1. Acceptance of Terms
By using FactLockCam, you agree to these Terms of Service. FactLockCam provides tamper-evident digital archive services for media certification, encryption, and workflow support.
2. Digital Archive Certification
FactLockCam supports authenticity heuristics through three technical pillars:
- Integrity: Cryptographic proof that a file is unaltered (SHA-256).
- Ownership: Association with your authenticated identity and device signing
where enabled. The
device_key_classrecorded in a manifest is reported by the device and is not independently attested; it describes the signing key class, not the camera hardware or scene authenticity. - Timestamping: A Polygon record of a signed capture manifest hash when notarization is active. The later bound is the block that included that transaction. When the device was online at capture, an earlier Polygon block hash is also committed, producing a capture window. Offline captures have no earlier bound.
This produces a certificate draft that documents the cryptographic state of a digital asset. It supports disclosure workflows but does not guarantee admissibility under FRE 902. Unlocking a shared proof package with a password confirms only that the package was sealed with that password; it is not proof that the hash was published on Polygon.
3. Permanent Ledger Records
You acknowledge that the Polygon blockchain is a permanent record. Once a cryptographic hash is anchored, it cannot be modified or deleted. FactLockCam has no authority or ability to alter blockchain records.
4. User Responsibility (The Verification Bridge)
A successful verification requires two components under your exclusive control:
- The Artifact: The original, unaltered file.
- The Identity: The credentials used to sign the asset.
If either is lost or modified, the cryptographic link for verification cannot be restored.
5. Non-Custodial Access Protocol
CRITICAL: FactLockCam utilizes non-custodial security. We do not store your encryption keys or backup passwords. We cannot reset your password, decrypt your archive, or recover lost keys. You are solely responsible for device access and for exporting and safeguarding your .factlock sovereign key backup (Account & Settings → Backup & Restore).
6. User-Managed Backups (Keys and Sealed Media Copies)
FactLockCam offers two user-managed backups, both created and stored by you. Neither is a download from our servers, and FactLockCam holds neither file nor its password.
- .factlock (keys): a password-protected file created in Account & Settings → Backup & Restore → Export archive keys. It contains your sovereign decryption keys (EVM signing key and archive AES key)—not your photos or videos. It is imported on the locked screen after Lock Archive or a reinstall and is the only way to read sealed files still on the device or in cloud sync.
- .flcproof (one sealed item): an optional password-protected copy of a single item created with Export sealed backup from any archive item. It contains that item's original media, title, description, and signed capture record. It is restored with Restore sealed backup (Account & Settings → Backup & Restore) and is unlockable with its own password even if your keys are lost.
Each file can be restored only with the password you set for it. FactLockCam cannot restore access to an archive without your .factlock backup and its password, and cannot recover a .flcproof whose password is lost. Restoring a sealed backup re-admits an existing record; it does not create a new seal, re-anchor the record, or consume plan capacity.
Re-export your .factlock periodically, before Lock Archive, before uninstalling the app, or before replacing your device. Keys are stable for a given app install; you do not need to export after every capture.
7. Where Your Archive Lives
FactLockCam is local-first:
- On your device: Sealed media is stored as encrypted
.sealfiles in the app sandbox. This is the archive you browse, verify, and export from the app. - On our servers (optional sync): After sealing, ciphertext may upload for the same signed-in account. These blobs are zero-knowledge—we cannot read them, and they are not a user-managed media backup you download from a dashboard. They can help re-sync after reinstall only when you import your .factlock keys and sign in with the same email.
- Send Proof and sealed backups: password-sealed
.flcproofpackages you deliver or store yourself. They have no expiry and no access-attempt limit, and FactLockCam cannot revoke them. A sealed backup copy can be restored into the app with its password, but it is not a substitute for your .factlock key backup.
8. Key Custody Scenarios
Losing your keys without a .factlock backup means permanent loss of access to
all encrypted assets still on the device or in cloud sync—local .seal
files and any cloud ciphertext for your account. Only .flcproof sealed backups you
already saved remain unlockable, each with its own password.
| Scenario | Local keys | Local .seal | Cloud + account | .factlock backup | .flcproof sealed backups |
|---|---|---|---|---|---|
| Normal use | Present | Present | Present if sync ran | Optional; re-export periodically or before Lock/uninstall | Optional per-item copies |
Keys lost (no .factlock) | Gone | Unreadable | Unreadable | N/A — total loss of device and cloud assets | Still unlockable with their passwords; restorable after new keys exist |
| Lock Archive | Purged from device | Remain on device | Unchanged on server | Import on the locked screen to resume | Not needed |
| App uninstalled | Gone (OS wipes sandbox) | Usually gone with app data | Still on server for same email | Must import after reinstall + sign-in to decrypt cloud sync | Restore each item from Backup & Restore |
| Burn Account | Purged locally | Wiped locally | Account and linked cloud data deleted | Useless for that burned identity | Still unlockable; restorable into a new account as Historical |
Lock Archive ≠ Burn Account. Lock removes keys from this device but leaves local sealed files; import .factlock to resume. Burn permanently deletes your Supabase identity, associated cloud ciphertext, local archive, and keys—a prior .factlock cannot restore a burned account or its cloud archive.
9. Burn Account Is Irreversible
Burn Account (Account & Settings, with double confirmation) permanently destroys your remote account, profile-linked cloud storage, local archive database and sealed files, and cryptographic keys on the device. A .factlock file created before Burn cannot resurrect that identity or decrypt cloud data tied to the burned account. You may create a new account with the same email only as a fresh identity with no restored prior archive.
10. Integrity Maintenance
If the original file is modified or access to the certifying identity is lost, the link to the blockchain record is broken. FactLockCam cannot restore this connection.
11. Proof Package Delivery
Send Proof produces an offline, password-sealed .flcproof package that you share
yourself. FactLockCam cannot expire, revoke, or cap how many times a recipient opens it. If
the password is lost, the media cannot be recovered. Recipients should confirm the owner
address with the sender out-of-band. Unlocking a package with a password is not a chain
attestation. Export sealed backup writes the same container for your own custody; those copies
are user-managed and are not a cloud media backup from FactLockCam.
12. Limitation of Liability
A certificate draft is a mathematical record of a digital state. It is not a guarantee of physical truth, accuracy of content, or legal standing. When a capture window is shown, FactLockCam documents that the hashed media existed no later than the anchoring Polygon block, and no earlier than a committed prior block hash when one is present. It does not verify the underlying claims within the file.
13. Service Availability
Services are provided "as is". FactLockCam is not liable for blockchain network congestion, device-level hardware failure, or third-party service interruptions that may affect the transmission or verification of assets. Ledger notarization uses Polygon mainnet and a relay service; FactLockCam does not guarantee network uptime, transaction speed, gas prices, or receipt timing. Outages and delays may occur, and a sealed record may remain in a pending state until the network accepts the transaction.
14. Subscriptions
A subscription is not required to use FactLockCam. Free includes 5 lifetime seals and unlimited
Send Proofs. Paid plans add sealing capacity only; they do not add key recovery, key escrow, cloud
media backup, or data recovery of any kind. Self-custody .factlock and
.flcproof backups are available on every plan and are managed by you. FactLockCam
cannot restore lost keys or decrypt your archive under any plan. Auto-renewing plans are charged to your app store account and renew unless
cancelled at least 24 hours before the current period ends; manage or cancel in your store account
settings. Records you have already sealed remain available if a plan expires.