Version 2026-08-26 · effective August 26, 2026 · supersedes August 3, 2026
PRYVC exists to give you control over your personal data, with evidence. That principle governs everything below — including the parts where we describe collection you might not expect, because a privacy product whose own policy omits things is not one.
PRYVC is operated by Many Software Enterprises LLC, a Delaware limited liability company, which is the data controller for the personal data described here. Address: 131 Continental Dr, Ste 305, Newark, DE 19713. Privacy contact: privacy@pryvc.com.
Scope. PRYVC is directed to United States residents. We do not target the European Economic Area or the United Kingdom; if you believe EEA/UK law applies to your use, contact privacy@pryvc.com before relying on the service.
Profile fields. The contact details you store — such as name, email, phone, and address — encrypted with AES-256-GCM under a key unique to you. We process them to execute shares you approve; we never sell, rent, or mine them.
Account and sign-in data. Google or Microsoft subject identifiers when you sign in with them, or a blind index of your email for code-based sign-in; session records including IP address and browser user agent, kept for security.
Consent and share records. When you approve a share, revoke one, submit a form through the widget or extension, or start a removal request, we record the event: the fields involved (names, not values, wherever possible), the disclosure text you were shown, the recipient, timestamps, and cryptographic fingerprints.
Device and technical evidence. Consent certificates and disclosure receipts include evidence of the submitting device: IP address, user agent, browser client hints, and approximate location (region and network, derived from the connection). Public certificate verification pages record each open — IP, user agent, operating system, and referring page — because "who checked this certificate, and when" is itself evidence. Public pages display IP addresses only in masked form.
Browser extension. Autofill with Proof runs only when you invoke it. Each fill records a disclosure receipt: the page address, which of your field names were filled (not free-form page content), a fingerprint, and a snapshot of the site's privacy policy and terms as they read that day. Receipts appear in your Data trail.
Imported account lists. If you import a list of accounts (for example a password-manager export), we store the site and the identifier you used there, encrypted, to power revocations you direct.
Declarations. If you execute a declaration under 28 U.S.C. § 1746 for a removal request, we store the declaration text's hash, your typed signature name (encrypted), and the IP address and user agent at execution — the record exists to be evidence, and evidence needs provenance.
Policy monitoring. For sites you have disclosed data to or hold an active share with, we periodically re-fetch their published privacy policy and terms and compare hashes; when a document changes we email you that it changed — the site, the document, and the date, never an analysis of the diff. This processes your disclosure history, not new personal data.
Billing. Payments are processed by Stripe; we receive subscription status and the minimum needed to operate your plan, never full card numbers.
Cookies and analytics. On our public websites we count visits with our own analytics, running on our own infrastructure — it sets no cookies, stores no personal data, and sends nothing to any third-party analytics company, so there is no consent banner because there is nothing to consent to. There is no analytics on app.pryvc.com or portal.pryvc.com, the signed-in surfaces, by deliberate choice. Full detail in the cookie policy. Separately, if you use address autocomplete in the app, the text you type in that field is sent to Google's Places service to produce suggestions.
Consent and data events are written to an append-only, hash-chained audit log whose skeleton is published at verify.pryvc.com/ledger: sequence numbers, event labels, entity types, timestamps, and hashes. Names, emails, and field values never appear there — the page cannot leak what it never receives. These public records are permanent by design: the tamper-evidence that protects you depends on history that cannot be quietly rewritten, including by us.
Recipients you direct. Businesses receive only the fields you approve, for the purpose and duration shown at consent. Removal and revocation notices you initiate are sent, at your direction and on your behalf, to the business concerned — they necessarily identify the account being removed. Ongoing updates flow only to businesses holding an active share whose scope includes the changed field.
Subprocessors. Cloudflare (hosting, delivery, and cookieless performance analytics — no cookies, no cross-site tracking, and nothing beyond what it already processes as our network), Neon (encrypted database), Stripe (payments), Resend (email delivery), DigitalOcean (hosts the server our self-contained visit-counting analytics runs on — aggregate page counts, no personal data stored), Google Places (address autocomplete in the app, only when used), and Engrave (tryengrave.com, operated by a company under common ownership with PRYVC), which receives only cryptographic hashes for external anchoring — never personal data.
Legal requirements. We disclose personal data when law compels it, and we limit any such disclosure to what is actually required.
For business users of the portal we hold workplace contact data — name, work email, sign-in records — plus your organization's domains, API keys, webhook endpoints, certificate and share records, and billing status. Certificates your organization holds embed the consumer data described above, encrypted; your access to them is logged like everyone else's.
You can appear in our systems without ever signing up. If you submitted a form on a business's website through the certified-consent widget, we hold that certificate — your submitted fields encrypted, the disclosure you were shown, and device evidence — on the business's behalf as its processor; you can verify the certificate at its public URL (which shows no personal details), opt out of future contact from that business through the certificate page, and direct rights requests to the business or to privacy@pryvc.com — we route and honor both. If you are a business contact who received a removal or revocation notice from us, we hold your work email and the correspondence trail as part of that request's record.
Event forms (pryvc.com/f/…). If you scanned a QR code at a business's booth or event and submitted one of our hosted forms, your submitted details are encrypted the moment they arrive and held only until the business receives its copy — delivered to the business's systems, or in an encrypted backup email — and are then permanently deleted from PRYVC. What we keep is evidence, not your data: a cryptographic hash of your submission, the exact consent text you were shown (hashed and versioned), the timestamp, and your IP address and browser identifier as consent evidence, plus a public-ledger entry that contains no personal details. Your receipt screen links that ledger entry. To revoke the consent, reply STOP to texts, use the unsubscribe link in emails, or contact the business named on the form; rights requests can go to that business or to privacy@pryvc.com and we will route them.
Profile fields and imported accounts: until you delete them or your account. Session records: for the life of the session plus a security window. Consent certificates, disclosure receipts, and their device evidence: for the evidentiary life of the record they support — that is their purpose. The audit chain: retained indefinitely; it is engineered to be PII-free, and its integrity depends on never being edited. Verification-page view records: retained with the certificate they evidence. Event-form submissions: encrypted and held only until delivered to the business — typically seconds, at most until the next daily backup — then deleted; the hash-based consent record is retained for its evidentiary life. Billing records: as tax and accounting law requires.
In the app: export everything you have with us (a DSAR, self-serve), edit any field, revoke any share, and delete your account — deletion revokes all active shares and erases your encrypted fields. The tamper-evident audit chain is retained as legal evidence of consent history; it is designed not to contain personal data.
By email: if you cannot use the app, or you are exercising rights for someone else as their authorized agent, write to privacy@pryvc.com. We honor authorized-agent requests with reasonable verification — being an authorized agent ourselves, we take that route seriously. We respond within the time state law allows, we do not discriminate against you for exercising any right, and if we refuse a request you may appeal by replying with "appeal"; a different reviewer decides, and we answer with reasons.
We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act, and we do not use it for targeted advertising or profiling with legal effects. There is nothing to opt out of; the right exists anyway and costs nothing to state.
PRYVC is not directed to children and accounts require the legal capacity to contract (18 in most states). We do not knowingly collect personal data from children under 13; if you believe we hold any, tell privacy@pryvc.com and we will delete it.
Consumer personal data is envelope-encrypted per user, with keys held separately from the database; decryption is request-scoped and every access path is written to the audit chain. We word this precisely rather than claiming we are incapable of reading what we hold — we hold the keys, and saying otherwise would be a lie. What we can prove is that access leaves a record you can check. If a breach affects you, we will notify you as state law requires — and we would rather over-notify than lawyer the threshold.
This policy is versioned and dated, and your acceptance at signup pins the version then in force — the same discipline we apply to consent records. Material changes are announced by email to account holders before they take effect. Our own policy-monitoring service watches this page like any other, so users with an active PRYVC share are notified of changes automatically. Prior versions are available on request.
privacy@pryvc.com · Many Software Enterprises LLC, 131 Continental Dr, Ste 305, Newark, DE 19713 · (973) 440-2441