PROOFCHAIN
Home Dashboard KYA Pricing Get Started
Legal · Cookie Policy

Cookie Policy

ProofChain is built on a minimal-data principle. We do not track you, we do not profile you, and we do not sell your browsing behavior to advertisers. This policy explains exactly what storage mechanisms the ProofChain website uses, why, and how you stay in control.

Effective: 11 August 2026 Jurisdiction: GDPR / ePrivacy (EU 2009/136/EC) Contact: dpo@proofchain.us
§1

Scope of This Policy

This Cookie Policy applies to the ProofChain website and service, available at proofchain.us and any subdomains or associated surfaces that link to this policy. It describes the cookies, localStorage entries, and similar client-side storage technologies used when you visit or interact with ProofChain, how we process the data they carry, and the choices available to you.

References to "we", "us", and "ProofChain" mean the operator of the ProofChain service. This policy supplements, and should be read together with, our Privacy Policy and Terms of Service.

§2

Our Core Principle: Minimal Storage, No Tracking

ProofChain operates a no-tracking-by-default website. We do not deploy analytics trackers, advertising pixels, fingerprinting scripts, or cross-site tracking identifiers. We do not use cookies to build a profile of you, to follow you across the web, or to target advertisements at you.

This is a deliberate architectural choice. The ProofChain product itself exists to make AI agent activity verifiable and accountable; it would be inconsistent with that mission to surveil our own visitors. Our storage footprint is limited to what is functionally necessary to operate the site and your session.

§3

Cookies We Use

The following table lists every cookie and storage mechanism used on the ProofChain website. Where a row is marked "None", we deliberately use no such mechanism.

TypePurposeDuration
Essential session cookieCore site functionality — maintaining your authenticated session and preventing CSRF on form submissions.Session / up to 30 days
Stripe checkout cookiesRequired by Stripe, our payment processor, to complete and secure payment transactions (see §6).Set by Stripe
Analytics cookiesNone — ProofChain deploys no first-party or third-party analytics cookies.—
Advertising / tracking cookiesNone — ProofChain does not run advertising, remarketing, or cross-site tracking.—
Third-party cookiesNone, except as technically required by the Stripe checkout integration (see §6).—
§4

localStorage for Session Preferences

In addition to cookies, ProofChain uses the browser localStorage API to remember lightweight, non-sensitive preferences between visits. Specifically, we store a single flag when you dismiss the cookie notice (so we do not re-show it on every page load).

localStorage entries are stored locally in your browser, are not transmitted to us as analytics, are not readable by third parties, and can be cleared at any time through your browser settings or by executing localStorage.clear() in your browser's developer console.

§5

No Third-Party Advertising Cookies

ProofChain does not use third-party advertising cookies. We do not participate in ad exchanges, retargeting networks, or behavioral advertising. No advertising identifier is ever written to your browser by our site, and no advertising partner receives data about your visits from us.

If you reached ProofChain through an advertising campaign on another platform (for example a search engine), that platform's own cookies may exist in your browser as a result of your interaction with that platform — those cookies are controlled by that platform, not by ProofChain, and are governed by that platform's privacy policy.

§6

Stripe Checkout Cookies

When you initiate a payment through ProofChain, the transaction is processed by Stripe, our payment processor. Stripe may place cookies necessary to complete, secure, and validate the checkout flow, including fraud-prevention and session-management cookies. These cookies are set and controlled by Stripe and are subject to Stripe's own privacy and cookie policies.

Stripe's cookies are used solely to process your payment. ProofChain does not use Stripe's cookies for advertising, analytics, or any purpose unrelated to completing your transaction. If you do not begin a checkout, Stripe cookies are not set.

§7

How to Control Cookies in Your Browser

You can control and delete cookies and localStorage at any time through your browser settings. Because ProofChain's storage footprint is minimal, blocking or clearing it will not degrade most of the site's functionality — though you may be asked to confirm the cookie notice again, and authenticated sessions will end when session storage is cleared.

  • Chrome / Edge: Settings → Privacy and security → Third-party cookies / Site data — view, block, or clear per-site cookies and site data.
  • Firefox: Settings → Privacy & Security → Cookies and Site Data — manage exceptions, clear data, or enable strict Enhanced Tracking Protection.
  • Safari: Settings → Privacy — block all cookies, or manage per-site website data.
  • Mobile browsers: Use the site-settings or privacy menu; most mobile browsers support per-site cookie blocking and clearing.

You may also use your browser's private / incognito mode, which discards cookies and localStorage when the window closes, or install a content-blocking extension that strips cookies and trackers by default.

§8

Legal Basis for Processing

Where we process personal data through the storage mechanisms described in this policy, the legal bases under Article 6 of the GDPR are:

  • Contract performance (Art. 6(1)(b)) — where storage is necessary to provide the service or complete a transaction you requested.
  • Legitimate interests (Art. 6(1)(f)) — for strictly necessary security and anti-fraud measures, including the integrity and confidentiality protections described in §10.
  • Consent (Art. 6(1)(a)) — where a mechanism is not strictly necessary and requires your consent; ProofChain does not currently deploy any non-essential, consent-requiring cookies.
§9

ePrivacy Compliance

Under the EU ePrivacy Directive (2009/136/EC), as implemented in EU member states and the UK (PECR), strictly necessary cookies and storage may be deployed without consent, while non-essential storage requires consent. ProofChain deploys only strictly necessary storage (session management, security, checkout), and therefore does not require a consent-management banner. We will update this policy and deploy a consent mechanism before introducing any non-essential cookie or tracker.

§10

GDPR Article 5(1)(f) — Integrity and Confidentiality

Article 5(1)(f) of the GDPR requires that personal data be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures."

ProofChain implements this obligation across the full data lifecycle:

  • Encryption at rest and in transit. All personal data processed through ProofChain — including agent operator identifiers, timestamps, and action logs — is encrypted at rest using HXMP and transmitted exclusively over TLS 1.2+ in transit.
  • Access control. Data is accessible only to authenticated principals via wallet-based authentication (AgentID), with per-key scoping enforced at the application layer.
  • Network security. The ProofChain infrastructure sits behind a firewall with CrowdSec-managed reputation filtering and rate limiting, reducing the attack surface for unauthorized access.
  • Confidentiality by erasure. Where erasure of on-chain records is required, ProofChain destroys the associated encryption keys, rendering the ciphertext permanently inaccessible — a form of erasure recognized under data protection law (§11 of the DPA).

The mechanisms described in this policy — minimal storage, no tracking, no third-party advertising cookies — are themselves part of our integrity and confidentiality posture: the less data we hold, the less there is to compromise.

§11

Data We Do Not Collect Via Cookies

For clarity, ProofChain does not use cookies or similar technologies to collect: browsing history across other websites; precise geolocation; device fingerprints; email addresses or contact details; social media activity; or any inferred interests or demographic attributes. The absence of these mechanisms is a design decision, documented here so you can rely on it.

§12

Retention of Session Data

Session cookies expire when your session ends or within 30 days, whichever comes first. The localStorage preference flag persists until you clear it or it is removed by browser storage-management policies. ProofChain server logs — which may record IP addresses and request metadata for security purposes — are retained for a limited period, access-controlled, and not used for advertising or profiling.

§13

Do Not Track

Because ProofChain does not engage in cross-site tracking, we honor the spirit of Do Not Track (DNT) and Global Privacy Control (GPC) signals by default: there is no tracking to disable. Where a browser sends a DNT or GPC signal, no additional action is required on our part because no tracking mechanisms are deployed.

§14

International Visitors

The ProofChain website is operated from the United States but is accessible worldwide. Visitors from the European Economic Area, the United Kingdom, and Switzerland retain the full protections of the GDPR, the UK GDPR, and the Swiss FADP respectively, including the integrity and confidentiality guarantees in §10. Where personal data is transferred across borders, such transfers are governed by Standard Contractual Clauses where applicable, as further described in our Data Processing Addendum.

§15

Changes to This Policy

We may update this Cookie Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be announced by posting the revised policy on this page, with the effective date updated accordingly. Where a change would introduce a new category of cookie or storage, we will obtain consent before doing so where required by law.

§16

Contact Us

If you have questions about this Cookie Policy, the storage mechanisms we use, or your rights, contact our Data Protection Officer:

dpo@proofchain.us security@proofchain.us Privacy Policy Data Processing Addendum

Summary. ProofChain uses no tracking cookies, no advertising cookies, and no third-party analytics. We use a single essential session cookie, a localStorage preference flag, and — only when you check out — Stripe's checkout cookies. You can clear or block all of these in your browser settings at any time. This policy is part of our GDPR Article 5(1)(f) integrity and confidentiality commitments.

PROOFCHAIN

Verifiable AI agent compliance infrastructure. On-chain identity. Tamper-evident audit trails. Automated regulatory reporting.

Product

Dashboard KYA Report Pricing

Legal

Privacy Policy Terms of Service Cookie Policy Data Processing Addendum

Trust

Security KYA Report a Vulnerability

Not Legal Advice. ProofChain is a technology platform and compliance automation tool. ProofChain is not a law firm, does not employ attorneys, and does not provide legal advice, legal opinions, or legal representation. The compliance reports, templates, and documentation generated by ProofChain are provided for informational and operational purposes only. You should consult qualified legal counsel regarding your specific regulatory obligations under the EU AI Act, GDPR, SOC 2, ISO standards, NIS2, or any other applicable law or regulation.

On-Chain Data. Agent audit trail data recorded on the X1 blockchain is immutable by design. ProofChain cannot delete, modify, or redact data committed to the blockchain. This is a feature, not a bug — it ensures tamper-evidence. Prior to recording agent actions on-chain, ProofChain encrypts all potentially personal data using HXMP such that only authorized key holders can decrypt it. If you require erasure of personal data under GDPR Article 17, ProofChain will destroy the encryption keys for the relevant records, rendering them permanently inaccessible, which constitutes erasure under applicable data protection law. However, the encrypted ciphertext will remain on the blockchain ledger. By using ProofChain, you acknowledge and accept this architectural constraint.

PROOFCHAIN · X1 CHAIN · FKwU1im523MSGnuJG6YLHEZu4rUGj3xqxHJ6ipQMBG9B © 2026 ProofChain. All rights reserved.