Consumer guide
PRYVC is free for consumers, forever. This guide walks through the app at app.pryvc.com.
Your profile
Section titled “Your profile”Sign in with Google, Microsoft, or an email code — no password to remember. Fill in the fields you want available for sharing (name, email, phone, address, and so on). Your details are encrypted with a key unique to you, kept separate from the database — no PRYVC screen, admin tool, or export displays them to staff. They are only decrypted to perform actions you request (like filling a form or completing a share you approved), and every access is recorded in the audit log — an append-only, hash-linked chain you can watch live on the public ledger, which shows sequence numbers, actions, and hashes only, never anyone’s details.
Start here: the browser extension
Section titled “Start here: the browser extension”This is the part you’ll use every day. Pryvc Autofill with Proof fills any form on any site — including the overwhelming majority that have never heard of PRYVC — from the profile you just filled in. Free, Chrome, and it works on the web as it actually is rather than the web we wish had integrated with us.
The toolbar button lights up by itself on pages that have a form worth filling, so you don’t have to remember we exist. Click it — or right-click and choose Fill with Pryvc — and a panel lists exactly which of your fields the form is asking for. Approve it and the fields fill; decline and nothing happens.
How it knows, without watching you. The rule is a list of things to look for, like “a field asking for an email address”. Chrome itself checks the page against that list and decides whether to light up the button. The extension is never told the answer, never sees the page, and holds no permission to read any website — it only gains access to a page at the moment you click, and only that page. There is no always-on script watching you type: the browser does the looking, and it does not report back to us.
Every fill is recorded in your Data trail: which site, which fields, when, and a copy of that site’s privacy policy and terms as they read that day. Field names only — the values you filled are never stored in the record.
Two things worth understanding about this, because they’re deliberate:
- It never ticks a consent checkbox for you. It fills name, email, phone and address, and skips every checkbox, radio and password field. If a form asks you to agree to be contacted, you tick that yourself — the consent stays yours, given by you.
- The receipt is yours, not theirs. The site has no integration with PRYVC and doesn’t know we exist, so nobody on the other end declared a purpose or a duration. Your record is evidence of what you disclosed, which is what makes a later revocation or complaint provable. It is not consent handed to that company — see the Share button for the case where a business is a party to the exchange.
When a site has the Share button
Section titled “When a site has the Share button”Some businesses integrate PRYVC directly. When they do you get something the extension cannot give you, because the business is a participant rather than a bystander: it has to declare its terms up front, and it keeps a matching receipt.
Wherever a site shows the Share with PRYVC button, clicking it opens a consent screen that tells you, before anything moves:
- who is asking (and that they’ve verified their domain),
- exactly which fields they want,
- why (the stated purpose), and
- how long the share lasts (usually 90 days).
Approve, and the form fills itself. Decline, and nothing is shared — ever. Every share you approve is recorded under Shares with a search box, so “wait, who has my phone number?” takes five seconds to answer.
On a laptop? Scan to share
Section titled “On a laptop? Scan to share”If you click Share with PRYVC on a computer where you are not signed in, the consent screen also shows a QR code: Continue on your phone. Point your phone’s camera at it, and the same consent screen opens on the phone — where you are probably already signed in. Approve there, and the form on the computer fills itself. No typing, no password on a device you may not trust.
Two things to know:
- The phone shows where the request came from — the browser, system, and approximate location of the computer displaying the code. If that is not the computer in front of you, decline. A code lifted from someone else’s screen cannot fake this.
- The code lasts three minutes and works once. Whatever you approve on the phone is a normal share: same fields, same receipt, same revoke button.
It is the same idea as paying by scanning a code with your phone, applied to your contact details — except nothing is charged, and you get the receipt.
Passkeys: approve with Face ID instead of an emailed code
Section titled “Passkeys: approve with Face ID instead of an emailed code”After your phone approves a share for the first time, it offers to add a passkey. Accept, and from then on that phone signs in to PRYVC with Face ID, Touch ID, or your screen lock — no code to fetch from email. You can also add or remove passkeys under Profile → Passkeys, and a passkey works on the sign-in screen anywhere: tap Use a passkey.
Passkeys are additive. Your emailed code and Google/Microsoft sign-in keep working, so removing a passkey can never lock you out. We store only the public half of each passkey; the private key never leaves your device or your platform’s keychain.
Confirming a share, like confirming a payment
Section titled “Confirming a share, like confirming a payment”Once your account has a passkey, approving a scan-to-share on your phone asks for Face ID, Touch ID, or your screen lock at the moment you tap Share — the same gesture as confirming a payment, every time, even if you are already signed in. That is deliberate: being signed in says who you are; the confirmation says it is you, right now, holding the phone.
If the passkey lives on a different device (say, your laptop’s Windows Hello) and your phone has none, the phone offers a one-time emailed code instead, so a passkey elsewhere never blocks you. Either way the receipt records how the share was confirmed.
What you actually see (and the machinery you can ignore)
Section titled “What you actually see (and the machinery you can ignore)”Every share and every fill lands in one plain-English list. No jargon, no hashes on screen — just the four things you’d actually want to know:
| Site | Who got it |
| Date and time | Exactly when |
| Information shared | Which fields — first name, email, phone — never the values themselves |
| Proof | A short reference you can hand to anyone who needs to check it |
That’s the whole consumer experience. If you never think about anything below this line, the product still works.
Why the list can be trusted
Section titled “Why the list can be trusted”Underneath, each record is sealed with the same cryptography blockchains are built on. Every entry carries a fingerprint of the entry before it, so the records form a chain: change one, and every record after it stops matching. Then, every fifteen minutes, the end of that chain is checkpointed into a separately operated ledger and published, where entries are signed and append-only.
The practical effect is simple. Anyone can write down today’s checkpoint — it is public. If the history behind it is ever altered, the checkpoint no longer matches, and the change is provable by whoever wrote it down. Detection does not depend on trusting us.
One disclosure. That ledger, Engrave, is operated by an affiliated company under common ownership. It is separate infrastructure, not a separate interest. We say so plainly because the protection here comes from checkpoints being public and independently recordable — not from the ledger being run by strangers. Anyone claiming the second thing while owning both sides would be selling you a story.
That is the point of the math: not to impress you, but to make “trust us” unnecessary.
You can watch the chain being built, live, at verify.pryvc.com/ledger. It shows sequence numbers, actions and hashes only — never anyone’s personal details.
Why the rules are public
Section titled “Why the rules are public”The format all of this is written in is an open specification, the Share Protocol, published under a Creative Commons license with its test vectors and an independent verifier that anyone can download and run.
That matters for a reason worth being blunt about: a privacy company asking you to take its word is doing the same trick as everyone else, in a nicer font. Because the rules are published, your evidence can be checked by an auditor, a regulator, a journalist, or you — without our cooperation and without our permission. Transparency you have to request isn’t transparency.
Telling a site you used PRYVC (optional)
Section titled “Telling a site you used PRYVC (optional)”Sometimes you’ll fill a form on a site that has never heard of PRYVC and think: they should offer this. You can tell them — once, by pressing a button, and only if you want to.
On any Data trail row, Let them know sends that site a single notice containing a link to your record. It says a verified PRYVC member filled their form and links to a page showing the site, the time, and which types of fields you shared. It does not include your name, your email, or any of the values you typed — they already have those, because you typed them into their form.
We are deliberately careful with this, because unsolicited email from a company built on consent would be indefensible:
- Nothing is automatic. No scheduled job, no default setting, no bulk send. It happens only when you press the button.
- Once per day, and once per site, ever. You can send at most one notice a day, and any given site can only ever hear from you once.
- Sites already using PRYVC never get one. If the business has verified the domain, they already give you real receipts — there’s nothing to tell them, so the button won’t offer it.
- Businesses can stop it permanently with one click, no account needed — and we check that list before sending anything.
- You need a verified email, because the notice’s whole value is that a real, verified person filled the form.
The page they land on tells them plainly that your record is your evidence and not consent they can rely on, and points them at integrating properly if they want that. You’re giving them fair notice and a chance to do better — not signing them up for anything.
When a share is about to expire
Section titled “When a share is about to expire”Shares run for a fixed period, usually 90 days, and then simply stop — no action needed from you, and no quiet auto-renewal. If a business still needs your details and you are happy for them to have them, Renew on the Shares page extends it for another 90 days.
Letting it lapse is always an option, and it is the default. Expiry that requires you to remember to cancel would not be consent.
Changing your details
Section titled “Changing your details”Update a field once under Contact details and every business with an active share that includes that field is notified automatically. Businesses you’ve revoked hear nothing.
Policy watch — the fine print, re-checked daily
Section titled “Policy watch — the fine print, re-checked daily”The day your information goes to a site — through a share or an extension fill — PRYVC saves that site’s privacy policy and terms exactly as they read, content-hashed (SHA-256). Every day after, we fetch the live text and compare checksums.
If the text has changed, everyone whose information went to that site gets an email naming the site, the document (privacy policy or terms), and the date the change was detected. Two things we deliberately don’t do:
- We don’t interpret the change. A moved comma and a new data-sale clause both count; reading the new text and deciding what it means is your call. Our job is proof that the document you agreed to is no longer the document in force — and when that happened.
- We don’t wait for them to announce it. The check is against the live page, not a changelog, so quiet edits count too.
Each detection is recorded in the audit chain (policy.changed), so the fact of the
change is itself tamper-evident. If the new terms don’t sit right, Revoke & sever is
one click away.
Taking your details back
Section titled “Taking your details back”Open Shares, click any share, and hit Revoke & sever. PRYVC sends the business a formal, timestamped cease-communication notice. They have 10 business days to comply — we track the deadline, and if they blow past it, you get a timestamped evidence pack for an FTC, state Attorney General, or TCPA complaint.
Withdrawing consent you gave on someone’s form
Section titled “Withdrawing consent you gave on someone’s form”Some sites use PRYVC to certify consent directly on their own form — you tick their box, and a certificate is issued. You don’t need a PRYVC account for this, and you may have one of these without ever having heard of us.
If you were given a verification link, or you find one in an email from that business, you can withdraw the consent from that page:
- Open the certificate’s verification page.
- Enter the email address you gave them.
- Enter the six-digit code we send to that address.
Proving you control the address is what authorizes it — that is the whole check, and the page tells you nothing about whose address is on the certificate unless you already know it.
What withdrawal does. The consent is marked revoked, timestamped. The business is emailed and has ten business days to stop contacting you, and that obligation is recorded. The certificate itself is not deleted — the record of what you agreed to, and of your withdrawal, both remain. That is deliberate: it is the evidence you would need if the business ignored you.
What it does not do. It doesn’t erase the data you typed into their form; they already have that. If you want it removed as well, that’s what a removal request is for — see below.
Cleaning up your past (White Glove)
Section titled “Cleaning up your past (White Glove)”The accounts you created before PRYVC existed are still out there. Under White Glove:
- Export your saved logins from Chrome, 1Password, LastPass, or Bitwarden as a CSV.
- Import it — the file is read in your browser and passwords never leave your device; we only keep the site and the username/email, encrypted.
- Verify any email address you want to act on (a one-time code proves it’s yours).
- Click Revoke on any account. We find the site’s privacy contact, send a deletion and cease-contact request on your behalf, and track the deadline to a response or an affidavit.
Every account includes 4 free revocations. White Glove ($29/yr) makes it unlimited and adds our team manually hunting down contacts automated discovery can’t find.
Rows you don’t want to chase
Section titled “Rows you don’t want to chase”An exported password file is a decade of noise: accounts that were never yours, sites that no longer exist, one-off logins you don’t care about. Press Stop tracking on any row and it grays out and stays put — still listed, so your import history stays honest, and reversible with Track again if you change your mind.
It deliberately does not cancel a notice already sent. Hiding a row from your own list is not the same as withdrawing a legal request from a company, and quietly retracting one would be worse than useless.
Filter the list by status — not requested, finding a contact, notice sent, they responded, deadline passed, affidavit ready, or not tracking — to see only what needs you.
What we actually sent
Section titled “What we actually sent”Open any revocation and you can read the exact message that went out under your name, along with who received it and when. It is stored verbatim rather than rebuilt from a template, so what you read is what they read — which is the point of having a record at all.
When an assistant does it for you
Section titled “When an assistant does it for you”AI assistants are starting to book, order and request quotes on people’s behalf. It is genuinely useful, and it removes the one person who used to see exactly what was handed over. PRYVC is built so that does not cost you the record.
An assistant cannot agree on your behalf. The interface we expose to agents has no way to grant consent — there is no such action available. An agent can list your shares, update a field, or revoke one. Agreeing to be contacted stays something only you do, at a consent screen, deliberately.
The receipt is the same either way. A disclosure lands in your Data trail identically whether a person or a program filled the form: which site, which fields, when, and what that site’s terms said that day. Revocation works the same too.
And the proof is machine-checkable. The format is an open specification with published test vectors, so software can verify one of your records without our involvement. That matters more as more of this is done by software: a screenshot is something only a human can look at, and a fingerprint is something a program can recompute.
If you never hand anything to an assistant, none of this changes what you have. It is here so that the day you do, nothing about your record changes either.
Your data, your exit
Section titled “Your data, your exit”Under Profile you can export everything we hold about you (a full DSAR export) or delete your account — which revokes all active shares and erases your encrypted fields immediately.