Legal

Privacy Policy

Last updated: June 21, 2026

Origo is a verified source registry for original images and digital identities. This Privacy Policy explains what data we collect, how we use it, and — critically — what we do to the images you view and register on our platform. We have written this policy to be transparent about practices that affect you, not merely to satisfy minimum legal obligations.

1. Who We Are

Origo ("we", "us", "our") operates the verified image registry and identity protection platform available at protectwithorigo.com. References to "you" mean any visitor, registered creator, or third party who views a public verification page.

2. How We Treat the Images You Register

Storage. When you register an original image, we store a copy of the file in our secure private storage. This copy is used exclusively to power verification comparisons, generate trust marks, and display the registered original on your asset's public verification page.

Fingerprinting. We compute a SHA-256 cryptographic hash and a perceptual fingerprint (a compact visual signature) of each registered image. These are stored in our database and used to detect visually similar or duplicate images submitted by other users.

Blockchain anchoring. A registration record containing your asset ID, SHA-256 hash, registration timestamp, and rights-holder name is submitted to the Polygon Mainnet blockchain. This creates an immutable, publicly auditable timestamp. The full image file is never stored on-chain.

AI comparison. When a comparison is requested (by you or a member of the public on a verification page), the uploaded image is temporarily processed by an AI vision model to assess visual similarity. Uploaded comparison images are not retained beyond the session.

We do not sell your images. Your registered originals are never sold, licensed to third parties, or used to train AI models outside of the comparison services you explicitly initiate.

3. Steganographic Session Watermarks — What They Are and Why We Use Them

We embed invisible forensic tokens into images displayed on public verification pages. This section explains exactly what that means.

What is a steganographic watermark? Steganography is the practice of hiding information within digital media in a way that is imperceptible to the human eye. When you view a registered original on an Origo verification page, our platform silently encodes a short session token — called a Scan ID — into the least-significant bits (LSBs) of the image's pixel data before it is rendered in your browser. This process happens entirely client-side in your browser using the HTML Canvas API. The modification is mathematically invisible: no human observer would detect any visual difference.

What is encoded. The embedded token is a short alphanumeric Scan ID (e.g. SCN-A7F3) tied to your page-view session. It is not your name, email address, IP address, or any other personal identifier. It is a random session reference that exists only for the duration of a single page visit and expires automatically.

Why we do this. The purpose of session watermarking is anti-impersonation and platform integrity — not user surveillance. If a bad actor screenshots or scrapes the registered original from a verification page and re-uploads it to a fake verification site, the embedded Scan ID persists in that copy. This allows Origo (or a creator) to forensically demonstrate that the fraudulent page sourced its image from a real Origo verification session. It is a technical proof against spoofing, not a tracking mechanism.

What we do not do. We do not log which session token was served to which visitor. The Scan ID is not linked to your account, your IP address, your device, or any behavioral profile. We do not retain the watermarked image version beyond your browser session. The original file stored in our system is never modified.

Opting out. The session watermark is rendered at the browser level for public verification pages and cannot be disabled by a viewer. Registered creators who do not wish their originals to be displayed with session watermarking may set their asset visibility to private in their dashboard, which removes the public verification page entirely.

4. Data We Collect From Creators

Account data. Name, email address, organization, account type, country, and website — provided during registration.

Identity verification data. If you submit an identity for verification (Origo Identity), this may include legal name, date of birth, social accounts, and representative relationship. This data is used solely for identity verification and impersonation monitoring and is never shared with third parties except as required by law.

Payment data. Payment card details are handled exclusively by our payment processor (Stripe or Wix Payments). Origo does not store card numbers.

5. Data We Collect From Verification Page Visitors

View counts. We increment a view counter for each asset's verification page. This is a simple integer count — not linked to any visitor identity.

Comparison uploads. If you upload an image for comparison, it is processed temporarily and not retained. We log that a comparison occurred (as an aggregate count on the asset record) but not the uploaded file content.

Misuse reports. If you submit a misuse report, your name and email are collected for correspondence purposes and to notify the rights holder.

Standard server logs. Like all web services, our infrastructure collects standard access logs (IP address, browser type, page URL, timestamp). These are used for security monitoring and retained for up to 90 days.

6. Cookies and Tracking

Origo uses session cookies necessary for authentication and platform operation. We do not use third-party advertising cookies or behavioral tracking pixels. We use basic analytics (aggregate page view counts) that do not profile individual visitors.

7. Data Sharing

We do not sell personal data. We share data only in the following circumstances:

  • Service providers: Cloud hosting, payment processing, and email delivery — each operating under data processing agreements.
  • Origo Resolve: If you submit a legal case intake form, relevant case details are shared with the assigned independent law firm for conflict review and evaluation.
  • Legal obligation: We may disclose information in response to a valid legal process.

8. Data Retention

Registered asset records and associated files are retained for the lifetime of your account. You may request deletion of your assets and account at any time by contacting us. Blockchain records (the hash and timestamp) are immutable and cannot be deleted — this is a fundamental property of public blockchains.

9. Your Rights

Depending on your jurisdiction you may have the right to access, correct, export, or delete your personal data. To exercise any of these rights, contact us at privacy@protectwithorigo.com.

10. Contact

Questions about this policy? Email privacy@protectwithorigo.com.