Legal
Privacy policy
Biometrics are irreplaceable, so Phone Vault is built to hold as little of them as possible. This page describes exactly what is derived, stored, shared and deleted.
1. What we collect
Phone Vault collects the minimum needed to decide whether a verification attempt is genuine. Biometric material is reduced to templates and metrics before it is stored.
- Account data: email, display name, organization membership and role.
- Biometric templates: derived feature representations for face, voice, signature dynamics and hand geometry. Not photographs, not audio files.
- Capture metrics: frame luminance, contrast, motion, audio energy, duration and SHA-256 digests binding a capture to a session.
- Device data: a device fingerprint, platform, label and attestation history.
- Session and audit records: factor scores, the weighted trust score, the assurance level and the decision outcome.
- Vault entries: credentials encrypted in your browser before upload.
2. What never leaves your device
Raw camera frames and the rendered signature image are processed locally and discarded. Only derived metrics and digests are transmitted.
Phone Vault credentials are encrypted client-side with a key derived from your passphrase via PBKDF2 and sealed with AES-GCM. The server stores ciphertext it cannot read, and the passphrase is never transmitted or recoverable.
3. Why we process it
Biometric data is processed for one purpose: authenticating you and detecting fraud against your own account. It is not used for advertising, profiling, training third-party models, or sold or rented to anyone.
4. Randomization and replay defence
Liveness prompts, hand-point order and voice phrases are generated per session and expire within seconds. These challenges are stored alongside the session so an expired or reused response can be rejected. This is a security record, not a behavioural profile.
5. Retention
Biometric templates are retained while enrollment is active and deleted when you remove that factor. Trusted devices are retained until revoked. Vault entries are retained until deleted. Capture metrics and challenge records are retained with their session.
Audit records of verification decisions are retained deliberately and are not editable from the application — an audit log that can be quietly rewritten provides no assurance.
6. Your controls
From the console you can:
- Re-enroll or delete face, voice, signature and hand references.
- Revoke a trusted device, which immediately blocks sessions from it.
- Delete Phone Vault credentials and passkeys.
- Review every verification decision made against your identity.
7. Sharing with connected applications
When an application authenticates through the Universal Access Gateway it receives assurance claims — for example identity_verified, device_verified and an assurance level — plus the identifiers it is scoped for. It never receives biometric templates, captures or raw scores.
8. Security
All biometric decisions are made server-side; scores submitted by a client are never trusted. Data is protected by row-level access rules scoped to your account and organization. Captured segments are hash-chained with server-assigned sequence numbers so tampering, gaps and replays are detectable.
9. Changes
Material changes to this policy will be surfaced in the console before they take effect. This is a reference deployment; contact your organization administrator for the operator-specific data controller details.
Common questions
The FAQ covers replay attacks, failed factors and what happens on mobile.