PRIVACY
WHAT I KEEP,
AND FOR HOW LONG.
IN SHORT. Proof First is run by one person, Christopher Rivero. I collect what you type into the form and nothing else on purpose. I keep it for the times written below, I don’t sell it, and you can ask me to delete it. Contact: christopherarivero@gmail.com. Last updated October 9, 2026.
WHO I AM
Proof First is operated by Christopher Rivero. For any question, request or deletion, write to christopherarivero@gmail.com.
WHAT YOU GIVE ME
- Your email address, so I can reply.
- What should happen and what happens instead. The form keeps your two answers together as one piece of text.
- A link, only if you choose to add one. I store it and do not open it automatically.
I don’t ask for your name, phone number, address or payment details. The form stops anything that looks like a key, a password or a card number before it is sent and asks you to remove it. Please never send secrets; if I need access to something later, I will tell you exactly what and ask for the least that works.
What you type into the first-screen box (“What isn’t working?”) stays in your browser. It is sent only if you continue into the form and press SEND THE BUG. That first-screen box is a fixed set of rules running in your browser. It is not an AI and it sends nothing anywhere.
WHAT THE SITE RECEIVES AUTOMATICALLY
Like any website, my hosting provider (Vercel) receives your IP address and browser details when you load a page or send the form, and may keep them in its own logs under its own policy. I don’t use them to track you. When you send the form, my server uses your IP address only to limit repeated submissions: it is turned into a one-way code, held for up to two days, and never stored as an address. The page also tells my server how long the form was open, which helps filter bots; that is not stored.
WHY I USE IT
To read your submission, decide whether I can take it, reply to you, define the check that must pass, and, if you go ahead, do the repair and show you the proof. I don’t use it for advertising, I don’t build profiles, and I don’t sell or rent it. I don’t run a mailing list or send marketing email; I only write to you about your submission.
WHERE IT IS KEPT, AND FOR HOW LONG
- Hosted database (Upstash). Your submission is stored here when you send it. It deletes itself 90 days after I receive it.
- My own computer. I copy submissions to a private operations desk on my computer, which I reach over a private network (Tailscale). When a case is closed, its local records are deleted 90 days later. A case that is still being worked on is kept while the work is active.
- Your code or files, if I ask for them. Temporary working copies are deleted 7 days after I hand the work back, sooner if you ask. The deletion runs on my computer, so if it is switched off it happens at the next run.
- Email. Messages we exchange are kept in my email account (Gmail) until I delete them. I will delete a thread if you ask.
- Payment records. Invoices and payment records are kept as long as accounting and tax rules require. The 90-day rule does not apply to them.
- Logs and backups. Anything my providers or my computer keep in their own logs or backups follows their own schedules, which I don’t control.
WHO ELSE HANDLES IT
- Vercel hosts this website and runs the code behind the form.
- Upstash hosts the database that holds submissions until they expire.
- Tailscale is the private network between my devices. It does not store submissions.
- Google (Gmail) handles our email if we correspond.
- Stripe handles card payments on its own page. Venmo and Bitcoin are the other ways to pay, if you prefer. See Payment below.
- AI services only if you approve them. See the next section.
There are no advertising networks, analytics, session recordings, tracking pixels, or third-party fonts and scripts on this site.
AI
By default, any AI tool that looks at your submission runs on my own computer. I send your information to a cloud AI service only if you explicitly approve it for that job, and I write that approval down. The services I might ask about:
- TypeSafe (its “Jev” text classifier). It would see the description of the problem only, not your email address or link.
- OpenAI (through its Codex tool). It would see only the minimum context needed, with email addresses and links removed.
If you don’t approve, nothing goes to them. Whatever tools are used, an AI saying something is fixed is not proof; the agreed check has to pass.
PAYMENT
Nothing is charged when you send a bug. If I prove the repair works, I send you a secure payment link. You can pay by card through Stripe, or by Venmo or Bitcoin. Card details are entered on Stripe’s page, and Proof First does not collect or store full card numbers. If you pay by Venmo or Bitcoin, I see what those services show me, such as a username and the transaction. I keep invoices and payment records as described above.
COOKIES AND DEVICE STORAGE
This site sets no cookies. If you use the light/dark switch, it remembers your choice in your browser’s local storage; that stays on your device. Nothing else is stored on your device.
PUBLIC RESEARCH (PROOF RADAR)
Separately from customers, I run a research tool that reads public GitHub and Hacker News posts about broken software. It keeps those public posts (their text, link and date) for research. It does not store the writer’s username, only a one-way code; the link or text can still contain public names. The posts are labelled by a cloud classifier (TypeSafe’s Jev) that receives the public text. The people who wrote them are not Proof First customers. I never email or privately message them; any reply I make stays public, in the same thread. If you wrote a post it holds and want it removed, email me the link and I’ll delete it. How it works is on the Radar methodology page.
YOUR CHOICES
You can ask me what I hold about you, ask me to correct it, or ask me to delete it. Email christopherarivero@gmail.com from the address you used. I’ll confirm the request comes from that address, then delete your submission from the hosted database and from the records on my computer, and the email thread if you ask, and tell you what I deleted. I can’t delete what my providers keep in their own logs or backups.
SECURITY
The site is served over HTTPS. The database needs a key to read or write, and my operations desk needs a login and is reachable only over my private network. No system is perfectly secure, and I don’t claim any security certification.
CHANGES
If something here changes in a way that matters, I will update this page and its date. Last updated October 9, 2026.