Photographers
Your portrait, re-uploaded without your terms attached.
A chain-of-custody ledger for media consent
Prove the consent behind a photo, clip, or track — even after it's cropped, recompressed, or stripped of every metadata tag on the way to a re-upload.
IMG_4471_final_v2.jpg
registered 2026-05-28 · Level 1 · active
Uploaded copy
IMG_4471_final_v2.jpg
✕ no EXIFIllustrative example — try it with a real file. Measured re-identification rate, false-match rate, and revocation latency available on request.
Any file that leaves your hands can lose its terms along the way. These are the four we hear about most.
Your portrait, re-uploaded without your terms attached.
A clip lifted into someone else's track, credit stripped.
A face used to train a model you never agreed to.
Work scraped into a dataset with the byline removed.
Private personal use only. Opts out of all display, dissemination, AI, or likeness extraction.
Public display for organic viewing. Prohibits monetization, AI crawl, copy, or likeness harvesting.
Allows commercial use on approved platforms subject to mandatory smart-contract royalties.
Allows unrestricted use, redistribution, and commercial dataset training on opt-in media.
Set monetization and AI training independently instead of picking a preset combination — e.g. non-monetized but AI-trainable, a combination none of the four presets cover.
Setting terms during registration looks like this — four preset consent levels plus independently configurable custom terms, each a W3C ODRL policy signed with a wallet or email-derived key.
The rights holder sets terms — commercial use, AI training, derivative works, monetization split — as a W3C ODRL policy, then signs it with a wallet or email-derived key. Fingerprints are computed from the file itself, client-side.
Every action — registration, amendment, revocation — is appended as a SHA-256-linked block. Each entry's hash depends on the one before it, so earlier history can't be quietly edited without breaking the chain.
An uploaded copy is resolved back to its original registration by what it is — perceptual and content-derived fingerprints — not by filename, embedded tags, or metadata that a platform may have already discarded.
Consent can be withdrawn at any time. The revocation is itself a permanent, timestamped ledger entry — never a silent deletion of the record.
Versus a C2PA manifest: a manifest travels attached to the file, so it's gone the moment a platform strips it or a screenshot is taken. ProveConsent is built to complement that approach, not replace it — resolution and revocation status come from the content itself, so the record is still reachable after the manifest isn't.
Register a file, set its terms, and know the record is still reachable — long after the metadata isn't.