Privacy Policy

Last updated: 2026-10-02.

What we never see

Your files do not reach our server. Hashing happens in your browser via crypto.subtle. For a single file, what crosses the network is the 32-byte SHA-256 digest, an optional SHA-512 sibling digest (recorded on the receipt but never anchored) and a short label: one you attach, or a fixed tag naming the page you anchored from. A folder anchor also sends its manifest; see What we collect. A digest cannot be reversed into your file; nobody can do that. The privacy claim is enforced by the structure of the protocol, not by our promise to behave.

What we collect

Who can read a receipt

Receipts come in exactly three postures; know which one you hold.

What we don't collect

Cookies and local storage

We keep a few things in your browser's localStorage, on your device only: your active Pack claim code (orpho_pack_token; the homepage spells it orph_pack_token), the receipts you anchored recently on this device (orpho_recent_receipts: receipt id, a short hash prefix and any label), the state of an anchor in progress so a reload can resume it (orpho_anchor_state, which can include the file's name), a referral code from a link you followed (orpho_ref_code), and, on the Writers page, its session notes (orpho_writer_sessions). The server cannot read any of it; the page sends your Pack code to the server only to show its remaining balance or to spend it on an anchor. Your browser's site-data controls clear all of it (on the homepage, “Switch to Free tier” also clears the Pack code it stored).

Third parties

Stripe processes Pack payments. They see your card details and your email; we never do. See stripe.com/privacy.

Resend delivers transactional emails (Pack claim codes, receipt copies). They see your email and the message contents. See resend.com/legal/privacy-policy.

OpenTimestamps calendar servers receive your 32-byte hash when we submit it. They batch many users' hashes into a single Bitcoin transaction; they do not receive your IP (we proxy the submission).

Fly.io hosts our server. Their infrastructure logs may capture connection metadata; we configure our application not to retain full IPs.

Retention

Your rights

Email [email protected] to request a copy of the data associated with your email address, or to request deletion. We respond within 30 days. EU/UK/California residents: you have the rights granted by GDPR / UK-GDPR / CCPA respectively, and we will honor them.

Changes

We may update this policy; the "Last updated" date will change. Material changes will be emailed to Pack purchasers when feasible.

Contact

Anonymous solo founder. Reach the privacy queue at [email protected].