Política de privacidad
Version 2
Privacy Policy
Last updated: July 2026
1. Scope and purpose
ProvenShot respects your privacy. This Privacy Policy explains how DLANPER TECH SLU processes personal data when you use the ProvenShot website at provenshot.com, the ProvenShot mobile applications for iOS and Android, the public verifier and related services (together, the “Service”).
This Policy applies to users who create accounts or proofs, visitors who use the public verifier, purchasers, people who contact or report content to us, and people whose rights may be affected by content shared through the Service.
2. Controller and contact details
The Service is operated by DLANPER TECH SLU, tax identification number B19482017, with registered address at Calle Palencia, 3, 28522 Rivas-Vaciamadrid, Madrid, Spain (“ProvenShot”, “we”, “us” or “our”). DLANPER TECH SLU is the controller of the personal data described in this Policy.
For privacy enquiries or to exercise your rights, contact privacy@provenshot.com.
3. Data we process
- Account and profile data: name, email address, password hash, public nickname, profile image, language, account settings, consent records and subscription status.
- Capture and proof metadata: capture date and time, precise GPS coordinates collected at the moment of capture, approximate location derived from those coordinates, device and security signals, proof identifiers, cryptographic fingerprints, integrity data, processing status and visibility settings.
- Media processed for the Service: the original capture remains in the user’s device gallery. The app processes and compresses the capture on-device and sends ProvenShot an encrypted compressed copy required to generate, maintain, verify and, when the user chooses, display the proof. We may also generate and store thumbnails, certified derivatives, QR assets and related technical files.
- Payment and subscription data: product or plan, price, currency, purchase date, renewal and cancellation status, transaction and platform references. Stripe, Apple or Google receives payment credentials directly; ProvenShot does not store complete card numbers or store-account credentials.
- Verifier data: file or screenshot submitted for verification, QR code or proof identifier, calculated fingerprint, verification result, query time, IP address, browser or device information and security logs. The submitted verification file is processed temporarily, removed from the processing environment immediately after the comparison and is not added to permanent media storage.
- Support, report and claim data: messages, attachments, report category, alleged infringement, identity and account information of the reporter, communications, moderation decisions and information necessary to investigate abuse or protect rights.
- Technical and usage data: IP address, device model, operating system, app version, browser, identifiers required for security, push-notification tokens, error and diagnostic information, verification events and consent records.
- Cookie and analytics data: information collected through necessary technologies and, where enabled after consent, Google Analytics. See the Cookies Policy.
4. On-device processing, cloud storage and encryption
The original photo or video remains in the user’s device gallery. ProvenShot does not use the cloud copy as a replacement for the user’s original master file.
The ProvenShot app processes the capture on the device, including compression and the generation or extraction of technical evidence needed for the proof.
ProvenShot stores an encrypted compressed copy and the technical assets required to operate the proof in secured cloud infrastructure. Stored media is not directly publicly accessible from the storage provider or content-delivery network.
When the user voluntarily shares a verification link or QR code, authorised ProvenShot systems may decrypt and display the compressed copy through the verifier. Media is delivered through signed, time-limited URLs. Direct access outside the authorised verification flow is not permitted.
Encryption reduces the risk of unauthorised access but does not make encrypted media anonymous where ProvenShot can lawfully decrypt it and associate it with a proof or account.
5. Location data and visibility controls
ProvenShot collects precise location only when the user actively captures a photo or video in the app and grants the required device permission. ProvenShot does not use location for background tracking.
Precise location is used to generate and maintain the location component of the proof and, where necessary, to derive an approximate location.
For each proof, the user decides what the verifier displays: precise coordinates, approximate location, a “location verified but hidden” status, or no public location detail. If precise location is not selected, precise coordinates are not displayed through the public verifier.
Selecting precise location triggers an additional warning explaining that coordinates may reveal a home, workplace, routine or sensitive place and requires an affirmative confirmation. The visibility choice is recorded as the user’s explicit instruction for that proof.
6. Voluntary sharing and public verifier
Creating a proof does not automatically make all proof information public. Before sharing, the user selects the information that will be visible, including location level, nickname, date and time, and cryptographic details.
The user may voluntarily share certified media, a verification link or a QR code. Anyone who receives a shared link or QR code may access the information selected by the user and may forward it to other people.
The public verifier displays only the proof information configured as visible and the media made available through the authorised sharing flow. It does not expose the original file stored in the user’s gallery or a direct storage URL.
Signed media URLs expire. Access may also stop if the proof is deleted, restricted, reported, withdrawn from public access or otherwise disabled.
Using the public verifier does not require an account. Submitting an in-product content report does require a signed-in ProvenShot account with a verified email.
7. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage accounts; provide proofs, verifier, downloads, sharing, plans and support. | Account, proof, media, location, technical and transaction data. | Performance of the contract or steps requested before entering into a contract. |
| Display information selected by the user to recipients of a shared proof. | Visibility settings and selected proof metadata. | Performance of the contract and the user’s explicit instruction for that proof. |
| Process payments and subscriptions. | Account, product, transaction and platform references. | Performance of the contract; legal obligations for accounting and taxation. |
| Protect the Service, prevent fraud and abuse, diagnose failures and defend claims. | Technical logs, verification events, account, proof and report data. | Legitimate interests in security, service integrity and legal defence; legal obligation where applicable. |
| Respond to valid authority requests and comply with law. | Data strictly required by the request or obligation. | Compliance with a legal obligation. |
| Operate optional analytics and non-essential cookies. | Cookie identifiers, device and usage data. | Consent. |
| Send marketing communications where permitted. | Name, email, customer relationship and preferences. | Consent or applicable similar-product rules, with the right to object. |
| Investigate identified content reports and preserve necessary evidence. | Reported media, proof data, reporter account, relevant access information and communications. | Legitimate interests, legal obligations and establishment, exercise or defence of legal claims. |
8. Service providers, public recipients and other recipients
We do not sell personal data. We disclose data only when necessary for the purposes described above, including to:
- AWS and CloudFront, for secured cloud storage, infrastructure and controlled media delivery.
- Google Maps services, for reverse geocoding and location-related functions.
- Firebase, where used, for push notifications, device messaging, security and diagnostics.
- Brevo, where used, for transactional and service communications.
- Stripe, for web checkout, payment processing and fraud prevention.
- Apple and Google, for in-app purchases, subscriptions, platform operation and app distribution.
- Professional advisers, auditors and insurers where necessary and subject to confidentiality.
- Public authorities, courts or law-enforcement bodies where disclosure is legally required or necessary to protect rights and safety.
- A purchaser or successor in a merger, acquisition, restructuring or asset sale, subject to appropriate safeguards.
- Recipients selected by the user, including anyone who receives or later obtains certified media, a verification link or QR code shared by the user.
Some payment and platform providers may process certain data as independent controllers under their own privacy notices.
9. International transfers
Some providers may process personal data outside the European Economic Area. Where required, ProvenShot relies on an adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism, together with supplementary measures where appropriate.
Information about safeguards applicable to a particular transfer may be requested at privacy@provenshot.com.
10. Retention and deletion
Account data is retained while the account is active. When an account is deleted, active account data is deleted or anonymised, except where limited retention is required by law, accounting obligations, security, an open report or the establishment, exercise or defence of legal claims.
Proof data, encrypted compressed media and related assets are retained while the proof remains active. Deleting a proof or account deletes or schedules for deletion the related active files, proof records, QR assets and public verification pages from production systems, subject to the limited exceptions below.
Temporary processing files may be retained for up to 24 hours for processing, recovery and controlled retry, after which they are automatically deleted.
Files submitted to the public verifier are removed immediately after verification and are not added to permanent media storage. Non-file technical logs may be retained under the internal retention schedule.
Payment, tax and accounting records are retained for the statutory periods that apply.
Security, fraud-prevention, verification-event and diagnostic logs are retained only for as long as necessary under ProvenShot’s internal retention schedule. Data connected with a specific incident or claim may be retained for the duration of that matter and the applicable limitation period.
Where encrypted backups exist, deleted data may remain until routine backup rotation. Backup copies are protected, not used for ordinary operations and restored only for disaster recovery.
Cryptographic hashes, timestamps or technical anchors recorded in an immutable system may remain where deletion is technically impossible. ProvenShot does not intentionally place original media, encrypted media, precise coordinates, names or email addresses on an immutable ledger. Where technically possible, off-chain references linking a deleted proof to an active account or public asset are deleted or detached.
11. Identified reports, moderation and restricted preservation
A signed-in user with a verified email may report a proof that allegedly exposes personal data, minors, private documents, sensitive locations, intellectual property, intimate content or other unlawful or rights-infringing material. Requiring an identified account helps reduce automated or malicious reports and enables follow-up.
People who cannot use the in-product reporting tool may submit an identified privacy or legal rights request to privacy@provenshot.com, including sufficient identity, proof reference and supporting information. Anonymous or insufficiently identifiable notices may not be processed unless applicable law or an imminent safety risk requires otherwise.
ProvenShot may immediately limit public access to the proof, certified media, verification page, link, QR code or visible metadata while the report is assessed.
If deletion is requested while a sufficiently substantiated report, legal request or claim is open, ProvenShot may preserve only the evidence reasonably necessary in a restricted environment. This preservation is exceptional, access-controlled, documented, reviewed and limited in time.
Unrelated account data and unreported content are not retained merely because a report exists. Preserved information is deleted when the justification ends, unless a legal obligation requires otherwise.
12. Security
ProvenShot uses technical and organisational measures appropriate to the risk, including encryption in transit, encryption of stored compressed media, restricted storage access, signed expiring delivery URLs, access controls, credential protection, logging, monitoring and deletion procedures.
No system is completely secure. Users should protect their credentials, devices, shared links and QR codes and notify ProvenShot promptly of suspected unauthorised access.
13. Automated security decisions
ProvenShot may use automated systems to detect suspicious activity, tampering, abuse, location anomalies or security threats. These systems may block a technical operation temporarily or flag it for review.
ProvenShot does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects on users. If that changes, this Policy will be updated with the information and safeguards required by law.
14. Data relating to people who are not users
A proof may contain personal data relating to people who do not have a ProvenShot account. Such data originates from content captured and shared by the user who created the proof. ProvenShot does not require or encourage users to identify people appearing in a capture.
Non-users may contact privacy@provenshot.com with an identified request or ask a signed-in account holder to use the reporting mechanism to request review, restriction or removal where applicable.
15. Your rights
- Request access to your personal data and information about its processing.
- Request correction of inaccurate or incomplete data.
- Request deletion, subject to legal exceptions.
- Request restriction of processing.
- Object to processing based on legitimate interests and object at any time to direct marketing.
- Request portability of data provided under contract or consent, where technically applicable.
- Withdraw consent at any time without affecting processing already carried out.
- Lodge a complaint with the Spanish Data Protection Agency or the supervisory authority of your habitual residence, place of work or alleged infringement.
To exercise a right, contact privacy@provenshot.com. We may request reasonable information to verify identity and will respond within the period required by applicable law.
Account deletion may be initiated through the deletion option available in the mobile app or through https://provenshot.com/account-deletion. Identity verification may be required to protect the account. ProvenShot will confirm completion or explain any limited lawful retention that continues to apply.
16. Children and minors
ProvenShot is not intended for children under 14 in Spain or under the minimum digital-consent age applicable in the user’s country, unless valid consent or authorisation is provided by a parent or legal guardian.
Users must not use ProvenShot to expose minors, their precise location, private documents or other sensitive information without an appropriate lawful basis and safeguards.
If ProvenShot learns that personal data has been processed in breach of applicable age rules, it may restrict or delete the account and related data.
17. Marketing communications
Where a user has expressly opted in, ProvenShot may use contact details to send product news, content, updates and offers relating to ProvenShot. Consent may be withdrawn at any time through the unsubscribe mechanism or by contacting us.
Where permitted by applicable law, ProvenShot may send existing customers communications about its own products or services similar to those previously purchased. Customers may object when their details are collected and in every communication.
A ProvenShot marketing choice is not permission to market unrelated DLANPER TECH SLU projects unless a separate, sufficiently specific legal basis has been obtained.
18. Changes to this Policy
We may update this Policy to reflect legal, technical or service changes. The current version will be published with a revised “Last updated” date. Material changes will be communicated through the Service, by email or by another appropriate method before they take effect where required.
19. Contact and complaints
Privacy enquiries and rights requests: privacy@provenshot.com.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.