Skip to content

FAQs

Answers are short and specific. Where the honest answer is “no” or “not exactly”, it says so. Click a question to open it.

Can PRYVC staff read my contact details?

Your fields are encrypted with a key unique to you, kept separate from the database. No PRYVC screen, admin tool, or export displays them to staff — the admin console shows metadata only, and there is no decryption path in it at all. They are decrypted only to perform an action you asked for, such as filling a form or completing a share you approved, and every access is written to the audit log.

That is a strong operational guarantee, and it is not the same as the claim that we are technically incapable of reading them. We hold the keys. We tell you what we do with them, and we make the record of every use tamper-evident so the claim can be checked rather than believed.

If I decline to share, what gets recorded?

Nothing. Closing the consent screen sends no request to us and creates no record. The business is not told you considered it and declined.

Does the browser extension tick consent checkboxes for me?

No. It fills name, email, phone and address fields and skips every checkbox, radio and password field. If a form asks you to agree to be contacted, you tick that yourself. This is the single rule the whole product is built around.

Does having the extension installed let PRYVC watch my browsing?

No. It acts only when you invoke it — the toolbar button or the right-click menu. There is no always-on script watching you type, and no background reporting of the sites you visit.

The toolbar button does light up on pages with a fillable form, which is worth explaining because it sounds like the opposite. The extension gives Chrome a list of things to look for — a field asking for an email address, say — and Chrome checks each page against it. The result stays inside the browser: we are not told which pages matched, the extension cannot read any site, and it holds no permission to. Access to a page happens only when you click, and only for that page.

What is the difference between an extension fill and a Share button?

An extension fill is your record of what you disclosed. The site has no integration with us and declared no purpose or duration, so nothing about it is consent that business can rely on — it is evidence you can produce later.

A Share button means the business is a participant: it declares who is asking, which fields, why, and for how long, and both sides keep a matching receipt.

What happens when a share expires?

It stops. Shares run a fixed period, usually 90 days, and then simply end — no auto-renewal, and nothing for you to remember to cancel. You can renew one from the Shares page if you want to.

I never had a PRYVC account, but a company gave me a certificate link. What is it?

A business used certified consent on its own form and you ticked its box. You can open the verification page, and you can withdraw the consent from it by proving you control the email address on it. No account needed, then or now.

Does withdrawing delete the data the company already has?

No, and it is not meant to. Withdrawal marks the consent revoked, timestamped, and starts a ten-business-day obligation to stop contacting you. The record of what you agreed to and of your withdrawal both remain — that is the evidence you would need if the business ignored you. To have the data itself removed, make a removal request.

If a consumer ignores the Share button, do I still get something?

Only if they consented some other way. The precise answer is four cases:

The visitor You hold
Shares and ticks your consent box A fingerprinted share and a certificate
Shares, leaves your box unticked The share only
Ignores the button, ticks your box The certificate only
Ignores the button, leaves your box unticked Nothing

The last row is not a defect: no consent was given, so there is nothing to certify. Mark your consent checkbox required and that row cannot occur — then every submission produces at least a certificate.

Is a share the same thing as a certificate?

No, and the difference matters when something is disputed. A certificate is publicly verifiable: anyone with the link can check it without involving you or us, and an evidence pack verifies offline. A share is auditable but not publicly verifiable: it is fingerprinted and written into the tamper-evident chain, but there is no public page a carrier can open.

The Share button is the better source of data. Certified consent is the better source of proof.

Will you tell me who declined?

No. There is no declined event, no report, and no hidden identifier tracking the attempt. Our script makes no network request at all until a person acts, which means we could not tell you even if we wanted to — and that is deliberate, since a script that phoned home on page load would make us a tracker on your site.

Does adding your script slow down or break my form?

Capture is fail-open. If anything goes wrong on our side the visitor’s submission still goes through — a lost lead is worse than a lost certificate.

Does the consumer need a PRYVC account?

Not for certified consent. They tick your box on your form and never need to know we exist. The Share button does require an account, which is why it is upside rather than a foundation.

Does this satisfy the FCC one-to-one consent rule?

That rule was vacated in January 2025 and is not in force, so nothing needs to satisfy it. CMS’s requirement to name each recipient in Medicare marketing is in force and is unaffected. We bind every named recipient into the certificate’s fingerprint, and where your form offers a per-recipient choice we record who was accepted and who was declined — and “asked, declined none” is stored differently from “never asked”. Treat anyone still selling compliance with the vacated rule with suspicion.

What happens to my evidence if PRYVC goes away?

Export evidence packs. They are self-contained and verify offline against sp1verify, an open-source tool written from the published specification rather than ported from our code. The format is an open standard with published test vectors, so your evidence does not depend on us existing, cooperating, or agreeing with you.

Why is everything driven by the consumer? I want something I control.

You have it — certified consent is yours, on every submission that carries consent. But evidence you can generate unilaterally is what every CRM already holds: a row saying consent = true, beside a page that has since changed. That is exactly what gets challenged and does not survive it.

A certificate holds up because a real person acted, the exact words they saw are fingerprinted, and a third party can verify it without asking either of us. That strength comes from the consumer having driven it. Making the artifact easier to produce on demand would make it worth less.

What happens when AI agents start filling my forms?

The lead is still real — someone genuinely wants the quote and handed the errand to an assistant. What breaks is the evidence underneath it.

Consent tooling built on session replay and behavioral signals exists to show a human was present: mouse movement, keystroke timing, time on page. An agent produces none of that. The session either looks like a bot and gets scored as fraud, or looks clean and proves nothing — and you cannot tell which from the outside.

Two things keep our records meaningful when the filling is automated. Consent stays human: our agent surface has no tool that can grant consent, so an agent can read, update and revoke but never agree — a person still ticks your box. And the evidence is recomputable rather than watchable: a fingerprint over canonical facts can be checked by software against a published spec, where a screen recording can only be watched by a person and vouched for by the vendor holding it.

We are not predicting when this becomes most of your traffic. The point is that evidence collected today should still answer a carrier’s question when it does.

Is the external anchoring a receipt for each share?

No. Anchoring exists to prove our chain has not been rewritten, not to notarise individual records. The chain head is checkpointed into an independent ledger every fifteen minutes, which covers every entry beneath it at once. Per-event anchoring is best-effort by design and never sits between a person and their consent.