Privacy

registry.falsify.dev · effective 2026-08-17 · controller: Cüneyt Öztürk (falsify.dev) · contact hello@falsify.dev

1 · The one rule that matters

Do not put personal data in a manifest. Not in producer.id, not in the optional handle, not anywhere. Receipts are public, content-addressed, independently timestamped and mirrored to the Rekor transparency log — erasure is technically impossible once committed. Identify as an organisation ("acme-evals") or a pseudonymous handle. The registry automatically rejects submissions whose identity fields look like an email address or phone number; everything subtler is your responsibility.

2 · What we process

Submitted content: the manifest bytes, their hash, a signed receipt, an RFC 3161 timestamp token — stored and public, treated as non-personal technical data.
IP addresses: used only for rate limiting; held in a counter that expires within 1 hour; never attached to receipts.
Page analytics: a first-party beacon stores host, path, referrer and country (no IP, no cookies, no fingerprint), retained up to 30 days.
Error reports: when the service throws an exception, the exception type, message and stack trace are sent to Sentry (Functional Software Inc., EU ingest region) so that faults get fixed. The request, its headers, query string, body, cookies, IP address and any user identifier are removed before the event leaves this worker — see scrubEvent in the source. Submitted manifests are never included. No tracing, no session replay, no performance data.
No accounts, no cookies, no third-party trackers, no advertising or analytics processors.

3 · Legal basis and your rights

Processing rests on legitimate interest (Art. 6(1)(f) GDPR): operating a public integrity log with the minimum data possible. For the transient data (rate-limit counters, analytics) you may request access or erasure at any time. For committed manifests, §1 applies: design-level immutability means the stored bytes can be unpublished from this service on request, but hashes already countersigned by external authorities cannot be recalled — which is why the front door refuses personal data in the first place. Complaints: your local data-protection authority; the controller is Falsify OÜ (reg. 17574308, Narva mnt 5, 10117 Tallinn, Estonia).