ProveConsent Β· Media Consent Registry
REGISTRY SNAPSHOT
REV. 2026-10-01

A chain-of-custody ledger for media consent

The record that survives the edit.

Prove the consent behind a photo, clip, or track β€” even after it's cropped, recompressed, or stripped of every metadata tag on the way to a re-upload.

Patent pending β€” KE/P/2026/6199, filed 28 May 2026 W3C ODRL policy terms MVP live

What one lookup returns

registry.proveconsent.app/verify
Uploaded copy IMG_4471_final_v2.jpg βœ• no EXIF
βœ• recompressed, cropped 12%
βœ• zero matching filename
Content-derived match pHash + fingerprint
resolved against registry
Consent active Resolved record βœ“ owner identity
βœ“ status: active
βœ“ terms + revocation log

Illustrative example β€” try it with a real file. Measured re-identification rate, false-match rate, and revocation latency available on request.

Why metadata isn't enough

Embedded metadata

  • βœ• Stripped on upload by most major platforms
  • βœ• Gone entirely from a screenshot or re-encode
  • βœ• Nothing left to trace back to original terms

The content itself

  • βœ“ A crop or recompression barely moves it
  • βœ“ Resolves back to the registered consent record
  • βœ“ Can't be removed without destroying the file

How the ledger works

registry.proveconsent.app/create

Level 0: Total Prohibition

Private personal use only. Opts out of all display, dissemination, AI, or likeness extraction.

Non-monetaryAI dataset opt-out

Level 1: Personal Showcase

Public display for organic viewing. Prohibits monetization, AI crawl, copy, or likeness harvesting.

Non-monetaryAI dataset opt-out

Level 2: Commercial Monetization

Allows commercial use on approved platforms subject to mandatory smart-contract royalties.

MonetaryAI dataset opt-out

Level 3: Full Rights & AI

Allows unrestricted use, redistribution, and commercial dataset training on opt-in media.

MonetaryAI dataset training allowed

Setting terms during registration looks like this β€” four preset consent levels, each a W3C ODRL policy signed with a wallet or email-derived key.

01

Register

The rights holder sets terms β€” commercial use, AI training, derivative works, monetization split β€” as a W3C ODRL policy, then signs it with a wallet or email-derived key. Fingerprints are computed from the file itself, client-side.

02

Chain

Every action β€” registration, amendment, revocation β€” is appended as a SHA-256-linked block. Each entry's hash depends on the one before it, so earlier history can't be quietly edited without breaking the chain.

03

Match

An uploaded copy is resolved back to its original registration by what it is β€” perceptual and content-derived fingerprints β€” not by filename, embedded tags, or metadata that a platform may have already discarded.

04

Revoke

Consent can be withdrawn at any time. The revocation is itself a permanent, timestamped ledger entry β€” never a silent deletion of the record.

Versus a C2PA manifest: a manifest travels attached to the file, so it's gone the moment a platform strips it or a screenshot is taken. ProveConsent is built to complement that approach, not replace it β€” resolution and revocation status come from the content itself, so the record is still reachable after the manifest isn't.

Sign with what you already hold

Solana wallets EVM wallets (MetaMask) Email-derived identity No prior Web3 experience required