Prooflens Privacy Policy

Last updated: 2026-02-01 · Effective: 2026-02-01

Prooflens is a forensic-grade camera that cryptographically timestamps your photos. It is privacy-first by design: images are captured, watermarked, and hashed entirely on your device, and the photo itself never leaves your phone.

1. What Leaves Your Device — and What Doesn't

  • Your photos never leave your device. Capture, watermarking, EXIF embedding, and SHA-256 hashing all happen locally.
  • To create a tamper-evident timestamp, Prooflens transmits only the SHA-256 hash of a photo — a one-way 64-character fingerprint from which the original image cannot be reconstructed.
  • The hash is sent to an RFC 3161 Time-Stamp Authority (e.g. freetsa.org) to obtain a signed timestamp token, and optionally anchored to the Bitcoin blockchain via OpenTimestamps. Both receive only the hash, never image content.

2. Permissions

  • Camera — required to capture evidence photos.
  • Location (optional) — used only to embed GPS coordinates into the watermark and EXIF when you enable it. You can capture without location.

3. Metadata and Anonymity

Captured photos embed standard EXIF metadata (timestamp, device model, and — if enabled — GPS). You may turn on Strip device serial from EXIF to produce anonymous evidence, and optionally round timestamps to the minute for private evidence sharing.

4. Blockchain Anchoring Is Public by Design

When you anchor a proof to OpenTimestamps, its hash becomes part of the public Bitcoin blockchain. This is what makes the timestamp independently verifiable forever — but it means the hash (not your photo) is publicly visible. Anchoring is opt-in per proof.

5. No Account, No Tracking

Prooflens requires no account. We collect no analytics, no telemetry, and store no cloud backups. Your proofs and their timestamp tokens live in the app's local storage; uninstalling the app removes them.

6. Contact

Questions? Reach us at [email protected].