Privacy notice
Effective July 28, 2026
RohaVerify is operated by Roha IT Solutions. This notice explains what the service processes and why.
What the browser workflow sends
When you issue or verify a credential through the RohaVerify web app, the browser computes a SHA-256 fingerprint on your device. The document file itself is not sent to RohaVerify. The service receives the fingerprint and, when an issuer registers it, the issuer-supplied name, type, issue date, and optional metadata.
The separate POST /api/hash developer utility is different: a caller who deliberately uses that endpoint uploads a file so the server can calculate its fingerprint. The endpoint does not save the file, but sensitive documents should be hashed locally instead.
When the optional malware scanner is enabled, “Scan selected file” is a separate, explicit action. Choosing it uploads the selected file over HTTPS and streams the bytes to RohaVerify’s private ClamAV service. File bytes are not written to the registry or retained after the request. We retain derived reputation metadata: the SHA-256 fingerprint, ClamAV verdict and detection name, engine/signature version, scan time, and observation count.
Other data we process
- Account and issuer identifiers used to authorize issuing, listing, and revoking credentials.
- Subscription and usage records when billing is enabled. Payment-card data is handled by Stripe, not stored by RohaVerify.
- Request metadata such as time, route, response status, client IP, and trace identifiers for security and reliability.
- Verification audit events, including the fingerprint checked, claimed issuer, outcome, and revocation state.
How we use and share data
We use this data to operate the registry, prevent abuse, enforce issuer access and plan limits, investigate incidents, and support customers. Infrastructure providers such as Amazon Web Services, Stripe, and a configured identity provider process data only as needed to provide those functions. We do not sell personal information.
Retention and deletion
Registered credential fingerprints and their metadata remain in the registry so verification and revocation continue to work. Revocation preserves the record and marks it invalid; it is not a deletion. Malware reputation records use a deployment-configured expiration period (30 days by default); DynamoDB removes expired items asynchronously. Operational logs are retained according to the deployed environment’s logging policy. An authorized issuer can request account or data deletion, subject to security, contractual, and legal retention requirements.
Your choices
Do not use the optional malware scan for a file that must remain on your device. Do not place secrets, full document contents, health information, government identifiers, or other unnecessary sensitive data in credential names or metadata. To request access, correction, or deletion, contact support@rohait.com.
Changes
We will update the effective date when this notice changes materially.