Privacy policy
VerifBox is designed to process as little data as possible: your files stay on your device, and the Service keeps no record of what you timestamp. This policy explains exactly what is processed, why, and for how long.
1. Data controller
HTTPS CARD — Internet Identity Card Limited, company no. 09168431, 124 City Road, London EC1V 2NX, United Kingdom, registered with the Information Commissioner’s Office (ICO) under number ZA457585. Contact: contact@verifbox.com. This policy is intended to meet the requirements of the UK GDPR and, where it applies, the EU General Data Protection Regulation (GDPR).
2. Your files never leave your device
The file you select is never sent to VerifBox. Its fingerprint is computed in your browser, and the signatures of a proof are verified in your browser. The PDF certificate and the image to share are also created in your browser and are not sent to the Service.
3. What the Service receives
When you create a proof, the Service receives only the SHA-256 fingerprint of the file. It adds the date and time, signs the result and returns the proof to your browser.
When you check a proof on the Verify page, the Service receives the Bitcoin anchor part of the proof, so that it can complete and check it. This part contains the file’s fingerprint.
In both cases, the data is processed in memory for the time of the request and is not stored: VerifBox has no user accounts and keeps no database of files, fingerprints or proofs.
A fingerprint does not allow the file to be reconstructed. However, someone who already holds a copy of a file can check whether it matches a given fingerprint. A fingerprint should therefore not be regarded as anonymous in every situation.
IIC TSA time-stamp token. Since 10 October 2026, when you create a proof, our server also sends the file fingerprint to the IIC TSA time-stamping service, operated by the same company (HTTPS CARD — Internet Identity Card Limited) on Google Cloud, in the europe-west1 region (Belgium). IIC TSA receives neither your file nor your IP address, and does not keep the fingerprint: its log, kept for twelve years, records only the serial number, the time and technical data of each token. Every night, an overall digest of this log is time-stamped by a third-party authority and anchored in Bitcoin; it contains no data about you.
4. Legal bases
Processing the fingerprint and the anchor data is necessary to provide the service you request under our terms of use. Processing IP addresses for security and abuse prevention relies on our legitimate interest in protecting the Service and keeping it available; this processing is limited to what is strictly necessary and lasts no more than a minute in the application, which we consider does not override your interests or rights.
5. IP addresses and technical logs
Like any hosting provider, Google Cloud processes connection data, including your IP address, in order to deliver the pages and route requests to the Service. Within the VerifBox application, your IP address is held in memory for no more than one minute, to limit the number of requests, and is never recorded by the application.
Request logs are disabled. Error logs produced by the hosting environment are kept for 30 days and contain neither file contents nor fingerprints.
6. Bitcoin anchor
To record a proof in the Bitcoin blockchain, our server submits to public OpenTimestamps calendar servers (opentimestamps.org, eternitywall.com, catallaxy.com) two values, derived respectively from the fingerprint and from the signed attestation, each randomised beforehand. These servers receive neither your file, nor its fingerprint, nor your IP address. Once recorded, these values remain permanently and publicly in the Bitcoin blockchain and cannot be deleted by anyone, but they do not allow the file or its fingerprint to be found.
To check an anchor, our server reads block headers from public Bitcoin explorers (blockstream.info, mempool.space), without sending them any data about you.
7. Cookies and browser storage
VerifBox uses no cookies and stores nothing in your browser. It uses no audience measurement, advertising or tracking tools, and loads no resources from third-party websites.
8. External links
Links to external websites (GitHub, X, Bitcoin blockchain explorers) send no data until you click them, and the destination site is not told where you came from. Once on those sites, their own privacy policies apply.
9. Processor and international transfers
The website and the Service are hosted by Google Cloud EMEA Limited (Ireland), acting as our processor, in the europe-west1 region (Belgium). Google may process or access data from outside the United Kingdom and the European Economic Area, in particular through its sub-processors, under its data processing terms and with the safeguards required by law, such as adequacy decisions and standard contractual clauses.
The OpenTimestamps calendars and the Bitcoin explorers mentioned above are independent third parties to which VerifBox sends no personal data. The third-party time-stamping authority that time-stamps the overall digest of the IIC TSA log every night receives only that digest, which contains no data about you.
10. Retention
Fingerprints and anchor data: not retained beyond the request. IP addresses in the application: one minute at most. Error logs: 30 days. IIC TSA log (serial number, time and technical data of each token, with no fingerprint and no IP address, hence no personal data): twelve years, the period during which a token must remain checkable and auditable after the fact. Values recorded in the Bitcoin blockchain: permanent, but they contain no personal data.
11. Your rights
Depending on the applicable law and the legal basis of the processing, you have the right to access your personal data, to have it rectified or erased, to restrict its processing and, where processing relies on our legitimate interest, to object to it. As VerifBox keeps almost no data, we will in practice usually hold no data about you; if a request requires it, we may ask for the information needed to identify the data concerned.
To exercise your rights or ask a question: contact@verifbox.com. You may also lodge a complaint with the ICO (ico.org.uk) or, if you live in the European Union, with the data protection authority of your country, such as the CNIL in France (cnil.fr).
12. Security and changes
We apply technical and organisational measures appropriate to the Service, starting with its design: files are never transmitted, and nothing about you is stored. No system can, however, guarantee absolute security. We may update this policy to reflect changes to the Service, our providers or the law; the current version is published on this page, with the date of its last update.
This policy is available in English and French. In the event of any discrepancy, the English version prevails.
Last updated: 10 October 2026.