DisinfaX 的隐私政策
Effective Date: August 1, 2026
DisinfaX ("we," "our," or "us") respects your privacy and is committed to protecting the personal data of our users. This Privacy Policy outlines how we collect, use, store, and safeguard your information when you use the DisinfaX browser extension and associated backend services (collectively, the "Service").
- Information We Collect
A. Account & Registration Data
When you register or sign in to DisinfaX via Google, Apple, or X, we collect basic profile identifiers:
Your full name
Your email address (or relay email provided by Apple)
Unique provider authentication ID
B. Feed & Social Media Content
To perform real-time verification, factual analysis, and claims processing:
DisinfaX reads public post content (including raw tweet text, translated text provided by the social media platform, and usernames alongside verification badges) directly from active social media feeds rendered in your browser.
We process and store cryptographic hashes of tweet source texts and usernames, extracted factual claims (contextualized for accuracy), vector embeddings, and AI-generated content in our backend database.
C. Local Browser Data
The DisinfaX extension retains temporary caches of tweets and claims strictly in browser volatile memory (RAM). The only persistent items written to local browser storage are extension settings and your authentication token.
D. Payment Information
Payment transactions are processed securely through Apple StoreKit (for top-ups performed through the Safari version of DisinfaX on iOS, iPadOS and macOS) or Stripe (for top-ups performed through the Chromium or Firefox versions of DisinfaX). We do not collect, process, or store credit card numbers, bank account details, or billing credentials on our infrastructure. Apple and Stripe handle all billing transactions as independent payment processors.
- Purpose & Lawful Basis of Data Processing
Under applicable data protection laws (including EU/UK GDPR, Quebec Law 25, and PIPEDA), we process your data based on Performance of Contract (delivering requested claim analysis) and Legitimate Interest (ensuring service accuracy and security). We use collected information solely to:
Analyze, fact-check, translate, and highlight factual claims on your social media feeds. AI-generated content is provided for informational purposes only and is generated via automated processing.
Manage your prepaid balance and account authentication states.
Enforce security, API rate limiting, and prevent service abuse.
Provide user support and respond to inquiries.
We never sell, rent, or trade your personal data, browsing history, or feed content to third parties or advertising networks.
- Third-Party Infrastructure & AI Service Providers
DisinfaX acts as a controller of your account credentials and a processor for feed content. To deliver automated fact-checking, translation, and analysis, feed data is transmitted transiently over secure, encrypted channels to vendor categories including:
Middleware & Database Infrastructure: Cloud-hosted serverless execution environments and managed relational databases used for API routing and data storage.
AI & Vector Embedding Providers: Enterprise artificial intelligence API services, large language model (LLM) inference routers, and vector embedding services used exclusively to process, evaluate, and embed text content.
Search Index & Web Retrieval Providers: Automated search indexing services used to retrieve real-time web references and context for factual verification.
Payment Processors: Third-party merchant systems (Apple StoreKit and Stripe) for transaction billing.
All third-party AI processing occurs transiently under commercial developer API agreements specifying zero model training on customer inputs and strict data protection parameters.
- Geographic Availability & Permitted Jurisdictions
Top-ups can be performed through the Safari version of DisinfaX (on iOS, iPadOS, and macOS) in all App Store-supported jurisdictions.
Top-ups from Chromium and Firefox versions of DisinfaX are legally available exclusively to residents in permitted jurisdictions. Payment attempts from unauthorized jurisdictions are strictly prohibited.
A. Permitted United States Jurisdictions
Alabama, Arizona, California, Colorado, Connecticut, Delaware, Florida, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Massachusetts, Mississippi, Missouri, Montana, New Hampshire, New Mexico, New York, North Carolina, North Dakota, Oklahoma, Oregon, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Washington, Wisconsin, and Wyoming.
(Note: Washington D.C., all U.S. territories, and any U.S. states not listed above are explicitly excluded.)
B. Permitted International Jurisdictions
Canada, Australia, New Zealand, Singapore, South Africa, Japan, Taiwan, Indonesia, Thailand, Philippines, Malaysia, Vietnam, and Switzerland.
- Data Rights & Retention
Depending on your jurisdiction (such as under the EU/UK GDPR, Quebec’s Law 25, Canadian PIPEDA, etc.), you possess explicit legal rights regarding your personal account data stored in our database (specifically your name, email address, and unique provider authentication ID).
Access, Updates, & Full Account Deletion: You have the right to access, rectify, or permanently delete your personal data (including complete account erasure under GDPR Article 17) at any time. To submit a request, email our Privacy Officer at privacy@disinfax.app. Upon receiving a verified request, we will permanently purge your account records from our production database.
Data Retention & In-Memory Caching: Full raw tweets or posts are never stored permanently in our database. We store only processed claims, AI-generated summaries, contextualized vector embeddings, and hashes to prevent redundant processing. Temporary feed caches retained in volatile browser memory (RAM) are automatically cleared when you turn off / refresh the extension or close your browser.
- Contact Us
For privacy-related questions or data requests, contact us at:
Privacy Email: privacy@disinfax.app
General Company Email: disinfax@disinfax.app
Founder Email: michael.pouget@disinfax.app
Mailing Address: DisinfaX, 770 Rue Notre-Dame Ouest, Montréal, QC H3C 1J5, Canada