Privacy Policy & Terms of Use

Captilo - Blockchain-Verified Photo Authentication App

Last Updated: November 2025

PLEASE READ THIS POLICY CAREFULLY BEFORE USING THE APP

1. Acceptance of Terms

By downloading, installing, accessing, or using the Captilo application ("App"), you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy and Terms of Use ("Agreement"). If you do not agree to all terms and conditions of this Agreement, you must not use the App. Your continued use of the App constitutes your ongoing acceptance of this Agreement and any updates thereto.

Defitec Solutions Ltd. reserves the right to modify this Agreement at any time. Changes will be effective immediately upon posting. Your continued use of the App after any modifications indicates your acceptance of the updated Agreement. It is your responsibility to review this Agreement periodically.

2. Introduction

Defitec Solutions Ltd. ("we," "our," "us," or the "Company") operates the Captilo mobile application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.

Privacy-First Architecture: Our core principle is that your photos and biometric data never leave your device. Only cryptographic hashes—mathematical fingerprints that cannot be reversed to reveal your data—are transmitted to enable verification.

3. Information We Collect

3.1 Information Stored Locally on Your Device

The following information is captured and stored exclusively on your device and is never transmitted to our servers or any third party:

Original Photos

All photos captured through Captilo remain in your device's encrypted storage, protected by your operating system's security features.

Biometric Data

Fingerprint templates and facial recognition data remain permanently in your device's hardware secure enclave (Secure Enclave on iOS, TEE/StrongBox on Android). This data is inaccessible to any software, including Captilo.

Private Cryptographic Keys

Generated and stored in hardware-backed keystores on your device, never exported or cloud-synced.

3.2 Information Transmitted to Blockchain

When you create a verified proof, approximately 3-4 kilobytes of non-sensitive, cryptographically irreversible data is transmitted to the blockchain:

Photo Hash

A 64-character SHA-256 cryptographic fingerprint. Cannot be reversed to reconstruct your photo.

Timestamp

The precise moment of capture in UTC format (millisecond precision).

GPS Coordinates

Latitude, longitude, accuracy radius, and altitude—only if you have granted location permission. Optional and user-controlled.

Public Key

Your cryptographic public key required for signature verification.

Biometric Commitment

A zero-knowledge proof hash that proves biometric authentication occurred without revealing any biometric data.

Fraud Detection Scores

Numerical integrity metrics computed locally.

Device Metadata

Device model, operating system version, and a pseudonymized device identifier.

Technical IDs

App Version, Blockchain Event ID, and Certificate ID for verification purposes.

4. How We Use Your Information

We use the transmitted information solely for the following purposes:

Verification Services

To create immutable blockchain records that enable independent verification of photo authenticity.

Fraud Detection

To analyze metadata patterns (not photo content) to identify potential manipulation or fraudulent submissions.

Service Improvement

To improve our fraud detection algorithms and application performance.

Technical Support

To diagnose and resolve technical issues when you contact us for support.

5. Data Storage and Security

5.1 Local Storage Security

Your photos and sensitive data are protected by multiple layers of security:

iOS Protection: Data Protection classes with keys derived from device passcode and Secure Enclave hardware.

Android Protection: File-based encryption with keys stored in TEE or StrongBox hardware modules.

Biometric Security: Biometric data remains in hardware secure enclaves physically separated from the main processor.

5.2 Blockchain Storage

Cryptographic hashes submitted to the blockchain are stored permanently and immutably. These hashes are pseudonymous data that cannot be linked back to individuals unless you choose to share your verification certificates.

5.3 Security Disclaimer

WHILE WE IMPLEMENT INDUSTRY-STANDARD SECURITY MEASURES, NO METHOD OF TRANSMISSION OVER THE INTERNET OR METHOD OF ELECTRONIC STORAGE IS 100% SECURE. We cannot guarantee the absolute security of your data. You acknowledge and accept that any transmission of data is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained in the App or your device.

6. Third-Party Services

We do not sell, trade, or rent your personal information to third parties. The only third-party services receiving data from Captilo are blockchain networks, which receive cryptographic hashes for permanent timestamping.

Third-Party Disclaimer: Sonic and Constellation Network are independent third-party blockchain infrastructures. Defitec Solutions Ltd. has no control over and assumes no responsibility for the content, privacy policies, practices, availability, or performance of these blockchain networks or any other third-party services. Your use of such third-party services is at your own risk and subject to the terms and conditions of those third parties.

7. Your Privacy Rights

You have the following rights regarding your data:

Right to Access

You can export all proofs as ZIP files containing photos and metadata JSON files.

Right to Deletion

You can delete proofs from your local device database instantly. Note that cryptographic hashes on the blockchain cannot be deleted due to blockchain immutability.

Right to Portability

ZIP export functionality allows you to move proofs to new devices or archive them.

Right to Rectification

You can modify local metadata like descriptions and tags. Core proof data cannot be modified after blockchain submission.

Right to Withdraw Consent

You can revoke permissions at any time through your device settings.

8. User Responsibilities and Acceptable Use

By using the App, you agree to the following responsibilities:

  • You are solely responsible for maintaining the security of your device, including keeping your operating system updated and using appropriate device security measures.
  • You are solely responsible for all activities that occur under your device and within the App.
  • You will not use the App for any unlawful purpose or in violation of any applicable laws or regulations.
  • You will not attempt to circumvent, disable, or interfere with security-related features of the App.
  • You will not use the App to create false, misleading, or fraudulent evidence or documentation.
  • You will not reverse engineer, decompile, disassemble, or attempt to derive the source code of the App.
  • You acknowledge that verification certificates are tools to support authenticity claims and are not a guarantee of legal admissibility in any jurisdiction.
  • You are responsible for backing up your own data. Loss of device data is your sole responsibility.

9. Disclaimer of Warranties

THE APP IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR COURSE OF PERFORMANCE.

No Guarantee of Legal Admissibility

While Captilo provides cryptographic verification and blockchain timestamping, Defitec Solutions Ltd. makes no representation or warranty that verification certificates will be accepted as evidence in any court, arbitration, insurance claim, or other legal or administrative proceeding.

No Guarantee of Fraud Detection

While Captilo includes fraud detection capabilities, Defitec Solutions Ltd. does not guarantee that all fraudulent, manipulated, or AI-generated images will be detected. Users should not rely solely on Captilo's fraud detection for critical decisions.

No Professional Advice

The App does not provide legal, insurance, financial, or professional advice. Always consult qualified professionals for legal, insurance, or other professional matters.

10. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL DEFITEC SOLUTIONS LTD., ITS DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, PARTNERS, SUPPLIERS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA, OR OTHER INTANGIBLE LOSSES.

This includes but is not limited to damages resulting from:

  • Your access to, use of, or inability to access or use the App
  • Any conduct or content of any third party on or related to the App
  • Loss of data stored on your device, including photos and verification proofs
  • Failure of verification certificates to be accepted as evidence in any proceeding
  • Errors, inaccuracies, or failures in fraud detection
  • Blockchain network unavailability, delays, or failures
  • Device hardware or software failures

IN NO EVENT SHALL DEFITEC SOLUTIONS LTD.'S TOTAL LIABILITY EXCEED THE AMOUNT YOU PAID TO DEFITEC SOLUTIONS LTD. DURING THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR ONE HUNDRED US DOLLARS ($100), WHICHEVER IS GREATER.

11. Indemnification

You agree to defend, indemnify, and hold harmless Defitec Solutions Ltd., its parent company, officers, directors, employees, agents, licensors, and suppliers from and against any claims, actions, demands, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to your use or misuse of the App, your violation of this Agreement, or your violation of any rights of another party.

12. Force Majeure

Defitec Solutions Ltd. shall not be liable for any failure or delay in performing its obligations under this Agreement where such failure or delay results from circumstances beyond Defitec Solutions Ltd.'s reasonable control, including but not limited to: acts of God, natural disasters, war, terrorism, riots, government actions, pandemic or epidemic, power outages, internet or telecommunications failures, blockchain network failures, cyberattacks, or failures of third-party service providers.

13. Dispute Resolution and Arbitration

PLEASE READ THIS SECTION CAREFULLY. IT AFFECTS YOUR LEGAL RIGHTS, INCLUDING YOUR RIGHT TO FILE A LAWSUIT IN COURT.

Informal Resolution: Before initiating any formal dispute resolution proceeding, you agree to first contact us at contact@captilo.app and attempt to resolve any dispute informally for at least thirty (30) days.

Binding Arbitration: If informal resolution is unsuccessful, any dispute shall be finally settled by binding arbitration in accordance with mutually agreed-upon arbitration rules.

Class Action Waiver: YOU AND DEFITEC SOLUTIONS LTD. AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING.

14. Governing Law and Jurisdiction

This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction in which Defitec Solutions Ltd. is incorporated, without regard to its conflict of law provisions.

15-17. Severability, Entire Agreement, Waiver

Severability: If any provision is held invalid, the remaining provisions continue in full force.

Entire Agreement: This Agreement constitutes the entire agreement between you and Defitec Solutions Ltd. regarding your use of the App.

Waiver: No waiver of any term shall be deemed a further or continuing waiver.

18. Device Permissions

Captilo requests the following permissions:

📷 Camera

Required to capture photos for verification. Photos remain on your device.

🔐 Biometric Authentication

Required to verify device owner authorization. Biometric data never leaves your device.

📍 Location (Optional)

GPS coordinates strengthen proof credibility but are not required.

🌐 Internet

Required to submit proofs to the blockchain for timestamping.

💾 Storage

Required to save photos and proof data locally on your device.

19. Children's Privacy

Captilo is not intended for use by children under 13 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at contact@captilo.app, and we will take steps to delete such information.

20. International Data Transfers

Cryptographic hashes are submitted to blockchain networks, including decentralized global blockchains. By using Captilo, you acknowledge that your cryptographic hashes (not photos or personal data) may be processed by blockchain nodes located in various jurisdictions worldwide.

21. Changes to This Agreement

We may update this Agreement at any time. We will notify you of material changes by posting the new Agreement in the App and updating the "Last Updated" date. Your continued use of the App after changes become effective constitutes your acceptance of the revised Agreement.

22. Contact Us

If you have questions about this Agreement or our privacy practices, please contact us:

contact@captilo.app
captilo.app
Captilo by Defitec Solutions Ltd.

23. Additional Information for EU/EEA Users (GDPR)

For users in the European Union and European Economic Area, Defitec Solutions Ltd. acts as the data controller for any personal data processed. Our legal basis for processing is your consent (which you provide by using the App) and our legitimate interest in providing verification services.

The biometric commitment stored on the blockchain is not considered "biometric data" under GDPR Article 9 because it cannot be used to identify individuals or be reconstructed to reveal biometric information.

You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates applicable law.

24. California Privacy Rights (CCPA)

California residents have specific rights regarding their personal information under the California Consumer Privacy Act (CCPA). We do not sell personal information to third parties. California residents may request disclosure of the categories and specific pieces of personal information collected, the sources of collection, the business purpose for collection, and the categories of third parties with whom information is shared. To exercise these rights, contact us at contact@captilo.app.

25. Summary

In summary: Your photos never leave your device. Your biometric data never leaves your device's secure hardware. Only mathematical fingerprints—which cannot reveal your photos or identity—are stored on the blockchain. The App is provided "as is" without warranties. Defitec Solutions Ltd.'s liability is strictly limited. By using the App, you accept all terms of this Agreement.