Legal

Privacy Policy

This document explains what personal data Homostamp collects, how it is used, and the rights you hold over your information.

Last updated: June 2026
01

Who We Are

Homostamp (homostamp.com) is a digital copyright registration and verification platform. We generate cryptographic proof packages — including RFC 3161-compliant timestamps and blockchain registry records — that support ownership claims for digital works created by humans.

Important Scope Note
Homostamp produces technical and cryptographic evidence to support ownership claims. We do not have the authority to grant legal title of ownership.
02

Data We Collect

Account Data

When you register, we collect and retain only the minimum data necessary for account operation:

· First and last name — displayed on your certificate and stored for account identification.
· Email address — used for login, notifications, and account recovery.
· Password — stored as a one-way bcrypt hash. We never store or access your plain-text password.

Registration Data

For each timestamp registration, we collect and store:

· SHA-256 hash of your file — computed in your browser and verified in our servers. The file content itself is transmitted to our servers to make hashing calculations. We delete your original file after stamping process unless optionally requested by you.
· File name and size — recorded for certificate purposes.
· TSA response data — TSA provider name, serial number, and RFC 3161 timestamp (UTC).
· AI analysis score and label — the result of our automated content analysis (e.g., Human Likely, Uncertain, AI Likely).
· Blockchain TxID and verification code — the Polygon transaction reference and your unique proof identifier.

Optional File Storage

Uploading your original file to our servers is entirely optional. During registration you may check "I want to store my original file." If you do not, only your file hash, TSA proof, and blockchain record are kept. Stored files are isolated per account and retained for the duration of your active subscription.

Payment Data

Payment processing is handled by third-party providers (Paddle, Stripe). We store only the transaction reference ID, provider name, currency, amount, and credit quantity. We never receive or store full card numbers, CVV codes, or bank account details.

Technical & Log Data

Our servers automatically record error logs, last login timestamps, and failed login attempt counts for security purposes. IP address data used during maintenance mode bypass checks is not persisted to the database.

03

How We Use Your Data

We use the data we collect solely to:

Create and manage your account and authenticate your sessions.
Process your timestamp registration — generate the TSA request, blockchain record, and PDF certificate.
Send transaction confirmation and system notification emails.
Process and verify credit purchase payments.
Maintain the security and integrity of our platform.
We do not sell your data
Your personal information is never sold, rented, or shared with third parties for advertising or marketing purposes.
04

Storage & Security

All personal data is stored on servers within the applicable jurisdiction. Our security measures include:

Password Hashing
All passwords are hashed with bcrypt (PASSWORD_BCRYPT). Plain-text passwords are never stored.
Isolated File Storage
User files and TSA proofs are stored outside the web root in UUID-namespaced directories.
Silent Error Logging
Software errors and system exceptions are never exposed to the browser; they are logged privately.
Account Lockout
After 5 consecutive failed login attempts, accounts are temporarily locked for 15 minutes.

All timestamps and records within the system are stored in UTC. No administrative access credentials are stored in the database; staff accounts are managed at the application configuration level, structurally preventing privilege escalation via SQL injection.

05

Blockchain Records

When a registration is successfully completed, a cryptographic registry seal — a SHA-256 hash derived from your file hash and a unique verification code — is written to the Polygon blockchain. This record is:

· Immutable — blockchain records cannot be altered or deleted by Homostamp or any third party.
· Not personally identifiable on-chain — the blockchain record contains only the registry seal hash. No name, email, or file content is written to the blockchain.
· Linkable via your certificate — the verification code in your PDF certificate connects the blockchain record to your account within our system.
Right to Erasure & Blockchain
If you request account deletion, your personal data (name, email) is anonymized and all linkage between your Homostamp account and the blockchain record is severed. The blockchain record itself, being immutable by nature, cannot be deleted. After anonymization it cannot be re-linked to you through our platform.
06

Your Rights

Under applicable data protection law (including GDPR), you have the following rights:

Access

You may request a copy of all personal data we hold about you.

Rectification

You may request correction of inaccurate or incomplete personal data.

Erasure

You may request deletion of your account. Name and email are permanently anonymized; all stored files are deleted. Blockchain records are severed from your identity but cannot be removed from the chain.

Restriction

You may request that we restrict processing of your data in certain circumstances.

Portability

You may request your data in a structured, machine-readable format.

Objection

You may object to certain types of processing where we rely on legitimate interest.

Account Deletion is Irreversible
Once your account is deleted, verification code mappings are permanently removed. You will no longer be able to link your certificate to a Homostamp account. Please download and safeguard your certificates and .tsr files before requesting deletion.

To exercise any of these rights, contact us at contact@homostamp.com. We will respond within 30 days.

07

Cookies & Sessions

Homostamp uses only technically necessary session cookies for authentication. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Specifically:

· Session cookie — a standard server side session cookie to keep you logged in. Expires when you close your browser or log out.
· Staff session cookie — a separate, isolated server side session used exclusively for the management panel. Not shared with user sessions.
No Third-Party Trackers
We do not embed Google Analytics, Facebook Pixel, or any similar tracking services on this platform.
08

Third-Party Services

The following third-party services receive limited data as part of our core functionality:

TSA Providers

Cryptographic

Our tsr providers receive your file's SHA-256 hash inside an RFC 3161 timestamp request. No personal data, file content, or account information is transmitted to TSA providers.

Polygon Blockchain

Blockchain

The registry seal hash is written to the Polygon public blockchain. This is a public ledger; the hash itself contains no personal information.

Payment Providers (Paddle / Stripe etc.)

Payments

Payment data is processed directly by Paddle/Stripe etc. on their PCI-compliant infrastructure. These providers have their own privacy policies. We receive only a transaction confirmation and do not handle raw card data.

Google Fonts

UI

Our interface loads the Inter typeface from Google Fonts, which may log your IP address per Google's own privacy policy. No other data is shared with Google through our platform.

09

Data Retention

· Account data — retained for the lifetime of your active account.
· TSA proof files (.tsr) — retained for the duration of your contract period; downloadable at any time from your dashboard.
· Optional uploaded files — retained for the duration of your active subscription; deleted upon account deletion or right-to-erasure request.
· Blockchain and cryptographic records — retained permanently per the nature of the blockchain; anonymized from account linkage upon deletion request.
· Payment records — retained as required by applicable financial and tax law.
10

Contact & Complaints

For any privacy-related questions, data requests, or complaints, please reach out to us directly. We are committed to responding within 30 days.

Email contact@homostamp.com
Platform homostamp.com
Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority (e.g., CNIL in France, ICO in the UK, or KVKK in Turkey).
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our services or applicable law. Material changes will be communicated via email or a prominent notice on the platform. Continued use of Homostamp after such notice constitutes acceptance of the updated policy.