Privacy Policy
Last updated: 2026-10-02.
What we never see
Your files do not reach our server. Hashing happens in your
browser via crypto.subtle. For a single file, what crosses the network is the 32-byte SHA-256 digest, an optional SHA-512 sibling digest (recorded on the receipt but never anchored) and a short label: one you attach, or a fixed tag naming the page you anchored from. A folder anchor also sends its manifest; see What we collect. A digest cannot be reversed into your file; nobody can do that.
The privacy claim is enforced by the structure of the protocol, not by our
promise to behave.
What we collect
- The fingerprints you submit — the SHA-256 digest, the optional SHA-512 sibling — plus a client label (max 200 chars): one you choose to attach, such as a filename, or a fixed tag naming the page you anchored from.
- Folder manifests, when you anchor a folder — each file's relative path, SHA-256 digest and byte size, and the folder's Merkle root. File contents are never sent. The paths are shown only to the receipt's owner unless you choose to make them public.
- Truncated IP prefixes for rate limiting (we keep the first three octets of IPv4 / 48 bits of IPv6 — enough to spot abuse, not enough to identify individuals). Full IPs are not retained.
- Email addresses for Pack purchases, supplied through Stripe Checkout. We use these only to deliver the claim code and the receipt, and to honor refund requests.
- Email addresses you type into a “keep me posted” form, where one is offered. Nothing on this site requires an address to anchor a file; these forms are optional and are the only place we ask for one outside a purchase. We store the address, the date, and which form it came from, so we know what you asked about. The first email we send there asks you to confirm: its link opens a page with one button, and until you press it the address is not added to our mailing list. We send that request at most once a day per address, and never to an address that has unsubscribed. We write to that address only about the thing it was given for, we do not sell or share it, and you can ask us to delete it at any time using the contact route below.
- The anchored receipt itself — receipt ID, hash, timestamp, OTS proof files.
- A notice address on a paid anchor, if you give one (a subscriber who gives none uses the sign-in address). We email the receipt there, and a notice when the receipt first reaches Bitcoin. The address is stored with the receipt until that notice is sent, then removed from a public receipt. A private receipt keeps it. It is never shown on a receipt's public page, JSON or downloads; while it is stored, the only place it appears is your own account's receipt export.
Who can read a receipt
Receipts come in exactly three postures; know which one you hold.
-
Public receipt (the default). Readable by anyone who
holds the receipt ID, via
/api/receipt/<id>and the receipt page. The ID is unguessable, but it is a bearer credential: whoever you give it to can read and share the receipt. Don't anchor secrets you wouldn't want a peer to verify. -
Private receipt (subscribers). Anchored with
private: true; readable only by the authenticated owner. If a private anchor cannot be honored as private, the request fails closed — the office will not quietly publish what you asked to keep private. -
Offline evidence. The downloaded receipt JSON and
.otsproof files live on your disk and verify with open-source tools, with or without us. Nothing about that copy touches our server again.
What we don't collect
- No analytics scripts, no third-party trackers, no cookies for tracking.
- No advertising IDs or fingerprinting.
- No file contents.
- No full IP addresses in logs or analytics.
Cookies and local storage
We keep a few things in your browser's localStorage, on your device only: your active Pack claim code (orpho_pack_token; the homepage spells it orph_pack_token), the receipts you anchored recently on this device (orpho_recent_receipts: receipt id, a short hash prefix and any label), the state of an anchor in progress so a reload can resume it (orpho_anchor_state, which can include the file's name), a referral code from a link you followed (orpho_ref_code), and, on the Writers page, its session notes (orpho_writer_sessions). The server cannot read any of it; the page sends your Pack code to the server only to show its remaining balance or to spend it on an anchor. Your browser's site-data controls clear all of it (on the homepage, “Switch to Free tier” also clears the Pack code it stored).
Third parties
Stripe processes Pack payments. They see your card details and your email; we never do. See stripe.com/privacy.
Resend delivers transactional emails (Pack claim codes, receipt copies). They see your email and the message contents. See resend.com/legal/privacy-policy.
OpenTimestamps calendar servers receive your 32-byte hash when we submit it. They batch many users' hashes into a single Bitcoin transaction; they do not receive your IP (we proxy the submission).
Fly.io hosts our server. Their infrastructure logs may capture connection metadata; we configure our application not to retain full IPs.
Retention
- Anchor records (hashes, timestamps, OTS proofs): retained indefinitely. They are the product.
- Free-tier receipts: retained on our servers, the same as paid receipts. Your local copy of the receipt JSON + .ots files also remains independently verifiable forever.
- Email addresses: retained for the life of the associated Pack credit balance, plus 7 years for tax/refund records.
- Notice addresses on receipts: on a public receipt, until its Bitcoin notice is sent; on a private receipt, for as long as the receipt is kept.
- Truncated IP prefixes in logs: 24 hours, then rotated.
Your rights
Email [email protected] to request a copy of the data associated with your email address, or to request deletion. We respond within 30 days. EU/UK/California residents: you have the rights granted by GDPR / UK-GDPR / CCPA respectively, and we will honor them.
Changes
We may update this policy; the "Last updated" date will change. Material changes will be emailed to Pack purchasers when feasible.
Contact
Anonymous solo founder. Reach the privacy queue at [email protected].