← BACK TO PRUF

Privacy Agreement

01What We Do Not Have

PRUF does not collect, store, process, or retain Personally Identifiable Information. This is enforced by system architecture, not by internal policy.

Biometric Data. None. No face images, face-derived measurements, face-derived hashes, fingerprints, voiceprints, or iris scans are stored anywhere in our systems — or anywhere at all, including your own device. Raw biometric data — camera frames, depth maps, sensor readings — is processed entirely on your device, only in volatile memory, only for the duration of a live verification, and destroyed immediately. Nothing derived from it survives. PRUF's biometric retention period is zero, everywhere, for everyone, with no opt-ins and no exceptions.

Direct Identifiers. No full legal names, physical addresses, email addresses, telephone numbers, social security numbers, government ID numbers, or external financial account numbers.

Tracking Data. No browsing history, search history, third-party website interaction logs, advertising identifiers, cross-app tracking tokens, or behavioral profiles.

Advertising Data. PRUF does not serve advertisements. There is no advertising infrastructure. There is no data collection for advertising purposes. Zero Ads is a structural covenant, not a feature toggle.

AI Training Data. PRUF does not use, license, sublicense, sell, or process any user-generated content for artificial intelligence training, machine learning model development, or any derivative computational purpose. Your content belongs to your hash.

02Your Face Is a Gate, Not a Record

2.1The Owner Check (Your Phone's Own Lock)

Before PRUF verifies you as human, your phone verifies you as its owner: the device's own Face ID or Touch ID runs, evaluated by Apple entirely inside your phone's secure hardware. PRUF never receives, touches, or transmits any part of this — no scan, no measurement, no score. PRUF learns exactly one bit: the phone's live owner is present, yes or no. Verified · not stored.

2.2The Liveness Ceremony

PRUF's camera then confirms you are a live, three-dimensional human — not a photo, a screen, or a replay. You look at the camera, turn left, turn right. The frames and depth readings are processed on your device in the moment and destroyed in the moment. Nothing is derived from them: no hash, no measurements, no record of any kind. The only thing that survives the ceremony is the result — a human was present.

2.3Your Account Is a Random Token

When you enroll, your account identity is minted as a random cryptographic token. It is not computed from your face, your body, or anything about you. Two enrollments by the same person would produce completely unrelated tokens. There is nothing to reverse, because the token was never derived from you in the first place.

2.4Camera Verification of Content

PRUF's camera system uses your device's sensors to verify that the camera was looking at real three-dimensional space at the moment of capture. This certifies provenance — who captured an image, where, and when — not the authenticity of the subject in frame. No system can prove that, and we do not claim to. PRUF does not receive or store the sensor data used for this verification; only the binary result (verified or not verified) is recorded as metadata on the photo.

03Your Recovery Anchors (None of Them Are Your Body)

Access to your account rests on three anchors, and every one of them is something you hold — never something you are:

Losing your phone does not lose your account: your recovery code — something no server holds — restores it, and adding another anchor makes it stronger. PRUF cannot use what it stores to impersonate or identify you: one-way hashes cannot be reversed, and there is no master key, administrative override, or backdoor. This is a mathematical constraint, not a policy decision.

04Your Content

Content you post belongs to your hash. PRUF does not claim ownership, license rights, or derivative rights over your content. We do not monetize or derive insights from user content.

Content moderation is performed by automated AI review before publishing, with human escalation for ambiguous cases and appeals. See Terms of Service for moderation details.

If your account is deleted, your content is removed. If your account is permanently suspended, your content access is revoked.

05Your Storage

5.1Local Storage

Verified photos are stored locally on your device in an encrypted vault. Local storage is free. PRUF does not access, sync, or back up local vault content.

5.2Published Content

When you publish a photo or letter to the PRUF network, your content is split into fragments and stored across PRUF's infrastructure. These fragments are identified solely by cryptographic hashes — not by your identity, your handle, or any personal information. The fragments and the instructions for reassembling them are stored in separate systems. A breach of any single system would not expose your content, because no single system contains both the pieces and the order in which they belong.

Published content is associated with your hash — not with you as a person. PRUF cannot determine who created a piece of content without external information, because PRUF does not know who any hash belongs to.

If your account is deleted, your published content is removed from PRUF's infrastructure. If your account is permanently suspended, your content remains but your access is revoked.

06Law Enforcement and Legal Compliance

6.1What We Can Provide

PRUF Systems Inc. is a Delaware corporation and complies with all valid legal process issued by courts and authorized government agencies, including subpoenas, court orders, and warrants.

Because PRUF does not know who its users are, legal process must identify an account by its username or hash. We have no way to look up a person, and we cannot confirm who holds any account.

For an identified account, we can disclose only what we hold: cryptographic hashes, public content posted by that account, verification tier and node assignment, timestamps of account activity, and — for a limited period around delivery — encrypted message and media content.

That message content is end-to-end encrypted and PRUF cannot read it. What we are able to produce is the ciphertext itself, which we have no ability to decrypt, together with the routing information that carries it: which accounts exchanged messages, and when.

6.2What We Cannot Provide

We cannot provide — because we do not possess:

Law enforcement may use the information we provide to identify individuals through independent investigative means. PRUF can confirm that a specific hash was associated with specific actions. PRUF cannot confirm who the hash is.

07Data Breach

If PRUF's systems are breached, the attacker obtains cryptographic hashes tied to other cryptographic hashes. There are no names to steal. There are no faces to leak. There are no biometrics to extract — in any form, encrypted or otherwise, because none exist. There are no emails to harvest. There are no passwords to crack. What we store is unreadable by design.

We will notify affected users through the PRUF network and public channels within 72 hours of discovering a breach, in compliance with applicable law.

08Your Rights

8.1Right to Deletion

You may request account deletion at any time through the app settings. Upon deletion, your content is removed and your identity token is retired. Anonymous transaction records may remain for system integrity. There is no biometric data to delete, because none was ever stored.

8.2Right to Data Export

You may request a complete export of all data associated with your hash.

09Changes to This Agreement

Updated terms will be published at pruf.net/privacy with a changelog. Because we have no email addresses, changes will be announced through the PRUF network and in-app notification. Continued use after updates constitutes acceptance.