Privacy Policy
ZKNOT, INC. ("ZKNOT," "we," "us") operates HashStamp. This policy explains what we process and why. HashStamp is offered to US customers only (see Terms).
1. The file never leaves your device
Your file is hashed in your browser. We receive only the SHA-256 fingerprint and any optional public label. We never receive, see, or store your file or its contents, and we cannot reconstruct your file from the fingerprint. We also do not receive your file's name for new records.
Do not assume "the file never leaves your browser" means we process no personal data. We do process the categories below.
2. What we collect, and why
| Category | What | Why | Where |
|---|---|---|---|
| Email address | If you buy Founding Supporter Status (collected by Stripe) or join the reserve list | Send your receipt; contact reserve-list subscribers; recover access by email | Stripe; our Cloudflare KV store |
| Payment information | Card details and billing info | Process payment | Stripe only — we never receive or store card numbers |
| Payment metadata | Amount, currency, Stripe session/payment identifiers, order reference, timestamps | Record and reconcile your purchase | Our Cloudflare KV store |
| File fingerprint (SHA-256) + timestamp + chain linkage | The committed record you create | Provide the verifiable record | ZKNOT chain database; public on the verifier; cryptographically committed — any later change is detectable |
| Optional public label | Free text you choose to attach to the record | Let you identify the record publicly | ZKNOT chain database; public on the verifier; display metadata — not part of the cryptographic commitment |
| Stamp list (only if you sign in) | If you choose to sign in at /account: your email address, and for each stamp you save there, its code, file fingerprint, optional public label, and timestamp | Show you your own stamps in one place | Our Cloudflare KV store; private to your account — never published, never shown to anyone you send a verify link to |
| Coarse location + device string | Approximate country (from your IP) and, for reserve signups, your browser's User-Agent | Anti-abuse; US-only screening; ops notice | Our Cloudflare KV store |
| Network/technical | Your IP address is used transiently to rate-limit requests | Prevent abuse | Not stored by us in application data; may appear in infrastructure logs |
We do not collect your file, your file's contents, or (for new records) your filename.
3. Public information — what is permanent, and what is not
The file fingerprint, timestamp, service signature, chain position, and any public label you enter are published and are verifiable by anyone. They do not all behave the same way.
Committed fields — tamper-evident. The fingerprint, timestamp, and chain linkage are cryptographically committed to a tamper-evident, hash-linked chain. We do not edit or delete them, and we could not do so undetectably: any change breaks the hash linkage, and the record stops verifying for everyone who checks it. Treat these fields as published permanently.
The public label — published, but not committed. Your label is separate display metadata. It is published and intended to persist, but it is not covered by the record's cryptographic commitment, and we retain discretion to stop displaying, suppress, or redact it (see Terms §7). Suppressing a label does not alter the committed fingerprint or timestamp. We do not promise label removal on request.
Do not put confidential or personal information in a public label. (See Section 5 for deletion requests and their limits.)
4. Who we share data with (processors)
- Stripe, Inc. — payment processing (card data, email, billing). Stripe's own privacy policy governs data you enter on its checkout page.
- Cloudflare, Inc. — hosting, the Worker, Pages, the KV store, and edge request logs (which may include IP address and requested path).
- Resend — sends your receipt email and our internal notifications; receives recipient email address and message content.
- Railway — hosts the ZKNOT chain database where records are stored.
Our pages load no third-party resources: fonts are served from our own domain, and the site embeds no advertising or analytics beacons.
We do not sell your personal information.
5. Retention, deletion, and your choices
How to request deletion. Email ops@zknot.io from the address associated with your purchase or reserve signup, or include your order reference. We will delete the personal data we hold about you — your email address and associated purchase and reserve records — within 30 days of verifying your request. This is a manual, human-handled process. The one exception is the optional stamp list described below, which you can delete yourself at any time from /account; everything else is handled by a person.
What we can delete: your email address and the purchase/reserve records that contain it, from our systems.
The stamp list is self-service and optional. Signing in at /account is never required to stamp a file, and nothing you stamped before you signed in is added to it. From that page you can remove any single entry or delete the whole list, including our record of your email address for it, without emailing anyone — that deletion is immediate and does not wait on the 30-day process above. Deleting the list removes only our private note of which stamps you saved: the stamps themselves are committed chain records that stay published and keep verifying, exactly as described below.
What we do not delete, and why:
- Committed chain fields — the file fingerprint, timestamp, and chain linkage — are cryptographically committed to a tamper-evident, hash-linked chain. We do not delete them, because removing or altering a committed field breaks the hash linkage and destroys the verifiability that every other record in the chain depends on. We are describing what we will not do, not asserting a technical impossibility. (The file fingerprint is a one-way hash from which your file cannot be reconstructed and which contains no name, email, or address.)
- Public labels are display metadata rather than committed fields, so suppressing one does not break any linkage. We nonetheless do not offer label removal as a right, and we ask you never to put personal or confidential information in a label. If you believe a label exposes personal data, contact ops@zknot.io; we will consider suppression case by case under Terms §7, but cannot guarantee an outcome.
- Payment records held by our payment processor (Stripe) are retained as required for tax, accounting, and fraud-prevention purposes and are governed by Stripe's own terms.
We will confirm when your deletion request is complete.
Retention otherwise: we keep account, purchase, and reserve data for as long as needed to provide the service and meet legal and accounting obligations, and then delete or de-identify it. You may unsubscribe from the reserve list at any time.
6. Logging
We keep operational logs to run the service reliably. Our application logs are written to avoid recording payer email addresses. Infrastructure and edge logs (Cloudflare, our host) may record IP addresses and request paths.
7. Conversion and advertising tracking
When active, HashStamp will use advertising and conversion-measurement technologies (for example, the Meta pixel and/or Google Ads conversion tags) that set cookies or similar identifiers and share limited event data (such as page views and completed purchases) with those platforms to measure and improve advertising. At that time we will provide a cookie/consent notice describing these technologies and your choices, and this section will take effect.
8. Contact
ZKNOT, INC., PO Box 993, Salt Lake City, UT 84110, USA · ops@zknot.io