Privacy Policy - Verify Promise
Last updated: [publication date]
This notice explains what information Verify Promise ("we," "the platform") collects, what we use it for, and what rights you have over it. It is drafted to comply with the main data protection laws applicable to a global audience, including Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), the European Union's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA).
1. Guiding principle
Verify Promise was designed from the start to request as little data as possible. It requires no account, no registration, and no personal data to use the core service (creating and verifying a commitment). This notice covers the few exceptions where data is collected, and why.
2. What information we collect
2.1 Your commitment's content
When you create a commitment, we store the short title, the secret content you write, and an optional security code. This content is cryptographically sealed (SHA-256 hash) and remains hidden until you choose to reveal it. Important warning: if you yourself include personal information within the content of your promise (for example, a name or an ID number), that information will become public once you reveal the commitment - it is your responsibility not to include sensitive data about yourself or third parties within the content you seal.
2.2 Private key
We generate a unique private key for each commitment. It is stored hashed (bcrypt), never in plain text - not even we can view or recover it. It is your responsibility to keep it safe; losing it means that commitment can never be revealed.
2.3 Email address (optional)
When creating a commitment, you may voluntarily provide an email address for two clearly separated possible purposes:
- Email backup (default): if provided, we send your public ID and private key to that email at the moment you create the commitment, as a personal backup. It's a one-time send at creation - we can't resend them later if you lose them, because the key is stored hashed (see section 2.2) and there's no way to read or recover it, not even with this email. We do not create any account with this data.
- Product communications (only with your explicit consent): only if you check the corresponding box at the time you provide it, we may use your email to send you product news or promotions. If you do not check that box, your email is never used for this purpose.
2.4 IP address
We use your IP address temporarily to limit request frequency (rate limiting) and prevent system abuse (for example, automated attempts to guess a private key). We do not permanently associate your IP with any commitment nor use it for profiling or advertising purposes.
2.5 Functional cookies
We use small, specific cookies to avoid counting the same visit to a certificate's public page multiple times (for example, if you reload the page repeatedly). These cookies:
- Do not track your activity outside Verify Promise.
- Are not used for advertising or profiling purposes.
- Are not shared with third parties.
We do not currently use advertising or third-party social media tracking cookies. If that changes in the future, we will update this notice and, where required by law (for example, under EU regulations), request your explicit consent before activating them.
2.6 General technical data
Like any website, our hosting provider (Vercel) and associated services may log standard technical data (browser type, operating system, pages visited) for service operation and security purposes.
3. What we DON'T do
- We do not sell your personal information to anyone, under any circumstances.
- We do not share your email address with third parties for marketing purposes unrelated to Verify Promise.
- We do not use your sealed content for purposes other than providing the commit-reveal service.
- We do not track your activity on other websites.
4. Legal basis for data processing (applicable under GDPR)
If you are located in the European Economic Area, we process your data under the following legal bases:
- Contract/service performance: to provide the core sealing and revelation function.
- Explicit consent: for using your email for marketing purposes (separate checkbox).
- Legitimate interest: for abuse prevention (IP rate limiting) and basic technical operation of the service.
5. Your rights
Depending on your location, you may have the following rights over your personal data:
- Access: request what data we hold about you.
- Rectification: correct inaccurate data (for example, a misspelled email address).
- Erasure: request that we delete your email address and any associated personal data.
- Objection: object to the use of your email for marketing purposes (you can do this at any time, without justification).
- Portability: request a copy of your data in a structured format.
Important limitation, and why it exists: the sealed commitment itself (the hash, the public ID, the sealing date, and the content once revealed) is a public record intentionally designed to be permanent and unalterable - that is literally the product's central purpose. For this reason, we do not delete or modify commitments that have already been sealed or revealed, even upon a deletion request, since doing so would destroy the integrity guarantee the service exists to provide. This limitation does not apply to peripheral personal data (such as the email you gave for the email backup), which can be deleted without affecting the integrity of any commitment.
To exercise any of these rights (where applicable), contact us at privacy@verifypromise.com.
If you are located in Mexico, these rights are known as ARCO rights (Access, Rectification, Cancellation, Opposition) under the LFPDPPP. If you are located in California, you have additional rights under the CCPA/CPRA, including the right to know what information is collected and the right to have your information not sold (we clarify: we never sell personal information).
6. International data transfers
Our infrastructure (hosting, database, email delivery) may be located in different countries. If you are in the European Economic Area and your data is transferred outside that region, we ensure our providers comply with adequate transfer mechanisms (such as the European Commission's Standard Contractual Clauses) where applicable.
7. Data retention
- Optional email address: retained while the associated commitment exists, or until you request its deletion.
- Commitment content: retained indefinitely as part of the public verification record, given the service's central purpose.
- IP data (rate limiting): retained for a short, limited period, solely for abuse prevention purposes.
8. Children
Verify Promise is not directed at individuals under 18 years of age. We do not knowingly collect information from minors. If you become aware that a minor has provided us with personal information, contact us so we can delete it.
9. Changes to this notice
We may update this notice as the service evolves. Any material change will be published on this same page with a visible update date.
10. Contact
For any questions about this notice or to exercise your privacy rights:
privacy@verifypromise.com
11. Language
The official versions of this notice are Spanish and English, both maintained and updated by Verify Promise. In case of discrepancy between them, the English version prevails, unless applicable law in your jurisdiction requires otherwise.
If you access this notice through your browser's automatic translation (for example, into French, Portuguese, German, or another language), note that such translation is offered solely as a courtesy, has no legal validity, and was not reviewed by Verify Promise - only the Spanish and English versions are binding.