About ScanRecords
A public, automated archive of what communication platforms say they do with your messages — built so that quiet edits stop being quiet.
Why this exists
Under the EU's Chat Control derogation (extended to April 2028), scanning of private communications is voluntary: each provider decides for itself whether to scan. That decision is rarely announced. When it appears anywhere, it appears as a small edit to a policy document.
Nobody was keeping the record, and a record like this cannot be reconstructed later — measurements of 26 Jul 2026 can only be taken on 26 Jul 2026. So the archive records every day, and the record keeps itself.
What is tracked
- Privacy policies and terms of service — where scanning must eventually be disclosed.
- Encryption description pages — if client-side scanning arrives, the sentence "we cannot read your messages" changes first.
- Law-enforcement and government-request pages, and community guidelines.
- App Store privacy labels — declared data collection, changed silently, archived by nobody else.
Method
- Every day at 06:17 UTC, a zero-dependency tool fetches each tracked document, extracts its readable text, and stores text, raw HTML, and a SHA-256 hash.
- A snapshot is committed only when the extracted text actually changed — presentation churn is filtered, so every recorded change is a real change.
- Git history is the timestamped, tamper-evident record. The repository is public: anyone can re-run the tools and verify any snapshot.
- When a change is recorded, the Internet Archive is asked to capture the source page the same day — an independent, third-party timestamp of the same document.
- Fetches identify themselves as ScanRecordsBot. When a site blocks the bot, the block is recorded before any workaround is considered.
What this is not
ScanRecords publishes observations, not conclusions. A recorded change means the document changed — nothing more. Interpretation is left to the reader. Corrections, vendor responses and takedown requests follow the fixed editorial policy.
Limitations
- Some pages render their content only with JavaScript; plain fetches archive the server response and are flagged limited.
- The archive records what platforms say, not what their software does. Behavioral measurement is a separate project.
Contact
Open an issue on GitHub.