Privacy
FactStamp is a paid machine-facing API. There is no account, no sign-up, no cookie, no analytics script and no advertising on it. We never ask for a name or an email address.
What we receive
- The text you send us: a figure claim, or a company name, LEI or CIK.
- Proof of payment: an on-chain USDC transfer on Base, or a prepaid pack code.
- Ordinary request metadata that our host (Cloudflare) records: time, IP address, user agent.
What we store
- For each paid call, the tool used, the verdict returned, the series involved, the registry and judge versions, the time, a hash of the payment proof, and a SHA-256 hash of your input, not the input itself.
- Prepaid pack codes: a code bought by card is held in plaintext only until it is first collected, and from then on the delivery row keeps a hash plus a short fragment (the hint shown back to the buyer). The balance itself lives against the hash, with a use count.
- Nothing else. No name, no email, no address, no device fingerprint, no cross-site identifiers.
What we do not want
Do not send personal, health, financial or otherwise identifying information about anyone, including yourself. This service exists for numbers a publisher already publishes and for companies on public registers. If such data reaches us, we will delete the record on request.
Who else sees anything
- Cloudflare hosts the service and therefore processes the requests.
- Payment rails: our configured x402 facilitator (currently
facilitator.xpay.sh) settles the USDC on Base; Stripe processes card payments for prepaid packs, and card details never reach us. - Public registers: the entity door reads the GLEIF LEI index, US SEC EDGAR and the Australian Business Register (via ABN Lookup), so the company name or identifier you send is disclosed to those registers as a search.
- Citation and dependency sources: the citation door sends your DOI, arXiv ID or title to Crossref and to the arXiv API; the dependency door sends the package name and version to its registry (npm, PyPI or crates.io) and to Google's OSV advisory database. Those lookups are disclosed as searches, and no account or identity of yours travels with them.
Retention and deletion
Usage rows contain no claim text and are kept while the service runs, so that a call can be shown to have happened and so abuse can be traced. Ask us at the address below and we will delete the rows attached to a payment proof you own.
Your choices
Nothing here is required of you: if you would rather not send a claim to a third party, do not call the
service. Free endpoints (/health, /series.json, /llms.txt) collect no
input at all.
Version 0.1.0. Last updated 29 September 2026. Support and takedown requests: info@alpineai.com.au