Recensa ← back to recensa.org

The standard

The Recensa Standard

Version 0.1 — draft, 13 August 2026

This standard is not yet in force.

No record is published under it yet. It is published in draft so that it can be read, checked and argued with before it binds anyone.

Recensa is operated by Probioform Norge AS (see the foot of this page). The standard takes effect for a given record on the day that record is published, and binds the operator from that same day under §5.

This document sets out the rules governing every customer record published using Recensa. It binds the brands that publish records, and it binds Recensa.

It is written to be read by anyone: a customer deciding whether to believe a record, a brand deciding whether to publish one, and a regulator deciding whether either of us is being honest.

Every version stays online permanently. Nothing is changed retroactively (§12).

Status: no live records exist under this standard yet. Recensa's published figures are currently zero. We would rather show zeros than numbers we cannot stand behind.

1What a record is, and is not

A Recensa record is a public account of what a brand's customers report, published on a domain the brand owns, under rules the brand cannot switch off.

Not independent. The brand owns the domain and pays Recensa. Every record states this above all content, in body text size, on every page.

Not an endorsement. We do not assess whether a product works, whether a company is good, or whether anyone should buy. We issue no scores, grades or ratings of brands.

Not an audit. We check specific things in specific ways, named in §3. We do not inspect premises, verify manufacturing, or investigate companies.

Not a directory. Recensa operates no consumer-facing index across brands, and ranks no brand against another (§5.7).

2Definitions

Record — the pages published at the brand's Recensa-served address. That address is either a domain registered to the brand, or a subdomain of a domain the brand already owns. Recensa never holds the registration in either case, and no particular naming pattern is guaranteed: where the obvious name is unavailable, an agreed alternative is used.

Review — a first-person account from someone who states they used the product.

Order-verified — matched to a completed order in a commerce system the brand connected, by order identifier.

Batch-verified — the reviewer gave a production batch code matching a run the brand recorded, with no order match. The normal case for shop purchases.

Unverified — neither match. Published, and labelled.

Brand statement — text or data the brand supplies about itself.

Connected data — read by Recensa from a connected system, on a schedule.

Calculated — a figure Recensa derives by counting published reviews.

Externally verified — checked against a source outside the brand: a company register, an accredited laboratory, a named publication.

3What we actually check

We publish only what we can describe precisely.

Order-verified review — we confirm an order exists in the connected system, that it completed, that it contained the reviewed product, and that the reviewer's contact matches it. We do not confirm identity beyond that.

Batch-verified review — we confirm the code matches a recorded production run. We do not confirm the reviewer bought that unit, or how it was stored after it left the brand.

Company facts — we confirm the registration exists in the named register, and publish the date last checked.

Laboratory results — we confirm a document exists, name the laboratory, and publish the document. We do not verify the testing itself.

Connected data — we publish the source system and the time of the last read.

We never infer, estimate, or fill gaps. Where we cannot verify something, the record says so — including in its own integrity figures (§5.8).

4What the brand cannot do

4.1Delete a review for being negative. Removal only on the closed grounds in §6.

4.2Edit the text of anyone's review. Only the author may amend their own, and both versions stay visible with their dates.

4.3Change a review's verification status, or exclude reviews from calculated figures.

4.4Invite only the customers likely to be happy. Invitations go to all buyers of the reviewed product within the defined window. Sentiment is not a field the invitation logic can act on.

4.5Accept a review for payment without labelling it. Any consideration — discount, free product, prize entry — is declared and labelled on that review, and may never be conditional on the review being positive.

4.6Hide the complaint summary or the record integrity figures. Both appear on every record and cannot be disabled, reordered out, or placed behind interaction.

4.7Call the record independent, third-party, or impartial, in the record or in any marketing.

4.8Present a brand statement as verified. The brand's own words and lists are labelled as brand statements (§7), and the brand is responsible for their accuracy.

4.9State or imply that a seller it does not supply is selling counterfeit goods. A brand may publish the channels it supplies and what it can confirm. Resale of genuine goods is lawful, and that accusation is not ours to host.

5What Recensa cannot do

These matter more than §4. They are why a record means anything.

5.1Sell placement, ranking, badges, favourable labels, or any change to a calculated figure. There is no price at which a figure moves.

5.2Offer a tier in which complaints or integrity figures are hidden. Trust is not a premium feature. Paying less buys less automation, never a less trustworthy record.

5.3Redefine a verification tier retroactively. A review verified under v0.1 stays labelled under v0.1.

5.4Hold a brand's address. The domain is registered to the brand, or is a subdomain of one the brand already owns, and remains its property in either case. Recensa is never the registrant.

5.5Withhold the export. On cancellation the brand receives a complete machine-readable export — reviews, verification states, removal log, history — within 14 days, at no charge.

5.6Sell, license or share review data or reviewer personal data with third parties, or use it to train models.

5.7Run a directory or comparison service across brands. Our customers are brands, and competing with them for their own audience would make every record suspect.

5.8Omit a gap. Where we cannot verify something a record claims, we mark it unverified on the record rather than leaving the section looking complete.

5.9Hide our own numbers. We publish records served, reviews removed with their grounds, brands suspended and brands departed — including when unflattering.

5.10Move an existing customer onto a different plan without their agreement, or apply a new price before telling them. When features not yet built are released, existing customers hear the price before it applies and keep what they are already paying for.

5.11Publish a record without disclosing a conflict. Where Recensa, its operating company, its owners, directors or controlling persons hold a financial interest in the brand whose record is being published, that relationship is disclosed on the record itself, in body text, not in a footnote. The disclosure changes nothing else: verification, removal, calculation and publication rules apply to that record identically.

A conflict that exists today. Recensa is operated by Probioform Norge AS, which holds a financial interest in Probioform. Probioform is used as the first example record for that reason, and every record involving it carries the disclosure required above.

6Removal: the closed list

A review may be removed only on these grounds.

  1. Fraud — fabricated, duplicated, automated, or written by someone with an undisclosed material connection to the brand or a competitor.
  2. Unlawful content — defamatory, unlawfully discriminatory, or otherwise illegal.
  3. Third-party personal data — identifies another person and cannot be redacted while remaining intelligible.
  4. Author request — the reviewer asks for removal of their review or their personal data. This right cannot be waived or contracted away.
  5. Court or regulator order.

Every removal is logged with its ground, its date, and who initiated it. Counts and the breakdown by ground appear on the record. Refused requests are counted too. Removed text is not republished.

7Provenance labels

Every section carries one label, with a fixed meaning.

LabelMeaning
Verified externallyChecked against a source outside the brand, named in the section.
Connected dataRead from a connected system. Source and last-read time shown.
Calculated from reviewsDerived by counting published reviews. The brand cannot adjust it.
Stated by brandThe brand's own words or list. Not verified by us, and labelled so.

A brand cannot change which label a section carries.

8How "cannot" is enforced

Three mechanisms, in increasing order of what it would cost us to break them.

8.1 In the software. Sentiment is not a field a brand can filter or act on. No delete-for-negative exists to be requested, escalated to, or granted as a favour.

8.2 In the contract. This standard is incorporated into the agreement. It binds the brand, and §5 binds Recensa — including the parts that cost us revenue.

8.3 In public. Every review is timestamped on arrival, before anyone sees it. Received, published and removed are counted separately, each removal against a ground in §6. The arithmetic is published, so a quiet deletion does not add up:

Received                          1,842
Published                         1,827
Removed — fraud or duplicate         13
Removed — reviewer's own request      2
Removed for being negative            0   (no mechanism exists)
The honest limit. Nothing prevents a brand cancelling and republishing elsewhere without its history. What it cannot do is edit the record and keep this standard on it.

9What a record must contain

  1. The ownership disclosure (§1, §4.7)
  2. Reviews with their dates, products and verification tiers
  3. A summary of what customers criticise, with counts (§4.6)
  4. Record integrity figures, including unresolved gaps (§4.6, §5.8)
  5. The removal log summary and the ledger arithmetic (§6, §8.3)
  6. A plain statement of how reviews are verified, with the proportion verified — as required of traders publishing consumer reviews in the EU
  7. A link to the version of this standard in force

Everything else is optional.

10Importing existing reviews

Recensa does not copy reviews belonging to a marketplace or a review platform. No Amazon, no Reddit, no scraping.

Reviews collected on a brand's behalf by a provider it authorises — Judge.me, Loox, Yotpo, Stamped and similar — are that brand's own first-party reviews. We import them where the brand's rights and the provider's terms allow, through the provider's API, with the brand's authorisation, and with their original dates intact.

Where a third-party platform's rating is shown, it appears as an attributed summary with a link out, never as republished content.

11Displaying the mark

A brand meeting this standard may state:

Customer record published under the Recensa Standard v0.1

A brand may not claim: certified, audited, accredited, approved, endorsed, independently verified, Recensa-rated, unalterable, tamper-proof, or cryptographically verified. We do none of those things. Claiming them is a misrepresentation we act on under §13.

12Changing this standard

Versions are numbered, dated, and stay published.

Weakening any rule in §4 or §5 requires 90 days' public notice, stating plainly what is being weakened and why.

Records display the version they were published under. Reviews retain the definitions in force when they were verified (§5.3).

13Breach

If a brand breaches §4:

  1. Notice — we describe the breach and set a period to correct it.
  2. Record notice — if uncorrected, a notice appears on the record stating that it no longer meets the standard, and which rule is unmet.
  3. Withdrawal — the mark is withdrawn, the record is no longer served under the standard, and the brand appears in our published withdrawal count (§5.9).

The brand keeps its domain and its export in every case (§5.4, §5.5).

If Recensa breaches §5, the remedy is that anyone can point at this document, and at the breach log we keep beside it. That is the only enforcement a standard operator can honestly offer without an external body, and it is why §5 is written narrowly enough to be kept.

14Disputes

A customer who believes a record is inaccurate can contact Recensa directly, not only the brand, at hello@recensa.org. We publish how many such contacts we receive and how they resolved.

A reviewer whose review was removed is told which ground under §6 applied.

A brand disputing a calculated figure can require us to show the underlying reviews. We do not adjust the figure.

15Scope of the first release

The first release covers the record itself: importing existing first-party reviews, verified collection, retained negatives, brand replies, complaint themes, provenance labels, the ownership disclosure, the ledger, export, and search measurement.

Batch verification, certificate handling, sales-channel and practitioner lookups, and multi-market records follow once the first records prove useful. Service businesses are not supported in the first release.

Sections of this standard describing features not yet built apply from the moment those features ship, and not before. We do not claim to operate what we have not built.


Open questions in v0.1

Named rather than hidden.