Privacy Notice

What is stored, why, for how long — and what is deliberately never collected.

Last updated: 5 September 2026

1. The short version

Your private key never leaves your device — we never process it. We hold: your public key and address (required for the service), the verification methods you add, the claims you store (name, photograph, face-scan enrolment, document photo), your display name if set, sessions, notifications, and security-audit events.

We do not hold, collect, or want: your PIN, your private key, your date of birth, your sex, your address of residence, your documents beyond the photograph you explicitly submit, or anything you never entered. The absence of fields is deliberate: data that does not exist cannot leak, be demanded, or be misused.

2. Controller

The controller is the operator of XityConnect, acting as part of the national infrastructure of the Republic of Xity. Contact: business@spacexity.org.

3. What we store, why, and on what basis

Address and public key — contract: necessary to provide the identity service you requested. Verification records (method + timestamp) — contract and legitimate interests: these are the assurance levels you asked to publish to relying services.

Vault claims, including your declared name, photograph, and face-s enrolment — contract: you explicitly store each one; we store only what you write, sealed with integrity hashes. Display name and preferences — consent: optional, removable at any time.

Sessions, notifications, audit events, verification-ceremony records — legitimate interests and legal obligation: security, fraud prevention, and the integrity of the 24-hour recovery timelock.

4. Biometric information

Biometric data is treated as highly sensitive. Your face-scan frames and document photograph are processed on your device; the automated comparison, where models are available, runs in your browser — the frames are not transmitted to perform it.

What may leave your device: signed capture manifests. These contain per-frame cryptographic hashes — not images. The hashes prove what was captured, when, under which session, without carrying the pixels.

If long-term biometric templates are ever required for authoritative verification, they will be encrypted under separate keys with strict access policies, audited access, a documented purpose, and a deletion policy — and this notice will say so before it happens. It has not happened yet.

5. The chain is public — what that means

Anchored events (registration, verification, recovery, key rotation) are applied to chain state. Payloads with identity data are redacted on public reads; what is public is the event type, the address, and the time.

Because the chain is append-only, deletion of an anchored event is not technically possible. This is precisely why we anchor only the fact of an event — never its contents — so the permanence of the ledger can never become a privacy problem.

6. Retention

Session records expire with the session. Verification codes are transient and single-use by design. Ceremony sessions expire within ten minutes. Vault claims persist until you overwrite or remove them. On-chain records persist for the life of the chain — inherent to an audit ledger.

During the development phase, notifications and pending-recovery lists are held in platform memory: a service restart clears them. This never weakens security (a restart also erases any in-flight recovery, which must re-serve its full waiting period), but treat notifications as a live view, not an archive.

7. Your rights

Access and portability: the API returns everything held about you — identity record, profile, vault claims, permissions, notifications, ceremony results. Rectification: profile and vault data you can change yourself; on-chain records change only through proper processes (they are facts about what happened, not opinions).

Erasure: clearing your browser storage removes your key. For identity-level deletion, contact business@spacexity.org — the status is set to DELETED through the operator process. Complaints: you may lodge a complaint with the supervisory authority at any time.

8. Sharing

Nothing is sold, advertised against, or shared for marketing. Data leaves the operator only when you direct it: a permission you grant, a claim you disclose, or a legal obligation that compels disclosure — in which case we disclose the minimum required, and these terms’ lawful-compulsion carve-out applies.

9. Security measures

Client-side key generation and sealing (Ed25519; AES-GCM under PBKDF2 with 600,000 iterations). Challenge-response authentication with single-use challenges. A server-owned verification ceremony with signed, hash-chained captures. Rate limiting on authentication and ceremony endpoints. A 24-hour recovery timelock with mandatory owner notification. PII redaction on all public chain reads. Non-revealing error messages with auditable internal references. Admin surfaces gated by a separate key.

10. Contact

Privacy questions and requests: business@spacexity.org.