Privacy Policy
Last updated: 6 October 2026
NotChanged (“we”, “us”) helps people prove that a PDF came from a stated source and has not changed since it was recorded. This policy explains what we collect when you use notchanged.com, our browser extensions, and our Android app.
Who we are
NotChanged is operated for the notchanged.com service. For privacy questions or data requests, email support@notchanged.com.
What the product does
- Browser extensions (Chrome, Firefox, and similar): when you download or prove a PDF over HTTPS, we record a fingerprint (hash) of the file, the source hostname (and a cleaned URL path without query tokens), and related capture metadata, then return a stamped verified PDF.
- Android app: when you share a PDF into NotChanged, we record the OS-attested sharing app identity (package name and signing certificate fingerprint) together with the file hash, and return a stamped verified PDF.
- Verify on the website: you upload a PDF; we compute its hash and look it up in our registry. We never store the file.
Information we process
- Document fingerprints: SHA-256 hashes of original and stamped PDFs, attestation or issuance identifiers, signatures, and source metadata (hostname, package name, certificate fingerprint, capture time, method).
- Device attestor keys: when an extension or app registers, we store a hashed API key and optional label so the device can create proofs.
- My Details (optional): if you choose to provide them — full name, email, phone, and/or address — we store them on your attestor profile, sync them from the extension or app, and may attach a snapshot to new proofs (shown on the verify page, not printed as raw personal data on the PDF stamp). We may check whether your full name appears in extractable PDF text and store a match result (matched / not found / unreadable / no profile name) without storing the PDF body.
- Email verification: if you add an email in My Details, we send a confirmation link via Resend from an address on notchanged.com (or a temporary fallback sender if needed). We store verification status and related tokens (hashed) with expiry.
- Admin sessions: the operator admin area may use cookies or session credentials to keep you signed in. Ordinary visitors of the public site do not need an account.
- Technical logs: hosting and database providers may process IP addresses, timestamps, and request metadata as part of operating the service.
What we do not do
- We do not sell your personal information.
- We do not retain the full PDF bytes after an attestation or verification response is produced (we keep hashes and metadata needed to verify later).
- We do not claim that a bank or other institution endorses the contents of a document — only what our proofs state (download origin or sharing app identity, and byte identity).
Cookies and similar technologies
The public verify and marketing pages do not rely on advertising cookies. The admin area may use session cookies or equivalent storage to authenticate operators. Browser extensions and the Android app store settings and optional My Details locally on your device as well as syncing them to our servers when you save.
We use PostHog (EU cloud by default) for product analytics: page views and anonymous events such as “PDF stamped” or “PDF verified” (with a high-level kind/outcome only — not your My Details or file contents). We may also use Vercel Web Analytics / Speed Insights for traffic and performance. These tools are not used for advertising. You can block analytics cookies via your browser settings.
Processors
We use service providers to run NotChanged, including:
- Hosting (e.g. Vercel)
- Database (e.g. Neon)
- Transactional email (Resend)
- Optional short links for QR stamps
- Product analytics (PostHog; optionally Vercel Analytics)
They process data only to provide their services to us.
Retention
Attestation and issuance registry records (hashes, metadata, signatures) are kept so documents can be verified over time. My Details remain until you clear them or ask us to delete them. Email verification tokens expire. Server logs are retained for a limited operational period.
Your rights
Depending on where you live (including the UK GDPR / EU GDPR), you may have rights to access, correct, delete, or restrict processing of your personal data, and to object or complain to a supervisory authority. To exercise these rights, email support@notchanged.com. We may need to verify the request.
Children
NotChanged is not directed at children under 16. Please do not submit personal details about children.
Changes
We may update this policy. The “Last updated” date will change when we do. Continued use of the service after an update means you accept the revised policy.