Consent Is a Receipt, Not a Checkbox

By , founder of PRYVC

PRYVC is live today. The whole company fits in one sentence: a checkbox is an assertion; a receipt is evidence — and consent should be a receipt.

Here’s the test I use. Months after someone opted in, can you produce what they were actually shown? Not your current privacy policy — the disclosure as it read that day, the fields they agreed to share, who was named as receiving them, on what page, at what time. If the answer is no, you don’t have consent. You have a memory of consent, and memories don’t survive audits.

What a receipt actually looks like

When someone shares through PRYVC — the Share button, a certified-consent form, the browser extension — both sides get the same thing: a certificate binding the verbatim disclosure text, the exact fields, the named recipients, the page, and the timestamp into a SHA-256 fingerprint. The certificate has a public verification URL. A carrier, an auditor, or a regulator can check it without asking us for permission — it shows the proof, never the personal details.

And every consent event gets appended to a public ledger where each entry cryptographically commits to the one before it. Rewrite history and the chain breaks, visibly, in anyone’s browser. Every fifteen minutes the chain head gets anchored to a separately operated ledger, so even we can’t quietly start over.

This is a business product wearing a consumer mission

People assume a consent company is anti-business. Backwards. The businesses buying leads are the ones holding the liability when proof doesn’t exist. The incumbent model charges them per certificate for evidence they can’t independently verify — evidence held by a custodian, priced by the record, on both sides of the same transaction.

We charge flat. $299 a year for the Share button and portal. $1,999 for certified consent at any volume — never metered, because metering prices the right thing to do in proportion to how much of it you do.

For consumers, the core is free forever: one encrypted profile, one-click sharing, a data trail of everywhere your details went, and revocation with an actual deadline attached. Encrypted meaning envelope-encrypted per person, keys held apart from the database, every access written to the audit chain. I won’t tell you we’re incapable of reading it — we hold keys, and saying otherwise would be a lie. I’ll tell you every access leaves a record you can check. That’s a claim I can stand behind.

Twenty-plus years of building other people’s software taught me you get maybe one shot at a company that’s an argument. This is mine: proof beats promises, for everyone in the transaction.

Go check the ledger. It’s running right now.

keep reading