1. Who We Are
BlockContentSeal is a content provenance infrastructure platform that cryptographically seals published articles on-chain. It is a joint venture operated by:
- Moonlorian (moonlorian.com)
- FortyTwo (fourtytwo.com)
References to "we", "us", or "BlockContentSeal" in this policy refer to the joint venture. For data protection purposes, the joint venture partners act as joint data controllers.
You can reach us at: blockcontentseal.com/contact or info [at] blockcontentseal.com
2. What We Do — and What We Don't Touch
When you seal an article via our API, the following data is recorded on the blockchain:
- SHA-256 hash of the article content
- Article URL or publisher-defined identifier
- Author identifier (as provided by you)
- Unix timestamp of the sealing request
- Publisher API key identifier (not the secret key itself)
This data is written to a public blockchain and is therefore permanent and publicly accessible by design — that is the foundation of our provenance guarantee. Do not include any personal or sensitive data in content identifiers or author fields beyond what you intend to be public.
3. Contact Form Data
When you use the contact form on blockcontentseal.com/contact, we collect:
- Your name
- Your email address
- The content of your message
This data is used solely to respond to your enquiry. We do not add you to mailing lists, share your details with third parties, or use them for marketing purposes without your explicit consent.
Contact form submissions are transmitted via encrypted SMTP and stored only in our email inbox. We retain correspondence for up to 24 months, after which it is deleted.
Legal basis (GDPR Art. 6 §1 lit. f): our legitimate interest in responding to business enquiries.
4. API Usage Data
When publishers integrate with our API, server logs may record:
- IP addresses of API requests
- Timestamps of API calls
- HTTP status codes and response times
- API key identifier (not the secret)
These logs are used exclusively for security monitoring, rate limiting, and debugging. They are retained for a maximum of 30 days on a rolling basis.
We use Redis to enforce per-IP rate limits on the contact form endpoint. These counters expire automatically after 1 hour and contain only an anonymised IP address.
5. Cookies and Tracking
This website does not use advertising trackers, third-party analytics cookies, or any form of cross-site tracking.
We do not use Google Analytics, Meta Pixel, or similar tools.
Session state for the contact form (HMAC challenge token) is a short-lived value transmitted with the form submission. It is not stored in a cookie and expires within 30 minutes.
If we introduce any cookies in the future, this policy will be updated and users will be informed.
6. Third-Party Services
The following external services are involved in operating BlockContentSeal:
- Public blockchain networks — Hash anchoring records are written to a distributed ledger. Blockchain data is public, permanent, and not within our control to modify or delete.
- Google Fonts — This website loads font files from Google's CDN, which means your browser makes a request to Google's servers. See Google's Privacy Policy.
- SMTP provider — Contact form emails are delivered via our SMTP provider. Message content is encrypted in transit.
7. Your Rights Under GDPR
If you are located in the European Economic Area, you have the following rights regarding any personal data we hold about you:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your data where no legal obligation to retain it exists
- Right to restriction — request that we limit how we use your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interest
Please note: data written to a public blockchain cannot be deleted or modified by us or anyone else — this is an inherent property of blockchain technology. We will not write any information to the blockchain that you have not explicitly provided as a content identifier.
To exercise any of the above rights, contact us via blockcontentseal.com/contact. We will respond within 30 days.
8. Data Security
We apply industry-standard security measures to protect your data:
- All data in transit is encrypted with TLS 1.2 or higher
- API keys are stored as hashed values; plaintext secrets are never logged
- Server access is restricted by IP allowlist and SSH key authentication
- Contact form submissions are protected by HMAC challenge tokens to prevent automated abuse
No method of transmission over the internet is 100% secure. In the event of a data breach affecting your personal data, we will notify affected parties as required by applicable law.
9. International Data Transfers
Our servers are located within the European Union. Where any processing or transfer occurs outside the EU/EEA, we ensure it is covered by an appropriate legal mechanism such as Standard Contractual Clauses (SCCs).
Blockchain data, by its nature, is replicated across nodes worldwide. This is disclosed in Section 2 and Section 6 above.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced on this page with an updated effective date. We encourage you to review this page periodically.
Continued use of BlockContentSeal after a policy update constitutes your acceptance of the revised terms.
11. Contact
Questions, requests, or complaints regarding this Privacy Policy can be directed to us via our contact page or by email:
blockcontentseal.com/contact
info [at] blockcontentseal.com
BlockContentSeal is a joint venture by Moonlorian and FortyTwo.