← Back to RohaVerify

Privacy notice

Effective July 28, 2026

RohaVerify is operated by Roha IT Solutions. This notice explains what the service processes and why.

What the browser workflow sends

When you issue or verify a credential through the RohaVerify web app, the browser computes a SHA-256 fingerprint on your device. The document file itself is not sent to RohaVerify. The service receives the fingerprint and, when an issuer registers it, the issuer-supplied name, type, issue date, and optional metadata.

The separate POST /api/hash developer utility is different: a caller who deliberately uses that endpoint uploads a file so the server can calculate its fingerprint. The endpoint does not save the file, but sensitive documents should be hashed locally instead.

When the optional malware scanner is enabled, “Scan selected file” is a separate, explicit action. Choosing it uploads the selected file over HTTPS and streams the bytes to RohaVerify’s private ClamAV service. File bytes are not written to the registry or retained after the request. We retain derived reputation metadata: the SHA-256 fingerprint, ClamAV verdict and detection name, engine/signature version, scan time, and observation count.

Other data we process

How we use and share data

We use this data to operate the registry, prevent abuse, enforce issuer access and plan limits, investigate incidents, and support customers. Infrastructure providers such as Amazon Web Services, Stripe, and a configured identity provider process data only as needed to provide those functions. We do not sell personal information.

Retention and deletion

Registered credential fingerprints and their metadata remain in the registry so verification and revocation continue to work. Revocation preserves the record and marks it invalid; it is not a deletion. Malware reputation records use a deployment-configured expiration period (30 days by default); DynamoDB removes expired items asynchronously. Operational logs are retained according to the deployed environment’s logging policy. An authorized issuer can request account or data deletion, subject to security, contractual, and legal retention requirements.

Your choices

Do not use the optional malware scan for a file that must remain on your device. Do not place secrets, full document contents, health information, government identifiers, or other unnecessary sensitive data in credential names or metadata. To request access, correction, or deletion, contact support@rohait.com.

Changes

We will update the effective date when this notice changes materially.