Privacy and data handling

Privacy Policy for Personhood Credential

Effective 2026-08-09Updated 2026-08-09

1. Introduction

Welcome to Personhood Credential. Your privacy is important to us. This Privacy Policy explains how we collect, use, and protect information when you use our mobile application (the “App”) and website to create, hold, present, and manage verifiable credentials.

2. Information We Collect

We process the information needed to provide the service:

a. Credential and identity information

  • Information you choose to include in a credential, such as information from a connected social-media account or a passport-based credential.
  • A confirmation generated when you complete an authentication or verification flow. We do not store your device biometric template.
  • Credential identifiers, status-list references, expiration information, and revocation information needed to issue and check credentials.

b. Device and service information

  • Technical information required to operate and secure the service, such as requests to our service, device and app version information, and diagnostic logs.
  • Information you provide when you contact us for support.

3. How We Use Your Information

  • Create, store, deliver, present, revoke, and verify verifiable credentials and their status.
  • Protect the service, prevent misuse, troubleshoot problems, and maintain the integrity of credential status information.
  • Respond to support requests and meet legal obligations.

4. Information Sharing & Disclosure

We do not sell or rent your personal information. We only share information in the following cases:

  • With your explicit consent when you choose to present a credential to a third party.
  • With service providers that help us operate and secure the App and service, subject to appropriate safeguards.
  • If required by law or legal process.

5. Data Security

We use reasonable technical and organizational safeguards, including:

  • Device-protected storage for private keys and credentials held in the App.
  • Secure transmission for communications with our services.
  • Access controls for service infrastructure.

Despite these efforts, no method of transmission or storage is completely secure.

6. Your Choices and Data Retention

  • Choose which credentials to create and when to present them.
  • Revoke credentials associated with your decentralized identifier in the App.
  • Adjust app permissions and limit data access through device settings.
  • Use “Clean up my data” in the App to revoke your credentials and remove data stored on your device.

Credential content held by our service is deleted when its status list is sealed. A sealed list retains the final revocation information and limited technical metadata needed for reliable status verification. We do not state a fixed sealing period here because retention timing is determined by our operational policy and may change.

Some features may be unavailable if required information is not provided.

7. Changes to This Policy

We may update this policy as our services evolve. We will post the updated policy here and revise the “Last Updated” date. Continued use of the App or service after changes take effect means you accept the updated policy.

8. Contact Us

If you have questions or concerns about this policy or your data, please contact us at contact@iamhuman.link.