The public registration endpoint is paused. The interface preview does not read, process, store or transmit audio. Do not send recordings, voiceprints, identity documents or other sensitive information to this site.
Who operates this site
The operator's legal identity and a public privacy contact channel have not yet been published. For that reason, the site does not currently accept public registration submissions. This notice must be updated before a real-person pilot reopens.
Current data flows
- Ordinary visits: the hosting and security provider may process IP address, request time, URL, user agent and related network/security data needed to deliver and protect the site.
- Record lookup: a registration identifier and optional purpose context are sent to the same-origin API. The application performs a read-only database lookup and returns a minimal status response. It does not add a lookup event to the rights-event chain.
- Public ledger lookup: the application returns limited receipt metadata only for records already classified as public. Restricted, sealed and missing records receive the same 404 response.
- Legacy pilot records: the database may contain a public label, privacy tier, selected purposes/languages, timestamps and hash-linked receipts submitted during the earlier minimum viable pilot. The current public verification response no longer exposes those profile fields.
What the current site does not collect
The current published workflow does not accept or intentionally collect audio, voiceprints, embeddings, biometric templates, government identity documents, payment information or model-training consent.
Public information and caching
Public receipt metadata may be visible to anyone who knows a public record identifier. API responses use Cache-Control: no-store, but no Internet service can guarantee that a recipient will not independently retain information already displayed to them.
Retention, correction and disputes
A controlled correction, dispute, withdrawal and deletion channel is not yet operational. Existing receipts are not silently changed or deleted because that would break the historical integrity chain. Before reopening, the project must publish a process that separates correction of current state from preservation or lawful deletion of historical and sensitive material.
Service providers and locations
The site is delivered using Cloudflare Workers, Static Assets and D1. Provider infrastructure and security processing may occur in multiple locations. No cross-border biometric processing is enabled because the current service accepts no biometric material.
Children and third-party recordings
Do not use this pilot for a child, a deceased person, a celebrity, a secretly recorded conversation or a recording containing another person. These categories require separate legal, consent and safeguarding processes that are not available here.
Changes and contact
This interim notice will change as the pilot governance and operator details are established. See the contact status page. Until a verified channel is published, do not submit personal or sensitive information.