The Pocket App Company
BS Meter

Privacy Policy

Last updated: September 22, 2026

This Privacy Policy explains how BS Meter ("BS Meter," "we," "us," or "our"), a product of The Pocket App Company, collects, uses, and protects information when you use the BS Meter application and related services (the "Service"). By using the Service, you agree to the practices described here.

1. The short version

2. What the app collects on your phone

Audio from the video being checked

To check a video the app has to hear it. There are two routes, and they capture different things.

Sharing or pasting a link (the main route). The app opens the video's own published embed inside its own window, plays it silently, and listens to its own player. Nothing else on the device is part of that audio path. No screen recording and no system audio capture is involved.

The floating meter (optional). This route uses Android's playback-capture API, which requires your explicit per-session consent through the dialog Android itself shows. It is restricted at the operating-system level to the specific social apps the meter supports, so audio from any other app — a music player, a call, anything else — never reaches the recorder.

The microphone is never recorded. The app declares the RECORD_AUDIO permission because Android requires it for playback capture, but no part of the app ever opens a microphone input.

Audio never leaves the device and is never written to storage. It is converted to text as it plays and then discarded.

Text, findings and history

Transcripts and the verdicts produced from them are stored on your phone, so that your past checks are available and so a check can be exported if you contact us for support. Deleting a check, or uninstalling the app, removes them.

Nothing else

No contacts, no location, no photos, no calendar, no device advertising identifier, and no list of your installed apps. The app asks the system about the handful of social apps the meter supports, and about nothing else.

3. What is sent to us

When you run a check, the app sends:

SentWhy
The transcript text of the videoIt is what gets fact-checked
The platform and video idUsed as a cache key, so the same video is not paid for twice
A credential: a per-install token, or an account id if you signed inMetering and abuse control
For an image check, the imageIt is what gets checked

Your name, phone number, contacts and location are not sent, because the app never has them.

Your email address is sent on exactly four requests, and only if you use the email-and-password sign-in: creating the account, confirming it with the mailed code, asking for a password reset, and signing in. It is not attached to a check, so nothing joins it to a video you looked at.

Your password is sent on those same requests over HTTPS and is never stored as you typed it — what we keep is a scrypt hash, which cannot be turned back into the password.

4. What we store

Every table in our database is listed here. There is no other storage.

StoredWhat is in itTied to you?
Cached analysesA completed analysis, keyed by a hash of the video referenceNo
Claim verdictsA checked claim's text and its verdictNo — keyed by the claim's content
Claim evidenceSources gathered for a claimNo
Scan logOne row per check: platform, counts, cost. Never contentNo
InstallsA SHA-256 hash of the install token, platform, timestamps, a countPseudonymous
AccountsThe sign-in provider and that provider's id for youPseudonymous
Email accountsAn email address, a scrypt hash of the password, and whether the address has been confirmedYes — an address identifies you
Quota usageA caller identity and a monthly countPseudonymous

These consequences are worth stating plainly, because they are the whole point:

The one place an IP address can be stored

The quota record notes who spent a check. In the published app that is a non-reversible fingerprint of your credential, not an address. If the Service is ever run without authentication, that field falls back to recording an IP address — and an IP address is personal data in the EU and UK. It is named here rather than omitted because it is a real branch in the code.

Ordinary web-server request logs at our hosting provider also contain IP addresses, as they do for every website.

5. Who else sees your data

We are not the only system involved in answering a check.

WhoWhat they receiveWhy
Anthropic (model provider)Transcript text and claim textExtracting and checking claims
A web search providerIndividual claims, as search queriesFinding evidence
Render (server hosting)Everything in transit, plus request logsRuns the server
Supabase (database hosting)The records listed aboveStores them
GoogleOnly that you chose to sign inSign-in, and only if you use it
Google WorkspaceYour email address and a 6-digit codeSending the confirmation and password-reset emails, and only if you use the email sign-in

Data is not sold, and is not shared with advertisers or data brokers. There are none involved.

6. How long things are kept

AudioNever stored. Discarded as it is transcribed.
On-device historyUntil you delete a check or uninstall the app.
Cached analyses and verdictsIndefinitely, as a shared cache. Not linked to you.
Scan logIndefinitely. Contains no content and no identifier.
Install and account recordsUntil the install is revoked or the account deleted.
An email address and password hashUntil the account is deleted. Deleting it removes the row.
A confirmation or password-reset code20 minutes, as a hash.

7. Your rights and how to use them

Wherever you live, you can:

If you are in the UK, EU or EEA, UK GDPR and GDPR give you rights of access, rectification, erasure, restriction, portability and objection. The lawful basis for processing a check is performance of a contract — you asked for the check — and for the caps and counters it is legitimate interests, specifically keeping the Service's costs from running away.

If you are in California, the CCPA/CPRA give you rights to know, delete and opt out of sale. There is no sale to opt out of.

To exercise any of these, write to the address in Section 11. If you signed in with an email address, write from that address. Otherwise we hold no address for you, so a request will need the install or account identifier the app can show you, or it cannot be matched to anything.

8. Children

BS Meter is not directed at children under 13, and no part of it is designed for them. No age is collected. If you believe a child has provided personal information, write to the address in Section 11 and it will be deleted.

9. Other people in the videos you check

A video you check contains someone else's speech, and that transcript is processed and cached. Two rules bound what the app does with it, and both are enforced in the software rather than merely promised here:

Please do not use the app on private recordings of people who have not published them.

10. Security

No system is perfectly secure, and this one is maintained by a very small team.

11. Contact us

For questions about this Privacy Policy or your information, contact:

The Pocket App Company
Email: support@thepocketappcompany.com

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where they change what is collected, in the app's release notes. The version that applies is the one published at this address.