What the service does
You send us a file. We record its SHA-256 fingerprint, anchor that fingerprint to a trusted timestamp under RFC 3161, encrypt the file, and store it. You receive a printed certificate carrying the fingerprint, the moment of sealing, the address of the file's page, an access code, and the decryption key.
What the certificate proves — and what it does not
It evidences that this exact file existed, in exactly this form, at the moment it was sealed. That is a strong claim and we stand behind it: the fingerprint and the timestamp are independently verifiable by anyone, using the RFC 3161 token, without our involvement or continued existence.
It makes no claim whatsoever about:
- Authorship. We cannot know who made the file, and do not assert it.
- Originality. Sealing a file says nothing about whether it is new, copied, or derived from something else.
- Ownership or legal rights. The certificate is not a registration, a deposit, or a grant of any right. It is not a substitute for copyright registration, a patent filing, or a trade mark.
- Content. We cannot read the file after encryption, so we assert nothing about what is in it.
The certificate records that a file was submitted on a date. We can verify submission. We cannot verify authorship, and we do not pretend to.
Your rights in what you upload
You confirm at checkout that you created the work, or that you have the right to submit it. You keep every right you had in the file; sealing it grants us no licence to it beyond storing the encrypted bytes and, in the plaintext window before encryption, computing the fingerprint your certificate carries. What you may and may not seal is set out in our acceptable use policy.
The key, and what it means that we do not hold it
The decryption key is generated when your file is sealed, shown to you once, and printed on your certificate. For a posted certificate we hold a copy until delivery is confirmed or 14 days after posting, whichever comes first — long enough to reprint and repost if the letter goes astray. For self-print we hold it until you confirm you have saved it, or 72 hours, whichever comes first. In no case longer than 90 days.
After that, no copy exists anywhere. Three consequences follow, and all three are permanent:
- If you lose the key, your file cannot be recovered — by you, by us, or by anyone. We cannot reissue it. There is no support process that can rescue this, because there is nothing to rescue it from.
- We can reprint the seal record — the fingerprint, the date, the timestamp — because we retain those. We cannot reprint the key.
- Once the key is destroyed we cannot produce the contents of your file to anyone, including in response to a court order, a police request, or a notice under the Investigatory Powers Act. That is a property of how the system was built, not a policy we could change under pressure. Before then, we can. During the custody window described above we hold a copy of your key, and a lawful order would reach it. We would rather say so than claim an absolute that has an unstated exception at the start of every order.
Storage
Storage is indefinite and paid for once. There is no subscription and no renewal. "Indefinite" means we do not set an end date — not that we guarantee eternity, which no company can. What makes the word honest is our wind-down policy, which commits to 6 months' notice and a download window if storage ever has to end.
Deleting your file
You can destroy your file at any time, using your decryption key, from your file's page. Deletion is held for 7 days and announced by email, then becomes irreversible. There is no refund: storage was paid for once and indefinitely, so deleting reclaims nothing. The details are in our refunds policy.
What we are liable for
We are liable for failing to store your file, and for failing to produce a certificate that accurately reflects what you sent us. Where we are at fault, our liability is limited to the amount you paid for that file.
We are not liable for the consequences of a lost decryption key, because we cannot be: we have no copy, and you were told so before purchase, on the certificate, and in the emails. We are also not liable for any outcome that depends on what a third party — a court, an insurer, a publisher, a buyer — decides to make of the certificate. It is evidence of existence at a point in time; how much that is worth in a given dispute is not something we control or claim.
Nothing here limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.
Ending the agreement
We may refuse or remove a file that breaches the acceptable use policy. Because we cannot read files after encryption, that decision can only ever be made in the plaintext window before sealing, or on the basis of information from outside the file itself.
Law
These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. If you are a consumer, this does not remove any protection you have under the law of the country you live in.
Who we are
MADE BY A HUMAN LTD, registered in England and Wales,
company number 17393678.
Birchett Road,Farnborough, Hampshire, UK