● Legal & Privacy

Your questions, answered plainly.

Everything you need to know about how ProofDrop handles your data, your rights, and what you're agreeing to — without the legalese.

🔒

Data & Privacy

We collect your name, email address, publication domain, and a bcrypt-hashed password — we never store your password in plain text. We also generate an API key tied to your account.

We don't collect billing details, phone numbers, or any information beyond what's needed to run the service.

No. ProofDrop never stores your article content. Our watcher fetches the #proofdrop-content section of your article page, computes a SHA-256 hash of the normalised text, and immediately discards the raw content.

Only the hash, a character count, and your article URL are stored in our database.

Each XRPL transaction contains a memo with: the event type (e.g. initial_verification, correction_declared), your article URL, the content hash, and a link to the previous related transaction if one exists.

The XRP Ledger is a public blockchain — anyone with the transaction hash can look up this memo.

🔒 No personal information (name, email, account details) is ever included in an XRPL transaction.

No. Once a transaction is confirmed on the XRP Ledger it is permanent and immutable — ProofDrop has no ability to modify or remove it.

This is by design: the value of the proof comes from the fact that no party, including us, can tamper with the timestamp or hash after the fact.

No. The proofdrop.js seal widget is a read-only display widget that runs in your reader's browser. It calls our public verification endpoint to retrieve the article's status, then renders the seal badge.

It does not set cookies, fingerprint visitors, collect IP addresses, or write anything to our database. It has no analytics or tracking functionality whatsoever.

When an account is deleted, all associated data — articles, declarations, strikes, payment requests, and admin notes — is permanently removed from our database.

XRPL records created during your subscription cannot be deleted (see FAQ 4) as they exist on a public blockchain. If you want a copy of your data before deletion, contact us and we'll provide an export.

Your article verification status and audit trail are publicly visible via the audit page — this is the point of the service.

Your correction notes, payment request details, account settings, and API key are private and only accessible to you when authenticated, or to ProofDrop admins for support purposes.

Passwords are hashed using bcrypt before storage and are never logged or transmitted in plain text. Authentication uses short-lived JWT access tokens (48-hour expiry) paired with rotating refresh tokens (30-day expiry).

We also generate a 12-word BIP39 recovery phrase at signup, stored as a bcrypt hash, which you can use to regain access if you lose your password.

Payment requests store the requested XRP amount, an optional merchant reference, status, and the XRPL transaction hash once payment is confirmed. We do not act as a payment processor or hold funds — payments go directly between XRP wallets on the ledger.

Admins can manually override a payment status if the XRPL monitor missed a valid transaction, and the overriding transaction hash is permanently recorded for auditability.

No. We use Resend to send transactional emails (verification, password reset, grace period alerts) — your email address is passed to Resend solely for delivery purposes.

No personal data is sold, shared with advertisers, or disclosed to any third party except as required by law. XRPL transactions are broadcast to the public XRP Ledger network by nature, but contain no personal data (see FAQ 3).

🇪🇺

GDPR & Data Rights

ProofDrop processes your personal data under three lawful bases under GDPR Article 6:

  • Contract performance — processing your name, email, domain, and account data is necessary to deliver the service you signed up for.
  • Legitimate interests — monitoring the articles you register and generating XRPL proofs is the core purpose of the service you explicitly submitted those articles for.
  • Legal obligation — we may retain certain records if required to do so by applicable law.

We do not rely on consent as a basis for processing account or service data. You are free to withdraw from the service at any time by deleting your account.

Under GDPR (and equivalent laws in the UK, EEA, and many other jurisdictions) you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate data (e.g. your name or email)
  • Erasure — request deletion of your account and all associated personal data
  • Restriction — ask us to pause processing while a dispute is resolved
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where consent was the basis, withdraw it at any time

To exercise any of these rights, contact us at privacy@proofdrop.co. We will respond within 30 days.

This is a known tension between GDPR and public blockchains. XRPL transactions recorded by ProofDrop contain no personal data — they hold only the article URL, a content hash, an event type, and a timestamp (see FAQ 3).

This means deleting your account fully satisfies the right to erasure: all personal data held by ProofDrop in our database is removed, and nothing on the blockchain can be linked back to you as an individual.

ⓘ This approach aligns with guidance from EU data protection authorities on pseudonymous blockchain data.

We retain your account data for as long as your account is active. If you delete your account, personal data is erased immediately.

We do not retain data for inactive accounts beyond a 90-day grace period after the last login, after which accounts are flagged for deletion and you are notified by email. We do not keep backups that persist personal data beyond 30 days after deletion.

ProofDrop is based in the United States and Canada. Your account data is stored on servers in the US. Transactional emails are processed via Resend, whose infrastructure may also involve US-based servers.

If you are accessing ProofDrop from the EU or EEA, your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) as the legal mechanism for those transfers where required under GDPR.

The XRP Ledger is a decentralised global network — broadcasting a transaction to it does not constitute a data transfer as no personal data is included in the transaction payload.

The ProofDrop dashboard stores a JWT access token in localStorage for authentication. This is not a cookie and is not shared with any third party.

Our public-facing pages (including this one) use Google Analytics 4 to collect anonymous usage data such as pages visited, time on page, general geographic region, and device type. This data is aggregated and used solely to understand how visitors use the site so we can improve it. We do not use it to identify individuals or serve advertising.

Google Analytics sets cookies (e.g. _ga, _ga_XXXXXXX) in your browser to distinguish unique visitors across sessions. These cookies are set by Google and governed by Google's Privacy Policy.

The proofdrop.js seal widget embedded on publisher sites does not set any cookies or local storage entries on your readers' browsers, and has no analytics functionality.

🔒 To opt out of Google Analytics across all sites, install the Google Analytics Opt-out Browser Add-on. You can also block analytics cookies via your browser's privacy settings or an ad blocker.

Our watcher system automatically detects content changes and may issue a strike or change your article's status without manual review. This is a core function of the service, not profiling.

You are always notified by email when an automated decision affects your account, and you have the right to request human review of any automated status change by contacting support. No decisions about creditworthiness, eligibility, or legal rights are made automatically.

If we discover a breach likely to affect your personal data, we will notify affected users without undue delay. Specifically:

  • EU/EEA users: We will notify the relevant supervisory authority within 72 hours as required by GDPR.
  • US users: We comply with applicable state breach notification laws — most require notification within 30–72 hours depending on the state.
  • Canadian users: We comply with PIPEDA's breach of security safeguards requirements, which require notification when there is a real risk of significant harm.

We maintain an internal breach log and conduct a post-incident review after any security event.

Yes. We do not sell personal information to third parties — this means CCPA's opt-out right is not triggered. California residents have the right to:

  • Know what personal data we collect (see FAQ 1 and FAQ 11)
  • Request deletion (handled via account deletion)
  • Not be discriminated against for exercising these rights

To make a CCPA request, contact privacy@proofdrop.co.

📋

Acceptable Use & Terms

You may not use ProofDrop to:

  • Submit URLs that host illegal, defamatory, or fraudulent content
  • Attempt to manipulate the system to create false proof of integrity for content you know to be inaccurate
  • Scrape, reverse-engineer, or systematically extract data from the API beyond your own account's data
  • Share your API key or account credentials with parties outside your organisation
  • Submit articles belonging to a domain you do not own or have authority over
  • Use the service in a way that places unreasonable load on our infrastructure

Violation of these terms may result in immediate suspension without refund.

ProofDrop is provided on a best-efforts basis. We do not guarantee 100% uptime or that every article change will be detected within any specific timeframe. Watcher checks are subject to an adaptive polling schedule based on article age.

We are not liable for indirect or consequential losses arising from a missed detection, a delayed XRPL transaction, or service unavailability. Our total liability in any 12-month period is limited to the fees you paid during that period.

Nothing in these terms excludes liability for fraud, death, or personal injury caused by our negligence.

You retain full ownership of your articles and their content. By submitting a URL you grant ProofDrop a limited, non-exclusive right to fetch that URL for the sole purpose of computing and monitoring content hashes.

We do not claim any ownership over your content, your correction notes, or the XRPL proof records generated from your submissions. You own those records — we simply facilitate their creation.

These terms are governed by the laws of the State of Delaware, United States, and applicable federal US law, without regard to conflict of law principles.

For users based in Canada, Canadian federal law (including PIPEDA) applies to privacy matters alongside these terms.

Any dispute that cannot be resolved informally within 30 days of written notice will be submitted to binding arbitration under the rules of the American Arbitration Association (AAA), conducted in English. EU and EEA consumers may also have access to local alternative dispute resolution mechanisms under their national law, which these terms do not override.

Yes. We reserve the right to update these terms, pricing, or features at any time. For material changes — including price increases or feature removals that affect your current plan — we will give you at least 30 days' notice by email before the change takes effect.

Continued use of the service after that date constitutes acceptance of the updated terms. If you do not accept the changes, you may delete your account before the effective date.

For data subject requests, GDPR/PIPEDA queries, or legal notices:

  • Email: hello@proofdrop.co
  • Response time: within 5 business days for general queries; within 30 days for formal data subject requests as required by GDPR, CCPA, and PIPEDA.

ProofDrop does not currently have a designated Data Protection Officer. EU/EEA users who are unsatisfied with our response have the right to lodge a complaint with their local supervisory authority. Canadian users may contact the Office of the Privacy Commissioner of Canada. California residents may contact the California Privacy Protection Agency.

Last updated: June 2026  ·  ProofDrop Inc.