why we built this
The consent layer for personal data — cryptographically provable, revocable, and published as an open protocol. The incumbent model sells screenshots and asks to be trusted. We built the alternative.
Many Software Enterprises LLC · sales@pryvc.com
01 · the problem
Type their details into hundreds of forms, keep no record of who has what, and have no practical way to revoke. When the spam starts, there's no receipt to point to.
Sit on decaying, legally ambiguous contact data. Their proof of consent is an artifact in a vendor's vault — unverifiable by anyone else, and increasingly insufficient when challenged.
Are the enforcers. TCPA verdicts keep setting records, so the carriers, lenders, and lead buyers writing the checks now audit consent before paying — and they want evidence naming exactly who got what, when, under which disclosure. Medicare wrote the naming requirement down explicitly; it is not the only place the bill arrives.
The market's answer to all three is custody: we recorded it, trust us. That's a trust product in an era that demands proof.
02 · the two models
Almost every consent record in existence is custodial: a vendor watched something happen, stored an artifact, and will vouch for it later. That works right up until the moment it's contested — because verifying it means asking the vendor to confirm its own record, and the party asking has no independent way to check.
| The custody model | What we built instead | |
|---|---|---|
| How it is verified | Ask the vendor; trust the answer | Recompute the hashes yourself, against a published spec |
| If the vendor disappears | The evidence goes with them | An evidence pack still verifies offline |
| Session replay | Yes — and genuinely useful | Not offered. We bet on re-computable over re-watchable. |
| The disclosure text | Often a screenshot of a page that has since changed | Verbatim words and their SHA-256, hashed into the record |
| The site's terms that day | Not captured | Snapshotted, content-hashed, re-checked daily afterwards |
| Every named recipient | A detail on the page | Sorted and hashed into the fingerprint |
| The end of consent | Out of scope | Revocation, cease deadlines, affidavits — first class |
| The person it is about | Not a participant | Free account, their own receipt, their own removals |
| Pricing | Metered per certificate | Fixed annual. Never metered |
We concede replay honestly — it is a real strength and we don't have it. A replay shows what a session looked like; a fingerprint proves what was agreed to, and can be checked by a carrier, a regulator, or a court without asking us anything.
On pricing, the honest version. Metered certificates are genuinely cheaper at low volume, and we would rather say so than pretend otherwise. Against our flat $1,999 the crossover sits somewhere around 1,100–2,800 leads a month, depending on your rate band. Above it the lines diverge and never reconverge: at 10,000 leads a month, metering runs roughly $7,200–$9,600 a year for evidence you still cannot independently verify — often paid on both sides of the same transaction. Our certified-consent tier is $1,999 at any volume. Metering prices the right thing to do in proportion to how much of it you do. A flat fee doesn't.
Figures from ActiveProspect's published TrustedForm Retain rates as of August 2026 ($0.12–$0.15 per certificate for the first 1,000, falling to $0.06–$0.08 above 50,000; Verify from $0.15 per lead). Enterprise contracts are negotiated individually and are not public — check your own quote rather than ours.
03 · what this is
A widget seals each form submission into a certificate binding the verbatim disclosure, the named entity list, the page, the timestamp, and the site's policies as they read that day — publicly verifiable at a URL by any carrier, buyer, or regulator. It requires no consumer adoption whatsoever: the visitor ticks the business's own box on the business's own form and need never have heard of PRYVC. This is the answer to the two-sided cold start — the revenue side works at zero network, and the network makes it better rather than possible.
One click shares exactly the fields a business requests — scoped, purposed, expiring, revocable. Update once, every active share refreshes. Revoke, and a tracked 10-business-day cease-contact clock starts. Silence becomes evidence.
A browser extension that fills any form on the web from the user's encrypted profile and records a receipt — even on sites that never integrated PRYVC. Zero-integration distribution: consumers bring PRYVC to the web themselves, and every fill feeds the Data trail and the removal funnel.
The mechanics are an open, published specification with normative test vectors (shareprotocol.org) — plus an independent verifier written from the spec text, not ported from our code. Two implementations agreeing is what makes SP/1 a protocol rather than a file format. PRYVC is the reference implementation: the standard-setting position, not one vendor among many. Export an evidence pack and it verifies offline, years later, whatever has happened to us.
All of it is live in production today — the app, the portal, the certificate API, the public ledger, the extension on the Chrome Web Store. Don't take that on faith either:
04 · why now
In January 2026, Verisk sold Verisk Marketing Solutions — the parent of Jornaya — to ActiveProspect, maker of TrustedForm. The two established consent-certification vendors are now one company. Every buyer renegotiation used to force each vendor to reference the other's pricing; that discipline is gone, and the only leverage left is whatever was drafted into contracts at signing. One supplier, metered pricing, custodial evidence — and if that supplier raises prices, changes terms, or gets acquired again, the records go with it. That is not a hypothetical anymore. It just happened to everyone holding a LeadiD certificate.
The second clock is quieter but longer: AI agents are beginning to fill forms and exchange personal data on people's behalf. Consent tooling built on session replay and behavioral signals assumes a human at a browser — mouse movement, keystroke timing, time-on-page. An agent produces none of that, so its session either looks like fraud or proves nothing. A protocol with published test vectors is exactly what agents can implement; screenshots are exactly what they can't. Our own agent surface deliberately offers no tool that can grant consent — an agent can read, update, and revoke, but agreeing still requires a person at a consent screen.
We're not claiming to know when agent traffic becomes the majority. We're saying evidence built to be recomputed survives that shift, and evidence built to be watched does not.
05 · what we refuse to do
We never sell, rent, or broker data. We are never a party to the disclosure — the consumer is. PRYVC records what they chose to share; it does not acquire it. A consent network representing only businesses is a data broker with better manners, so the consumer side is free and stays free.
We don't read what we hold. Consumer PII is envelope-encrypted per user, keys held apart from the database, with no staff read path — decryption is request-scoped and every access is written to the audit chain. We word this precisely rather than claiming we're incapable of reading it: we hold the keys, and saying otherwise would be a lie. What we can prove is that every access leaves a record you can check.
We don't meter consent. Fixed annual pricing, never per-lead, never per-record. There is no per-record price because there is no record for sale.
We don't grant consent for anyone. Not for agents, not for the extension, not for a business. Every mechanism we ship — the Share button, the widget, the MCP server — is structurally incapable of ticking a box on a person's behalf.
We don't ask to be believed. The audit chain is public, anchored externally every 15 minutes, and verifiable in your own browser. The spec is open under CC BY 4.0 with no patent claims over independent implementations. If we vanished tomorrow, every evidence pack ever exported would still verify.
Everything here is built and running. If you run forms that collect personal data — or you're simply tired of not knowing who has yours — both sides are open today, and the specification is open whether you use us or not.
Last reviewed August 2026. This page cites dated market events and competitor pricing; both move.
TrustedForm and ActiveProspect are trademarks or registered trademarks of ActiveProspect, Inc. Jornaya, LeadiD, and Verisk are trademarks or registered trademarks of their respective owners. Third-party marks appear here for identification and factual comparison only; their use implies no affiliation, sponsorship, or endorsement, in either direction.