Privacy & data statement

Last updated: June 2026

At Primary Source, we believe trust is built on transparency. This statement describes how Cabrillo Labs, LLC (“we,” “us,” or “our”), operating the Service under the brand Primary Source and product names including triff, handles information when you use the Service. It is incorporated by reference into our Terms of Service.

What we collect

When you use triff, we collect:

  • The content you submit for analysis (the article, draft, research paper, or other document)
  • Your Google account information (if using the Google Docs add-on or signing in via Google) — limited to email address, name, and account ID for authentication and access control
  • Metadata about your analyses (when runs occurred, which document they were associated with, high-level statistics about the findings)
  • Feedback you provide (thumbs up/down on findings, comments about source alignment)

We do not collect:

  • Your browsing history
  • Personal information beyond what's needed for authentication
  • Any data from documents you don't explicitly submit for analysis

What we do with your content

When you submit content for analysis, triff:

  1. Extracts the claims worth comparing
  2. Retrieves relevant primary sources
  3. Compares the claims against those sources
  4. Generates findings (Verified, Delta, Conflicting, Unverified) describing how each claim aligns with the cited sources
  5. Creates an evidence package with references

After the analysis is complete, we retain:

  • The submitted document content (or a processed/extracted version of it)
  • The extracted claims and their associated findings
  • The primary sources used and the specific data retrieved from them
  • The final analysis result (the triff summary and per-claim findings)
  • Metadata about when the analysis occurred and which document it was associated with

We store the document you submit so that findings can be properly associated with their source material and so you can return to past analyses. This content is tied to your account and is not used to train large language models.

Self-learning and improvement

The system improves from every analysis it runs. This learning happens through:

  • Feedback signals (when you mark a finding as helpful or not helpful)
  • Pattern recognition about which claim types are hard to compare against sources
  • Identification of coverage gaps in our primary source database

Important: We do not train large language models on your content. Your submitted articles are not added to any training dataset. The self-learning is narrow and focused on improving claim detection, source selection, and finding quality — not on memorizing or reproducing your specific content.

Data retention

  • Findings and analysis results: Retained indefinitely so you can return to past analyses
  • Raw document content: Only retained as long as needed to complete the analysis and associate findings with the document. Full text is not stored long-term
  • Feedback data: Retained to improve the system
  • Account information: Retained as long as your account is active

You can request deletion of your analysis history at any time. Some metadata may be retained in anonymized form for system improvement.

Who has access

  • Your team: If you are part of an organization account, designated members of your organization can see your analysis history
  • Our team: Limited access for debugging, support, and system improvement. We only access content when necessary to resolve technical issues or honor support requests
  • Service providers: We use a small number of infrastructure and model providers (such as cloud hosting and large language model APIs) strictly to run the Service. They process content only on our instructions and are bound by confidentiality and data protection terms
  • No third parties: We do not sell your data. We do not share your content with advertising networks or data brokers

Google Docs integration

When you use the Google Docs add-on, we request the minimum permissions necessary:

  • Ability to read document content for analysis
  • Ability to add comments (not edit text)
  • Ability to see document metadata

We never modify your document text. We only add comments. You can revoke these permissions at any time through your Google account settings.

Your rights

You have the right to:

  • Access the data we hold about you and your analyses
  • Request deletion of your analysis history
  • Ask us to explain any finding or source used in an analysis
  • Receive support if something doesn't look right

To exercise these rights, contact privacy@primarysource.ai.

EU, UK, and Swiss residents

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following also applies to you.

Controller and processor. When you submit content on your own behalf, Cabrillo Labs is the data controller. When you submit content on behalf of an organization (for example, through an organization account or the Google Docs add-on used in your work), Cabrillo Labs typically acts as a data processor for your organization, and your organization is the controller; in that case our processing is also governed by the Data Processing Addendum referenced below.

Legal bases. We process personal data on the following legal bases under the EU GDPR and UK GDPR: (a) performance of a contract with you (operating the Service and your account); (b) our legitimate interests in securing, supporting, and improving the Service in ways that are not overridden by your interests or fundamental rights; (c) compliance with a legal obligation; and (d) your consent, where required (for example, for optional integrations).

Your rights. In addition to the rights listed above, you have the right to rectification, restriction of processing, objection to processing, data portability, and to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). To exercise these rights, contact privacy@primarysource.ai.

International transfers. The Service is operated from the United States, and your information may be transferred to and processed in the United States and other countries where we or our service providers operate. Where personal data is transferred from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum (or the UK International Data Transfer Agreement, as applicable), and recognized Swiss transfer mechanisms.

Data Processing Addendum. Organization customers may request our Data Processing Addendum, which incorporates the transfer mechanisms above and governs our processing of personal data on the customer's behalf. Email privacy@primarysource.ai to request the DPA.

Retention specifics for personal data. Personal data is retained only for as long as necessary for the purposes described in this statement. Where you request deletion of your analysis history, we will delete or anonymize associated personal data within a reasonable period, subject to limited retention required by law or for the establishment, exercise, or defense of legal claims.

We are not perfect

triff is in beta. While we take data protection and source-comparison quality seriously, mistakes can happen. If you see a source that was misread, a finding that seems wrong, or have any privacy concern — please tell us. Your feedback helps us improve both the technology and our practices.

Changes to this statement

We may update this statement from time to time. We will post a new “Last updated” date at the top and, for material changes, provide reasonable advance notice (for example, by email or an in-Service notice).

Questions?

If you have any questions about this privacy statement or how we handle data, please reach out to privacy@primarysource.ai. For other matters, you can contact us at hello@primarysource.ai.

We will respond promptly and honestly.


Cabrillo Labs, LLC
Operating as Primary Source AI · triff
Tim Pratt, Founder
hello@primarysource.ai