Last updated: October 2026 — claim visibility defaults, live chat, warranty certificates, what deleting a claim removes, retention periods, zero retention, ad audiences, OpenAI Ads, ad conversions, checked drafts and citation checks, deleting a draft, what Google keeps, suggested edits, uploaded Word documents, the providers zero retention avoids
Introduction
Lenz (“we”, “us”, or “our”) is a verification service that uses AI, available at lenz.io. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
Information We Collect
Account information
When you create an account (directly or via Google sign-in) we store your email address and name. If you sign in with Google, we receive your basic profile information (name, email, and profile picture URL) as authorized by you through Google’s OAuth consent screen.
Claim data
When you submit a claim for verification, we store the text you provide and the analysis results generated by our analysis pipeline. When you check a draft, we store the draft, the statements and citations found in it, and the results of the checks run on it. To check a citation, we read the cited page through Exa or Firecrawl and look up a cited DOI at doi.org, Crossref and OpenAlex; they receive the cited link or DOI, not your text. When you upload a Word document to check in the Workbench, we also keep the file itself, so that we can give it back to you with our comments. It is stored in a private Google Cloud Storage bucket in the United States that only Lenz’s own services can read, and it is deleted after 30 days, or earlier when you delete the check, when your retention period passes, or when you delete your account. The copy with our comments is made when you download it and is not stored. If you paste a link to a Google Doc shared with anyone who has the link, we fetch the document once from Google’s export address, with no sign-in, and then handle it as an upload. Every claim you check is private by default: on the website, in the Workbench, through the API, WhatsApp or an assistant connector. The one exception is a claim you ask the Lenz bot to check on X, which it answers in public. You can change the visibility of each claim report at any time. Options are “Private” (visible only to you) or “Public”. Public claims are accessible to anyone with the link, may be included in the Library, and may be used for research. An account on Pro or Scale can set a retention period and turn warranty certificates off on the API credentials page; see how long we keep data below.
Usage data
We collect basic usage information such as page views, votes, and interaction patterns to improve the service. We use cookies to maintain your session and remember your authentication state.
Payment information
Payments are processed by Stripe. We do not store your credit card details. Stripe may collect information necessary to process your transaction in accordance with their own privacy policy.
Contact form
If you contact us through our contact form, we store your email address, subject, and message to respond to your inquiry.
How We Use Your Information
- To provide and operate the verification service
- To authenticate your account and manage your session
- To process payments and manage subscriptions
- To respond to your inquiries and support requests
- To improve and optimize the service
- To detect and prevent abuse or misuse
Data Sharing
We do not sell your personal information. We share data only with:
- AI model providers (e.g., Google Gemini) — the claim text you submit is sent to third-party AI models for analysis. Google (Gemini) stores none of it, apart from the search queries of a check grounded in Google Search; the other providers keep it for the periods listed on our subprocessors page. If you use the Lenz API, text you submit is processed the same way — see the Data We Process section of the Terms of Service.
- Stripe — for payment processing.
- Timestamping services — where a verification is warranted, a SHA-256 hash of its certificate is sent to a qualified trust service provider in the EU and to the public OpenTimestamps calendars, which publish it permanently, to fix the time it was issued. The hash carries no claim text and no personal data, and cannot be reversed; the certificate itself is not sent.
- Sentry — for error monitoring and service reliability.
- Google Analytics (GA4) — for usage analytics (page views, interactions, conversion events). We use Google Analytics with Google Consent Mode: the Google tag loads on every page but honours your consent choice. In regions where consent is required, it sets no cookies until you accept; if you decline, it sets no cookies and sends only limited, cookieless technical signals that Google uses for statistical modelling. We also use Google Signals, which supplements our analytics with aggregated data from users who are signed into their Google account and have turned on Ads Personalization. Signals enables cross-device reporting, remarketing audiences, and aggregated demographic and interest insights. If you are signed into Lenz, we also send a pseudonymous, hashed identifier derived from your account for cross-device analytics. This identifier cannot be used to recover your email or personal details. You can opt out of Google Analytics using the Google Analytics opt-out browser add-on, or manage your Ads Personalization settings at Google Ads Settings. Google may process this data in accordance with their privacy policy.
- Google Ads — for advertising measurement and audience building. We use Google Ads conversion tracking with Enhanced Conversions. When you sign up, get API credentials, make your first API call or make your first purchase, we send Google a SHA-256 hashed version of your email address, plus Google’s ad click identifier if you came from a Google ad. If you declined cookies, we tell Google so with each of these. Google uses the hash to match the conversion to your Google account (where one exists). The hash is one-way and cannot be reversed to recover your email. We do not share your raw email, or any of the text you check. We may also give Google a list of hashed email addresses of Lenz accounts, so our ads reach people like our users, or skip people who already use Lenz. Google may process this data in accordance with their privacy policy.
- User-provided data (Google Analytics) — the same SHA-256 hashed email described above is also provided to Google Analytics via the user-provided data feature, to improve attribution and audience matching between Analytics and Google Ads. No raw personal information is transmitted; only the irreversible hash.
- Microsoft Clarity — for anonymous behavioral analytics (click heatmaps, scroll depth, session recordings) to help us understand and improve the user experience. Clarity collects only anonymous usage data and does not track personal information. Clarity may process this data in accordance with Microsoft’s privacy statement.
- WhatsApp interactions — when you start a conversation with the Lenz WhatsApp bot from a web page, we correlate the click with your WhatsApp activity (claim checks, follow-up questions) and send the same analytics signals (Google Analytics events) we would send for equivalent activity on the website. No message content, phone numbers, or WhatsApp identifiers are sent to Google. This correlation only happens where you have granted analytics consent.
- LinkedIn Ads — for advertising measurement. When you sign up, get API credentials, make your first API call or make your first purchase, we share a hashed version of your email with LinkedIn, plus LinkedIn’s ad click identifier if you came from a LinkedIn ad, so it can tell which of its ads led to it. We may also give LinkedIn a list of hashed email addresses of Lenz accounts, for the same ad audiences as Google above. LinkedIn processes this data in accordance with their privacy policy.
- OpenAI Ads — for advertising measurement. When you sign up, get API credentials, make your first API call or make your first purchase, we share a hashed version of your email with OpenAI, plus OpenAI’s ad click identifier if you came from a ChatGPT ad, so it can tell which of its ads led to it. OpenAI receives none of the text you check, and processes this data in accordance with their privacy policy.
- HubSpot — for business analytics and the “Talk to us” chat. Its on-site tracking shows us which organizations visit our pages, for analytics and outreach; it does not identify you unless you sign in or give your email in the chat. Chat messages and that email are stored in HubSpot so we can reply. If you are signed in, the chat may identify you to HubSpot by your account email and link HubSpot’s cookies in that browser to you; signing out deletes those cookies. HubSpot processes this data in accordance with their privacy policy.
- Google Cloud — our infrastructure provider.
- WorkOS, Inc. — authorization (OAuth) for connecting third-party AI assistants. Processes a pseudonymous account identifier, authorization/connection metadata, and security technical data (which may include IP/device) in the United States, with EEA/UK/Swiss transfers governed by Standard Contractual Clauses.
The current list of subprocessors is at lenz.io/subprocessors.
Connecting Third-Party AI Assistants & Tools
You can connect third-party AI assistants and developer tools (for example, Claude or Cursor) to your Lenz account through our MCP server or using an API key. When you connect such a tool and grant it access:
- It can submit fact-check requests and retrieve results on your behalf, subject to your account’s plan limits and the permissions you grant when connecting.
- Any text or claims you submit through a connected tool are processed in the same way as claims you submit directly on Lenz (see Claim data above).
- We record usage information associated with these requests (such as which tool was used, the time of the request, and your account) for the purposes of enforcing usage limits, securing the service, and preventing abuse.
You remain in control of these connections at all times. You can disconnect a tool at any time:
- For tools connected with an API key, delete or revoke the key in your account settings under API credentials.
- For tools connected via authorization (OAuth), open your account settings under Connected apps and disconnect the tool — the associated access and refresh tokens are then invalidated. Deleting your Lenz account revokes all such connections as well; you can also contact us at support@lenz.io for help.
Authentication & Authorization for Connected Apps
To let you securely connect third-party AI assistants to your Lenz account, we use WorkOS, Inc. as a sub-processor to provide the authorization (OAuth) layer for these connections.
When you connect a tool through this flow, WorkOS processes:
- a pseudonymous identifier for your Lenz account;
- authorization and connection metadata, including the identity of the connecting application, authorization and consent events, and the access and refresh tokens issued for the connection;
- technical information used for security and fraud prevention, which may include IP address and device/browser information.
WorkOS does not receive your Lenz login credentials (you sign in directly on Lenz), and does not receive the content of the claims or fact-checks you submit.
WorkOS processes this information in the United States. Where your information is transferred outside the European Economic Area, the United Kingdom, or Switzerland, that transfer is governed by the Standard Contractual Clauses. You can review how WorkOS handles data in the WorkOS Privacy Policy, and its sub-processors at workos.com/legal/subprocessors.
Claims in the Library & Published Claims
When you mark a claim as “Public”, the claim text, analysis, score, and conclusion become publicly visible and may be included in the Library. By default, published claims are completely anonymous — no personal information such as your name, email address, or account details is shared with other users or displayed alongside the claim.
We do not publish your name anywhere. Published claims carry no contributor attribution, and notes you add to a claim are private to your account. The one exception is a claim you asked us to check publicly on X: that page credits the X handle you used, linked to your own post.
Data Retention & Deletion
By default we keep the claims you submit, their analysis and our operational logs of your API requests for as long as your account exists. An account on Pro or Scale can set a retention period, in days, on the API credentials page. It covers everything the account submits, on every channel (the website, the Workbench, WhatsApp, the API and connected AI assistants), and takes effect 24 hours after it is set, so a mistaken value can be changed back first. From then on, anything older than the period is removed within an hour: the text you sent, the analysis, evidence and report of each verification, your follow-up questions, each draft you checked with its statements, quick checks, citation checks, suggested edits and the Word document it came from, the text in your credit history and in our logs of your API requests, and our log of the messages you sent us on WhatsApp. The period applies to your history to date, not only to new claims. A removed verification keeps its identifier, verdict and dates, with none of its text; a removed draft keeps its identifier and dates, with none of its text.
When you check a draft, on the website, in the Workbench or through the API, we store the draft, the statements found in it, the result of every quick check run on them, whether it ran on its own or you started it, each citation check, with the cited link or DOI and the passage quoted from the source, and each suggested edit, with the words of the draft it replaces and the words that replace them. A list in the Workbench is a checked draft, stored the same way. The retention period covers all of it. A quick check of a single statement sent through the API or a connected AI assistant, and an extraction, create no record: their text and result are held in caches for up to 24 hours, and in your account’s API-call log, which the retention period also covers. A retention period does not remove warranty certificates: a certificate retains the checked statement, which can be identical to the text you submitted, the verdict, the summary and the sources, for as long as the warranty needs it. Posts that ask us on X to check a claim have no Lenz account behind them and are outside it.
The shortest retention period is zero retention. With it, what the account submits is never written to our database: not the claims you send, not their analysis or evidence, not a draft you check, its checks or its suggested edits, not a Word document you upload (its download is then made from the draft’s text, without the document’s formatting), not the text in your credit history or in our logs of your API requests, not our log of your WhatsApp messages. If we offer you a choice between claims on WhatsApp, that choice is held until you answer, or for at most an hour. A result stays readable from our cache for 24 hours, where you can also ask follow-up questions about it, and is then gone. Because nothing is written to our database, nothing reaches our backups. Certificates are off while zero retention is set, because a certificate retains the checked statement. What it does not change: the task queue holds a check for the minutes it runs, request logs keep identifiers only, a note or follow-up question you add on the website to a public verification someone else ran is kept for up to an hour, and the model and search providers keep what their own terms say (see subprocessors), with two exceptions: with zero retention, Gemini searches the web through Google’s Web Grounding for Enterprise, which keeps nothing, instead of Google Search, and Perplexity is not used.
You can permanently delete individual claims at any time. Deletion is irreversible: the claim text, its analysis, the report and any follow-up questions are removed. It does not reach our log of the messages you sent us on WhatsApp or our record of a post that asked us on X to check a claim. You can also delete all claims at once from your history page, which also deletes every draft you checked. You can delete a single draft you checked on the website or in the Workbench: that removes its text, the statements found in it, its quick checks, its citation checks and its suggested edits, and the Word document it came from. A draft checked through the API has no delete of its own; deleting all claims, the retention period and deleting your account remove it. A verification started from a draft is a claim of its own: deleting the draft leaves it, and you can delete it like any other. Where the verification was warranted, its certificate is retained — see Verification certificates below.
Deleting a claim also removes its text from your credit history and from our operational logs of the API requests that submitted it, which we keep to run and support the service; a record that each request was made remains, with its date, cost and outcome. You can delete your account from your profile settings; that erases the text you sent and the responses we returned from those logs, leaving only an anonymous record that a request happened, with no account attached to it.
Copies held in our caches expire within 24 hours. Our database backups are kept for a limited time, so content you delete, or the content of an account you delete, leaves them within 60 days.
Cookies
We set a small number of first-party cookies ourselves, and they are
always on. They keep you signed in (__session,
csrftoken, lenz_last_user); remember choices
you made, including the appearance, the currency prices are shown in,
and your answer to this cookie banner (lenz_theme,
lenz_currency, lenz_consent); and let us
count visitors and keep each one on a consistent version of the site
when we test a change (lenz_aid,
lenz_campaign_visit). The last two hold a random
identifier that is not linked to your name or email. None of them
last longer than two years.
With your consent, we also record the site that referred you to us,
once, in _lenz_ref, so we can tell which channels bring
people to Lenz. Declining, or withdrawing consent later, expires it,
along with the provider cookies below.
With your consent, we also set analytics and advertising cookies from the following providers:
-
Google Analytics (GA4) — served from our
own subdomain
t.lenz.io; sets first-party cookies (e.g._ga,_ga_*) to collect anonymous usage statistics such as page views and interactions. Google's tag runs in a consent-aware mode (Google Consent Mode): it loads before you choose, and in regions where consent is required it sets these cookies only after you accept; declining keeps it cookieless. -
Google Ads — sets first-party cookies
(e.g.
_gcl_au, and_gcl_awif you arrived from one of our ads) to measure ad performance and to build the audiences described above. Like Google Analytics, the tag runs under Google Consent Mode: in regions where consent is required it sets no cookies until you accept, and declining keeps it cookieless. Withdrawing consent expires these cookies. -
Microsoft Clarity — sets cookies
(e.g.
_clck,_clsk) for behavioral analytics such as click heatmaps, scroll depth, and session recordings that help us understand and improve the user experience. -
HubSpot — sets cookies
(e.g.
hubspotutk,__hstc,__hssc,__hssrc) to recognise returning visitors for business-to-business analytics, and, for the chat,messagesUtk,hs-messages-is-openandhs-messages-hide-welcome-messageto keep a conversation and the chat window’s state across pages.
In regions where consent is required, Microsoft Clarity and HubSpot
only load after you accept; Google's tag loads in the
cookieless consent-aware mode described above and sets cookies only
after you accept. You can change your choice at any time: select
Cookies here, or in the site
footer.
Declining stops Clarity and HubSpot from loading, closes
the HubSpot chat on the page you are on, keeps
Google's tag cookieless, and removes the first-party analytics
cookies Lenz set (such as _ga); some cookies set
directly by third parties are managed by those providers. Essential
cookies remain.
International Data Transfers
Your personal data may be processed and stored in the United States, where our infrastructure and several of our service providers (Google, Stripe, Sentry, Microsoft) are located. Where such transfers occur, we rely on appropriate safeguards including the EU-US Data Privacy Framework, Standard Contractual Clauses, or equivalent mechanisms recognised under applicable law.
Children’s Privacy
Lenz is not intended for use by children under 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by posting a notice on the site. Continued use of the service after changes constitutes acceptance of the updated policy.
Verification certificates
Where a verification is warranted, we create a certificate: a signed, independently timestamped record of the analysis, including the statement checked, the verdict, the supporting sources and the applicable terms. We retain certificates indefinitely and do not delete them when an account is closed. A certificate may need to be produced years after it was issued in order to establish, or to answer, a claim under our warranty, and a record that can be deleted by one party cannot serve that purpose.
A certificate contains the statement checked and our conclusion about it. It does not contain your name, your email address or your account identifier, but the statement itself may contain personal data if you submitted some.
When you close your account — whether you do so yourself, or ask us to erase your data — we delete your account record and sever its link to any certificate. The certificate itself is retained. We rely on our legitimate interest in establishing, exercising or defending legal claims (Article 6(1)(f) GDPR) as the basis for that retention, and on Article 17(3)(e) GDPR to keep it after an erasure request.
Who is the data controller
The controller of your personal data is Lenz IO DPK, a company registered in Bulgaria, EU VAT Identification Number (VATIN) BG208892119.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please reach out through our contact page.