Privacy Agreement
PRUF does not know who you are. This is not a policy decision — it is an architectural constraint. The system cannot store your identity because the system was designed never to receive it.
Your face is never stored. It is never hashed. Nothing derived from your face is ever computed, kept, or transmitted — not an image, not a measurement, not even a fingerprint of one. Your face is used exactly twice, both times as a live gate on your own phone: your device's own Face ID confirms the phone belongs to the live person holding it (Apple's check, inside your phone's secure hardware — PRUF learns exactly one bit: yes or no), and PRUF's camera ceremony confirms you are a live, three-dimensional human (processed in the moment, destroyed in the moment).
Your account is a random token with no mathematical relationship to your body. Your recovery anchors are things only you hold: a recovery code on paper, a Mind Code in your memory, a hardware key in your phone. We store one-way hashes of them. None of them are biometric.
There is no database of users. There is a database of hashes. If we are breached, the attacker gets hashes. No names. No faces. No biometrics. No emails. Nothing.
01What We Do Not Have
PRUF does not collect, store, process, or retain Personally Identifiable Information. This is enforced by system architecture, not by internal policy.
Biometric Data. None. No face images, face-derived measurements, face-derived hashes, fingerprints, voiceprints, or iris scans are stored anywhere in our systems — or anywhere at all, including your own device. Raw biometric data — camera frames, depth maps, sensor readings — is processed entirely on your device, only in volatile memory, only for the duration of a live verification, and destroyed immediately. Nothing derived from it survives. PRUF's biometric retention period is zero, everywhere, for everyone, with no opt-ins and no exceptions.
Direct Identifiers. No full legal names, physical addresses, email addresses, telephone numbers, social security numbers, government ID numbers, or external financial account numbers.
Tracking Data. No browsing history, search history, third-party website interaction logs, advertising identifiers, cross-app tracking tokens, or behavioral profiles.
Advertising Data. PRUF does not serve advertisements. There is no advertising infrastructure. There is no data collection for advertising purposes. Zero Ads is a structural covenant, not a feature toggle.
AI Training Data. PRUF does not use, license, sublicense, sell, or process any user-generated content for artificial intelligence training, machine learning model development, or any derivative computational purpose. Your content belongs to your hash.
02Your Face Is a Gate, Not a Record
2.1The Owner Check (Your Phone's Own Lock)
Before PRUF verifies you as human, your phone verifies you as its owner: the device's own Face ID or Touch ID runs, evaluated by Apple entirely inside your phone's secure hardware. PRUF never receives, touches, or transmits any part of this — no scan, no measurement, no score. PRUF learns exactly one bit: the phone's live owner is present, yes or no. Verified · not stored.
2.2The Liveness Ceremony
PRUF's camera then confirms you are a live, three-dimensional human — not a photo, a screen, or a replay. You look at the camera, turn left, turn right. The frames and depth readings are processed on your device in the moment and destroyed in the moment. Nothing is derived from them: no hash, no measurements, no record of any kind. The only thing that survives the ceremony is the result — a human was present.
2.3Your Account Is a Random Token
When you enroll, your account identity is minted as a random cryptographic token. It is not computed from your face, your body, or anything about you. Two enrollments by the same person would produce completely unrelated tokens. There is nothing to reverse, because the token was never derived from you in the first place.
2.4Camera Verification of Content
PRUF's camera system uses your device's sensors to verify that the camera was looking at real three-dimensional space at the moment of capture. This certifies provenance — who captured an image, where, and when — not the authenticity of the subject in frame. No system can prove that, and we do not claim to. PRUF does not receive or store the sensor data used for this verification; only the binary result (verified or not verified) is recorded as metadata on the photo.
03Your Recovery Anchors (None of Them Are Your Body)
Access to your account rests on three anchors, and every one of them is something you hold — never something you are:
- Device Key — a hardware key sealed in your phone's secure chip. It never leaves the chip.
- Recovery Code — a code shown to you once, held on paper. We store only a one-way hash.
- Mind Hand — five playing cards you memorize, where order never matters. It lives in your memory (and, for your convenience, sealed on your phone behind your device's Face ID, viewable only by you). We store only a one-way hash. The hand itself is never transmitted to or stored by PRUF in any form.
Losing your phone does not lose your account: your recovery code — something no server holds — restores it, and adding another anchor makes it stronger. PRUF cannot use what it stores to impersonate or identify you: one-way hashes cannot be reversed, and there is no master key, administrative override, or backdoor. This is a mathematical constraint, not a policy decision.
04Your Content
Content you post belongs to your hash. PRUF does not claim ownership, license rights, or derivative rights over your content. We do not monetize or derive insights from user content.
Content moderation is performed by automated AI review before publishing, with human escalation for ambiguous cases and appeals. See Terms of Service for moderation details.
If your account is deleted, your content is removed. If your account is permanently suspended, your content access is revoked.
05Your Storage
5.1Local Storage
Verified photos are stored locally on your device in an encrypted vault. Local storage is free. PRUF does not access, sync, or back up local vault content.
5.2Published Content
When you publish a photo or letter to the PRUF network, your content is split into fragments and stored across PRUF's infrastructure. These fragments are identified solely by cryptographic hashes — not by your identity, your handle, or any personal information. The fragments and the instructions for reassembling them are stored in separate systems. A breach of any single system would not expose your content, because no single system contains both the pieces and the order in which they belong.
Published content is associated with your hash — not with you as a person. PRUF cannot determine who created a piece of content without external information, because PRUF does not know who any hash belongs to.
If your account is deleted, your published content is removed from PRUF's infrastructure. If your account is permanently suspended, your content remains but your access is revoked.
06Law Enforcement and Legal Compliance
6.1What We Can Provide
PRUF Systems Inc. is a Delaware corporation and complies with all valid legal process issued by courts and authorized government agencies, including subpoenas, court orders, and warrants.
Because PRUF does not know who its users are, legal process must identify an account by its username or hash. We have no way to look up a person, and we cannot confirm who holds any account.
For an identified account, we can disclose only what we hold: cryptographic hashes, public content posted by that account, verification tier and node assignment, timestamps of account activity, and — for a limited period around delivery — encrypted message and media content.
That message content is end-to-end encrypted and PRUF cannot read it. What we are able to produce is the ciphertext itself, which we have no ability to decrypt, together with the routing information that carries it: which accounts exchanged messages, and when.
6.2What We Cannot Provide
We cannot provide — because we do not possess:
- The real name of any user
- The face of any user
- The email, phone number, or physical address of any user
- Biometric data of any kind — raw, hashed, derived, or encrypted. No such data exists in our systems in any form, for any user, under any setting.
Law enforcement may use the information we provide to identify individuals through independent investigative means. PRUF can confirm that a specific hash was associated with specific actions. PRUF cannot confirm who the hash is.
07Data Breach
If PRUF's systems are breached, the attacker obtains cryptographic hashes tied to other cryptographic hashes. There are no names to steal. There are no faces to leak. There are no biometrics to extract — in any form, encrypted or otherwise, because none exist. There are no emails to harvest. There are no passwords to crack. What we store is unreadable by design.
We will notify affected users through the PRUF network and public channels within 72 hours of discovering a breach, in compliance with applicable law.
08Your Rights
8.1Right to Deletion
You may request account deletion at any time through the app settings. Upon deletion, your content is removed and your identity token is retired. Anonymous transaction records may remain for system integrity. There is no biometric data to delete, because none was ever stored.
8.2Right to Data Export
You may request a complete export of all data associated with your hash.
09Changes to This Agreement
Updated terms will be published at pruf.net/privacy with a changelog. Because we have no email addresses, changes will be announced through the PRUF network and in-app notification. Continued use after updates constitutes acceptance.
By verifying as human and entering the PRUF network, you acknowledge that your identity is a random cryptographic token, that your face was used only as a live gate on your own device, and that PRUF does not know who you are, cannot determine who you are, and has designed its systems to make identification impossible without external legal process.
You are not a user. You are a hash.
That is the privacy agreement.
These features exist in the architecture but are not active on Day 1. This agreement will be updated when they launch:
- Passport verification — NFC passport scan for enhanced account tier
- Guardian Protocol — supervised accounts for minors
- Cloud storage tiers — paid encrypted cloud sync (Basic / Pro / Vault)
| Version | Date | Changes |
|---|---|---|
| 1.0 | Dec 2, 2025 | Original privacy agreement |
| 2.0 | Feb 7, 2026 | Rewrite aligned with current architecture |
| 3.0.0 | Jun 3, 2026 | Stripped proprietary technical details. User-facing promises only. |
| 4.0.0 | Jun 3, 2026 | Day 1 release — removed Passport verification, Guardian Protocol, paid cloud tiers, jury moderation, Foundation reference. Added AI moderation language. Simplified deletion. |
| 4.1.0 | Jul 14, 2026 | Accuracy correction: disclosed the encrypted face-verification record then held for re-verification; "zero-knowledge, not zero-storage" standard. |
| 4.2.0 | Jul 16, 2026 | Device-only default (Build 965): the face-verification record stays on the phone by default; server holds at most one encrypted opt-in copy. |
| 5.0.0 | Jul 17, 2026 | Patent T architecture (Build 980): zero biometric storage, period. No face-derived data exists anywhere — no hash, no derived record, no encrypted copy, no opt-in path. Face is a live on-device gate (owner check + liveness ceremony); account identity is a random token; recovery anchors are recovery code + Mind Code + device key (all non-biometric one-way hashes). Removed the prior §2.3 custody language and the Account Recovery opt-in it described; rewrote the 30-second version, Sections 1–3, 6.2, 7, 8.1, and the Acknowledgment. Effective on the Patent T reset: accounts enrolled under earlier builds retain the prior architecture's data only until the pre-launch reset purges it. Pending privacy-counsel review. |
| 6.0.0 | Jul 25, 2026 | Beta accuracy pass. Corrected three claims that were false against the shipped build: "no anchor works alone" (the recovery code alone restores an account, by design), "encrypted at rest" for posted media (posted content is stored unencrypted and gated by the audience you choose), and the depth-verification claim (it certifies provenance, not that a subject is not a reproduction). Mind Code updated to the Mind Hand (five cards). Added: on-device vault encryption, end-to-end messaging, third-party sync, and encrypted message content to the law-enforcement disclosure list. Service restricted to 18+. |