Moolam

Legal

Privacy

Sur cette page

Last updated: 21 September 2026.

The short version

Registering a picture publishes it, permanently, and nobody can take that back. Verifying a picture stores nothing at all. Moolam sets no cookies and runs no analytics of its own. There is no Moolam account database: sign in is Privy's, and this service sees only a user id and a wallet address. Nothing is sold and there is no advertising.

Registering is publishing

Read this before you register anything.

Registering pins four files to public IPFS through Pinata: the signed picture, a thumbnail 512 pixels on its longest side, a readable copy of the C2PA manifest, and a metadata document carrying the title, the fingerprints, what you said about AI use, and for a picture the agent drew, the prompt and the model. Pinned means public: anyone holding the content id can fetch a copy, and Moolam cannot recall one.

The passport goes on Monad: the sha256 of the file, its two perceptual fingerprints, your wallet address, the agent id where an agent drew it, the hash of the manifest, the address of the metadata document, and the time of the block it was written in. Nobody can edit or delete that record, including whoever runs Moolam: the registry is immutable, has no upgrade path, and its owner can pause new writes and nothing else.

Your statement about how AI may use the picture is a second public record on Monad. Entries are appended and never edited, so an old statement keeps its date and stays readable beside the new one, and any conditions you typed, up to 256 bytes, sit on chain as you typed them.

Binding a passkey writes its public half on chain against your wallet address. The private half is made inside your device and never leaves it.

A right to have data erased cannot reach a public blockchain or a pinned IPFS file. Decide before you press register: there is no delete.

Verifying stores nothing

A file you drop on the verify page goes from your browser to Moolam's verify service, which fingerprints it in memory, matches it against the registry's fingerprints, reads any C2PA manifest, and answers. The bytes are never written to disk and never pinned. A picture you name by URL is fetched, matched and dropped the same way.

What the site keeps on your device

No page on Moolam sets a cookie, and a page you only read stores nothing until you touch the theme toggle.

Stored in your browserWhat it is for
themeLight or dark, so the site opens the way you left it
moolam:wallet:returningA flag that this browser has signed in before, so the sign in library loads early
moolam.passkey.<your address>Which passkey belongs to your account, and its public half, so signing does not make you pick from a list. Never the key itself

On the three pages where you can sign in, the studio, the resolver console, and a passport page once you have signed in here, Privy's library keeps your wallet session there too and sets an id of its own, privy:caid, for Privy's product analytics.

Analytics

Moolam runs no analytics of its own. Vercel Web Analytics and Speed Insights count page views and measure how fast pages load, in aggregate. They set no cookies and store nothing on your device.

What the servers write down

The verify service writes one line per request: the route, the status, how long it took, and the caller's IP address as the host's proxy reports it. A refused request adds the reason. A prepare, an edit or a generation also logs the Privy user id it was for, and the model that drew. The uploaded file itself is never logged. Vercel, which hosts the site, keeps its own request logs. No retention period of Moolam's own is set on either host.

Accounts

Sign in is Privy's, by email, Google or a passkey. Privy holds the account and the key material for your embedded wallet. Moolam's service sees your Privy user id and your wallet address, and checks Privy's token on every request. Moolam never sees a password or a private key and keeps no account database. Privy's own policy is at https://privy.io/privacy-policy.

Pictures the agent draws

Your prompt goes to OpenAI's image API, which draws the picture. The prompt is the only text sent: nothing is wrapped around it. If you then register what came back, the prompt and the model are pinned in the public metadata.

Who else handles something

WhoWhat they see
VercelHosts the site, keeps request logs
RailwayRuns the verify service, keeps request logs
PinataThe four files pinned at registration
PrivyYour account, sign in and embedded wallet
OpenAIPrompts, and the pictures drawn from them
EnvioIndexes public events on Monad
A Monad RPC providerReads and transactions, including those your browser makes
ChainlinkA CRE workflow fetches the public thumbnail to re-check a passport

No data is sold, and there is no advertising.

Children

Moolam is not directed at children. Who may hold an account is decided by Privy's own terms.

Who runs this

Moolam is one person's project entered in a hackathon, not a company. Ramakrishnan builds it and runs it, and questions about this page go to ramakrishnanhulk20@gmail.com.