Core Privacy Philosophy
Zero-Knowledge Architecture
Our system is built so that we cannot and do not access your sensitive personal information. This is a property of the architecture, not a policy choice. Key Principles- Privacy by design: Privacy protections are built into the technology, not added later.
- Data minimization: We collect only what verification requires.
- User control: You decide what to share and with whom.
- Cryptographic guarantees: Mathematical proofs ensure privacy, not just promises.
What We Never Collect or See
Financial Information
Cr3dentials never has access to your financial data.| Never Collected | Why We Don’t Need It |
|---|---|
| Bank account numbers | Zero-knowledge proofs verify ownership without revealing accounts |
| Account balances | We verify threshold compliance, not exact amounts |
| Transaction histories | Pattern verification happens locally on your device |
| Credit card information | Not required for our verification process |
| Investment portfolios | Outside scope of current verification types |
| Credit scores | We verify creditworthiness claims, not scores themselves |
| Tax documents | Income verification through secure third-party proofs |
| Loan information | Not collected or needed for verification |
Personal Identifiable Information (PII)
We operate without accessing traditional PII.| Never Collected | Alternative Approach |
|---|---|
| Social Security Numbers | Identity verified through cryptographic proofs |
| Driver’s license numbers | Age/identity verified without document access |
| Passport information | Citizenship claims verified through ZK proofs |
| Home addresses | Location verification without address disclosure |
| Birth dates | Age verification without revealing exact birth date |
| Phone numbers* | Only collected if you choose it for communication |
| Biometric data | Never collected or processed |
| Government ID photos | Identity verified through other means |
Phone numbers are only collected if you explicitly provide them for account recovery or communication preferences.
Employment and Professional Information
Your career details remain private.| Never Collected | How We Verify Instead |
|---|---|
| Salary amounts | Income threshold verification through ZK proofs |
| Employment contracts | Employment status verified through third parties |
| HR records | Professional claims verified without record access |
| Performance reviews | Skill attestations from colleagues/supervisors |
| Job titles | Professional credentials verified independently |
| Employer names* | Employment verification without revealing employers |
| Start/end dates* | Employment duration verified in ranges |
Employer names and employment dates may be disclosed at your discretion for specific verification types.
Health and Medical Information
We never process health data.| Never Collected | How We Verify Instead |
|---|---|
| Medical records | Health claims verified through ZK proofs |
| Insurance information | Coverage verification without policy details |
| Prescription data | Medical credentials without personal health info |
| Health test results | Compliance verification without result disclosure |
| Mental health records | Professional credentials only |
| Disability information | Accommodation verification without disclosure |
What We Do Collect
Account and Authentication Data
Required for account creation- Email address: For account creation, recovery, and important notifications.
- Stored encrypted in our database.
- Used only for authentication and critical communications.
- Can be updated or removed when closing your account.
- Wallet address: For blockchain-based authentication.
- Public key only, never private keys.
- Used for Web3 authentication and attestation signing.
- A standard blockchain address, publicly visible by nature.
- Display name: A user-chosen identifier for attestations. Can be pseudonymous or anonymous, and changeable at any time.
- Communication preferences: Email frequency settings and notification types (verification updates, security alerts). Modifiable in account settings.
Verification Metadata
Request information- Verification type: What kind of verification was requested (income, employment, etc.)
- Requirements: Threshold amounts, time periods, criteria (e.g., “income > $50k”)
- Request timestamp: When verification was initiated
- Expiration date: When the request expires
- Status: Current state (pending, completed, failed, expired)
- Cryptographic proof hashes: Mathematical representations of proofs, not original data
- Validation results: Whether proofs passed or failed
- Validation timestamp: When validation occurred
- Proof method: Which method was used (Reclaim, direct attestation, etc.)
- Attestation UIDs: Unique identifiers for blockchain attestations
- Schema information: Structure of attestation data
- Blockchain network: Which network the attestation was created on
- Public keys: For attestation signature verification
Technical and System Data
API usage logs- Request timestamps, endpoint access, response codes
- IP addresses for security monitoring and fraud prevention
- User agent for browser/app compatibility
- Error messages (never containing personal data)
- Stack traces (scrubbed of sensitive information)
- Performance metrics and anonymous, aggregated usage statistics
- Login attempts (successful and failed)
- Suspicious activity and unusual access patterns
- Rate limiting for abuse prevention
- Audit trail of sensitive operations (without personal data)
Data Processing Methods
Zero-Knowledge Proof Processing
Local proof generation
Raw credentials are processed on your device only. Zero-knowledge proofs are generated locally. Cr3dentials never receives raw data.
Proof transmission
Only cryptographic proofs are sent to our servers. Proofs contain no personal information, and mathematical validation is possible without data access.
Proof validation
We validate proof authenticity and correctness against the requested criteria. We have no access to the underlying data used in the proof.
Reclaim Protocol Integration
Secure data sourcing- Reclaim connects directly to data sources (banks, employers, etc.).
- TLS witnessing ensures data authenticity.
- Cr3dentials never sees the source data.
- Raw data is processed by Reclaim’s zero-knowledge engine.
- Cryptographic proofs are generated to meet your requirements.
- Only mathematical proofs are transmitted to Cr3dentials.
- Source data never leaves Reclaim’s secure environment.
- Cr3dentials receives only proof validation results.
- A full audit trail exists without personal data exposure.
Data Storage and Security
Encryption Standards
Data at rest- AES-256 encryption: All stored data is encrypted with industry-standard encryption.
- Key rotation: Encryption keys rotated every 90 days.
- Separate key management: Encryption keys stored separately from data.
- Hardware security modules: Keys protected by HSMs in production.
- TLS 1.3: Latest transport layer security for all communications.
- Certificate pinning: Prevents man-in-the-middle attacks.
- Perfect forward secrecy: Each session uses unique encryption keys.
- End-to-end encryption: Sensitive operations encrypted client-to-server.
Data Sharing and Third-Party Access
What We Never Share
- Raw personal data: Never shared, because we don’t collect it.
- Financial information: Never accessed or shared.
- Identity documents: Never collected or shared.
- Private communications: User messages or personal interactions.
- Location data: Precise location is never collected.
- Browsing history: We don’t track or share web activity.
Limited Sharing Scenarios
Authorized verification results- Cryptographic proof results: Shared only with parties you authorize.
- Attestation references: Public blockchain references that contain no personal data.
- Verification status: Pass/fail results for authorized verifiers.
- Compliance claims: Regulatory compliance status when required.
- Law enforcement requests: Limited to proof metadata, never raw credentials.
- Court orders: Compliance with valid legal process.
- Regulatory audits: Anonymized data for compliance verification.
- National security: As required by law; we will fight overreach.
- Infrastructure partners: Hosting, security, and monitoring (with strict DPAs).
- Blockchain networks: Public attestation data only.
- Email service: For account communications (encrypted).
- Security services: Threat detection and prevention (anonymized data).
Third-Party Service Agreements
All service providers sign comprehensive Data Processing Agreements (DPAs) with strict limitations on data use and processing, regular compliance audits, and the right to terminate for privacy violations.| Category | Providers | Data Shared |
|---|---|---|
| Infrastructure | AWS, Google Cloud | Encrypted data only |
| Security | Threat detection services | Anonymized logs |
| Communication | Email delivery services | Minimal data |
| Monitoring | Performance and uptime | No personal data |
User Rights and Controls
Data Access Rights
View your data- Account dashboard: See all data we have about you.
- Verification history: Complete record of your verifications.
- Attestation registry: All attestations created for you.
- Data export: Download your data in JSON format.
- Instant export of verification history and attestations.
- Standardized JSON format compatible with other systems.
- Proof metadata exportable for independent verification.
- Attestation references (blockchain UIDs) for public verification.
Privacy Controls
Verification privacy settings- Disclosure level: Choose how much to reveal per verification.
- Verifier authorization: Control who can request verifications from you.
- Attestation visibility: Public, private, or semi-private attestations.
- Expiration settings: Set automatic expiration for sensitive attestations.
- Notification preferences: Choose what communications you receive.
- Contact methods: Select preferred channels.
- Marketing opt-out: No marketing communications.
- Emergency contacts: Optional emergency notification settings.
Account Management
Profile controls- Pseudonymous operation: Use chosen names or identifiers.
- Multiple identities: Create separate verification identities.
- Identity switching: Switch between professional and personal identities.
- Anonymous verification: Option for completely anonymous attestations.
- Two-factor authentication: Required for sensitive operations.
- Login notifications: Alerts for new device access.
- Suspicious activity: Automatic alerts for unusual account activity.
- Session management: View and terminate active sessions.
