ProveConsent · Media Consent Registry
REGISTRY SNAPSHOT
REV. 2026-10-05

A chain-of-custody ledger for media consent

The record thatsurvives the edit.

Choose how your photos, videos, and audio may be used. Register the permission, trace it back from an edited copy, and keep a record when consent changes.

Studio portrait An illustrator at work in their studio
Photographer
Musician
Patent pending — KE/P/2026/6199, filed 28 May 2026 W3C ODRL policy terms Firestore-backed ledger, anchored to Sigstore Rekor MVP live

From creation to revocation

Follow a single illustrative file through its whole lifecycle — registered, chained, shared, checked, and withdrawn.

Studio portrait An illustrator working on a painting in their studio
Not yet registered

Start with the original

An illustrator finishes a piece in their own studio. Before sharing it anywhere, they decide what other people may do with it.

studio-work.jpg · permission record does not yet exist

Illustrative walkthrough using a stock photo, not a live verification result. Matching depends on the file and the edits made to it; a fingerprint match is not a guarantee that every altered copy can be identified.

Whose work travels without them

Any file that leaves your hands can lose its terms along the way. These are the four we hear about most.

Photographer

Photographers

Your portrait, re-uploaded without your terms attached.

Musician

Musicians

A clip lifted into someone else's track, credit stripped.

Model / talent

Models & talent

A face used to train a model you never agreed to.

Illustrator

Illustrators

Work scraped into a dataset with the byline removed.

Why metadata isn't enough

Step 01 — Original File leaves the camera EXIF intact, terms attached, owner known.
Step 02 — Platform Upload & re-encode ✕ metadata stripped on ingest
Step 03 — Re-upload Copy circulates ✕ no trail back to original terms
✓ the pixels themselves are unchanged

Embedded metadata

  • ✕ Stripped on upload by most major platforms
  • ✕ Gone entirely from a screenshot or re-encode
  • ✕ Nothing left to trace back to original terms

The content itself

  • ✓ A crop or recompression barely moves it
  • ✓ Resolves back to the registered consent record
  • ✓ Can't be removed without destroying the file

How the ledger works

registry.proveconsent.app/create
L0

Total Prohibition

Private personal use only. Opts out of all display, dissemination, AI, or likeness extraction.

Non-monetaryAI dataset opt-out
L1

Personal Showcase

Default

Public display for organic viewing. Prohibits monetization, AI crawl, copy, or likeness harvesting.

Non-monetaryAI dataset opt-out
L2

Commercial Monetization

Allows commercial use on approved platforms subject to mandatory smart-contract royalties.

MonetaryAI dataset opt-out
L3

Full Rights & AI

Allows unrestricted use, redistribution, and commercial dataset training on opt-in media.

MonetaryAI dataset training allowed
—

Custom Terms

Power users

Set monetization and AI training independently instead of picking a preset combination — e.g. non-monetized but AI-trainable, a combination none of the four presets cover.

Monetary or notAI training: your choice

Setting terms during registration looks like this — four preset consent levels plus independently configurable custom terms, each a W3C ODRL policy signed with a wallet or email-derived key.

01

Register

The rights holder sets terms — commercial use, AI training, derivative works, monetization split — as a W3C ODRL policy, then signs it with a wallet or email-derived key. Fingerprints are computed from the file itself, client-side.

02

Chain

Every action — registration, amendment, revocation — is appended as a SHA-256-linked block in a real Firestore-backed ledger, then anchored to the public Sigstore Rekor transparency log: an independent, permanent record outside ProveConsent's own database. Each entry's hash depends on the one before it, so earlier history can't be quietly edited without breaking the chain.

03

Match

An uploaded copy is resolved back to its original registration by what it is — perceptual and content-derived fingerprints — not by filename, embedded tags, or metadata that a platform may have already discarded. In our own measurements against this matching code: 95–100% of lightly re-encoded or resized copies, 80–90% of heavily cropped or recompressed ones, with 0% false matches across unrelated images in the same test.

04

Revoke

Consent can be withdrawn at any time. The revocation is itself a permanent, timestamped ledger entry — never a silent deletion of the record.

Versus a C2PA manifest: a manifest travels attached to the file, so it's gone the moment a platform strips it or a screenshot is taken. ProveConsent is built to complement that approach, not replace it — resolution and revocation status come from the content itself, so the record is still reachable after the manifest isn't.

Methodology for the match-rate figures above: measured directly against this app's own production matching code (real perceptual hashing and real content-derived embeddings — never a simulated stand-in) across 7 real photographs and 10 realistic transformations (JPEG recompression, resize round-trips, center crops, and brightness/contrast shifts, at light/moderate/heavy severity), plus every cross-pair among those 7 photos for the false-match figure. A small sample from an early-stage product, not a large-scale study — re-measured whenever the matching code changes.

R&D in progress, not yet in the live matching above: a prototype technique that tries several simulated crop alignments plus 9 overlapping regions per registered photo lifts heavy-crop matching from 80–90% to 100% in the same test, and separately catches 14–100% of tight, off-center crops (e.g. zoomed into just one detail of a photo) depending on how closely the crop lines up with a stored region — averaging around 40% across the 5 crop positions tested, with no change to the 0% false-match rate. Benchmarked, not shipped: rolling it into live matching needs a registry schema change this hasn't gone through yet.

Sign with what you already hold

Solana wallets EVM wallets (MetaMask) Email-derived identity No prior Web3 experience required

Put your work on the record.

Register a file, set its terms, and know the record is still reachable — long after the metadata isn't.

Open the live registry →