Policy and data handling

Privacy Policy

How information is collected, used, disclosed, retained, and protected when you visit larriverification.org, download protocol materials, contact us, or use the hosted conceptual demonstrations.

Effective
21 July 2026
Last updated
21 July 2026
Inquiries
hello@larriverification.org

Privacy and all other inquiries: hello@larriverification.org

Privacy at a glance

TopicOur practice
Website servicesProtocol publication, a conceptual LARRI Core receipt-generation interface, and a conceptual LARRI Verifier interface.
UploadsSource files for receipt generation; trust bundles and .zip packages for verification.
PurposeTo perform the operation requested by the user and return an illustrative receipt or verification result.
Normal upload retentionTemporary uploads, extracted files, generated receipts, and results are deleted from active application storage within 24 hours.
HostingGoDaddy and its authorized affiliates and subprocessors provide hosting, infrastructure, delivery, and related security services.
Advertising and saleWe do not sell personal information, disclose it to data brokers, or use uploads for targeted advertising.
AI trainingWe do not use uploaded files, trust bundles, packages, receipts, or verification results to train artificial-intelligence or machine-learning models.
Contacthello@larriverification.org

1. Scope and operator

LARRI Verification operates larriverification.org and is referred to in this policy as “LARRI Verification,” “we,” “us,” or “our.” This Privacy Policy explains how information is collected, used, disclosed, retained, and protected when you visit the website, download protocol materials, contact us, or use the hosted LARRI Core and LARRI Verifier conceptual demonstrations.

The website provides:

  • public access to the LARRI protocol specifications and related technical materials;
  • a conceptual LARRI Core interface through which a user may upload a file and generate an illustrative LARRI receipt; and
  • a conceptual LARRI Verifier interface through which a user may upload a trust bundle and a .zip package and receive an illustrative verification result.

Contact: hello@larriverification.org

2. Information you must not upload

The demonstrations are designed for synthetic and non-sensitive test information. Unless LARRI Verification has expressly agreed otherwise in a separate written agreement, do not upload:

  • protected health information, medical records, genetic information, or other health data;
  • Social Security numbers, passport or driver-license numbers, financial-account data, payment-card data, biometric identifiers, or authentication answers;
  • information about children or information collected from a child;
  • confidential legal, employment, insurance, benefits, claims, licensing, or disciplinary records;
  • trade secrets, privileged information, source code, proprietary datasets, or confidential business records;
  • passwords, access tokens, API keys, recovery codes, or other credentials;
  • private signing keys, private-key seeds, key-store exports, or hardware-security-module secrets;
  • malware, executable payloads, weaponized documents, or unlawful content; or
  • any information that you do not have authority and a lawful basis to upload and process.

No HIPAA or regulated-data arrangement. The website is not offered under a HIPAA Business Associate Agreement or other regulated-data processing agreement unless LARRI Verification has expressly signed such an agreement. Do not use the demonstrations for regulated production data in the absence of the required written arrangement.

3. Information we collect and process

3.1 Files uploaded to LARRI Core

When you use LARRI Core to create an illustrative receipt, the service may process:

  • the content of the file you upload;
  • the filename, file type, byte length, and related file metadata;
  • values you enter or select in the interface;
  • cryptographic digests and commitments calculated from the file;
  • receipt identifiers, issuer-asserted timestamps, signatures, and other generated receipt fields;
  • the generated receipt and related diagnostic or status information; and
  • technical request information needed to complete and secure the operation.

3.2 Files uploaded to the LARRI Verifier

When you use the LARRI Verifier, the service may process:

  • the trust bundle you upload, including public keys, fingerprints, key identifiers, permitted targets, and trust metadata;
  • the .zip package you upload and the files contained within it;
  • manifests, receipts, commitments, evidence objects, registries, reports, and other protocol artifacts contained in the package;
  • archive paths, filenames, byte lengths, digests, compression metadata, and package-safety information;
  • verification settings selected by you;
  • normalized verification outcomes, refusal codes, check statuses, warnings, and diagnostics; and
  • technical request information needed to complete and secure the operation.

Private keys are not required for verification and must not be uploaded. The Verifier is intended to use public trust material. A public key or fingerprint may still be personal information when it is associated with an identifiable person.

3.3 Website, hosting, and security information

When you visit the website or use an interface, GoDaddy and the website infrastructure may automatically process limited technical information, such as:

  • Internet Protocol address;
  • request date and time;
  • requested page, document, interface, or file;
  • browser, device, and operating-system information;
  • referring page and approximate region inferred from an IP address;
  • response status, upload size, and request duration;
  • cookie and consent-preference information; and
  • security, availability, abuse, and error information.

3.4 Correspondence

If you contact us, we may process your name, email address, organization, message, attachments, and any information reasonably necessary to respond to your inquiry, privacy request, or security report.

4. How uploads and generated artifacts are processed

Files submitted through the hosted demonstrations are transmitted to the service infrastructure and processed for the limited purpose of completing the operation requested by you.

LARRI Core. The service reads the uploaded file, calculates protocol commitments, and generates an illustrative receipt or related output.

LARRI Verifier. The service inspects the uploaded trust bundle and .zip package, applies the selected protocol checks, and returns an illustrative verification result.

Uploaded files and generated outputs:

  • are not sold;
  • are not disclosed to data brokers;
  • are not used for targeted or cross-context behavioral advertising;
  • are not used to train artificial-intelligence or machine-learning models;
  • are not added to a public dataset;
  • are not used to build user profiles or make unrelated decisions;
  • are not intentionally reviewed by personnel except where reasonably necessary for a support request, security incident, abuse investigation, legal obligation, or technical fault investigation; and
  • are not executed as code merely because they are contained in an uploaded package.

Hashes are not anonymization. A digest, fingerprint, receipt identifier, or signature may permit correlation or guessing, especially when the underlying information has low entropy or is already known. Generated receipts may contain metadata derived from an uploaded file. Review a receipt before distributing it.

5. Purposes of processing

We process information only as reasonably necessary to:

  • deliver the website and protocol publications;
  • operate the LARRI Core and LARRI Verifier conceptual demonstrations;
  • receive uploaded files and return the requested receipt or verification result;
  • calculate hashes, commitments, identifiers, signatures, and related protocol values;
  • inspect trust bundles and .zip packages;
  • apply file, archive, parsing, trust, signature, manifest, commitment, and verification checks;
  • detect malformed, excessive, unsafe, or malicious submissions;
  • maintain availability, diagnose errors, and prevent misuse;
  • respond to correspondence, privacy requests, and security reports;
  • comply with applicable law and valid legal process; and
  • establish, exercise, or defend legal rights.

We do not use the demonstrations or their outputs to make decisions concerning healthcare, insurance, employment, credit, licensing, benefits, legal rights, or access to essential services.

6. Legal bases

Where the GDPR, UK GDPR, or another law requiring a legal basis applies, we rely on the following bases as appropriate:

Performance of a user-requested service. We process uploaded files and related information to perform the receipt-generation or verification operation that you request.

Legitimate interests. We process limited technical, diagnostic, security, and abuse-prevention information to operate and protect the website, provided those interests are not overridden by individual rights and interests.

Consent. We rely on consent for optional analytics, non-essential cookies, or communications where applicable law requires consent. You may withdraw consent without affecting earlier lawful processing.

Legal obligation and legal claims. We may process or retain information to comply with law or valid legal process, or to establish, exercise, or defend legal rights.

7. Cookies and analytics

The website may use cookies or similar technologies supplied by GoDaddy or other authorized website components.

Essential technologies. These support website delivery, security, load balancing, upload handling, session continuity, and storage of privacy choices.

Analytics technologies. The website may use analytics to understand aggregate traffic and improve website experience. Where consent is legally required, non-essential analytics are used only after consent. You may manage cookies through the available consent controls and your browser settings.

We do not intentionally place uploaded file contents, trust-bundle contents, package contents, generated receipts, verification results, private keys, or substantive demonstration inputs into analytics events. We do not use cookies for targeted advertising, cross-site behavioral profiling, or data-broker activity.

8. Retention and deletion

We retain information only for as long as reasonably necessary for the purpose for which it was processed. Normal retention periods are shown below.

InformationNormal retention period
Uploaded source files, trust bundles, .zip packages, and temporary extracted contentDeleted from active application storage within 24 hours after processing; where technically feasible, deleted sooner after the result is returned.
Generated receipts, verification results, and temporary operation dataDeleted from active application storage within 24 hours after processing, unless the user downloads or independently retains a copy.
Routine website, access, and security logsUp to 30 days, unless reasonably required for an active security, abuse, or availability investigation.
Analytics informationUp to 14 months, or a shorter period configured through the analytics service.
Cookie-consent recordsUp to 12 months before consent is requested again, unless a shorter period applies.
Ordinary correspondenceUp to 24 months after the last substantive communication.
Privacy, security, and legal-request recordsAs reasonably necessary to handle the matter and document compliance.
Information subject to a legal preservation requirementFor the duration of the applicable requirement.

9. GoDaddy hosting and service providers

larriverification.org is hosted using services provided by GoDaddy. GoDaddy and its authorized affiliates and subprocessors may process customer data and service information as necessary to provide hosting, storage, website delivery, availability, security, support, and related infrastructure services.

GoDaddy may process uploaded data passing through its infrastructure, server and access logs, IP addresses, account and service metadata, security information, and other information required to provide its services. GoDaddy’s processing is governed by the applicable service agreement and, where applicable, its data-processing terms.

We may also use limited service providers for security, malware detection, error monitoring, email, technical support, and professional advice. Providers receive only the information reasonably necessary to perform their services and are subject to applicable contractual and legal obligations.

10. Disclosure of information

We may disclose information to:

  • GoDaddy and its authorized affiliates and subprocessors;
  • security, malware-detection, error-monitoring, and technical-support providers;
  • email and communications providers;
  • legal, accounting, privacy, and security advisers;
  • public authorities where disclosure is required by valid legal process or applicable law;
  • emergency responders where disclosure is reasonably necessary to protect a person from serious harm; or
  • a successor operator in connection with a legitimate merger, acquisition, restructuring, or transfer of the website, subject to appropriate protections.

We do not sell personal information. We do not disclose personal information to data brokers or share it for cross-context behavioral advertising.

11. International processing

Information may be processed in the United States and in other countries where GoDaddy or another authorized provider operates. Data-protection laws in those locations may differ from the laws where you live.

Where applicable law requires safeguards for an international transfer, we use or rely on a legally recognized mechanism, such as an adequacy decision, approved contractual clauses, an applicable certification framework, or another authorized safeguard.

12. Security

We use reasonable administrative, technical, and organizational safeguards designed for the nature of the website and the risks created by file uploads. These safeguards may include:

  • encrypted HTTPS transmission;
  • restricted administrative access and account-security controls;
  • temporary and non-public upload locations;
  • file-size, request-rate, and resource limits;
  • safe archive inspection, including path and expansion checks;
  • separation of uploaded content from public website files;
  • automatic deletion controls;
  • security and abuse monitoring;
  • software and platform maintenance; and
  • incident-response procedures.

No Internet transmission, hosting platform, file parser, archive processor, or storage system can be guaranteed completely secure. You remain responsible for selecting appropriate test material and for protecting any receipt or verification result that you download.

13. Automated technical processing

The demonstrations automatically calculate cryptographic values and apply protocol and file-safety checks. They may produce outputs such as receipt generated, verification passed, verification refused, trust mismatch, signature failure, malformed object, unsupported feature, unsafe archive, or resource limit exceeded.

These outputs describe the technical treatment of the submitted artifact. They are not automated decisions that produce legal or similarly significant effects about a person, and they must not be used as a substitute for an authorized human, legal, clinical, regulatory, or business decision process.

14. Uploads made on behalf of another person or organization

If you upload information concerning another person, or act for an organization, you are responsible for ensuring that:

  • you have authority and a lawful basis to upload and process the information;
  • the upload is compatible with notices given to affected individuals;
  • the information is limited to what is necessary for the test;
  • required consent, authorization, or organizational approval has been obtained;
  • contractual, professional, confidentiality, healthcare, employment, and security obligations are satisfied; and
  • use of a conceptual demonstration is appropriate for the information and purpose.

Organizations that intend to submit personal information as part of regular operations should contact us before doing so. In the absence of a separate written data-processing agreement, uploads should be restricted to synthetic, public, non-confidential, or otherwise appropriately authorized test information.

15. Your privacy rights

Depending on your location and applicable law, you may have rights to:

  • request confirmation of whether we process your personal information;
  • request access to personal information;
  • request correction of inaccurate information;
  • request deletion;
  • request restriction of processing;
  • object to certain processing;
  • receive portable information where applicable;
  • withdraw consent without affecting processing that was lawful before withdrawal;
  • opt out of sale, sharing, or targeted advertising where applicable;
  • appeal certain decisions concerning a privacy request where applicable; and
  • complain to an appropriate privacy or data-protection authority.

To make a request, email hello@larriverification.org with the subject line “Privacy Request.”

We may request information reasonably necessary to verify and respond to the request. Because uploads are normally deleted within 24 hours and may not be associated with a user account or persistent identity, we may be unable to identify or recover a particular upload after the processing session or retention period ends.

We will not discriminate against a person for exercising an applicable privacy right.

16. Global Privacy Control and browser signals

Where applicable law requires it, we recognize a valid Global Privacy Control signal as a request to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising.

Other browser “Do Not Track” signals may not have a standardized legal or technical meaning. Cookie and analytics preferences can also be managed through available website controls and browser settings.

17. Children

The website, protocol materials, and demonstrations are intended for adult technical, professional, research, standards, and evaluation audiences. They are not directed to children under 13, and we do not knowingly request personal information from children.

If you believe a child has submitted personal information, contact hello@larriverification.org so that we can investigate and delete the information where appropriate.

18. Public submissions, links, and independent implementations

The website may link to public repositories, standards organizations, research publications, service providers, or independent LARRI implementations. Those third parties operate under their own terms and privacy policies. A link, protocol reference, compatibility statement, or conformance claim does not mean that LARRI Verification controls the third party’s privacy practices.

Comments, proposals, issue reports, or contributions submitted to a public repository or discussion system may become public and may be retained as part of the protocol-development record. Remove unnecessary personal or confidential information before submitting to a public channel.

This policy does not govern independently operated LARRI software, services, clients, verifiers, or deployments.

19. Security and privacy reports

Security vulnerabilities, suspected misuse, privacy concerns, and requests for a secure reporting channel may be sent to hello@larriverification.org.

Do not include real personal information, protected health information, private keys, or confidential production artifacts in an initial report. We may retain reports and related technical information as reasonably necessary to investigate, remediate, document, and disclose an issue responsibly.

20. Changes to this policy

We may update this Privacy Policy when website functionality, upload processing, retention, hosting, service providers, cookies, analytics, law, or security practices change. The effective date at the beginning of the policy will be updated when changes are published. Material changes may be accompanied by a prominent notice on the website.

The policy will be reviewed when a production service, account system, mailing list, additional upload type, new analytics service, or new processing purpose is introduced.

21. Contact

All privacy, security, legal, and general inquiries: hello@larriverification.org

LARRI Verification