Legal

Privacy

This is what EXHIBIT B stores, for how long, and which outside services ever see a cited URL or a document's hash. It is short on purpose. If something here is unclear, the support address in the footer reaches a person.

Your document

Your document's text is never written to disk. It is held in memory only long enough to find and check what it cites, then discarded — typically within seconds of upload, and always at the end of the session. What survives in a small database is metadata: hashes, character spans, counts, timestamps and job status. Never the document, never a claim's wording, never a cited source's full text.

The free check is a preview, not a record: the spans, hashes and counts it shows live in memory until the session expires, and nothing is sealed or kept unless you pay to seal it. The demo shows this as it happens: a timer names the moment your document was discarded, and the preview expires shortly after. You can delete even that at any point with one click.

The add-in, EXHIBIT B

EXHIBIT B is also a task pane that runs inside your document editor. What it sends, it sends to us and to nobody else, and there are three things on the list. First, once per check: the document's text, assembled from the body, the footnotes and the endnotes, with the exact assembly published so anyone holding the document can rebuild it. Second, the address you type when you seal, so the receipt can be sent to you. Third, once per installation, on the first open: which kind of machine the pane opened on, which level of the editor's own interface it found, and the add-in's version — device capability, carrying nothing whatever from the document.

What it never sends: the file itself, its formatting and styles, headers and footers, existing comments and who wrote them, tracked-change history, text deleted but not yet accepted, revision authors, embedded images, the file name, the folder it sits in and every other piece of the document's metadata. It sends no page view and no count derived from a document to the analytics; the payment window sends nothing at all. Before the first send it tells you, in numbers, how many characters and how many paragraphs and footnotes are about to go, and you can send a selection instead of the whole document.

What it writes into your file: nothing at all until you seal. The marks you see while checking are drawn by the editor's own reviewing layer and are not saved into the document — close it and they are gone. The anchors it uses to find a citation again carry an opaque number and no verdict, so nothing in the file records this tool's opinion of any sentence you wrote. At the moment you seal, and only then, two readable facts are written as document properties: the receipt's identifier and the date it was sealed. The receipt table it appends is a table you asked for and can delete.

The text the add-in sends is handled exactly as an uploaded document is: held in memory for the check, never written to disk, discarded at the end of the session. The add-in stores nothing on your machine but the session it is currently working on, and it holds no account, no key and no password, because it has none to hold.

What the receipt contains, and what it does not

A receipt carries hashes, character spans, counts, timestamps, public locators reduced to their domain, a signature and a position in the chain. It does not carry the claim text, the quotes or the cited URLs. Those stay on your side, in the full receipt file you download and hand to whomever you choose. A public projection of the receipt — what a reader sees at its link — reveals nothing about the document, its subject or the quoted text.

Outside services, by the role they play

The services below are the only ones that ever touch anything related to a check. Each sees only what its job requires; none receives your document to train on.

Service, by roleWhat it sees
Model providerthe document, for the step that finds what it cites, and one sentence per claim if HOLDS is run by hand. Not used for training.
Payment provideryour email and the amount. Never the session, the receipt id or the document.
Email serviceyour email and the receipt link, to deliver the record you bought.
Analyticswhich page and step a visitor reached, under a fixed label for every private page. Cookieless. No document data, no identifiers.
Web archive and citation registriesthe cited URLs and identifiers only, to keep a copy and to resolve a DOI, PMID or case citation.
A second fetch vantage in another networkthe cited URLs only, so a source can be fetched from two places and compared.

Retention

How long the full receipt file is served depends on the tier. After that window the file is no longer downloaded from us, but the receipt stays in the chain, stays public as a projection, and still re-derives — a closed download window is not a deleted record. The recurring tiers keep the file for as long as the plan runs. A check that was never sealed keeps nothing at all.

TierKept
Free check (the preview)nothing sealed, nothing kept: spans, hashes and counts in memory until the session expires
CHECK ($9)receipt file served for 90 days; chain position permanent
Check, unchained ($19)receipt file served for 1 day; issued off the chain
RECORD ($39/mo)receipt file kept while the plan runs; 7-year retention
PRACTICE ($199/mo)receipt file kept while the plan runs; 7-year retention

Analytics, refunds, contact

Analytics are cookieless and carry no document data — only which step of the site a visitor reached, never a receipt id, a session or a query. Refunds are granted without argument; a refunded receipt stays valid, because it is an honest record of a check that happened at that time. To ask a question, or to have something deleted, write to the support address in the footer.