Skip to content
Menu

Legal

Privacy Policy

Effective September 15, 2026

The short version: the system is designed so that we hold as little as possible, and nothing that can be used to log in as you. This policy covers the Identizen iOS and Android apps, the public index at index.identizen.com, the dashboard at app.identizen.com, and this website.

What the public index stores

The index is a directory and relay. When you register a phone it stores, for that phone:

  • Public keys for your identity and for the device. Never private keys, the recovery phrase, or anything that can sign on your behalf.
  • A push token so a sign-in request can reach the phone. The only thing ever sent through a push service is an opaque request id.
  • A Bluetooth key used to derive an identifier that rotates every 15 minutes. Only the index can resolve it; nothing identifying is broadcast.
  • Per-site identifiers. Each site you sign in to gets its own identifier for you. The index keeps the mapping so revoking a device can sign you out everywhere.
  • Paired browsers: a public key for each browser you paired, the browser's user-agent string, and the IP address it connected from, so you can recognize and unpair it.
  • Sessions at each site: an opaque session id and its expiry, so you can end them from your phone.
  • Activity records: sign-ins, approvals, denials, enrollments, pairings, and revocations, with timestamps, the site involved, and, for approvals, the short description the site attached to the request (for example the amount and payee of a transfer).
  • An optional handle, only if you choose one in Settings. Handles are public and resolvable through WebFinger.

The index does not store your name, email address, phone number, contacts, photos, or location. The camera is used only to read a sign-in code, and no image leaves the phone.

What sites receive

A site that you sign in to receives a stable identifier that is specific to that site, an opaque device identifier, a session id, and how the approval was authenticated (for example Face ID). If you have set a handle and the site asks for it, the handle is included. Sites do not receive an email address, a name, or any identifier that can be matched across sites.

What this website and the dashboard collect

This website and the documentation site count page views with a cookieless, first-party analytics script served from analytics-collect.identizen.com, on a server we run. It records the page path, the referrer, the screen width, and a random session id kept in your browser's session storage for thirty minutes; no cookies, no fingerprinting, no query strings, no third party, and nothing that follows you to other sites. The dashboard and the login pages run no analytics at all. There are no advertising scripts anywhere. Contact-form submissions are protected by Cloudflare Turnstile and sent to us by email. The dashboard keeps your session in your browser only. Our hosting providers keep standard request logs (IP address, user agent, URL, time) for a short period for security and operations.

Who processes data on our behalf

  • Cloudflare, Inc., which hosts the index, dashboard, and websites.
  • Neon, Inc., which hosts the index database in the United States (AWS us-east-1).
  • Apple Inc. and Expo (650 Industries, Inc.), which deliver push notifications. The notification payload is an opaque request id only.

We do not sell personal data and do not share it with anyone for advertising.

Retention

Records are kept while your identity is registered. Revoking a device disables it immediately; revoking your last device disables the identity. Disabled records are kept so that revocation stays effective and can be audited, and are deleted on request (see below). Hosting request logs are deleted automatically within days.

Your choices and rights

  • Revoke any device, session, or paired browser at any time from the app or the dashboard.
  • Turn nearby sign-in over Bluetooth off in the app's Settings.
  • Remove your identity from a phone at any time ("Forget identity" in Settings).
  • Ask us to export or delete everything the index holds about an identity by writing to the address below (see Delete your identity and data for the steps). We will need you to prove control of the identity, which you do by signing a request from your phone.

Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to access, correct, delete, or restrict processing of your data, and the right to complain to a supervisory authority. We honor these for everyone.

Children

The services are not directed at children under 13, and we do not knowingly register them.

Changes

We will post changes to this page and update the effective date. Material changes to what the index stores will also be announced in the app before they take effect.

Contact

privacy@identizen.com