RightsRoot

Privacy

Last updated 7 September 2026

There is no account, no email address, no password on our servers, no cookie, and no analytics.
Every claim on this page is one you can check yourself. Where we cannot make a claim honestly, we say so instead of rounding it off.

What never reaches us

Your signing key is generated in your browser and never leaves the device it was created on. Neither does anything derived from it. We cannot sign as you, we cannot read your vault, and we cannot recover your account — not as a policy choice, but because we do not have the material required to do any of it.

Notices and their PDFs are built in your browser and downloaded directly. They are never uploaded. That is why a notice can carry your plate while your published policy cannot.

What we receive, and only when you press publish

We store the signed bytes exactly as you produced them, and serve them back unchanged. We do not parse, rewrite, enrich, or index the contents.

What our hosting provider sees

This is the part most privacy policies leave out. RightsRoot runs on Vercel. Like any web host, Vercel processes your IP address and request details in order to deliver the page and to defend against abuse. We do not add to that, we do not query it, and we do not join it to anything you publish — but we would be misleading you if we claimed nobody sees an IP.

If that matters for your situation, you can reach this site over Tor or a VPN, and you can verify any published policy entirely offline without contacting us at all.

No analytics, and how to confirm it

There is no analytics script, no session recording, no tag manager, no advertising pixel, and no third-party resource of any kind. The page loads only its own JavaScript.

Check it: open your browser’s network tab and load any page here. Every request goes to this domain. Or read the source — the repository is public.

Cookies

None. We do not set any, for any purpose, including “essential” ones.

Your browser stores your encrypted vault and your drafts in local storage on your own device. That never leaves your machine and is not readable by us. Clearing your browser data deletes it, and without your backup phrase it cannot be recovered.

Publishing is a public act

A published policy is meant to be read. Anyone with the link can fetch it, and search engines or archives may copy it. It contains no raw identifiers, but it is permanent in the sense that anything public is permanent.

Two honest limits. If you give the same published policy to two organizations, those two can tell they received the same document. And if you tell someone your handle, you have linked yourself to it — we cannot undo that.

Deletion

You can ask us to remove a published policy and its handle, and we will. Because there is no account, tell us the handle and prove you control the key by signing the request — that is the only way we can tell it is yours.

We cannot delete copies other people already downloaded, and we would not claim otherwise. Anything you delivered to a recipient is in their hands.

Children

RightsRoot is not directed at children, and we have no way to know a user’s age because we ask nothing about you.

Changes

If this policy changes materially, the change will be visible in the public repository’s history alongside the date above. There is no mailing list to notify, because we do not have your email address.

Contact

RightsRoot is operated by Breezy Point Beach LLC. Privacy questions: privacy@rightsroot.com.