What the registry stores
For each entry, the registry stores:- A 32-byte keyed hash of the user’s normalised email (see Hashing).
- The category of harm.
- Which member reported it, and that member’s case reference.
- The entry status and its dates: created, last reported, expiry, and revocation.
What the registry never stores
- No email addresses. Members send a SHA-256 hash, never the email. The registry does not keep that hash either: it stores only an HMAC of it, computed with a secret key.
- No names, no other account data. The registry accepts an email hash and nothing else about the user.
- No content. A report never includes the images, text or other material behind a ban. The evidence stays with the member that made the ban.
- No trace of checks that do not match. A check that matches nothing adds one to your daily check count. Nothing else is kept about the identifier.
The database rejects any stored identifier that is not a 32-byte keyed hash. A plain SHA-256
digest or an email cannot be written to it by mistake.
Why a keyed hash
A plain SHA-256 of an email is not anonymous. Anyone with a list of email addresses can hash each one and look for a match, and large lists of addresses are easy to obtain. If the registry stored plain hashes, a copy of it would reveal which of those addresses belong to banned users. The registry stores an HMAC instead, computed with a secret key that only Omnifence holds. The key never leaves the registry service. Without it, the stored values do not match any hash of any email, so a copy of the registry reveals nothing. Omnifence holds the key, so Omnifence can compute the stored value for an email it is given. Omnifence does this only to answer a request from the person named, or to handle a dispute. Every such lookup is recorded in an audit log with its purpose.Who can see what
A member cannot read, change or revoke another member’s entries. The registry enforces this in the
database itself, not only in the API.
Retention
Every entry has a fixed retention period that depends on its category. The period restarts when the member reports the user again.
When the retention period ends, the entry stops matching. It is deleted 30 days later. A revoked
entry is deleted 30 days after it is revoked. Deletion removes the entry and every record linked to
it.