Last updated: August 8, 2026
Lantern LLC ("Lantern," "we," "us," "our") operates the Lantern Provenance System, including:
api.lantern-us.comThese collectively are the "Service." This policy explains what data we collect, how we use it, and what rights you have over it.
Data controller: Lantern LLC, 3100 33rd Pl NW, Washington, DC 20008, United States. Contact: contact@lantern-us.com.
When you create a Lantern account, we collect and store:
If you sign up with "Continue with Google," we additionally store Google's opaque stable user ID (sub) so we can recognize you on return visits. We do not store your Google name, Google profile picture, or any other Google profile field.
When you register a piece of work, we collect and store:
LNTN-xxxxxxxx) we assignProtection copy and preview thumbnail (from the effective date). When you register a work, we also keep:
Both are on by default. You can turn either one off for any individual work from your dashboard (Settings on the work card), and you can set an account-level default for future registrations. Turning the protection copy off deletes it from our storage; hiding the thumbnail deletes the public file (already-cached copies expire from the content delivery network within about 1 hour).
We still do not retain your original file. The full-resolution file you upload is used transiently to compute the hashes, vectors, and the resized copies above, and is then discarded. If you turn the protection copy off, no image content is retained for that work at all: only the hashes and vectors (which are mathematical summaries, not recoverable images) remain.
Works registered before the effective date: we hold no image copy for these. If the same image passes through Lantern again after the effective date (for example you re-index it, or our source-check worker re-fetches it from the platform URL you registered it from and the bytes match exactly), a protection copy and thumbnail are created at that point under the same rules and controls, unless you have opted the work or your account out.
Child-safety screening (from the effective date): before storing any image copy, we screen it against databases of known child sexual abuse material. The screening software runs on Lantern's own servers: it converts your image into an irreversible numerical signature (roughly 1 KB), and only that signature is sent to the matching service (Microsoft PhotoDNA, see §4.3). Your image itself is never transmitted, and the signature cannot be reversed to reconstruct it. Apparent child sexual abuse material is never stored as a protection copy or thumbnail and is reported as described in §4.4.
During the processing step, image bytes are transmitted to our neural-inference provider (Modal, see §4.3) so the embedding vectors can be computed on GPU hardware. Modal's containers terminate after inference and do not retain the image bytes.
If you link a social media account to prove platform ownership (Twitter, Pixiv, DeviantArt, ArtStation, Instagram, etc.), we store the platform name, your username on that platform, and the verification status of the link.
If you file a dispute or report against a registered work, we store your email, your name (if you provide it), your claim description, and any evidence URLs you submit.
DMCA takedown notices you submit become part of our records for the duration required to comply with the notice-and-takedown process and any associated legal obligations.
To keep your account secure, we store:
jti), the approximate IP address of the most recent request, the user-agent string, and the timestamps of issuance, last use, and last re-authenticationThe Lantern browser extension:
LNTN-xxxxxxxx) on supported art platforms to display verification badgeschrome.storage for up to 1 hourThe extension does not track browsing history, collect data from non-art-platform sites, or transmit any data about your browsing to us.
Where GDPR applies, we process your personal data on the following bases:
We do not sell your personal information. We share data only in these cases:
The following are intentionally public and visible to anyone, including search engines:
/verify/{LNTN-ID} page and indexed by search enginesWhen a registration confirms, the content hash and your wallet address are written to the Base blockchain (an Ethereum Layer 2 network). Blockchain records are public and cannot be deleted. This permanence is required for provenance to be verifiable by anyone. Image files, protection copies, and thumbnails are never written to the blockchain.
We use the third-party service providers below to operate the Service. The authoritative list is published at lantern-us.com/subprocessors.
| Provider | Purpose | Data shared |
|---|---|---|
| Resend (Delaware, US) | Transactional email delivery | Email address, display name, email body (verification links, password reset links, account notices) |
| Google LLC (Delaware, US) | OAuth identity provider for "Continue with Google" | Only what you consent to at Google's sign-in prompt: email, display name, profile picture URL, Google sub ID. Only applies if you click the Google sign-in button. |
| Modal (Delaware, US) | Serverless GPU inference for neural-matcher embeddings (candela-2.2, SSCD, DINOv3, CopyNCE) | Image bytes you upload at registration or image-based verification are transmitted to Modal for embedding computation. Modal returns numerical vectors; image bytes are not retained by Modal after processing. No account identifiers (email, display name, wallet address) cross this boundary. |
| DigitalOcean (New York, US) | Cloud hosting for the Lantern application server, managed PostgreSQL database, and object storage for image copies | All account data we store (email, display name, encrypted wallet key, registration records, dispute history) resides on DigitalOcean infrastructure. From the effective date, protection copies and preview thumbnails of registered works (Section 2.2) are stored in DigitalOcean Spaces object storage in the United States. DigitalOcean does not have application-level access; they operate the underlying compute and storage. |
| Microsoft PhotoDNA (Washington, US) | Child-safety screening of image copies before storage (from the effective date) | An irreversible numerical signature (roughly 1 KB) computed from the image on Lantern's own servers, using screening software Microsoft licenses to us. Only the signature is sent, to be checked against databases of known child sexual abuse material. The image itself never leaves our infrastructure, and the signature cannot be reversed to reconstruct it. No account identifiers (email, display name, wallet address) cross this boundary. |
| Base network public RPC endpoints: Coinbase (mainnet.base.org) with PublicNode (base.publicnode.com) as fallback | Base blockchain RPC access (transaction relay and on-chain reads) | When a registration is written to the Base blockchain, we submit the transaction (content hash, metadata URI, creator wallet address, signature) through these public RPC endpoints. These fields are public on-chain by design; no email or display name crosses this boundary. These are unauthenticated public endpoints: Lantern holds no account with either operator, and every field transmitted becomes public blockchain data regardless of transport. Before July 16, 2026 this role was filled by Alchemy (San Francisco, US); Alchemy no longer receives any Lantern traffic. |
We may disclose data when required by law, legal process, or to protect the rights, property, or safety of Lantern, its users, or others. This includes responding to valid subpoenas, court orders, and DMCA takedown notices (see lantern-us.com/dmca).
Mandatory child-safety reporting: if we become aware of apparent child sexual abuse material on the Service, US law (18 U.S.C. § 2258A) requires us to report it to the National Center for Missing & Exploited Children (NCMEC). A report may include the image, its hashes, the upload timestamp, the source URL if the image was registered from a platform page, the account email address, and related log data. Federal law requires us to preserve the content of a report for one year after submission. We do not notify the reporting account.
| Category | Retention |
|---|---|
| Account (email, display name, password hash, wallet) | For the life of your account, plus up to 30 days after deletion to process the deletion |
| Email verification and password reset tokens | 15 and 30 minutes respectively; deleted on consumption |
| Active sessions | 90 days of inactivity, then auto-pruned |
| Throttle / rate-limit events | Up to 24 hours |
| Content registrations (off-chain metadata) | Until you delete or revoke; revoked records are marked revoked but retained for audit |
| Content registrations (on-chain record) | Permanent (Base blockchain). Cannot be deleted. |
| Protection copy of a registered work (from the effective date) | Until you turn it off for the work, opt your account out, or delete your account with the revoke-everything option; deletion from storage is immediate. Revoked works keep their protection copy (privately) while reactivation remains possible. |
| Preview thumbnail (from the effective date) | Until you hide it, opt out, revoke the work, or a dispute against the work is upheld; the stored file is deleted immediately and cached copies expire from the content delivery network within about 1 hour |
| Child-safety report contents | One year after the report is submitted, as required by 18 U.S.C. § 2258A(h); report metadata retained indefinitely |
| Dispute and DMCA records | Retained as required by law; typically 3 years |
| Admin action logs | Indefinite; required for audit |
To exercise these rights, email contact@lantern-us.com. We may ask you to verify account ownership before acting on sensitive requests.
If you are in the EU, UK, or EEA, you additionally have the right to data portability, the right to object to processing based on legitimate interests, and the right to lodge a complaint with your local data protection authority.
If you are a California resident, you have the rights described above plus the right to know what categories of personal information we collect, the right to opt out of the sale or sharing of personal information (note: we do not sell or share for cross-context behavioral advertising), and the right to non-discrimination for exercising these rights.
You can delete your Lantern account at any time from /dashboard/security (the "Delete account" card at the bottom of the page). The deletion is permanent and cannot be undone.
What gets deleted: your email, password hash, encrypted wallet private key, all sessions (you are signed out everywhere), email-verification and password-reset tokens, two-factor secrets and backup codes, linked-platform handles (Twitter, Pixiv, etc.), and in-flight registrations that have not yet confirmed on chain. Terms-of-service assent records are also deleted; an internal audit log retains a record that the deletion happened (date, the disposition you picked, and counts) for compliance purposes, but does not retain the email or wallet in any user-searchable form.
What happens to registered work: at the moment you delete, you choose one of three options:
/verify and to platforms checking the API, including any protection copies and thumbnails they have (you can turn those off per work before deleting). Your account is gone but your provenance record is intact.[deleted account]. Your wallet address still shows because it is on the blockchain and cannot be erased. Pick this if you want your name off the public record while keeping the work registered.revoked) before your account is deleted, and every stored protection copy and thumbnail for your works is deleted from our storage. If any step fails, nothing happens and your account stays alive so you can retry. Revocation is permanent on chain.What we cannot delete: on-chain records on the public Base blockchain. Your wallet address, the content hashes you registered, and the timestamps of those registrations are visible on chain regardless of what you do here. You can revoke a registration so it displays as revoked, but the historical record stays on chain. By using Lantern you acknowledge this permanence; do not register anything you may need to have permanently and entirely removed.
If self-service does not work for you (for example, two-factor authentication enabled, lost access to your email, or you cannot sign in), email contact@lantern-us.com with the email address on the account and we will action the deletion manually within 30 days. We may ask you to confirm your wallet address or sign a verification message to prove ownership.
Lantern is operated from the United States. If you access the Service from outside the US, your personal data is transferred to the US for processing. Our US-based subprocessors that handle personal data (Resend, Google, Modal, DigitalOcean, Microsoft) process it subject to US law. Each of those subprocessors' standard Data Processing Agreements (incorporated into their Terms of Service, which we accepted at account creation) includes the EU-approved Standard Contractual Clauses for international transfers; the authoritative links are on our Subprocessors page. Blockchain RPC transport uses public, unauthenticated endpoints and carries only fields that are public on-chain by design (see Section 4.3).
Technical measures we apply:
No system is perfectly secure. If you believe your account has been compromised, email us immediately at contact@lantern-us.com and change your password via the forgot-password flow.
Lantern is not directed at children under 13 years of age (or the equivalent minimum age in your jurisdiction). At account creation we require every user to confirm they are at least 13 years old. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, email contact@lantern-us.com and we will take steps to delete it.
Lantern uses localStorage to store your session token on your device so you stay signed in across page loads. We do not use cookies for tracking and do not set third-party advertising cookies. The browser extension uses chrome.storage for local preferences and a short verification cache; nothing in this store is sent to us.
See lantern-us.com/dmca for our DMCA takedown and counter-notice procedures. Our designated DMCA agent is registered with the U.S. Copyright Office (DMCA-1071708).
We may update this policy from time to time. We will update the "Last updated" date at the top. For material changes that affect your rights, we will email registered users with reasonable advance notice before the change takes effect.
For privacy questions, data-subject-rights requests, or general inquiries, email contact@lantern-us.com.
For DMCA notices, see the contact at /dmca.