Privacy Policy

Last updated: 2026-05-12.

What we never see

Your files do not reach our server. Hashing happens in your browser via crypto.subtle. What crosses the network is the 32-byte SHA-256 digest and — when the anchoring page computes it — an optional SHA-512 sibling digest, recorded on the receipt but never anchored. A digest cannot be reversed into your file; nobody can do that. The privacy claim is enforced by the structure of the protocol, not by our promise to behave.

What we collect

Who can read a receipt

Receipts come in exactly three postures; know which one you hold.

What we don't collect

Cookies and local storage

We use one localStorage entry, orpho_pack_token, to remember your active Pack claim code across page loads. It's local to your browser; we never read it from the server. Clear it any time via the "remove" button on the Pack banner or your browser's site-data controls.

Third parties

Stripe processes Pack payments. They see your card details and your email; we never do. See stripe.com/privacy.

Resend delivers transactional emails (Pack claim codes, receipt copies). They see your email and the message contents. See resend.com/legal/privacy-policy.

OpenTimestamps calendar servers receive your 32-byte hash when we submit it. They batch many users' hashes into a single Bitcoin transaction; they do not receive your IP (we proxy the submission).

Fly.io hosts our server. Their infrastructure logs may capture connection metadata; we configure our application not to retain full IPs.

Retention

Your rights

Email [email protected] to request a copy of the data associated with your email address, or to request deletion. We respond within 30 days. EU/UK/California residents: you have the rights granted by GDPR / UK-GDPR / CCPA respectively, and we will honor them.

Changes

We may update this policy; the "Last updated" date will change. Material changes will be emailed to Pack purchasers when feasible.

Contact

Anonymous solo founder. Reach the privacy queue at [email protected].