The short version: your draft is analysed for this review and is not kept as a permanent post archive. We keep anonymous counts, like “a review happened on Instagram with two privacy notes”, so we can tell whether T.A.P. is working. We never keep what you wrote or the photos you added.
What is sent for analysis
When you press Review my post, your browser sends the following to our server over an encrypted (HTTPS) connection:
- your caption or post text;
- the platform and audience you selected;
- the names you entered as mentioned or tagged;
- the link you plan to include, as text (T.A.P. does not open it);
- your photos, already resized and re-saved by your browser. Re-saving drops hidden metadata such as the GPS location your camera may have recorded;
- if video review is enabled on this site, the video file, from which a few still frames are taken.
If T.A.P. finds factual claims worth checking, a second request sends those claims and your caption, as text only, so they can be checked against web sources. Your photos are never part of the fact-check request.
What is processed temporarily
On the server, each uploaded photo is moved into a private temporary folder that is outside the website’s public files and blocked from web access. It gets a random file name. The server checks it is a real image, then converts it into a fresh JPEG in memory, which also removes any remaining metadata. The temporary file is deleted at that point, before the review begins.
Your text and the converted images exist in the server’s memory only while your request is being handled. The review that comes back is sent to your browser and kept only in that browser tab. Close the tab or start a new check, and it’s gone. T.A.P. doesn’t put your draft in your browser’s storage either.
What is stored
Our database keeps one anonymous record per review. It contains:
| Stored | Why |
|---|---|
| A random review ID and the time | Counting reviews; letting the second fact-check step find its review |
| Platform and audience you picked | Understanding where T.A.P. is useful |
| Rough caption length (e.g. “≤500 characters”) | Performance planning. The exact length isn’t kept |
| Number of photos, number of names, whether there was a link | Performance planning |
| How long the review took, the AI model used, and token counts | Speed and cost monitoring |
| Counts per category (e.g. “2 privacy notes, 1 claim checked”) | Knowing which checks are useful |
| Whether you chose Edit draft or Run again, and whether you finished the final check | Knowing whether reviews lead to changes |
| How many consent choices of each kind were made (not who they were about) | Understanding how people use the consent prompts |
| Any error code, e.g. “timeout” | Fixing problems |
These anonymous records are deleted after 400 days.
Feedback is stored only if you send it: your rating and, optionally, a short comment, linked to the anonymous review ID. Please don’t include names or personal details in comments.
What is not stored
- Your caption or any text you wrote
- Your photos, screenshots or video
- The names you entered, or your link
- The AI’s review of your post: findings, questions, suggested rewordings, fact-check results
- Your IP address in readable form (see analytics)
- Any account, email address or profile. T.A.P. has no user accounts
When temporary files are deleted
Normally, within the same second they are created: right after the photo has been checked and converted, before any AI processing. As a second safety net, the server deletes any file it created during a request when that request ends, even if the request fails partway.
As a third safety net, a scheduled cleanup job removes anything in the temporary folder older than 30 minutes. That covers rare cases like the server being restarted mid-request.
How AI processing works
T.A.P. uses a third-party AI provider, accessed through its business API, to read your draft and write the review. Your text and converted photos are sent from our server to the provider for that one review. Every request is sent with the provider’s response storage option turned off, so the review isn’t saved in the provider’s system for later retrieval.
The provider processes this data under its own API data policies, which cover things like limited retention for abuse monitoring and not using API data to train its models by default. For fact-checking, the provider’s web search tool looks up the claims; the search queries are based on those claims.
Your browser never talks to the AI provider directly. The connection runs only between our server and the provider, and the credentials for it are held only on our server.
How analytics work
The admin dashboard shows only totals and averages calculated from the anonymous records above: reviews per day, average review time, how many privacy notes or consent questions came up, and how many people revised their draft. There are no third-party analytics, tracking pixels, advertising scripts or externally hosted fonts on this site.
To prevent abuse, the server counts how many reviews come from each connection per hour. It doesn’t store your IP address for this. It stores a one-way keyed hash of it that can’t be turned back into the address, and deletes those counters after a day.
Admin and server logging
Application logs record errors and warnings, such as “the AI service timed out”, without the content of anyone’s draft. API keys are automatically scrubbed from log lines. These logs are kept for 30 days.
Admin audit log: sign-ins and settings changes made by site administrators are recorded so changes can be traced. Secret values are never written to it.
Web server logs: like almost every website, the web server run by our hosting provider keeps standard access logs: IP address, time, the address of the page requested, and browser type. Your draft is sent in the body of the request, not in the address, so it doesn’t appear in these logs. Their retention is set by the hosting provider.
Cookies
T.A.P. sets no cookies for visitors. The only cookie the application uses is a sign-in cookie for site administrators on the admin pages.
Questions about this page? The same principle applies to every change we make: if the software doesn’t do it, this page won’t claim it.