Last updated: September 22, 2026
This Privacy Policy explains how BS Meter ("BS Meter," "we," "us," or "our"), a product of The Pocket App Company, collects, uses, and protects information when you use the BS Meter application and related services (the "Service"). By using the Service, you agree to the practices described here.
To check a video the app has to hear it. There are two routes, and they capture different things.
Sharing or pasting a link (the main route). The app opens the video's own published embed inside its own window, plays it silently, and listens to its own player. Nothing else on the device is part of that audio path. No screen recording and no system audio capture is involved.
The floating meter (optional). This route uses Android's playback-capture API, which requires your explicit per-session consent through the dialog Android itself shows. It is restricted at the operating-system level to the specific social apps the meter supports, so audio from any other app — a music player, a call, anything else — never reaches the recorder.
The microphone is never recorded. The app declares the RECORD_AUDIO permission because Android requires it for playback capture, but no part of the app ever opens a microphone input.
Audio never leaves the device and is never written to storage. It is converted to text as it plays and then discarded.
Transcripts and the verdicts produced from them are stored on your phone, so that your past checks are available and so a check can be exported if you contact us for support. Deleting a check, or uninstalling the app, removes them.
No contacts, no location, no photos, no calendar, no device advertising identifier, and no list of your installed apps. The app asks the system about the handful of social apps the meter supports, and about nothing else.
When you run a check, the app sends:
| Sent | Why |
|---|---|
| The transcript text of the video | It is what gets fact-checked |
| The platform and video id | Used as a cache key, so the same video is not paid for twice |
| A credential: a per-install token, or an account id if you signed in | Metering and abuse control |
| For an image check, the image | It is what gets checked |
Your name, phone number, contacts and location are not sent, because the app never has them.
Your email address is sent on exactly four requests, and only if you use the email-and-password sign-in: creating the account, confirming it with the mailed code, asking for a password reset, and signing in. It is not attached to a check, so nothing joins it to a video you looked at.
Your password is sent on those same requests over HTTPS and is never stored as you typed it — what we keep is a scrypt hash, which cannot be turned back into the password.
Every table in our database is listed here. There is no other storage.
| Stored | What is in it | Tied to you? |
|---|---|---|
| Cached analyses | A completed analysis, keyed by a hash of the video reference | No |
| Claim verdicts | A checked claim's text and its verdict | No — keyed by the claim's content |
| Claim evidence | Sources gathered for a claim | No |
| Scan log | One row per check: platform, counts, cost. Never content | No |
| Installs | A SHA-256 hash of the install token, platform, timestamps, a count | Pseudonymous |
| Accounts | The sign-in provider and that provider's id for you | Pseudonymous |
| Email accounts | An email address, a scrypt hash of the password, and whether the address has been confirmed | Yes — an address identifies you |
| Quota usage | A caller identity and a monthly count | Pseudonymous |
These consequences are worth stating plainly, because they are the whole point:
scrypt hash of it. Deleting your account deletes the address, in the app under Settings or at the deletion page.The quota record notes who spent a check. In the published app that is a non-reversible fingerprint of your credential, not an address. If the Service is ever run without authentication, that field falls back to recording an IP address — and an IP address is personal data in the EU and UK. It is named here rather than omitted because it is a real branch in the code.
Ordinary web-server request logs at our hosting provider also contain IP addresses, as they do for every website.
We are not the only system involved in answering a check.
| Who | What they receive | Why |
|---|---|---|
| Anthropic (model provider) | Transcript text and claim text | Extracting and checking claims |
| A web search provider | Individual claims, as search queries | Finding evidence |
| Render (server hosting) | Everything in transit, plus request logs | Runs the server |
| Supabase (database hosting) | The records listed above | Stores them |
| Only that you chose to sign in | Sign-in, and only if you use it | |
| Google Workspace | Your email address and a 6-digit code | Sending the confirmation and password-reset emails, and only if you use the email sign-in |
Data is not sold, and is not shared with advertisers or data brokers. There are none involved.
| Audio | Never stored. Discarded as it is transcribed. |
| On-device history | Until you delete a check or uninstall the app. |
| Cached analyses and verdicts | Indefinitely, as a shared cache. Not linked to you. |
| Scan log | Indefinitely. Contains no content and no identifier. |
| Install and account records | Until the install is revoked or the account deleted. |
| An email address and password hash | Until the account is deleted. Deleting it removes the row. |
| A confirmation or password-reset code | 20 minutes, as a hash. |
Wherever you live, you can:
If you are in the UK, EU or EEA, UK GDPR and GDPR give you rights of access, rectification, erasure, restriction, portability and objection. The lawful basis for processing a check is performance of a contract — you asked for the check — and for the caps and counters it is legitimate interests, specifically keeping the Service's costs from running away.
If you are in California, the CCPA/CPRA give you rights to know, delete and opt out of sale. There is no sale to opt out of.
To exercise any of these, write to the address in Section 11. If you signed in with an email address, write from that address. Otherwise we hold no address for you, so a request will need the install or account identifier the app can show you, or it cannot be matched to anything.
BS Meter is not directed at children under 13, and no part of it is designed for them. No age is collected. If you believe a child has provided personal information, write to the address in Section 11 and it will be deleted.
A video you check contains someone else's speech, and that transcript is processed and cached. Two rules bound what the app does with it, and both are enforced in the software rather than merely promised here:
Please do not use the app on private recordings of people who have not published them.
scrypt hash.No system is perfectly secure, and this one is maintained by a very small team.
For questions about this Privacy Policy or your information, contact:
The Pocket App Company
Email: support@thepocketappcompany.com
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where they change what is collected, in the app's release notes. The version that applies is the one published at this address.