Legal
Last updated: 21 March 2026
Prooflayer ("we", "us", "our") operates the platform at proof-layer.net. We are the data controller for personal data processed through our platform. Contact us at [email protected] for any privacy-related enquiries.
We collect the following categories of personal data:
Account data
Name, email address, password (hashed)
Account creation and authentication
Profile data
Creator type, disciplines, stated intentions
Personalisation and discovery matching
Proof metadata
Proof titles, descriptions, categories, tags, timestamps
Providing the proof registration service
File data
Uploaded files stored encrypted at rest (AES-256)
Storing registered proof content
Cryptographic data
SHA-256 hashes, RFC 3161 tokens, blockchain transaction hashes
Generating and verifying proof certificates
Payment data
Transaction references, subscription status (card details processed by Stripe — we do not store card data)
Billing and subscription management
Usage data
Pages visited, features used, timestamps
Platform improvement and security
When you register a proof, your file or content is hashed in your browser using the Web Crypto API before anything is sent to our servers. This means the cryptographic fingerprint (SHA-256 hash) is computed client-side.
If you choose to store your file on our platform, it is uploaded encrypted and stored in AWS S3 (eu-west-2, London) with AES-256 encryption. You can choose not to store the file — in which case only the hash and metadata are stored.
Public proofs may be visible to other users. Private proofs are accessible only to you.
Where blockchain anchoring is used, we write a SHA-256 hash to the Polygon blockchain. We do not write any personal data to the blockchain — only the cryptographic hash of your content. Blockchain data is public and permanent by its nature and cannot be deleted.
We share data with the following third parties:
We do not sell personal data to third parties.
If you are in the UK or EU, you have the following rights:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
We will honour erasure requests for account data, profile data, and stored files. However, proof metadata and cryptographic hashes cannot be deleted where doing so would undermine the integrity of a timestamped record. This is because the entire purpose of the platform is to create a permanent, verifiable record.
Blockchain-anchored data is irreversible by the nature of blockchain technology and cannot be erased from the chain.
We use essential cookies only — those required for authentication and session management. We do not use advertising or tracking cookies. We do not use Google Analytics or any third-party analytics that track you across sites.
We take data security seriously. We use encryption in transit (TLS) and at rest (AES-256 for stored files). Our infrastructure is hosted within the EU/UK. We conduct regular security reviews.
If you discover a security vulnerability, please contact us responsibly at [email protected] before public disclosure.
For all privacy enquiries: [email protected]