Last updated: September 2026 — claim visibility defaults, live chat, warranty certificates
Introduction
Lenz (“we”, “us”, or “our”) is a verification service that uses AI, available at lenz.io. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
Information We Collect
Account information
When you create an account (directly or via Google sign-in) we store your email address and name. If you sign in with Google, we receive your basic profile information (name, email, and profile picture URL) as authorized by you through Google’s OAuth consent screen.
Claim data
When you submit a claim for verification, we store the text you provide and the analysis results generated by our analysis pipeline. Claims submitted through the API, WhatsApp or the workbench, and statements verified from a draft on the website, are private by default. On the website, the exception is a single statement checked with the “Check one statement” form on the Try Lenz page: it is public (“Public”) by default, and the form says so and lets you make it private before you submit it. You can change the visibility of each individual claim report at any time. Options are “Private” (visible only to you) or “Public”. Public claims are accessible to anyone with the link, may be included in the Library, and may be used for research.
Usage data
We collect basic usage information such as page views, votes, and interaction patterns to improve the service. We use cookies to maintain your session and remember your authentication state.
Payment information
Payments are processed by Stripe. We do not store your credit card details. Stripe may collect information necessary to process your transaction in accordance with their own privacy policy.
Contact form
If you contact us through our contact form, we store your email address, subject, and message to respond to your inquiry.
How We Use Your Information
- To provide and operate the verification service
- To authenticate your account and manage your session
- To process payments and manage subscriptions
- To respond to your inquiries and support requests
- To improve and optimize the service
- To detect and prevent abuse or misuse
Data Sharing
We do not sell your personal information. We share data only with:
- AI model providers (e.g., Google Gemini) — the claim text you submit is sent to third-party AI models for analysis. These providers may have their own data retention policies. If you use the Lenz API, text you submit is processed the same way — see API Terms section 5.
- Stripe — for payment processing.
- Timestamping services — where a verification is warranted, a SHA-256 hash of its certificate is sent to a qualified trust service provider in the EU and to the public OpenTimestamps calendars, which publish it permanently, to fix the time it was issued. The hash carries no claim text and no personal data, and cannot be reversed; the certificate itself is not sent.
- Sentry — for error monitoring and service reliability.
- Google Analytics (GA4) — for usage analytics (page views, interactions, conversion events). We use Google Analytics with Google Consent Mode: the Google tag loads on every page but honours your consent choice. In regions where consent is required, it sets no cookies until you accept; if you decline, it sets no cookies and sends only limited, cookieless technical signals that Google uses for statistical modelling. We also use Google Signals, which supplements our analytics with aggregated data from users who are signed into their Google account and have turned on Ads Personalization. Signals enables cross-device reporting, remarketing audiences, and aggregated demographic and interest insights. If you are signed into Lenz, we also send a pseudonymous, hashed identifier derived from your account for cross-device analytics. This identifier cannot be used to recover your email or personal details. You can opt out of Google Analytics using the Google Analytics opt-out browser add-on, or manage your Ads Personalization settings at Google Ads Settings. Google may process this data in accordance with their privacy policy.
- Google Ads — for advertising measurement and audience building. We use Google Ads conversion tracking with Enhanced Conversions. When you are signed in to Lenz, we send Google a SHA-256 hashed version of your email address alongside conversion events (such as sign-up and return visits). Google uses the hash to match your conversion to your Google account (where one exists) so that ad performance can be measured even when cookies are unavailable. The hash is one-way and cannot be reversed to recover your email. We do not share your raw email with Google. Google may process this data in accordance with their privacy policy.
- User-provided data (Google Analytics) — the same SHA-256 hashed email described above is also provided to Google Analytics via the user-provided data feature, to improve attribution and audience matching between Analytics and Google Ads. No raw personal information is transmitted; only the irreversible hash.
- Microsoft Clarity — for anonymous behavioral analytics (click heatmaps, scroll depth, session recordings) to help us understand and improve the user experience. Clarity collects only anonymous usage data and does not track personal information. Clarity may process this data in accordance with Microsoft’s privacy statement.
- WhatsApp interactions — when you start a conversation with the Lenz WhatsApp bot from a web page, we correlate the click with your WhatsApp activity (claim checks, follow-up questions) and send the same analytics signals (Google Analytics events) we would send for equivalent activity on the website. No message content, phone numbers, or WhatsApp identifiers are sent to Google. This correlation only happens where you have granted analytics consent.
- LinkedIn Insight Tag — for advertising measurement and conversion tracking. We use LinkedIn’s Insight Tag to understand which LinkedIn ads lead to sign-ups and API usage. When you submit your email address (e.g. when signing in), it may be shared with LinkedIn in a protected form to improve conversion matching; LinkedIn does not share it onward and processes it in accordance with their privacy policy.
- HubSpot — for business analytics and the “Talk to us” chat. Its on-site tracking shows us which organizations visit our pages, for analytics and outreach; it does not identify you unless you sign in or give your email in the chat. Chat messages and that email are stored in HubSpot so we can reply. If you are signed in, the chat may identify you to HubSpot by your account email and link HubSpot’s cookies in that browser to you; signing out deletes those cookies. HubSpot processes this data in accordance with their privacy policy.
- Google Cloud — our infrastructure provider.
- WorkOS, Inc. — authorization (OAuth) for connecting third-party AI assistants. Processes a pseudonymous account identifier, authorization/connection metadata, and security technical data (which may include IP/device) in the United States, with EEA/UK/Swiss transfers governed by Standard Contractual Clauses.
Connecting Third-Party AI Assistants & Tools
You can connect third-party AI assistants and developer tools (for example, Claude or Cursor) to your Lenz account through our MCP server or using an API key. When you connect such a tool and grant it access:
- It can submit fact-check requests and retrieve results on your behalf, subject to your account’s plan limits and the permissions you grant when connecting.
- Any text or claims you submit through a connected tool are processed in the same way as claims you submit directly on Lenz (see Claim data above).
- We record usage information associated with these requests (such as which tool was used, the time of the request, and your account) for the purposes of enforcing usage limits, securing the service, and preventing abuse.
You remain in control of these connections at all times. You can disconnect a tool at any time:
- For tools connected with an API key, delete or revoke the key in your account settings under API credentials.
- For tools connected via authorization (OAuth), open your account settings under Connected apps and disconnect the tool — the associated access and refresh tokens are then invalidated. Deleting your Lenz account revokes all such connections as well; you can also contact us at support@lenz.io for help.
Authentication & Authorization for Connected Apps
To let you securely connect third-party AI assistants to your Lenz account, we use WorkOS, Inc. as a sub-processor to provide the authorization (OAuth) layer for these connections.
When you connect a tool through this flow, WorkOS processes:
- a pseudonymous identifier for your Lenz account;
- authorization and connection metadata, including the identity of the connecting application, authorization and consent events, and the access and refresh tokens issued for the connection;
- technical information used for security and fraud prevention, which may include IP address and device/browser information.
WorkOS does not receive your Lenz login credentials (you sign in directly on Lenz), and does not receive the content of the claims or fact-checks you submit.
WorkOS processes this information in the United States. Where your information is transferred outside the European Economic Area, the United Kingdom, or Switzerland, that transfer is governed by the Standard Contractual Clauses. You can review how WorkOS handles data in the WorkOS Privacy Policy, and its sub-processors at workos.com/legal/subprocessors.
Claims in the Library & Published Claims
When you mark a claim as “Public”, the claim text, analysis, score, and conclusion become publicly visible and may be included in the Library. By default, published claims are completely anonymous — no personal information such as your name, email address, or account details is shared with other users or displayed alongside the claim.
We do not publish your name anywhere. Published claims carry no contributor attribution, and notes you add to a claim are private to your account. The one exception is a claim you asked us to check publicly on X: that page credits the X handle you used, linked to your own post.
Data Retention & Deletion
You can permanently delete individual claims at any time. Deletion is irreversible — the claim text, its analysis and the report are removed from our systems. You can also delete all claims at once from your history page. Where the verification was warranted, its certificate is retained — see Verification certificates below.
Deleting a claim does not remove our operational logs of the API request that created it, which we keep to run and support the service. You can delete your account from your profile settings; that erases the text you sent and the responses we returned from those logs, leaving only an anonymous record that a request happened, with no account attached to it.
Cookies
We use essential cookies to maintain your authenticated session and CSRF protection. These are always on — the service does not work without them.
With your consent, we also set analytics and advertising cookies from the following providers:
-
Google Analytics (GA4) — served from our
own subdomain
t.lenz.io; sets first-party cookies (e.g._ga,_ga_*) to collect anonymous usage statistics such as page views and interactions. Google's tag runs in a consent-aware mode (Google Consent Mode): it loads before you choose, and in regions where consent is required it sets these cookies only after you accept; declining keeps it cookieless. -
Microsoft Clarity — sets cookies
(e.g.
_clck,_clsk) for behavioral analytics such as click heatmaps, scroll depth, and session recordings that help us understand and improve the user experience. -
LinkedIn Insight Tag — sets advertising
cookies (e.g.
li_fat_id,bcookie) to measure LinkedIn ad performance and conversions. -
HubSpot — sets cookies
(e.g.
hubspotutk,__hstc,__hssc,__hssrc) to recognise returning visitors for business-to-business analytics, and, for the chat,messagesUtk,hs-messages-is-openandhs-messages-hide-welcome-messageto keep a conversation and the chat window’s state across pages.
In regions where consent is required, Microsoft Clarity, LinkedIn
and HubSpot only load after you accept; Google's tag loads in the
cookieless consent-aware mode described above and sets cookies only
after you accept. You can change your choice at any time: select
Cookies here, or in the site
footer.
Declining stops Clarity, LinkedIn and HubSpot from loading, closes
the HubSpot chat on the page you are on, keeps
Google's tag cookieless, and removes the first-party analytics
cookies Lenz set (such as _ga); some cookies set
directly by third parties are managed by those providers. Essential
cookies remain.
International Data Transfers
Your personal data may be processed and stored in the United States, where our infrastructure and several of our service providers (Google, Stripe, Sentry, Microsoft) are located. Where such transfers occur, we rely on appropriate safeguards including the EU-US Data Privacy Framework, Standard Contractual Clauses, or equivalent mechanisms recognised under applicable law.
Children’s Privacy
Lenz is not intended for use by children under 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by posting a notice on the site. Continued use of the service after changes constitutes acceptance of the updated policy.
Verification certificates
Where a verification is warranted, we create a certificate: a signed, independently timestamped record of the analysis, including the statement checked, the verdict, the supporting sources and the applicable terms. We retain certificates indefinitely and do not delete them when an account is closed. A certificate may need to be produced years after it was issued in order to establish, or to answer, a claim under our warranty, and a record that can be deleted by one party cannot serve that purpose.
A certificate contains the statement checked and our conclusion about it. It does not contain your name, your email address or your account identifier, but the statement itself may contain personal data if you submitted some.
When you close your account — whether you do so yourself, or ask us to erase your data — we delete your account record and sever its link to any certificate. The certificate itself is retained. We rely on our legitimate interest in establishing, exercising or defending legal claims (Article 6(1)(f) GDPR) as the basis for that retention, and on Article 17(3)(e) GDPR to keep it after an erasure request.
Who is the data controller
The controller of your personal data is Lenz IO DPK, a company registered in Bulgaria, EU VAT Identification Number (VATIN) BG208892119.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please reach out through our contact page.