Skip to content
FactLockCam

Legal

Terms of Service

Last updated September 2026. Verifies the exact file and signed record — not the physical truth of the scene.

1. Acceptance of Terms

By using FactLockCam, you agree to these Terms of Service. FactLockCam provides tamper-evident digital archive services for media certification, encryption, and workflow support.

2. Digital Archive Certification

FactLockCam supports authenticity heuristics through three technical pillars:

  • Integrity: Cryptographic proof that a file is unaltered (SHA-256).
  • Ownership: Association with your authenticated identity and device signing where enabled. The device_key_class recorded in a manifest is reported by the device and is not independently attested; it describes the signing key class, not the camera hardware or scene authenticity.
  • Timestamping: A Polygon record of a signed capture manifest hash when notarization is active. The later bound is the block that included that transaction. When the device was online at capture, an earlier Polygon block hash is also committed, producing a capture window. Offline captures have no earlier bound.

This produces a certificate draft that documents the cryptographic state of a digital asset. It supports disclosure workflows but does not guarantee admissibility under FRE 902. Unlocking a shared proof package with a password confirms only that the package was sealed with that password; it is not proof that the hash was published on Polygon.

3. Permanent Ledger Records

You acknowledge that the Polygon blockchain is a permanent record. Once a cryptographic hash is anchored, it cannot be modified or deleted. FactLockCam has no authority or ability to alter blockchain records.

4. User Responsibility (The Verification Bridge)

A successful verification requires two components under your exclusive control:

  • The Artifact: The original, unaltered file.
  • The Identity: The credentials used to sign the asset.

If either is lost or modified, the cryptographic link for verification cannot be restored.

5. Non-Custodial Access Protocol

CRITICAL: FactLockCam utilizes non-custodial security. We do not store your encryption keys or backup passwords. We cannot reset your password, decrypt your archive, or recover lost keys. You are solely responsible for device access and for exporting and safeguarding your .factlock sovereign key backup (Account & Settings → Backup & Restore).

6. User-Managed Backups (Keys and Sealed Media Copies)

FactLockCam offers two user-managed backups, both created and stored by you. Neither is a download from our servers, and FactLockCam holds neither file nor its password.

  • .factlock (keys): a password-protected file created in Account & Settings → Backup & Restore → Export archive keys. It contains your sovereign decryption keys (EVM signing key and archive AES key)—not your photos or videos. It is imported on the locked screen after Lock Archive or a reinstall and is the only way to read sealed files still on the device or in cloud sync.
  • .flcproof (one sealed item): an optional password-protected copy of a single item created with Export sealed backup from any archive item. It contains that item's original media, title, description, and signed capture record. It is restored with Restore sealed backup (Account & Settings → Backup & Restore) and is unlockable with its own password even if your keys are lost.

Each file can be restored only with the password you set for it. FactLockCam cannot restore access to an archive without your .factlock backup and its password, and cannot recover a .flcproof whose password is lost. Restoring a sealed backup re-admits an existing record; it does not create a new seal, re-anchor the record, or consume plan capacity.

Re-export your .factlock periodically, before Lock Archive, before uninstalling the app, or before replacing your device. Keys are stable for a given app install; you do not need to export after every capture.

7. Where Your Archive Lives

FactLockCam is local-first:

  • On your device: Sealed media is stored as encrypted .seal files in the app sandbox. This is the archive you browse, verify, and export from the app.
  • On our servers (optional sync): After sealing, ciphertext may upload for the same signed-in account. These blobs are zero-knowledge—we cannot read them, and they are not a user-managed media backup you download from a dashboard. They can help re-sync after reinstall only when you import your .factlock keys and sign in with the same email.
  • Send Proof and sealed backups: password-sealed .flcproof packages you deliver or store yourself. They have no expiry and no access-attempt limit, and FactLockCam cannot revoke them. A sealed backup copy can be restored into the app with its password, but it is not a substitute for your .factlock key backup.

8. Key Custody Scenarios

Losing your keys without a .factlock backup means permanent loss of access to all encrypted assets still on the device or in cloud sync—local .seal files and any cloud ciphertext for your account. Only .flcproof sealed backups you already saved remain unlockable, each with its own password.

Scenario Local keys Local .seal Cloud + account .factlock backup .flcproof sealed backups
Normal use Present Present Present if sync ran Optional; re-export periodically or before Lock/uninstall Optional per-item copies
Keys lost (no .factlock) Gone Unreadable Unreadable N/A — total loss of device and cloud assets Still unlockable with their passwords; restorable after new keys exist
Lock Archive Purged from device Remain on device Unchanged on server Import on the locked screen to resume Not needed
App uninstalled Gone (OS wipes sandbox) Usually gone with app data Still on server for same email Must import after reinstall + sign-in to decrypt cloud sync Restore each item from Backup & Restore
Burn Account Purged locally Wiped locally Account and linked cloud data deleted Useless for that burned identity Still unlockable; restorable into a new account as Historical

Lock Archive ≠ Burn Account. Lock removes keys from this device but leaves local sealed files; import .factlock to resume. Burn permanently deletes your Supabase identity, associated cloud ciphertext, local archive, and keys—a prior .factlock cannot restore a burned account or its cloud archive.

9. Burn Account Is Irreversible

Burn Account (Account & Settings, with double confirmation) permanently destroys your remote account, profile-linked cloud storage, local archive database and sealed files, and cryptographic keys on the device. A .factlock file created before Burn cannot resurrect that identity or decrypt cloud data tied to the burned account. You may create a new account with the same email only as a fresh identity with no restored prior archive.

10. Integrity Maintenance

If the original file is modified or access to the certifying identity is lost, the link to the blockchain record is broken. FactLockCam cannot restore this connection.

11. Proof Package Delivery

Send Proof produces an offline, password-sealed .flcproof package that you share yourself. FactLockCam cannot expire, revoke, or cap how many times a recipient opens it. If the password is lost, the media cannot be recovered. Recipients should confirm the owner address with the sender out-of-band. Unlocking a package with a password is not a chain attestation. Export sealed backup writes the same container for your own custody; those copies are user-managed and are not a cloud media backup from FactLockCam.

12. Limitation of Liability

A certificate draft is a mathematical record of a digital state. It is not a guarantee of physical truth, accuracy of content, or legal standing. When a capture window is shown, FactLockCam documents that the hashed media existed no later than the anchoring Polygon block, and no earlier than a committed prior block hash when one is present. It does not verify the underlying claims within the file.

13. Service Availability

Services are provided "as is". FactLockCam is not liable for blockchain network congestion, device-level hardware failure, or third-party service interruptions that may affect the transmission or verification of assets. Ledger notarization uses Polygon mainnet and a relay service; FactLockCam does not guarantee network uptime, transaction speed, gas prices, or receipt timing. Outages and delays may occur, and a sealed record may remain in a pending state until the network accepts the transaction.

14. Subscriptions

A subscription is not required to use FactLockCam. Free includes 5 lifetime seals and unlimited Send Proofs. Paid plans add sealing capacity only; they do not add key recovery, key escrow, cloud media backup, or data recovery of any kind. Self-custody .factlock and .flcproof backups are available on every plan and are managed by you. FactLockCam cannot restore lost keys or decrypt your archive under any plan. Auto-renewing plans are charged to your app store account and renew unless cancelled at least 24 hours before the current period ends; manage or cancel in your store account settings. Records you have already sealed remain available if a plan expires.