rumors.fyi

Privacy Policy

Last updated: May 31, 2026

This Privacy Policy explains how we collect, use, and disclose information when you visit rumors.fyi (the “Site”) or submit information through it. We have deliberately designed the Site to collect as little information about you as practicable. The most important thing to know:we do not collect personal information for our own profiling, but we do display third-party advertising via Google AdSense; Google and its partners may read cookies and device identifiers directly from your browser. Under the California Consumer Privacy Act (CCPA/CPRA), permitting that activity may qualify as a “sale” or “share” of personal information for cross-context behavioral advertising, even though we receive no identifiable data ourselves. Sections 4 and 5 below explain this and how to opt out.

1. Who We Are

The Site is operated by the team behind rumors.fyi (“we,” “us,” or “our”), who act as the data controller for the purposes of the EU and UK General Data Protection Regulations. For any privacy question or request, contact privacy@rumors.fyi.

2. Information We Collect

We collect a deliberately small set of data. Using the California Consumer Privacy Act's statutory categories:

  • Identifiers- None for general browsing. For rumor submissions, we record a one-way SHA-256 hash of your IP address (truncated to 32 characters) and a copy of your browser's user-agent string in our submission log. The raw IP address is never stored.
  • Internet or other similar network activity - Server-side, our hosting and infrastructure providers receive and may log standard request data (IP, time, page, referrer, browser/OS, approximate location derived from IP) to operate and secure the Site. We also maintain two aggregate per-item counters and an event log, all of which are anonymous: a detail-view counter, an in-viewport list-impression counter, and a vote-event log (rumor identifier, “yes” or “no,” and timestamp - no IP, no user-agent, no identifier of any kind).
  • Inferences - None.
  • Sensitive personal information - None.
  • Commercial information - None.
  • Biometric information - None.
  • Geolocation - None precise; coarse country-level inference may occur in server logs.
  • Audio, electronic, visual, thermal, or similar - None.
  • Professional or employment-related - Only as contained in the free-text fields of a Submission you choose to send us.
  • Education information - None.
  • Submission data. If you use the submission form, we collect the information you choose to provide: a company name, the rumor text, an optional source URL, and an optional source-platform identifier. We do not ask for your name or email. If you choose to include identifying information in free-text fields, you do so voluntarily and at your own risk; we recommend you do not.
  • Correspondence. If you email us, we receive your email address and any other information you choose to provide.

3. What We Do Not Collect or Do

  • We do not require user accounts; we do not collect usernames, passwords, names, or email addresses from general visitors.
  • We do not knowingly collect financial information, government identifiers, or precise geolocation data.
  • We do not run our own ad-targeting profiles, do not perform cross-context behavioral profiling, do not share Submissions or correspondence with advertisers, and do not use the information we collect to build advertising profiles.
  • We do not deploy “session replay,” keystroke logging, or behavioral-fingerprinting tools.
  • We do not make automated decisions that produce legal or similarly significant effects about you.

4. Cookies, Advertising, and Your Choices

Essential storage.The Site uses your browser's local storage to remember which rumor you have voted on so that the “you voted Yes/No” indicator appears on return visits. This local-storage value lives on your device and is never transmitted except as the contents of an authenticated call to our vote endpoint.

Advertising. We display advertising through Google AdSense. Google and its advertising partners use cookies, device identifiers, and similar technologies to deliver, measure, and (where permitted) personalize ads. This data is collected directly by Google and its partners from your browser; it is not stored on our servers and is not used by us for any purpose. For visitors in the European Economic Area, the United Kingdom, and Switzerland, we use a Google-certified consent management platform (CMP) to present a 3-choice consent message before advertising cookies are used for personalization, and ads are handled according to your choices.

CCPA / CPRA characterization.Although we do not receive identifiable data from these activities, permitting advertising networks to use cookies for cross-context behavioral advertising may fall under the definitions of “sell” or “share” under the California Consumer Privacy Act and California Privacy Rights Act. See Section 5 for opt-out mechanisms.

Your choices. Where the consent message is shown, you can accept, decline, or manage your options, and you can re-open it later to change your choice. You can also control ad personalization directly with Google at adssettings.google.com, and opt out of many third-party vendors at optout.aboutads.info (US) or youronlinechoices.eu (EU). How Google uses data from sites that use its services is described at policies.google.com/technologies/partner-sites. Your browser also lets you refuse or delete cookies; refusing non-essential cookies does not affect your ability to read or vote on rumors.

5. Do Not Sell or Share My Personal Information; Global Privacy Control

California residents have the right to opt out of the sharing of personal information for cross-context behavioral advertising. You can exercise this right in two ways:

  • Through Google's CMP.Open the consent message at the bottom of any page (a small “Privacy options” or similar link surfaced by the CMP) and decline advertising cookies for personalization.
  • Global Privacy Control (GPC). We honor the GPC signal as a valid opt-out request from California residents. To enable GPC, install a browser extension or use a browser that supports it (see globalprivacycontrol.org). When we detect a GPC signal, advertising cookies for personalization are not set for that session.

You have the right not to receive discriminatory treatment for exercising any of these rights.

6. How We Use Information (and Our Legal Bases)

For visitors in the European Economic Area, the United Kingdom, and Switzerland, our lawful bases under Article 6 of the GDPR are mapped to each purpose:

  • Operating, securing, and improving the Service - legitimate interests (Art. 6(1)(f)). This covers server logs, the view counter, the list-impression counter, and the vote-event log used for abuse detection.
  • Curating, editing, and moderating Submissions - legitimate interests (Art. 6(1)(f)) and, where you have submitted content, performance of the implicit user agreement created by your Submission (Art. 6(1)(b)).
  • Anti-abuse logging (the SHA-256 hashed IP and user-agent in our submission log) - legitimate interests (Art. 6(1)(f)) for fraud prevention and Site integrity, and legal obligation (Art. 6(1)(c)) where applicable.
  • Advertising cookies for personalization- consent (Art. 6(1)(a)), obtained for EEA/UK/CH visitors through Google's CMP. Where consent is declined or not given, only non-personalized ads are served.
  • Responding to correspondence and legal requests - legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)).

7. Service Providers and Sub-processors

We rely on a small number of third-party providers. These providers process information on our behalf and are not authorized to use it for their own purposes (except where expressly noted as independent controller):

  • Vercel Inc. (United States) - hosting and edge delivery of the Site. Vercel processes incoming requests and may log technical information described in Section 2.
  • Supabase, Inc. (United States) - database and backend infrastructure that stores Submissions, curated content, and the aggregate counters and event log described above.
  • Google LLC (United States) - advertising via Google AdSense and consent collection via the AdSense CMP. Loaded only after you reach a page; the CMP runs first for EEA/UK/CH visitors. Google acts as an independent controller of the data it collects through its cookies for advertising purposes.
  • Brandfetch (United States / EU) - third-party CDN that serves company logos directly from cdn.brandfetch.io when you load a page. The CDN request includes the standard headers your browser sends (IP, user-agent, referrer); Brandfetch does not receive any data we hold about you. Where you have not loaded a page, no request is made.
  • Wikimedia Foundation (United States) - we fetch short company descriptions from the public Wikipedia API server-side (not from your browser); no data about you is sent to Wikimedia by reason of your use of the Site.

We may also use an email provider to receive messages sent to our published addresses. We may add or replace providers from time to time; material changes will be reflected in this policy.

8. International Transfers

The Site is operated from, and information is processed in, the United States. If you access the Site from outside the United States, your information will be transferred to, stored in, and processed in the United States and other jurisdictions where our service providers operate. Data-protection laws in these countries may differ from those of your country of residence. We rely on appropriate transfer mechanisms, including the European Commission's Standard Contractual Clauses (Modules 2 and 3)with our sub-processors, and, where applicable, on a sub-processor's certification under the EU-US Data Privacy Framework (currently relevant for Google and Vercel).

9. Data Retention

  • Aggregate view and impression counters - retained indefinitely as aggregate, non-personal totals.
  • Vote event log (rumor id, vote side, timestamp) - retained for up to 90 days for abuse detection, then aggregated and rows deleted.
  • Submission log (company, SHA-256 hash of rumor text, SHA-256 hash of IP, user-agent, timestamp) - retained for up to 12 months for anti-abuse and audit, then deleted. The raw IP is never stored.
  • Submissions, whether or not published, may be retained indefinitely as part of our editorial record; however, we will honor verified deletion requests as described in Section 10 to the extent required by applicable law.
  • Email correspondence - retained for as long as needed to address the inquiry and for a reasonable period thereafter.
  • Server logs at our infrastructure providers - governed by those providers' default retention (typically up to 30 days).

10. Your Rights

Depending on where you live, you may have certain rights with respect to your personal information. Because we hold very little personal information and have no way to authenticate most visitors, our ability to fulfill some requests is limited.

European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR). You have the right to: (i) access the personal data we hold about you; (ii) request correction of inaccurate data; (iii) request erasure; (iv) request restriction of processing; (v) object to processing based on legitimate interests; (vi) data portability where applicable; (vii) withdraw consent for any processing based on consent (notably advertising cookies); and (viii) lodge a complaint with your national supervisory authority. Our legal bases are mapped in Section 6.

California (CCPA / CPRA).California residents have the right to: (i) know the categories of personal information we have collected, the sources, the purposes, and the recipients; (ii) request deletion of personal information; (iii) request correction of inaccurate personal information; (iv) opt out of the sharing of personal information for cross-context behavioral advertising (see Section 5); and (v) not be discriminated against for exercising these rights. We do not engage in “sales” for monetary consideration as that term is defined under California law and do not use or disclose sensitive personal information in a manner that would trigger the right to limit.

Other US state privacy laws. If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or other states with comparable laws, you may exercise rights analogous to those described above to the extent provided by the applicable law.

Anonymous-user limitations. Because rumors.fyi does not require accounts, we usually cannot identify the data that belongs to you. The most actionable request we can service for an anonymous submitter is deletion of a specific submission: re-supply the original text you submitted; we will hash it and remove matching rows from our submission log and, where the Submission was published, evaluate it for removal from public view. Other rights (access, portability, objection) apply only where we can identify your data.

To exercise any right, contact privacy@rumors.fyi. We may need to verify your identity or the relevance of your request before we act. You may also designate an authorized agent to make a request on your behalf, subject to verification.

11. Security

We use commercially reasonable administrative, technical, and organizational measures to protect the limited information we hold, including: TLS in transit, encryption at rest at our database provider, least-privilege service accounts, and SHA-256 hashing of IP addresses in our submission log (raw IP is never written to disk). No system is perfectly secure, however, and we cannot guarantee the security of any information transmitted to or stored by us.

12. Children

The Site is not directed to anyone under 16. We do not knowingly collect personal information from anyone under 16. If you believe a person under 16 has provided information to us, please contact privacy@rumors.fyi and we will take prompt steps to delete it.

13. About the Companies and Subjects Discussed

Content on rumors.fyi is user-submitted and unverified by us. Company names, logos (served via Brandfetch), and short descriptive text (fetched from Wikipedia) are used editorially to identify the subject of community discussion and do not imply endorsement, sponsorship, affiliation, or authorization by the company referenced. Companies or individuals who believe content is inaccurate or infringing may contact legal@rumors.fyi for correction, debunking, or removal as described in our Terms of Service.

14. Legal Disclosures

We may disclose information when we believe in good faith that disclosure is required by law, subpoena, or other legal process; necessary to protect our rights, property, or safety, or those of others; or appropriate in connection with an investigation of suspected or actual unlawful activity, including apparent insider-trading misuse of the Service. If we receive a legal demand we believe to be overbroad or improper, we may, in our discretion, challenge it.

In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.

15. Do Not Track

Some browsers transmit “Do Not Track” signals. Because no consistent industry standard exists for these signals, we do not respond differently to them. We do, however, honor the Global Privacy Control signal for California residents as described in Section 5.

16. Third-Party Links

The Site contains links to third-party websites - most prominently, source links accompanying confirmed and debunked rumors, and outbound links in advertisements. We are not responsible for the privacy practices or content of those sites. Review their policies before providing them any information.

17. Changes to This Policy

We may update this policy from time to time. We will post the revised version on the Site and update the “Last updated” date above. Material changes will, where practicable, be flagged on the Site. Your continued use of the Site after the effective date constitutes your acceptance of the revised policy.

18. Contact

For any privacy question, request, or concern: privacy@rumors.fyi. EEA/UK users have the right to lodge a complaint with their local data-protection authority; California residents may contact the California Privacy Protection Agency.

This page was last updated on May 31, 2026. We recommend reviewing it periodically.