Version 7 · Last updated: 21 September 2026 · Version française
In short: no data sold, no advertising, no profiling. This site sets no cookies. Your account data is hosted in France and the most sensitive of it is encrypted at rest. You delete your account directly in the app. One thing to know: the file of a sealed proof carries its exact position; the public verification page only shows an approximate area.
Evidiq, a French société par actions simplifiée with a capital of €1,000, registered with the Paris Trade Register (R.C.S.) under number 107 992 760, headquartered at 47 rue Vivienne, 75002 Paris, France. For any question about your data: contact@evidiq.io.
If you captured a proof from a link an organisation sent you, that organisation is responsible and Evidiq is its processor: see If you received a capture link.
This site sets no cookies, embeds no trackers and loads no third-party resources (no remote fonts, no audience analytics). Browsing it collects no personal data, apart from the server’s technical logs (IP address, timestamp), kept temporarily for security purposes.
Information sent by email to contact@evidiq.io is used only to answer your request. It is neither shared nor used for any other purpose.
Evidiq lets you capture photos and videos, then seal them to prove their origin. To deliver this service, the app and the API process the following data.
No data is sold. No advertising. No profiling for commercial purposes.
We rely on processors for five functions: hosting of the servers and data (in France), sending of sign-in emails (in the European Union), automated detection of AI-generated or AI-manipulated content, processing of purchases through the app store, and mapping and address suggestions (in the European Union). Weather at the time of capture relies on another recipient, MET Norway (European Economic Area), which receives only a position rounded to about 1 km. The detailed list, with each one’s location, is kept up to date on the Subprocessors page.
The AI-detection analysis covers the complete sealed file and may involve processing outside the European Union. We transmit the file only for this analysis. The country of processing and its contractual safeguards will be published on the Subprocessors page as soon as they are contractualised.
Proofs are anchored in time via Bitcoin (OpenTimestamps). Only a Merkle root, an anonymous digest committing a whole batch of proofs, is published. Neither your photos and videos, nor their fingerprints, nor any personal data go to the blockchain. The link between your proof and that root is kept only at Evidiq and deleted with your account: after deletion, the public root no longer points to anything.
When you share a proof, you create a public link. Anyone who holds it can view the verification page (verdict, approximate capture area) and download the original file, which contains the exact position and the capture details. Share a link the way you would share the file itself.
You can revoke each link at any time from the app (“My links”): the page stops responding. These pages are not indexable by search engines. A copy already downloaded or saved by someone before revocation is, however, beyond our reach.
You are responsible for the content you capture, including when third parties appear in it: make sure you have the right to photograph or film them. Evidiq processes this content on your behalf, as described here. If a person appearing in a proof exercises their rights with us, we handle their request under the GDPR and may need to relay it to you.
Each proof receives an index out of 100. It adds up the points of the checks measured at capture: it evaluates the origin of the file and its integrity since sealing. It does not judge the truthfulness of the photographed scene. The scoring rubric is public: how to read the index. If you dispute the result of a proof, write to contact@evidiq.io: your request is reviewed by a person, not by an algorithm.
The most sensitive data stored in the database (email address, position, capture timestamps, manifests, sensor fingerprints, logs) is encrypted at rest (AES-256-GCM). All communications are encrypted in transit (TLS). The servers are hosted in France.
Under the GDPR, you have the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of your consent.
API integrators have dedicated endpoints for deletion and export, described in the integration documentation.
You can also lodge a complaint with the CNIL, the French data protection authority: cnil.fr.
An organisation that is an Evidiq customer can send you a link to capture a proof at its request (a photo of a meter, a parcel, damage…). You have no Evidiq account, and you do not create one.
Who is responsible. The organisation that sent you the link is the data controller: it decides the precise purpose and the legal basis. Evidiq acts as its processor and handles your data on its instructions. This section describes what Evidiq does for it; for its own rules, see its privacy policy.
What is collected:
Why. To build the proof requested, seal it, and let the organisation, then those it shares it with, verify it. No advertising, no profiling.
Who receives it:
How long. For as long as the organisation keeps the proof. Our backups are erased within 90 days at most.
Your rights. You can ask for access to your data or its erasure without an account, at contact@evidiq.io. We forward your request to the organisation and act on its instructions: a proof may be part of a file it must keep. You can also lodge a complaint with the CNIL: cnil.fr.
The service is intended for people aged 15 and over. Signing up only requires an email address and age is not verified; if we learn that an account belongs to someone younger, we delete it.
Every substantial change is announced by email to account holders, and the version number at the top of this page is updated. Previous versions are available on request.