nothing in this policy is legal advice.

6. Voice, speaker separation, and biometric law

With local speech recognition — the default — Debunked does not distinguish between voices at all. Every utterance is treated as coming from one unlabelled speaker, and cards never name who spoke. That is enforced in the app, not merely a default: speaker naming stays switched off and unavailable unless a backend that separates speakers is running.

If you switch to Cloud speech, Deepgram separates the audio by speaker so the transcript can show who said what. You may then optionally turn on speaker naming.

This matters legally. Illinois' Biometric Information Privacy Act treats a voiceprint as a biometric identifier, and courts have accepted that separating speakers by their vocal characteristics can amount to creating one. Comparable rules exist in Texas and Washington. So, precisely:

If you would rather none of this happen, do nothing: local speech recognition is the default and separates nothing.

7. Your controls

8. The website and waitlist

If you join the early-access list, we collect the email address you submit, and the word "hero" or "footer" recording which form you used so we can see which part of the page works. We use it solely to contact you about Debunked's availability and related product news. We do not sell it or share it with third parties for their own purposes. Every email we send includes a working unsubscribe link, and unsubscribing removes you from the list. The site sets no advertising or analytics cookies.

This site is hosted by Netlify, which also receives and stores the early-access form when you submit it, and which acts as a processor of that address on our behalf. As the host, Netlify additionally processes ordinary web-server request data — including your IP address — in the course of serving these pages. If we later move the list to a dedicated email service, this section will name that provider before the change takes effect.

9. Data retention

10. Security

API keys are encrypted at rest with Windows DPAPI and are readable only from your Windows user account. All traffic to the providers in section 3 uses encrypted connections (HTTPS/WSS). The app's local web interface is bound to your own machine and protected against access by other software and websites with a per-session token and origin checks. No security measure is absolute, but the most effective one here is architectural: data that never leaves your device, and never touches our servers, cannot leak from either.

11. Your rights

Because the app collects nothing, there is usually nothing for us to give you, correct, or delete — the controls in section 7 already put all of it in your hands. Where we do hold something about you, which means your waitlist email and, in the private beta, your redemption record, you have the right to ask us to access, correct, delete, or provide a copy of it, and to object to our using it. Email the address in section 15 and we will answer within 30 days. You will never be treated differently for asking.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other US state privacy laws. We have never done so.

If you are in the UK or EEA: our lawful basis for the waitlist is your consent, which you may withdraw at any time by unsubscribing; for beta redemption records it is our legitimate interest in preventing one beta key being used on many computers. You also have the right to complain to your data protection authority.

12. International transfers

We are based in the United States, and the providers in section 3 may process data in the United States and elsewhere. If you are outside the US, information you choose to send — a claim to Anthropic, audio to Deepgram if you enable Cloud speech, your waitlist email — will be processed in countries whose data protection law may differ from your own. Where those transfers require a safeguard, we rely on the providers' own standard contractual clauses.

13. Children

Debunked is not directed at children under 13, and we do not knowingly collect personal information from them. The app collects no personal information from anyone, and the waitlist is intended for adults. If you believe a child has given us an email address, tell us and we will delete it.

14. Changes to this policy

If we change this policy in a way that matters — above all, anything new leaving your device — the app will tell you before the change takes effect, and the site will show the revised policy with a new effective date. We will not retroactively apply a weaker policy to data handled under a stronger one.

15. Contact

Questions, requests, or concerns about privacy: sam@de-bunked.com.