Back to Angel

Last updated September 17, 2026

About Angel & team →

Privacy

This Privacy Policy describes how Angel ("we", "us") collects, uses, and protects information when you use the Angel browser extension and the Angel web dashboard (together, the "Service"). This policy applies to all users globally, including those in the United States and European Union. Angel is currently offered as a closed beta; see the separate Beta Terms of Use for beta-specific terms.

Data controller

The data controller for Angel is Sami Al-Khafaji. Contact: sami@withangel.io.

Account information

Using the Service requires an account, authenticated via Firebase Authentication. When you create an account, we collect and store your email address; name and username; authentication provider (e.g. email/password, Google); profession and company name, if you provide them; and your account role and subscription/usage tier. This information is stored in our database and is retained for as long as your account exists.

Information sent when you analyze a claim

When you highlight text and click "Analyze," or type a claim into the manual-scan box, the following is sent from your browser to our backend: the claim text, either the text you highlighted on the page or the text you typed manually (we do not scan or transmit the rest of the page); the current page URL (full address, including query string), used to give the analysis context; and your account identity, via an authentication token, used to attribute the request to your account and apply usage limits. We do not currently scan or transmit full page content automatically; only text you explicitly select or type is sent.

Third parties that process your claim text

To produce an analysis, your claim text (and text derived from it) may be sent to the following processors:

Each of these providers processes data under its own privacy policy; we do not control how they retain or log data beyond the request itself. We do not sell your data to any third party.

Analytics

We use analytics to understand how Angel is used and to improve it. On this website, analytics is off until you opt in. In the web dashboard, the stored analytics identifier and session recording only start once you accept the Privacy Policy. The browser extension does not run analytics. You can withdraw your consent at any time.

You can change your choice for this website here: Cookie settings. For the web dashboard, you can withdraw your consent by contacting us. Analytics data is not used for advertising and is not sold.

Data storage and retention

Analysis records: every analysis request, including the claim text, page URL, the sources found, and the verdict, is stored in our database to power your history, the public-sharing feature, and to debug and improve the Service. We do not currently have an automated deletion schedule for these records; they are retained until you request deletion or your account is deleted. We are working on adding a retention/deletion policy for this data.

Audit logs: for security and debugging, we log the full request and response of API calls to our backend, which includes claim text, URLs, and result content. Sensitive fields such as passwords, tokens, secrets, cookies, and authorization headers are automatically redacted before storage; claim text and URLs are not redacted. These logs are also not currently subject to an automated deletion schedule.

Local storage on your device: the extension stores your recent claims (including the claim text, verdict, and page URL) in your browser's local storage so you can see your session's results. This data has no automatic expiry and remains on your device until you log out (which clears it) or uninstall the extension. Your account details (email, name, profession, company, subscription/usage status) are also cached locally while you are logged in, for the same reason.

Rate-limiting: to prevent abuse, we track request counts. This is currently keyed by your account or, if unavailable, your IP address, held in server memory only (not written to a database).

Analytics and session recordings: product usage events and session recordings are held by PostHog in the EU and are deleted when you ask us to delete your account.

Public sharing feature

The web dashboard lets you mark an analyzed claim as "public" and generates a shareable link. Anyone with that link can view the claim text, the URL it came from, and the analysis result. This is a deliberate feature you control, not a default. Do not mark a claim public if you do not want its content visible to anyone with the link.

What we do not collect

No advertising or cross-site tracking cookies, and no analytics cookies until you opt in on this website or accept the Privacy Policy in the dashboard (see Analytics, above). No device fingerprinting or system/platform metadata beyond standard HTTP request headers and what PostHog records for analytics (browser, operating system, approximate location derived from your IP address). No payment information is handled directly by us; payments go through a dedicated processor. No page content is transmitted unless you explicitly select or type it and click Analyze.

Legal basis for processing (GDPR)

For users in the European Union, we process data under contract (processing your claim text and account information is necessary to provide the analysis you request) legitimate interest (rate-limiting, audit logging, and security monitoring, to keep the Service reliable and prevent abuse), and consent (the PostHog identifier and session recording in the web dashboard, which start when you accept the Privacy Policy, and Google Analytics on this website, which starts when you accept analytics cookies; you can withdraw either at any time).

Your rights

For EU users (GDPR): the right to access a copy of the data we hold about your account; the right to deletion of your account and associated analysis records, including your PostHog profile, its analytics events and any session recordings linked to it; the right to object to processing, or ask us to restrict it, subject to our ability to continue providing the Service; and the right to data portability, to receive your data in a portable format.

For California residents (CCPA/CPRA): the right to know the categories of personal information we collect (see Account Information and Information Sent When You Analyze a Claim, above); the right to delete your account and data, including your analytics profile and session recordings; and the right to opt out; we do not sell personal information.

To exercise any of these rights, contact sami@withangel.io. As this is a small, closed beta, requests are handled manually and we will confirm completion directly with you.

Children's privacy

The Service is not intended for users under 16 years of age. We do not knowingly collect information from children.

Security

Data is transmitted over HTTPS. Our backend infrastructure is hosted in the EU (europe-north1).

International data transfers

Our backend is hosted in the EU. Some of our third-party processors (see above) are based outside the EU, e.g. the United States; by using the Service you consent to your claim text being processed by these providers under their respective privacy policies.

Changes to this policy

We may update this policy as the Service evolves, particularly as it moves out of closed beta. The "Last updated" date above reflects any changes. Material changes will be communicated to beta users directly.

Contact

For privacy questions, contact sami@withangel.io.