Legal

Privacy Policy

Effective August 19, 2026

This policy describes what MVM Ventures, LLC ("we," "us"), a Pennsylvania limited liability company, collects when you use Root Witness, and what we do with it. The short version: we collect very little, we run no trackers, and in hash-only mode we never see your content at all.

1 · What we collect

Account information. When you create a log, we collect your email address and your chosen log name. Your API key is shown to you once and stored on our side only as a hash — we cannot read it back, which is also why we cannot recover it for you.

Billing information. Payments are processed by Stripe. Stripe collects your name and payment card details under its own privacy policy; we never receive your card number. From Stripe we receive your subscription status, the email you used at checkout, and the log name you entered so we know which log to upgrade.

Log content — depends on the mode you use.

  • In standard mode, we store the records you submit to your log.
  • In hash-only privacy mode, you send us only cryptographic hashes. We never receive the underlying content, cannot reconstruct it, and could not disclose it to anyone because we do not have it.

We do not analyze, mine, or train anything on your log content. It is stored to be served back to you and proven, nothing else.

Operational data. Our servers keep standard request logs — IP address, timestamp, endpoint, and response status — used for security, debugging, and rate limiting (for example, limiting how many logs one address can create in a minute).

Correspondence. If you email us, we keep the thread. Our email is hosted on Google Workspace.

2 · What we do not collect

  • No analytics or advertising trackers on the website — no Google Analytics, no pixels, no fingerprinting.
  • No tracking cookies. The website works without them.
  • No selling or renting of personal information to anyone, and no sharing for cross-context behavioral advertising, in California Consumer Privacy Act terms or anyone else's.

3 · How we use information

  • To operate the service: append your submissions, sign checkpoints, serve proofs, and show you your own data.
  • To bill you and manage your subscription.
  • To secure the service: rate limiting, abuse prevention, and investigating incidents.
  • To communicate with you about your account, service changes, and — sparingly — things we think genuinely matter to you as a customer. No marketing blasts to log-only free users.

We do not use your data for advertising, and we do not train machine-learning models on it.

4 · The nature of a transparency log

Two properties of the service matter for privacy, and it would be misleading not to state them plainly:

  • Entries cannot be selectively deleted. The log is append-only by design; removing or altering an entry would break the verification that is the point of the service. Treat anything you submit in standard mode as permanent. If your records contain personal data, use hash-only mode, where the permanent artifact is a hash, not the data itself.
  • Proofs are meant to be shared. Receipts, checkpoints, and inclusion proofs contain log names, positions, timestamps, and hashes — not record content. Anyone you give a proof to can verify it. On the Regulated tier, checkpoint hashes may additionally be anchored to public timestamping infrastructure (such as the Bitcoin blockchain via OpenTimestamps); anchored hashes are public and permanent, and cannot be recalled by us or anyone.

A hash does not reveal the content it was computed from, but if the underlying record ever becomes known, anyone can confirm it matches the hash. Choose what you submit accordingly.

5 · Who we share data with

Only service providers that operate the product, and only what they need:

ProviderPurposeWhat they handle
StripePaymentsBilling details, subscription status
RailwayHosting (API and database)Everything the service stores
Google WorkspaceEmailYour correspondence with us
OpenTimestamps / Bitcoin networkAnchoring (Regulated tier)Checkpoint hashes only — public by design

We disclose information beyond this only if required by law (for example a valid subpoena), to protect the rights or safety of us or others, or as part of a sale or merger of the business — in which case this policy continues to apply to data collected under it and we will notify account holders.

In hash-only mode, note what this means concretely: even a subpoena served on us cannot produce your record content, because we do not possess it.

6 · Retention

  • Account data: kept while your account is active, deleted within 90 days after account deletion, except records we must keep for tax and accounting.
  • Log entries: kept while the log exists, subject to Section 4 — entries in a live log are not selectively deletable. Deleting an entire log removes its content from the service; already-issued proofs and anchored hashes remain valid and public wherever they already are.
  • Server logs: rotated on a short cycle, typically within 90 days.
  • Billing records: kept as long as tax law requires.

7 · Your rights

Email hello@rootwitness.com to exercise any of these. We answer within 30 days.

  • Access and portability: your entries, receipts, and checkpoints are exportable through the API at any time; we can also provide the account data we hold about you.
  • Correction: we will correct account information. Log entries themselves cannot be edited (Section 4) — the honest remedy is appending a correcting record, which is how audit logs are meant to work.
  • Deletion: we will delete your account data, and entire logs on request, within the limits of Section 4. We will tell you exactly what could and could not be removed.
  • California residents: you have the rights to know, delete, correct, and not be discriminated against for exercising them. We do not sell or share personal information, so there is nothing to opt out of.
  • EU/UK visitors: we process account data to perform our contract with you and operational data in our legitimate interest in running a secure service. The rights above track your GDPR rights; we honor them for everyone rather than checking passports.

8 · Security

API keys are stored only as hashes. Traffic is encrypted in transit with TLS. The audit infrastructure itself is designed to be tamper-evident and independently verifiable, and the database roles the service runs under are deliberately stripped of destructive privileges — the running service cannot delete evidence tables even if compromised. No security is absolute; Section 8 of our Terms of Service states plainly what the design can and cannot do.

If we learn of a breach affecting your personal data, we will notify you without undue delay, consistent with applicable law.

9 · Children

The service is not directed at children under 16 and we do not knowingly collect their data. It is a B2B audit tool; if a child has somehow created a log, contact us and we will delete the account.

10 · Changes

We may update this policy. Material changes get at least 30 days' notice by email to account holders before taking effect. The current version always lives at this page with its effective date.

11 · Contact

MVM Ventures, LLC
Philadelphia, Pennsylvania
hello@rootwitness.com