Fill out one insurance quote form and your name, phone number, and address end up in nine places. Maybe more.
I know because I built some of the nine.
For a big chunk of my career I built lead generation and lead distribution platforms. The flagship at 360Connect ran on a single codebase across about twenty vertical sites. At Request Path Media I designed a platform that processed millions of lead requests a day with real-time bidding and distribution. I know exactly how a form submission becomes a record, how that record gets sold, resold, and routed, and how little of that journey the person who typed it in ever sees.
I'm not here to confess to anything. That industry funds a lot of the free internet, and most of the people in it are playing by the rules. But after twenty years on the building side, one thing kept bothering me.
No Receipt
Handing over your contact details is the most common transaction on the internet. It's also the only one with no receipt.
Buy a coffee and you get a receipt. Sign a lease and you get a copy. Type your phone number into a form and you get... nothing. No record of what you shared, with whom, under what terms. And when a call center rings you three weeks later, you have no way to prove you never agreed to it, and they have no clean way to prove you did.
That last part is the one people miss. Businesses have the same problem from the other side. Consent disputes are expensive, and "our vendor says the checkbox was ticked" isn't a great position to defend.
What PRYVC Is
PRYVC (pronounced like "privacy") is OAuth for contact details. You keep one encrypted profile. When a site wants your details, you share them in a click, and you get a receipt: exactly which fields went where, when, and under what terms.
Change your mind later? Revoke it. PRYVC serves the cease-contact notice, tracks the deadline, and keeps the proof. If the business stays silent, that silence gets recorded too.
The browser extension went live in the Chrome Web Store this week. It only talks to our API, only runs when you click it, and never ticks a consent box on your behalf. That last rule is deliberate. The day a privacy tool starts manufacturing consent is the day it becomes the problem it was built to solve.
How a Share Works
If you've implemented OAuth, the shape will feel familiar:
- The site redirects you to PRYVC with a PKCE challenge. You approve exactly the fields it asked for.
- The site gets a single-use share code that expires in 60 seconds and returns your fields exactly once. No long-lived access tokens sitting in somebody's database waiting to leak.
- Every share gets a SHA-256 fingerprint over its canonical JSON, and every event lands in an append-only audit log where each row's hash includes the one before it.
Every field is encrypted with AES-256-GCM under a per-user key, and each share derives its own key. And I'll say the uncomfortable part plainly, because the site does too: we hold the keys. A lot of privacy products imply they can't see your data when they can. Saying otherwise would be a lie, and a privacy company that starts by lying has already lost the plot.
Proof That Doesn't Depend on Me
An audit log I control is the same problem I wrote about with Engrave: testimony, not evidence. So PRYVC anchors the head of its audit chain to Engrave's Merkle ledger on a schedule, and the ledger is public. If anyone, including me, rewrote history, the anchors wouldn't match.
Full disclosure, because it matters in exactly this context: Engrave is also mine. It's the same technique I'd recommend to any client. Commit your log to something with public, independently verifiable proofs, and let people check the math instead of trusting the operator.
For Businesses
The business side is a single <script> tag. Zero dependencies, a few kilobytes. Put a Share button on your form and you get verified contact details with a consent record attached, instead of whatever the user fat-fingered into the phone field.
For regulated lead flows like insurance, mortgage, solar, and legal, there's a certified-consent mode. It fails open by design: if capture fails for any reason, the form still submits. Your conversion rate shouldn't depend on my uptime.
The Protocol Is Free
The share format is an open spec, SP/1, published at shareprotocol.org under CC BY 4.0. No patents. Anyone can implement it, including competitors.
That might sound backwards. It isn't. Consent records only matter if the other side can verify them without buying my software. A proprietary consent format is just a nicer-looking vendor lock-in. I'd rather PRYVC win on being the best implementation of an open standard than on being the only one.
Consumers use it free, forever. Businesses pay a flat annual price. Not per lead. Metering prices the right thing to do in proportion to how much of it you do, and that's exactly backwards.
PRYVC is live at pryvc.com, and the extension is in the Chrome Web Store. If you run a lead flow and consent disputes are a line item you'd like to shrink, let's talk.