Register
The rights holder sets terms β commercial use, AI training, derivative works, monetization split β as a W3C ODRL policy, then signs it with a wallet or email-derived key. Fingerprints are computed from the file itself, client-side.
A chain-of-custody ledger for media consent
Prove the consent behind a photo, clip, or track β even after it's cropped, recompressed, or stripped of every metadata tag on the way to a re-upload.
Uploaded copy
IMG_4471_final_v2.jpg
β no EXIFIllustrative example β try it with a real file. Measured re-identification rate, false-match rate, and revocation latency available on request.
Private personal use only. Opts out of all display, dissemination, AI, or likeness extraction.
Public display for organic viewing. Prohibits monetization, AI crawl, copy, or likeness harvesting.
Allows commercial use on approved platforms subject to mandatory smart-contract royalties.
Allows unrestricted use, redistribution, and commercial dataset training on opt-in media.
Setting terms during registration looks like this β four preset consent levels, each a W3C ODRL policy signed with a wallet or email-derived key.
The rights holder sets terms β commercial use, AI training, derivative works, monetization split β as a W3C ODRL policy, then signs it with a wallet or email-derived key. Fingerprints are computed from the file itself, client-side.
Every action β registration, amendment, revocation β is appended as a SHA-256-linked block. Each entry's hash depends on the one before it, so earlier history can't be quietly edited without breaking the chain.
An uploaded copy is resolved back to its original registration by what it is β perceptual and content-derived fingerprints β not by filename, embedded tags, or metadata that a platform may have already discarded.
Consent can be withdrawn at any time. The revocation is itself a permanent, timestamped ledger entry β never a silent deletion of the record.
Versus a C2PA manifest: a manifest travels attached to the file, so it's gone the moment a platform strips it or a screenshot is taken. ProveConsent is built to complement that approach, not replace it β resolution and revocation status come from the content itself, so the record is still reachable after the manifest isn't.