Policy
Privacy
Prufture is designed so that a report can be trusted without knowing who sent it. This page describes what actually happens to your data, including the parts that cannot be undone.
Last updated: 30 September 2026
In short
- You do not create an account. We never ask for your name, email, phone number or ID.
- Your photo stays on your phone. We upload a fingerprint of it, not the picture, unless you choose to share it with the programme team.
- Only an approximate area is published — never your exact position.
- A small, fixed set of non-personal fields is written to a public blockchain, where it is permanent and cannot be deleted by anyone, including us.
What leaves your phone when you send a report
Exactly four pieces of information, plus a signature proving they came from your device:
- Photo fingerprint
- A SHA-256 hash of the photo — a one-way fingerprint. The image itself is not uploaded unless you choose to share it (see “Sharing a photo” below). The fingerprint cannot be turned back into the picture.
- Activity
- Which field activity you are reporting on. Not linked to a person.
- Approximate area
- A 5-character geographic cell, roughly a few kilometres across. This is the only location that is signed or published. See “Location” below.
- Capture time
- When the photo was taken.
- Device signature
- A digital signature and its matching public key, created by a private key generated on your phone and held in the operating system’s secure storage (iOS Keychain / Android Keystore). The key never leaves the device and is not linked to your identity.
What stays on your phone
- The photo itself, unless you choose to share it.
- The private signing key.
- Your queue of reports, including any not yet sent.
Deleting the app removes all of these from your device. Reports already sent cannot be recalled — see “What is permanent”.
Sharing a photo
A photo is not uploaded unless you choose to share it. That happens only in two ways: you turn on “Share photos with the programme team” for a report (it starts off), or the programme team asks to see the photos of a report and you say yes in the app. You can say no; the report still counts.
- A shared photo is encrypted on your phone to the programme team’s key before it is sent. The servers that store it cannot open it.
- It is deleted after 90 days.
- It is never shown on the public report page and never written to the blockchain.
Location
Location is required to submit a report, because a report about a place is not useful without one. Two different things happen to it, and the difference matters:
- The approximate area — a coarse cell of roughly a few kilometres — is the only location that is signed, published, or written to the blockchain. It is shown on the public verification page.
- The precise point is encrypted on your phone to the programme team’s key before it is sent. It is stored as an unreadable blob. It is never published, never written to the blockchain, and the servers that hold it cannot open it. Only a holder of the programme team’s private key can, for audit purposes.
What is permanent
When a report is confirmed, the photo fingerprint, activity, approximate area and capture time are written to a public blockchain (Base). This is what makes a report independently checkable later. It also means:
- That record is public and readable by anyone.
- It cannot be edited or deleted — not by you, not by the programme team, not by us. No deletion request can remove it, because no one controls the network.
- This is why no personal data is ever put there. The four fields above are all that is written.
Face check
Prufture has an optional live-person face check on iPhone (Me → Face check). It is never required to send a report. Nothing in this section happens unless you choose to take the check.
It asks only one question: was a live person in front of the camera? It does not identify you, match your face against anyone, or prove that you are a unique person.
- Processed by Amazon Web Services. During the check, a short video of your face is streamed from the app to AWS (Amazon Rekognition Face Liveness), which analyses it on our behalf and returns a result to our server.
- No face image is stored. We set up the check so AWS writes no images to storage and returns no audit images. AWS’s answer can still include a single still frame; our server reads only the pass/fail result and the confidence score from that answer and discards the rest in memory, without storing, logging or forwarding any image. No image of your face ever reaches the app, our database, the public verification page or the blockchain.
- Only a yes/no is kept. From the check, Prufture keeps one pass/fail value. If you pass, your phone keeps a signed receipt (a pass/fail value and a time, no image) for up to 30 days, and each report you send in that time is marked “verified person: yes”. A failed or unfinished check keeps nothing.
- No face template or other biometric identifier is created or kept by Prufture, and nothing from the check is written to the blockchain.
An older selfie step is also switched off by default and is not part of the standard reporting flow. Where it is switched on, a few camera frames are sent once to our server to produce the same yes/no answer and are not stored.
Programme pass
The app makes a pass code on your phone and keeps it there (Me → Programme pass). If you take part in a programme, you show the code to your coordinator once, in person, and they add it to the programme list.
- After a report is sent, the phone attaches a check that says only that the report came from someone on the programme list. It does not reveal which person, and it does not send the code, your name, phone number or location.
- The result (confirmed or not) is stored with the report on our server. Nothing from the pass is written to the blockchain.
- The pass is optional. Reports send whether or not you are on a list.
Notifications
If you allow notifications, the app registers a push token against a randomly generated device identifier. It is not connected to your name, phone number or report history.
Subscriptions
Reporting is free and always will be. A paid subscription exists only for programme coordinators and organisations reviewing reports. Purchases are processed by Apple or Google and managed through RevenueCat; we receive a subscription status against an anonymous identifier. We never receive your card details. We do not require an email address to subscribe.
What we do not do
- No advertising, no ad identifiers, no third-party analytics or tracking SDKs.
- We do not sell or share personal data, because we do not collect it.
- We do not upload your photo library. The app cannot read it.
- We do not record audio.
Your choices
You can withdraw camera, location or notification permission at any time in your device settings; the app will stop being able to create new reports. Deleting the app erases the on-device data listed above. Because reports carry no identifier for you, we cannot locate “your” reports in order to delete them on request — and the blockchain records cannot be deleted by anyone in any case. This is a deliberate trade-off: it is the same property that stops anyone linking a report back to you.
Children
Prufture is intended for adults taking part in a field programme. It is not directed at children and we do not knowingly collect data from them.
Status of this software
Prufture is an independent prototype, built in response to a challenge presented by UNICEF at a hackathon. It is not a UNICEF product and carries no UNICEF endorsement, partnership or adoption. Data is currently written to a test network.
Contact
Questions about this policy: see the support page.