đź§ą wyper.io

Privacy Policy

Last updated: 25 July 2026

This policy explains what data the wyper.io browser extensions (“wyper.io Social Cleanup” and “wyper.io Fact-Check”), the website wyper.io and our backend process, why, and your rights under the EU General Data Protection Regulation (GDPR).

The short version. The Cleanup tool runs entirely in your browser - nothing you delete and no login ever leaves your device. The Fact-Check tool sends only the text/transcript you explicitly ask it to check (with emails, phone numbers and card numbers stripped out first) to our server, which relays it to AI providers for verification. We never receive your social or Google passwords, we never sell your data, and we don’t use it for advertising.

1. Who is responsible (Controller)

Gelato Zupply LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA - the operator of the wyper.io tools (the "Controller").
Contact for all privacy matters: support@wyper.io.

2. What the products do

3. Data processed - by feature

3.1 Social Cleanup - processed locally only

All actions run on your device inside your logged-in session. We do not receive, transmit or store your posts, likes, follower lists, account credentials, session tokens or any content. To operate, the extension reads counts and lists from the page and stores small settings locally in your browser (chrome.storage.local), e.g. an interface-language preference and progress state. This never leaves your browser. The only optional exception is an anonymous count of items removed, used solely for aggregate statistics (see §3.4a) - a number, never any content.

3.2 Fact-Check - data sent to our backend

When you trigger a check, the extension sends the following to our backend (operated on our behalf; see §5):

This content is relayed to our AI sub-processors (Google - Gemini; xAI - Grok) to produce the verdict and is used only to answer that request.

Video analysis (when a video has no readable captions): if you ask us to check a video and no caption text is available, we send the video’s URL to our backend instead of page content. For YouTube links the URL is passed to Google (Gemini), which retrieves and analyses the video on Google’s side; for posts on X our backend downloads the video file and passes it to Gemini. Gemini returns a short list of the factual claims made in the video, and only that list is then fact-checked like any other text. We do not store the video or an audio copy, and results produced this way are labelled as AI video analysis in the interface. This never happens automatically - only for a video you explicitly asked to check.

Camera scan (app): photos you take to scan a headline are processed on your device (local text recognition) - images never leave your phone; only the extracted text is sent for checking.

Voice check / “Listen” (app): the short voice recording (max. 20 s) you explicitly make is sent to our backend and relayed to Google Gemini solely to produce a transcript; the transcript is then checked like any text. Recordings are not retained after transcription.

Abuse prevention: to enforce free-tier limits we additionally keep a daily counter per IP address in hashed form only (the hash includes the date, so it self-rotates daily and cannot be linked across days; no clear-text IP is stored). For paid licences, the anonymous installation IDs using a key are bound to that key (a bounded number of device “seats”) to prevent key sharing - no additional personal data is collected for this.

3.3 Proof Library (Pro)

If you have an active Pro plan and use the Proof Library, the verification records you create (claim, verdict, sources, date) are stored on our backend and linked to your licence so you can view them in the extension. You can request deletion at any time (see §9).

3.4 Website & payments

3.4a Anonymous usage counters

We keep aggregate, anonymous totals to run the product and show public counters (e.g. total fact-checks run, total items cleaned). These are plain numbers incremented on our server - they contain no content and no identifier of who did what, and cannot be traced back to you. The Social Cleanup tool may report only a count of items it deleted locally (never what was deleted); it still sends no posts, likes, lists or credentials.

3.5 Public sharing & the proof ledger

Sharing is optional and happens only when you choose it. If you share a verification (creating a public /v/ link), the shared result (claim, verdict, sources and date) becomes public: it is shown on a public web page and also posted, as a link, to our public Telegram channel WYPER.io PROOF (@wyper_io_proof), which serves as a transparent, append-only record. Your private Proof Library entries are not published - only items you explicitly share.

Anyone may dispute a public verification. A dispute requires a supporting source link and an identity - either an email or a public X (Twitter) handle. If you provide an X handle it is shown publicly next to your dispute on the channel; an email is kept private in our database and used only to follow up. Disputes are published publicly (threaded onto the original entry) so corrections stay transparent and traceable.

Because these posts are public by design, they may be seen, cached or indexed by third parties and remain visible until removed. To have a shared verification or a dispute removed, contact support@wyper.io (see §9).

4. Legal bases (GDPR Art. 6)

PurposeLegal basis
Providing the fact-check you requestedArt. 6(1)(b) - performance of a contract / pre-contract
Fair-use limits, abuse prevention, securityArt. 6(1)(f) - legitimate interests
Subscriptions & licence management (Stripe)Art. 6(1)(b) - contract
Proof Library storageArt. 6(1)(b) - contract (feature you enabled)

5. Sub-processors & recipients

We share the minimum necessary data with these providers, each acting under a data-processing agreement:

ProviderPurposeLocation
Google (Gemini API)AI fact-checkingEU / USA
xAI (Grok API)AI cross-check & deep researchUSA
StripePayments & subscriptionsEU / USA
Hetzner Online GmbH (data centre in Germany, EU)Backend hostingGermany / EU
CloudflareCDN, TLS, securityEU / USA

We do not sell your data and do not share it with advertisers or data brokers.

6. International transfers

Some providers are located in the USA. Where data is transferred outside the EU/EEA, it is protected by appropriate safeguards, in particular the EU Standard Contractual Clauses and the providers’ certifications.

7. Retention

8. Google API / Chrome Web Store “Limited Use”

wyper.io’s use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use the data solely to provide and improve the user-facing features described here, do not sell it, do not use it for advertising, and do not allow humans to read it except as necessary for security, legal compliance, or with your consent.

9. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, and to object. To exercise any of these, or to delete your Proof Library or installation data, contact support@wyper.io. You also have the right to lodge a complaint with a supervisory authority.

10. Children

wyper.io is not directed to children under 16 and we do not knowingly process their data.

11. Changes

We may update this policy; the “last updated” date reflects the current version. Material changes will be announced on this page.