Effective date: 2026-07-10 · Applies to the Trustamp Android app (com.trustamp.camera) and the trustampcamera.com website.
Trustamp is built privacy-first. Most of what you do happens entirely on your phone, and you can use the core watermark camera without an account and without sending us anything. This policy explains exactly what leaves your device, when, and why.
Trustamp does not require you to sign up or provide a name, email, or phone number. On first launch, the app generates a random anonymous device identifier (a UUID) stored on your device. It is sent with credential requests so we can group a device's own credentials together. It is not linked to your real-world identity and is not an advertising identifier.
Watermark mode (free):
Photos are captured and watermarked entirely on your device. Nothing is transmitted to us.
"Witness" mode (when you choose to make a photo verifiable):
Witnessing anchors when and where a photo was taken to our server. We send the following to record it:
We do not receive your photo, and we do not receive a hash or fingerprint of it. Image tamper-evidence is handled separately, by C2PA, below.
C2PA Content Credentials (optional, off by default):
If you turn on C2PA signing, the app embeds a tamper-evident Content Credential in the photo. This is created and cryptographically signed entirely on your device — the credential lives inside the image file, and our servers are not involved in it. Nothing about your image is sent to us to produce it.
Crash diagnostics:
We use Google Firebase Crashlytics to detect and fix crashes. If the app crashes, Crashlytics may collect a crash log (stack trace), diagnostic information about the device and app state at the time, and a Crashlytics installation identifier. This helps us keep the app stable and is not used for advertising.
The trustampcamera.com website does not ask for or store any personal information — there is no sign-up form or account. Downloads happen through the Google Play Store under Google's own terms.
We do not sell your data or share it for advertising. We use these service providers (data processors) to run Trustamp:
A credential is designed to be checkable. When you share a credential's verification URL, anyone with that link can view the credential details (time, location, and verification status). You control who receives the link. Don't share a verification URL if its details are sensitive.
We keep credential records for as long as needed to provide verification. Because the app is anonymous, deletion is by device identifier: email [email protected] from within the app (Settings includes your device ID) or with your device ID, and we will delete your associated records within 30 days.
Trustamp is a tool for work and professional documentation and is not directed to children under 18. We do not knowingly collect data from children.
Trustamp serves a global audience. Data may be processed on Cloudflare and Google infrastructure in countries other than yours, with safeguards appropriate to the transfer.
We'll update this policy as the app evolves (for example, if a future version adds optional photo upload). Material changes will be reflected by a new effective date on this page.
Trustamp · [email protected]