Privacy
Last updated: 29 September 2026
This policy explains which personal data YourID processes, why, who helps us process it, how long we keep it, and what your rights are. YourID is currently in private beta.
Who is responsible
The controller is Stichting YourID, a foundation established in the Netherlands. For anything about your data, email privacy@yourid.org.
What we process
Your email address. The public keys of your passkeys — the private keys stay on your devices and never reach us. Session records, including your IP address and browser user-agent, so you can see your signed-in devices and sign them out. An activity log of security-relevant account events, including IP address. Profile data you choose to enter yourself. The result of an identity verification and the claims taken from it (such as name, birthdate, nationality and document type). Your consent decisions for connected services. And, if you register an app as a developer, that app's details and redirect URIs. If you request beta access, we keep your email address and preferred language to send you an invitation.
Sensitive profile data
Medical and financial profiles are not available during the beta. Once they are: profile fields can hold medical and financial information. Medical data is special-category data under the GDPR, and financial data is sensitive too. We only process it because you explicitly choose to enter it, and it is only shared with a service when you approve that specific field on the consent screen. You can change or remove it at any time.
Why we process it, and on what legal basis
To provide your account and sign you in: performance of our agreement with you. To verify your identity when you ask us to: performance of that agreement, plus your explicit consent for the face comparison. To share claims with a service you sign in to: your consent, given per service and per field on the consent screen, which you can withdraw at any time. To process medical profile data: your explicit consent. To keep the service secure — session records, the activity log and abuse prevention: our legitimate interest in protecting you and the service.
What services receive
Only the claims you approve on the consent screen, for as long as you allow it. An age check delivers a single yes or no — never your birthdate. You can see every connection in your dashboard and revoke it with one tap: that service's access and refresh tokens are cut off immediately. Data a service has already received is governed by its own privacy policy.
Who helps us
Supabase — our database, hosted in the EU (Ireland). Vercel — hosts the website and the application; Vercel is a US company, and transfers are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses. iDenfy (Lithuania, EU) — checks identity documents, once identity verification is enabled; until then, no document is processed. Resend — sends sign-in codes and beta invitations; Resend is a US company, and transfers are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses.
What we never store
Passwords — there are none. Document images: during a real check, your ID scan is processed by our verification partner and is not kept by YourID. We use no analytics trackers, advertising identifiers or third-party cookies.
How long we keep it
Sign-in codes expire after 10 minutes. A sign-in session ends at the latest 7 days after you sign in. Your account data — including session records and the activity log — is kept until you delete your account. Deleting your YourID removes your data from our live database immediately. A beta access request is kept until you have been invited and created your account, or until you ask us to remove it.
Cookies
We set one strictly necessary cookie that keeps you signed in, and one cookie that remembers your language. No analytics, advertising or tracking cookies — which is why there is no cookie banner.
Your rights
You have the right to access, rectify and erase your data, to data portability, to object to processing, and to withdraw your consent at any time. Erasure is self-service: Settings → Delete my YourID. For everything else, email privacy@yourid.org. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).