Privacy Policy

Effective date: June 7, 2026 Last updated: September 24, 2026

This Privacy Policy explains how Platform Technology Ventures LLC ("CertifiedPhotos," "we," "us," or "our") collects, uses, and shares information when you use the CertifiedPhotos mobile application (the "App") and related services (collectively, the "Services").

We are the data controller for personal information collected through the Services. If you have questions about this policy or how we handle your information, contact us at [email protected] or by mail at Platform Technology Ventures LLC, One Broadway, 14th Floor, Cambridge, MA 02142, USA.


1. Summary

CertifiedPhotos lets you capture photographs and create a tamper- evident record of when and how each photograph was made. To do this, the App needs access to your camera, your device's location (if you allow it), and a small set of account information used to identify you and secure your data.

We do not sell your personal information. We do not use your information for advertising. We do not share your photographs with third parties for their own purposes. We use a small number of carefully chosen service providers to operate the Services, listed in §4 below.

Service availability. The Services are currently offered only to users located in the United States. We do not offer the Services to users located in the European Economic Area, the United Kingdom, Switzerland, or other regions outside the United States. We may expand service availability in future versions of the App; when we do, we will update this policy and provide any additional disclosures required by the laws of the new region.

Tier-specific data flows. Some data-processing flows described in this policy apply only to specific tiers of the Services. In particular, the public ledger entries described in §2.2 apply only to the Enterprise tier of the Services; Free and Pro tier certifications do not involve any ledger entries. See the Terms of Service for the full description of each tier.


2. Information we collect

2.1 Information you provide directly

Account information. When you create an account, we collect your email address and, depending on the verification method you choose, your phone number. We use a third-party authentication provider (Privy, see §4) to verify your contact information and to generate a unique account identifier associated with you. You may also choose to provide a display name, which appears as the creator attribution on photographs you certify.

Payment information. If you purchase a paid plan or premium features, payment is handled by a third-party payment processor. The processor collects your payment method details directly; we receive a payment token, your billing email, and a record of your purchase. We do not see, store, or have access to your full card number.

Customer support communications. If you contact our support team, we collect the contents of your messages and any information you choose to provide.

2.2 Information collected through your use of the App

Photographs and embedded metadata. When you capture a photograph through the App, we receive and store the photograph itself along with its embedded metadata. This metadata includes information your device records as part of the image file, such as the time of capture, camera model and settings, and — if you have granted the App location permission — the precise GPS coordinates of where the photograph was taken. Location data in photographs is used to support the authentication and provenance features of the Services. You can disable location permission at any time in your device settings; if disabled, photographs will not include location data.

Certification records. For each certified photograph, the Services generate and store an immutable verification record consisting of cryptographic fingerprints, a timestamp, and an account identifier necessary to support provenance and integrity verification.

Invisible watermark and verification registry (Pro tier). For Pro-tier certifications, we embed an invisible watermark in the pixel data of the photograph and maintain an internal registry that lets us identify a previously certified Pro-tier photograph when a copy is submitted to our verification surface. The registry is keyed by the cryptographic identifier embedded in the watermark; it associates that identifier with the certification record. When the user-facing verification surface ships, it will return only the fact that a photograph was certified, the timestamp of certification, and (if you have shared the photograph with location enabled) the precision-controlled location data described in our Terms of Service. The verification surface does not return the certifier's display name, email address, account identifier, or any other information that directly identifies the user who certified the photograph. Identity- attached verification, if offered in the future, would be a separate opt-in feature.

Public ledger entries (Enterprise tier only). For users on the Enterprise tier of the Services, a cryptographic fingerprint of the photograph is also anchored to a public, append-only ledger utilized by the Services. The recorded entry does not contain the photograph itself, your name, your email address, your account identifier, or any other information that directly identifies you. A cryptographic fingerprint is a one-way mathematical value from which the original photograph cannot be reconstructed.

If you are an Enterprise-tier user, you should understand the following about ledger entries:

publicly visible.** A party who already possesses the photograph can confirm that it was certified through the Services by computing its fingerprint and locating the corresponding ledger entry. A party who does *not* possess the photograph cannot determine its content from the ledger entry alone.

account, we remove from our systems the link between you and your ledger entries. The entries themselves remain on the ledger but become disassociated from your identity in our records.

Free and Pro tier certifications do not involve public ledger entries.

Device and app integrity information. To protect the Services from fraud, tampering, and abuse, the App uses Apple's App Attest service (on iOS) and Google's Play Integrity API (on Android). These services allow our servers to verify that requests are coming from a genuine, unmodified installation of the App on a genuine, unmodified device. This produces an attestation token that includes information about your device and app installation. We use this information only for security, fraud prevention, and ensuring the integrity of certification records.

Diagnostic information and App Set ID. If the App crashes or encounters an error, we collect a diagnostic report through Firebase Crashlytics (a service provided by Google). This report typically includes: the type of error, the part of the App where the error occurred, your device model, your operating system version, your App version, and a Crashlytics installation identifier. On Android, this identifier is generated using Google's App Set ID, which is scoped to our App and the other apps we publish (if any). We use App Set ID and the associated diagnostic data solely for analytics and to identify and fix bugs. The App Set ID is not used for advertising personalization or ads measurement, and is not linked to your Android Advertising ID or any other persistent device identifier. The diagnostic report may also include your account identifier if you are signed in.

Verification lookup requests. When someone — you or a third party — submits an image to our public verification surface, we process the image to attempt to recover a CertifiedPhotos watermark and return a verification result. For each lookup, we log a hashed identifier of the submitted image, the result, the caller's tier (anonymous, authenticated Free, or authenticated Pro), and a hashed identifier of the caller's IP address. We use this log data only for abuse detection, rate limiting, and operational monitoring. The image submitted for verification is not retained beyond the time required to compute the result.

Usage information. We collect basic information about how the App is used — for example, which features are accessed and how often the App is opened. We use this information to understand how the App is performing and to prioritize improvements.

2.3 Information we do not collect

We do not collect:

differ — see the App's iOS permissions if applicable)

SIM serial number, MAC address, or Android Advertising ID

to use your device's biometric sensor — for example, your fingerprint or face — to unlock locally stored credentials. This biometric data is processed entirely on your device by your device's operating system, and never transmitted to us.)


3. How we use information

We use the information described in §2 for the following purposes:

processing certifications, storing your photographs, and making certification records available to you and to parties you choose to share them with.

detecting fraud and abuse, and protecting the cryptographic integrity of certification records.

check it against lists of known child sexual abuse material maintained by child-protection organizations. This check runs on every photograph submitted for certification. When a photograph matches, we decline to certify it, preserve it and the related account information, and report it to the National Center for Missing & Exploited Children (NCMEC) as federal law requires.

resolving issues you report.

used, diagnosing bugs, and prioritizing new features.

(account notifications, receipts, security alerts) and, if you have opted in, product update emails. You can unsubscribe from product update emails at any time.

contractual obligations.

We do not use your information for behavioral advertising, ad targeting, or sharing with advertising networks.


4. How we share information

We share information only as described below.

4.1 Categories of recipients and named partners

We use the categories of service providers and the named partners described below. Except where noted, each processes information only on our instructions and under contractual obligations to protect that information. We require our providers to comply with applicable privacy and data protection laws and with the policies of the platforms on which the App is distributed, including the Google Play Developer Program Policies and the Apple Developer Program License Agreement.

Categories of service providers

transactional data.

host and protect encrypted user content and deliver it to authorized users.

performance, track bug reports, and improve App stability.

We will provide the names of the specific providers in these categories upon written request to [email protected].

Named partner

provisioning. Verifies your email or phone number, manages your account identifier, and provisions and secures the cryptographic credentials associated with your account. Privy operates as an independent data controller with respect to certain categories of personal information it collects through the authentication flow, including your email address, phone number, and device/IP data, which it processes for its own purposes of fraud prevention, security, and service operation. Privy's privacy policy governs that processing: https://www.privy.io/privacy-policy

Named partners for child-safety screening

Shield)** — Winnipeg, Canada. Receives a copy of each photograph submitted for certification with location data and descriptive metadata removed, and checks it against known child sexual abuse material. We use the screening result solely to decide whether to certify the photograph. By submitting photographs, you acknowledge that metadata-stripped image data is transferred to Canada for this screening process.

4.2 Public ledger (Enterprise tier only)

For users on the Enterprise tier of the Services, as described in §2.2, cryptographic fingerprints of certified photographs are anchored to a public, append-only ledger utilized by the Services. This anchoring is intentional and central to the authentication functions of the Enterprise tier. Ledger entries do not identify you and cannot be used to reconstruct the underlying photograph, but they are publicly visible and, once recorded, cannot be removed.

Free and Pro tier certifications do not involve public ledger entries.

4.3 Verification lookup responses

When a third party submits an image to our public verification surface and we return a positive verification result, the response describes the fact of certification and associated non-identifying metadata (timestamp, location at the precision described in the Terms of Service, exact-original-vs-copy status). The response does not include the certifier's display name, email address, account identifier, or any other information that directly identifies the user who certified the photograph.

4.4 At your direction

If you choose to share a certification with another party — for example, a publisher, an insurer, or another user — we provide that party with the information you direct us to share. We do not share certifications with third parties on our own initiative.

4.5 Legal disclosures

We may disclose information when we believe in good faith that disclosure is required by law, legal process, or governmental request; necessary to enforce our terms; or necessary to protect the rights, property, or safety of CertifiedPhotos, our users, or the public. Where permitted, we will notify you of any legal request for your information before responding.

4.6 Business transfers

If Platform Technology Ventures LLC is involved in a merger, acquisition, sale of assets, or bankruptcy, information may be transferred as part of that transaction. We will notify you and, where required, obtain your consent.

4.7 No sale of personal information

We do not sell personal or sensitive user information as that term is defined under the California Consumer Privacy Act, the Google Play Developer Program Policies (which define "sale" as the exchange or transfer of personal and sensitive user data to a third party for monetary consideration), or any comparable law or platform policy. We have not done so in the preceding twelve months.


5. Data retention

We retain personal information for as long as your account is active and for a reasonable period afterward to satisfy our legal, accounting, and operational obligations. Specifically:

active and for up to 12 months after account closure.

retained for as long as your account is active, and accessible to you for export before account closure.

cryptographic identifier embedded in the watermark of your Pro-tier photographs is retained for as long as your account is active. When you delete your account, the registry entry is dissociated from your identity in our systems but the identifier itself remains in the registry, so a third party who possesses the photograph can still confirm it was certified through the Services without learning who certified it. We do not consider this to be personal information about you once dissociated, because it no longer identifies you.

Enterprise-tier certifications, ledger records cannot be deleted from the ledger after they are recorded. Deletion of your account does not remove the ledger records, which do not directly identify you. Free and Pro tier certifications do not involve ledger records.

purposes, as required by law.

for abuse detection and operational monitoring.

after the matter is resolved.

preserved alongside related account details for one year from the match in a separate, access-restricted store, and provided to NCMEC and law enforcement as required by 18 U.S.C. § 2258A. These photographs remain uncertified and unpublished.


6. Your rights and choices

6.1 All users

information we hold about you.

information.

and the personal information associated with it. You may initiate account deletion in two ways: 1. In-app — open the App, go to Settings → Account → Delete Account, and follow the prompts. 2. On the web — visit https://certified.photos/delete-account and submit the deletion form. You do not need to be signed in to the App to use the web form.

Once we receive your deletion request and confirm your identity, we will delete the personal information we hold about you within 45 days, subject to the limited retention exceptions described in §5 (for example, payment records we are required to retain by law). For Enterprise-tier users, public ledger records cannot be removed; the link between your identity and those records will be severed in our systems as part of the deletion process. For Pro-tier users, watermark registry entries are dissociated from your identity but remain in the registry as described in §5; this means third parties may still confirm the certification status of Pro photographs you previously shared, but they cannot identify you as the certifier.

and notification permissions at any time in your device settings.

update emails using the unsubscribe link in those emails. Transactional emails (account, security, payment) cannot be opted out of while you maintain an active account.

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law (typically 45 days under CCPA).

6.2 Additional rights for California users

If you are a California resident, you have additional rights under the CCPA, including the right to know the specific categories and sources of personal information we have collected; the right to delete personal information (subject to the public ledger exception for Enterprise-tier users and the watermark registry retention described in §5); the right to correct inaccurate information; the right to opt out of any sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising); and the right to non-discrimination for exercising these rights.

You can designate an authorized agent to make a request on your behalf.


7. Children's privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us at [email protected] and we will delete it.


8. Security

We use technical and organizational measures designed to protect your personal information, including:

account information;

Integrity) on every request to our servers;

principle of least privilege;

No system is perfectly secure, however, and we cannot guarantee the absolute security of your information. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities in accordance with applicable law.


9. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify you through the App, by email, or by other appropriate means before the changes take effect. The "Last updated" date at the top of this policy reflects the most recent revision.


10. Contact us

For privacy questions, requests, or complaints:

Floor, Cambridge, MA 02142, USA