Who We Are
Vorthra provides a platform for creating Vorthra Records for digital content. Users can upload a file or submit a public URL, make a legal confirmation, and generate a Vorthra Record with a unique Vorthra Record ID, recorded timestamp, SHA-256 hash, badge, QR code, and PDF record.
- Legal entity: Verified Presence Protocol, Inc.
- Registered address: 16192 Coastal Highway, Lewes, Delaware 19958, United States
- Mailing address: 3250 NE 1st Ave, Suite 305, Miami, FL 33137, United States
- Privacy contact: privacy@vorthra.com
- Security contact: security@vorthra.com
- Support contact: support@vorthra.com
- Legal contact: legal@vorthra.com
Scope
This Privacy Policy applies to:
- The Vorthra website and authenticated dashboard.
- Organization workspaces and team features.
- Public Vorthra Record pages, including QR, PDF, badge, and API projections.
- Billing and subscription flows.
- API access and API key usage.
- Support, security, and operational communications.
This policy does not apply to third-party websites or services that you access through public source URLs, payment pages, OAuth providers, external thumbnails, or linked content.
Information We Collect
Depending on how you use Vorthra, we may collect:
- Account and authentication data, including user ID, name, email, email verification status, profile image URL, authentication/account state used to distinguish standard and enhanced account verification states, OAuth account data, and session records.
- Organization and workspace data, including organization name, slug, type, display name, legal name, logo URL, website, industry, country, billing email, support email, members, roles, and public indexing preferences.
- Invite and email data, including invitee email, invited role, invite timestamps, and hashed invite tokens.
- Vorthra Record data, including source type, title, URL or file metadata, thumbnail data, source metadata, SHA-256 hash, recorded timestamp, authentication/account verification level, creator user or API key, processing status, and failure reason.
- Billing and subscription data, including Stripe customer ID, subscription ID, plan, status, billing period, trial dates, and webhook event records.
- API key data, including key name, prefix, scopes, creator, last-used timestamp, revocation timestamp, expiry timestamp, and HMAC hash of the raw key.
- Audit logs for security, accountability, and organization administration.
- Technical logs and operational context used to debug errors and protect the service.
Public Vorthra Records
Public Vorthra Records are intentionally public. Anyone with the URL may be able to view the record, download a PDF, fetch a public JSON projection, generate a QR code, or access badge data.
A Vorthra Record proves that a verified person created a Digital Record for a specific version of a file at a recorded point in time. A Vorthra Record does not prove authorship, factual truth, legality, who physically created the content, official status, copyright ownership, license scope, consent validity, or legal enforceability.
Public records may show:
- Vorthra Record ID, status, recorded timestamp, SHA-256 hash, and record creation time.
- Source title, content kind, source URL for URL records, thumbnail URL, and file size label where available.
- Verified person display name, profile image, and authentication/account verification level.
- Rights holder name, organization display name, organization logo, and branding settings.
If content later produces a different cryptographic hash from the original Vorthra Record, the content may no longer correspond to the originally recorded state and may be identified as modified or altered.
Visual overlays, QR codes, badges, and public trust marks are designed as verification indicators only. Verification validity should be confirmed through the active public Vorthra Record, associated cryptographic hash, and current verification status.
Vorthra does not independently determine whether content is AI-generated, synthetic, manipulated, misleading, deceptive, or altered before recording unless explicitly stated otherwise by the platform.
Public records are configured not to be indexed by search engines by default unless the organization opts in to public indexing.
Public Record Analytics
When someone views a public Vorthra Record, Vorthra collects limited analytics so organizations can understand record usage.
- Vorthra Record ID of the viewed record.
- View source, such as direct, QR, embed, or share.
- Daily salted SHA-256 hash of the visitor IP address.
- User agent and referrer, both truncated to maximum lengths.
- Country code and city hints from hosting or proxy headers where available.
- Device kind and timestamp.
We do not store the raw visitor IP address for public record analytics. The raw IP address is used transiently from request headers to generate a daily salted hash. We do not call an external geolocation API for this analytics flow.
How We Use Information
- Create and manage user accounts.
- Authenticate users with magic links, OAuth, sessions, and cookies.
- Provision and manage personal and business organizations.
- Create, process, display, and verify Vorthra Records.
- Generate QR codes, badges, PDFs, and public Vorthra Record pages.
- Calculate and display record and organization analytics.
- Provide billing, checkout, customer portal, and subscription management.
- Enforce plan limits, roles, feature access, and API key scopes.
- Maintain audit logs, investigate issues, prevent abuse, and improve reliability.
- Comply with legal obligations and enforce our terms.
Cookies And Similar Technologies
Vorthra uses cookies and similar technologies primarily for authentication, session management, route protection, and security. Public record analytics are sent through first-party requests and do not store raw visitor IP addresses.
More detail is available in our Cookie Policy at /cookies.
How We Share Information
We do not sell personal data. We may share information with:
- Hosting, database, CDN, object storage, Redis or queue infrastructure, email, logging, and monitoring providers.
- Stripe for checkout, billing portal, subscription management, invoices, and payment-related events.
- Google OAuth when Google sign-in is enabled.
- Organization owners, admins, and members according to their roles.
- Platform administrators for support, security, billing, and operations.
- Public viewers when information is intentionally included on public Vorthra Records.
- Authorities or third parties when required by law, legal process, or to enforce our rights.
Retention And Your Rights
We retain information for as long as needed to provide the service, maintain security, comply with legal obligations, resolve disputes, and enforce agreements. Public Vorthra Records, audit logs, billing records, and security logs may need to be retained for legitimate business, legal, compliance, or fraud prevention reasons.
Depending on your location, you may have rights to access, correct, delete, export, object to, or restrict certain processing of your personal data. To make a privacy request, contact privacy@vorthra.com.
Security And Contact
Vorthra uses hashed magic-link tokens, hashed invite tokens, HMAC-hashed API keys, session-based authentication, role-based organization access, restricted public record projections, daily salted IP hashes for public analytics, rate limiting, and audit logs.
For security reports, contact security@vorthra.com. For support, contact support@vorthra.com.