1. Acceptance of Terms
By using FactLockCam, you agree to these Terms of Service. FactLockCam provides tamper-evident digital archive services for media certification, encryption, and workflow support.
2. Digital Archive Certification
FactLockCam supports authenticity heuristics through three technical pillars:
- Integrity: Cryptographic proof that a file is unaltered (SHA-256).
- Ownership: Association with your authenticated identity and device signing
where enabled. The
device_key_classrecorded in a manifest is reported by the device and is not independently attested; it describes the signing key class, not the camera hardware or scene authenticity. - Timestamping: A Polygon record of a signed capture manifest hash when notarization is active. The later bound is the block that included that transaction. When the device was online at capture, an earlier Polygon block hash is also committed, producing a capture window. Offline captures have no earlier bound.
This produces a certificate draft that documents the cryptographic state of a digital asset. It supports disclosure workflows but does not guarantee admissibility under FRE 902. Unlocking a shared proof package with a password confirms only that the package was sealed with that password; it is not proof that the hash was published on Polygon.
3. Permanent Ledger Records
You acknowledge that the Polygon blockchain is a permanent record. Once a cryptographic hash is anchored, it cannot be modified or deleted. FactLockCam has no authority or ability to alter blockchain records.
4. User Responsibility (The Verification Bridge)
A successful verification requires two components under your exclusive control:
- The Artifact: The original, unaltered file.
- The Identity: The credentials used to sign the asset.
If either is lost or modified, the cryptographic link for verification cannot be restored.
5. Non-Custodial Access Protocol
CRITICAL: FactLockCam utilizes non-custodial security. We do not store your encryption keys or backup passwords. We cannot reset your password, decrypt your archive, or recover lost keys. You are solely responsible for device access and for exporting and safeguarding your .factlock sovereign key backup (Account & Settings → Backup & Restore).
6. User-Managed Backups (Keys and Sealed Media Copies)
FactLockCam offers two user-managed backups, both created and stored by you. Neither is a download from our servers, and FactLockCam holds neither file nor its password.
- .factlock (keys): a password-protected file created in Account & Settings → Backup & Restore → Export archive keys. It contains your sovereign decryption keys (EVM signing key and archive AES key)—not your photos or videos. It is imported on the locked screen after Lock Archive or a reinstall and is the only way to read sealed files that are still on this device.
- .flcproof (one sealed item): an optional password-protected copy of a single item created with Export sealed backup from any archive item. It contains that item's original media, title, description, and signed capture record. It is restored with Restore sealed backup (Account & Settings → Backup & Restore) and is unlockable with its own password even if your keys are lost.
Each file can be restored only with the password you set for it. FactLockCam cannot restore access to an archive without your .factlock backup and its password, and cannot recover a .flcproof whose password is lost. Restoring a sealed backup re-admits an existing record; it does not create a new seal, re-anchor the record, or consume plan capacity.
Re-export your .factlock periodically, before Lock Archive, before uninstalling the app, or before replacing your device. Keys are stable for a given app install; you do not need to export after every capture.
7. Where Your Archive Lives
FactLockCam is local-first:
- On your device: Sealed media is stored as encrypted
.sealfiles in the app sandbox. This is the archive you browse, verify, and export from the app. - On our servers (account records only): Authentication, quota, and proof-ledger metadata (hashes, timestamps, and chain identifiers). Sealed photos and videos are not uploaded. There is no cloud media sync and no dashboard download of your archive.
- Send Proof and sealed backups: password-sealed
.flcproofpackages you deliver or store yourself. They have no expiry and no access-attempt limit, and FactLockCam cannot revoke them. A sealed backup copy can be restored into the app with its password, but it is not a substitute for your .factlock key backup.
8. Key Custody Scenarios
Losing your keys without a .factlock backup means permanent loss of access to
all encrypted assets still on the device—local .seal
files. Only .flcproof sealed backups you
already saved remain unlockable, each with its own password.
| Scenario | Local keys | Local .seal | Account + ledger | .factlock backup | .flcproof sealed backups |
|---|---|---|---|---|---|
| Normal use | Present | Present | Account and ledger records if signed in | Optional; re-export periodically or before Lock/uninstall | Optional per-item copies |
Keys lost (no .factlock) | Gone | Unreadable | Unreadable | N/A — total loss of device assets | Still unlockable with their passwords; restorable after new keys exist |
| Lock Archive | Purged from device | Remain on device | Account and ledger unchanged | Import on the locked screen to resume | Not needed |
| App uninstalled | Gone (OS wipes sandbox) | Usually gone with app data | Account and ledger remain for the same email | Must import after reinstall + sign-in to unlock any local files that survived | Restore each item from Backup & Restore |
| Burn Account | Purged locally | Wiped locally | Account, ledger, and quota records deleted | Useless for that burned identity | Still unlockable; restorable into a new account as Historical |
Lock Archive ≠ Burn Account. Lock removes keys from this device but leaves local sealed files; import .factlock to resume. Burn permanently deletes your Supabase identity, ledger and quota records, local archive, and keys—a prior .factlock cannot restore a burned account.
9. Burn Account Is Irreversible
Burn Account (Account & Settings, with double confirmation) permanently destroys your remote account, ledger and quota records, local archive database and sealed files, and cryptographic keys on the device. A .factlock file created before Burn cannot resurrect that identity. You may create a new account with the same email only as a fresh identity with no restored prior archive.
10. Integrity Maintenance
If the original file is modified or access to the certifying identity is lost, the link to the blockchain record is broken. FactLockCam cannot restore this connection.
11. Proof Package Delivery
Send Proof produces an offline, password-sealed .flcproof package that you share
yourself. FactLockCam cannot expire, revoke, or cap how many times a recipient opens it. If
the password is lost, the media cannot be recovered. Recipients should confirm the owner
address with the sender out-of-band. Unlocking a package with a password is not a chain
attestation. Export sealed backup writes the same container for your own custody; those copies
are user-managed and are not a cloud media backup from FactLockCam.
12. Limitation of Liability
A certificate draft is a mathematical record of a digital state. It is not a guarantee of physical truth, accuracy of content, or legal standing. When a capture window is shown, FactLockCam documents that the hashed media existed no later than the anchoring Polygon block, and no earlier than a committed prior block hash when one is present. It does not verify the underlying claims within the file.
13. Service Availability
Services are provided "as is". FactLockCam is not liable for blockchain network congestion, device-level hardware failure, or third-party service interruptions that may affect the transmission or verification of assets. Ledger notarization uses Polygon mainnet and a relay service; FactLockCam does not guarantee network uptime, transaction speed, gas prices, or receipt timing. Outages and delays may occur, and a sealed record may remain in a pending state until the network accepts the transaction.
14. Subscriptions
A subscription is not required to use FactLockCam. Free includes 5 lifetime seals and unlimited
Send Proofs. Paid plans add sealing capacity only; they do not add key recovery, key escrow, cloud
media backup, or data recovery of any kind. Self-custody .factlock and
.flcproof backups are available on every plan and are managed by you. FactLockCam
cannot restore lost keys or decrypt your archive under any plan. Auto-renewing plans are charged to your app store account and renew unless
cancelled at least 24 hours before the current period ends; manage or cancel in your store account
settings. Records you have already sealed remain available if a plan expires.