Privacy, explained
How pruf.net protects what’s yours.
Messages, posts and vault files each follow their own rules. Here’s exactly how each one works, what our storage illustration shows, and where our planned products stand.
Scope
Your questions, answered plainly.
What happens at signup?
Signup asks for no name, no email and no phone number, and there’s no face on file. You enroll with a live presence check and your phone’s own device credentials, and PRUF keeps no biometric template. So we know a real person is behind the account, but we don’t know who you are. Be human, keep your identity private: how much of yourself you show on pruf.net is up to you.
Who can read my private messages?
Only the people you send them to. Messages are end-to-end encrypted: PRUF delivers them without being able to read them, and only your recipients’ authorized devices can open them. The routing and delivery information we need to get a message there is kept separate from what the message says.
What is the pruf Vault?
Your messages and files, encrypted at rest, in your pruf Vault on your phone. No one can open it but you. It’s separate from anything you post. Originals, exports and backups you keep in other places follow those services’ rules, so protect them there too.
What happens when I share?
Posts are seen by the audience you post to. Sending a file gives its recipient access, and their copy can be protected in their own vault. As anywhere else, removing someone from a conversation doesn’t take back what they’ve already received.
What does PRUF keep?
Zero-PII is how PRUF is designed: we’re built never to collect personally identifiable information and never to store it in plain text. To run the service we still use account and device identifiers and routing metadata, and we treat encrypted content as data that deserves protection too. Our product privacy agreement has the full disclosures.
What if I lose my phone?
Keep your recovery material somewhere only you control. Recovering your account gets you back into pruf.net, but your existing vault contents also need the original key material and the stored files.
What does a photo’s verification record show?
Photos taken in the app carry a capture and edit record that anyone you share with can check on their own device. pruf.net takes no uploads, so what’s posted was taken in the app. A record shows how a photo was made in pruf.net; it can’t vouch for everything in front of the lens, or follow every copy once it’s exported.
What if someone copies the storage?
A copy of PRUF-protected storage isn’t enough to read your files. Opening them also takes separate material held by your device and by PRUF. That protection covers PRUF-protected storage; readable exports and other files on the same drive aren’t covered.
How is this different from encrypting a file?
Encryption can already hide data from a storage provider. PRUF’s design goes further: it separates the stored object, the material you hold and the material PRUF holds, so what anyone can read depends on what they hold. It also does away with the email and password other encrypted services still need to run an account. Splitting a file across clouds, on its own, doesn’t create that separation.
Is the storage illustration real?
It’s an illustration. It uses a fictional photo to explain the design; no real files, cameras, authentication or production encryption are involved. The three roles it shows aren’t three equal cryptographic shares, and an unlocked compromised device, recovery material, cached copies or readable exports can change the privacy boundary.
What does the human check confirm?
That a real person is behind every account. Bots can’t get in: every account needs a live person with Face ID on a real iPhone, at signup and each time the app opens. Face ID runs on your phone, and PRUF holds no biometric registry. It’s one person, one phone: each active account needs its own device, so someone with several phones can hold several accounts. The check confirms that someone is human, not who they are or whether they mean well, and it isn’t a government ID check.
Are you building more than pruf.net?
Yes. Our account architecture is built to power more than one product. On the roadmap: a verification mode for websites, where you approve what you share; partner APIs; and human control for AI agents you approve. pruf.net is the only product shipping today. Planned features aren’t part of the current beta, aren’t for sale and may change. Age proof will need supported credentials, and a website may keep the details you approve sharing with it.
Does this stop every kind of access?
No system can promise that, and we won’t. Someone you’ve authorized can read what you send them, and a compromised device that’s unlocked can read what’s on it. Plaintext kept elsewhere and reconstruction material can also change the boundary. Patent-pending status isn’t a security certification or a guarantee of regulatory compliance.