Witness Record

Who made Witness Record

One person, no company, and a short list of things I cannot see.

Witness Record is built by Olmo Parenti. Not a company, not a team, not a startup with a funding round. One independent developer, working alone, who answers his own support email.

If you are deciding whether to trust an app with footage of something that matters, you should know who is behind it and what they can reach. That is what this page is for.

What I can and cannot see

This is the part that actually matters, so it goes first.

I cannot see your footage. There is no mechanism by which I could. Witness Record has no backend of any kind. Video goes from your device directly to the Google Drive, Dropbox, Nextcloud or WebDAV account you connected, and nowhere else. I do not operate a server that receives it, so there is no copy for me to look at, lose, sell, or be compelled to hand over.

Concretely, here is the complete list of what leaves your phone and where it goes:

WhatGoes toCan I see it?
Your video and audioYour own cloud accountNo
Your location, if recordedYour own cloud accountNo
The session manifestYour own cloud accountNo
A SHA-256 hash of the manifestA time-stamp authorityNo, and neither can they
Anything elseThere is nothing else. No analytics, no crash reporting to me, no account system.

The hash is the only thing that reaches any third party, and a hash cannot be reversed. The time-stamp authority learns that some document existed at a moment in time. It never learns what the document said, where it was made, or who made it. That is the entire point of the design, and it is written up in full.

There is also no account to create. You authenticate with your own storage provider, and that relationship is between you and them. I am not in it.

Why it works this way

Because a server I control is a server that can be subpoenaed, breached, or quietly changed. The strongest promise I can make is not "I would refuse to hand your footage over." It is "I do not have it." The second one survives me being wrong, being pressured, or being replaced.

It costs something. Emergency-contact sharing has to work through your storage provider's API, which is why it works on Google Drive and Dropbox and not on WebDAV. I would rather have that limitation than a copy of your footage.

Things I am not

I am not a lawyer. This site has a lot of material about recording law, and every page of it says the same thing: I read the primary sources carefully while building an app, and that is a different thing from legal advice. For the actual law, go to the EFF, the ACLU or the National Lawyers Guild.

I am not WITNESS. WITNESS is an international human rights organisation that has trained people to document abuse on video since 1992. They are excellent, they are cited throughout this site, and they have nothing to do with me. I chose a name without realising how thoroughly it was already taken, which was careless. The full disambiguation is here.

I am not a security researcher or a cryptographer. The cryptography here is standard and boring on purpose: SHA-256 and RFC 3161, both decades old, both verifiable with OpenSSL by anyone. I did not invent anything, and you should be suspicious of anyone in this space who did.

Conflicts I declare

Several pages on this site compare Witness Record to other apps, or recommend tools. I make one of the things being compared, so:

What happens if I stop

A fair question about a one-person project holding something you rely on, and one most developers dodge.

The honest answer is that the design already limits the damage. Your footage lives in your cloud account, in standard formats, alongside a manifest and a time-stamp token that anyone can verify with OpenSSL. If I disappeared tomorrow, every recording you already made stays exactly where it is, readable and verifiable, with no dependency on me or on anything I run. That is not an accident of the architecture; it is most of the reason for it.

What you would lose is future updates and iOS compatibility over time. That is a real cost and I am not going to pretend otherwise.

Get in touch

Support, bug reports, feature requests, criticism, or enquiries from newsrooms, legal teams and organisations: olmaster13@gmail.com.

It reaches me directly, not a ticketing system. I answer everything, including the messages telling me I have got something wrong — several pages on this site exist because someone did exactly that.

If you coordinate volunteers, run legal observer trainings, or work in a newsroom, I will help you set the app up at no cost. Just ask.