Privacy Policy
Last updated: September 25, 2026
Summary
Clarity is designed so your messages stay on your device. We do not operate accounts, servers that receive your pasted text, or analytics that track what you analyze.
What we do not collect
For Clarity:
- Messages you paste or type into the analyzer (we do not receive them on any server)
- Analysis results or scores sent to Clarity
- Personal identifiers or account information (there are no accounts)
- Usage analytics or behavioral tracking
How analysis works
When you analyze a message, processing happens entirely in your browser using local JavaScript. Nothing is uploaded to Clarity or any third-party service for analysis.
The Summary and How analysis works sections describe Clarity, the private message analyzer.
Media Lens preview
Media Lens is a separate, experimental preview for public articles, advertisements, speeches, and campaign material. It is not part of this Clarity site. A limited Jev-only Media Lens preview runs on a separate operator host, ml-jev.manipulationscore.com. It analyzes one public web page at a time, and only from a short list of hosts the operator allows. The Media Lens page sends only https addresses. The worker on the operator host also accepts http addresses sent directly to its API, under the same host list, address checks, and redirect rules. Live pasted-text analysis is off. The secondary classifier, classifier.dev, is off. Media Lens is not production-ready, and the operator can pause it at any time with a kill switch. Do not enter private messages or material you are not authorized to review. Clarity’s private analyzer remains governed by the on-device behavior described above.
Examples on the Media Lens page that are labeled as fixtures or samples are made up. Comparing how different outlets covered the same story is not live, because no approved source exists for finding other reports of the same story.
Media Lens live URL analysis
This section applies only to Media Lens on the operator host. Clarity message analysis stays on your device, as described above.
Before anything is sent, the page asks you to confirm that the material is public and that you are allowed to review it. The URL is not sent until you confirm, and the operator host rejects an analysis request without that confirmation. That consent covers the operator host requesting the page and sending prepared public span text to TypeSafe AI’s Jev service.
A confirmed analysis involves these network steps:
- Your browser sends the URL to the operator host inside the request body.
- The operator host, not your browser, requests the public page at that URL. The destination site and its content network see the operator host’s network address, not yours. The request carries no cookies from your browser.
- The operator host prepares the page text and sends prepared public span text to TypeSafe AI’s Jev service, one request per span, repeated up to three more times after some errors. Each request holds the page title, the kind of material (for example, article), the span’s id and role (for example, quoted), the span text (up to 1,200 characters), and the first 400 characters of the spans just before and after it. Spans marked as bylines or boilerplate are not sent, either on their own or as neighbouring text. Each request also carries Media Lens’s fixed questions and the requested Jev model name. TypeSafe processes it under TypeSafe’s own policy. TypeSafe does not fetch the URL, and Media Lens does not send the URL to TypeSafe.
- The result, including the prepared span text, is returned to your browser.
What the operator host keeps:
- Media Lens does not keep the full article text after the analysis, does not write Media Lens history, and does not create an account. If you use the page’s evidence-only export, that file is saved on your device, and deleting it removes that copy.
- The Media Lens worker writes redacted audit lines to the host’s system log. They contain only fields from a fixed list: the time, the event type, the worker mode, the input mode (for example, url), the error code, which rate limit was reached, the kill switch and live flag states, whether a URL allowlist is configured, the response status, how long the analysis took, counts of Jev calls, Jev failures, and abstentions, the abstention reason when a page could not be fetched, whether the reported Jev model matched, and classifier.dev counters and state, plus its reported model name and version labels when it runs (classifier.dev is off on the operator host, so its counters are zero). When a URL is refused or rate-limited, the line also records the URL’s scheme, whether its host is a domain name or an IP address, and for a domain name its registered domain, for example wikipedia.org. Audit lines do not include the full URL, the page path or query, an IP address from the URL, article text, span text, or your IP address.
- An ESTIMATED TypeSafe spend record stores only the month, a count of Jev calls, an estimated token count, and whether a spend warning was issued. It stores no text and no URLs.
- The operator host’s web server keeps a standard access log. It records request metadata such as your IP address, the time, the requested path, and browser details. It does not record request bodies, so the URL you submit is not in that log. The access log is set in the host’s web server configuration, which is not part of this repository.
How long the operator host keeps its system log and access log is set on that host and is not yet documented here.
Do not submit private messages, passwords, medical or financial records, information about children, or any URL you are not authorized to fetch. Do not use a URL to reach internal, loopback, or other non-public systems. Media Lens rejects URLs that contain a username or password. Media Lens does not bypass paywalls. When it recognizes a page as paywalled, it analyzes only the visible excerpt in the page the operator host received, and prepared spans from that excerpt may be sent to TypeSafe as described above. The result notes that the analysis is limited to the visible excerpt.
This policy does not claim that TypeSafe retains nothing, deletes on request, or offers zero data retention. Prepared public span text is processed under TypeSafe’s own policy.
Media Lens does not claim that TypeSafe AI will not retain, delete, train on, or otherwise use submitted inputs. Those practices are governed by TypeSafe’s applicable policy or written agreement. Media Lens makes no ZDR, deletion, or no-training claim unless a written agreement is attached to the release packet.
The only production provider in scope for live URL mode is the pinned TypeSafe Jev integration. classifier.dev remains disabled, evaluation-only, and is not a fallback, second model, cascade, or production dependency.
Live pasted-text analysis stays disabled. classifier.dev remains off / KEEP_EVALUATION_ONLY. Private messages belong in Clarity and must not be submitted to Media Lens as a URL.
Media Lens public claims
The Media Lens preview on the operator host is experimental and not production-ready. It is not deployed on the public Clarity site. It is not generally available. Live pasted-text is prohibited. There is no accuracy claim and no named-person scoring product.
Media Lens does not claim that it:
- is production-ready
- is generally available
- detects manipulation with guaranteed accuracy
- fact-checks claims
- identifies manipulative people, outlets, or political actors
- compares coverage across outlets in live results
- provides anonymous or zero-retention processing
- guarantees no training or third-party processing
- is a diagnosis, safety assessment, or definitive credibility judgment
This policy also does not claim TypeSafe ZDR or that article text is deleted from TypeSafe without a written agreement attached to the release packet. It does not claim that classifier.dev is part of the live path. Incident copy must not say that Media Lens detected an attack on a named outlet or person.
Local storage on your device
Clarity may store two kinds of data locally in your browser:
- App cache (service worker): public app files so the tool can work offline after your first visit. This cache does not contain your messages.
- Optional analysis history: if you turn on “Save recent analyses on this device,” Clarity stores up to eight recent analyses (full message text, screening result, and timestamp) in
localStorageunderclarity-history-v2on this device only. History is off by default. Legacy data from earlier releases without explicit opt-in is removed when you load the current version.
You can delete individual saved analyses or use “Delete all history” to remove all stored message text and results. Disabling the save toggle stops new writes; delete controls remove what is already stored.
Browser local storage may persist until you clear site data in your browser settings.
Fonts and hosting
Fonts are self-hosted from the same origin as the app. No third-party font or script requests are made when you use Clarity.
Your hosting provider
If you access Clarity through a website host (for example GitHub Pages), that host may collect standard web server logs (IP address, user agent, request time) as part of normal HTTP delivery. Clarity itself does not receive those logs.
Children
Clarity is not directed at children under 13. We do not knowingly collect information from children.
Changes
We may update this policy as the product evolves. Material changes will be reflected in the “Last updated” date above.
Contact
For privacy questions, email feedback@manipulationscore.com with Privacy in the subject line, or see Contact and Corrections for full instructions. Do not include private message content in your report.