Privacy Policy
Last updated: 18 August 2026
HonestID is operated by Honest Identity Ltd (“HonestID”, “we”, “us”), a company registered in England and Wales under number 16999205, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We are the data controller for the personal data described here, and we are registered with the Information Commissioner’s Office under reference ZC154651.
This policy explains what we collect, why, how long we keep it and the rights you have over it. HonestID is privacy-preserving by design: the most sensitive part of a verification, the Honest Key and the security questions and answers you share with a contact, is encrypted on your device and is never readable by us.
Data we collect
Account. Your first name, last name and email address. Your sign-in credentials, including passwords and passkeys, are held by our authentication provider, not by us. We never see or store your password.
Sign-in through your organisation. If you sign in through an employer’s identity provider, we record that your account is federated and the name of that provider, so your contacts can see your account is backed by a corporate sign-in.
Device. An HonestID account is bound to one device. We store a public key for that device, the model and name your device reports, its operating system and version, and a push notification token. On iOS we store the App Attest key and attestation Apple issues for your app installation; on Android we store the Play Integrity verdict. These prove the app is genuine and unmodified, and are the reason an attacker cannot register a device in your name.
Security records. We keep a security log of events on your account: sign-ins and failed sign-ins, device changes and device transfers, and similar. Each entry records the time, the event, your IP address and the app or browser user agent. Our API also writes access logs of the requests your app makes.
Contacts and invitations. The people you connect with on HonestID, the status of each connection, and how it was established. If you invite someone who is not yet on HonestID, we store the email address you gave us so we can connect you when they join.
Verification records. When you run a verification we keep a record of it: who was involved, when, the channel being verified (a call or a message), the category of the request, the outcome, and the short free-text note the person starting the verification typed. That note is written to be shown to the other person, so please keep it brief and avoid putting anything sensitive in it.
Company directory. If your email domain belongs to an organisation that has been onboarded onto HonestID, your name and work email are visible to colleagues on that same domain so they can add you as a contact. This applies only to onboarded organisations, and the organisation can turn it off.
This website. If you submit your email address to be notified at launch, we store it to contact you about HonestID. This site sets no cookies and runs no advertising or analytics scripts. The blog stores your light or dark preference in your browser and nothing about it reaches us.
We use no third-party advertising or analytics SDKs in the app, and we do not track you across other apps or websites.
What we never see
Your shared Honest Key phrases, and the security questions and answers you exchange with a contact, are end-to-end encrypted on your device and compared using keys only your two devices hold. They never reach us in readable form. The temporary data used while a verification is running is deleted automatically within minutes, whether or not the verification completes.
We do not read, intercept, record or store the calls and messages you are verifying. HonestID sits alongside your conversation; it is never inside it.
Why we use it, and our legal bases
- To provide the service: authenticating you, binding your account to your device, connecting you with your contacts, delivering verification requests and showing you your history. Legal basis: performance of our contract with you.
- To keep accounts secure: detecting and investigating fraud, impersonation, abuse and attacks, and proving what happened on an account if it is disputed. Legal basis: our legitimate interest in the security of the service and of our users.
- To improve HonestID: understanding, in aggregate, how verifications are used and where they fail. Legal basis: our legitimate interest in improving the service.
- To contact you about launch, if you asked us to. Legal basis: your consent, which you can withdraw at any time.
- To meet legal obligations, where the law requires us to keep or disclose something. Legal basis: legal obligation.
We do not sell your personal data, and we do not use it for automated decisions that produce legal effects for you.
Who we share it with
Your contacts. Someone you connect with sees your name, your email address, and whether your account is backed by a corporate sign-in.
Our service providers. We use a small number of providers, each processing data only on our instructions:
- Amazon Web Services: hosting, database, authentication, push delivery and email.
- Apple: push notifications and App Attest, for the iOS app.
- Google: push notifications and Play Integrity, for the Android app.
We may also disclose data where the law requires it, or to establish or defend legal claims. If HonestID is ever sold or merged, your data may transfer with the business, and this policy will continue to apply until you are told otherwise.
Where your data is processed
Account and operational data are processed in the United Kingdom. Push notifications and app attestation involve Apple and Google, which may process data outside the UK. Where data leaves the UK we rely on an adequacy decision or on standard contractual clauses with the UK addendum.
How long we keep it
- Account, contacts, verification history and security records: for as long as your account exists.
- Temporary verification data: minutes, deleted automatically.
- Invitations to people not yet on HonestID: 7 days, then deleted automatically.
- Application logs: 30 days. API access logs: 90 days.
- Backups: deleted data can persist in our rolling backups for up to 35 days before ageing out.
- Launch notification list: until you ask us to remove you.
Deleting your account
You can delete your account at any time from the app. Deletion is immediate and permanent: your account, contacts, invitations, verification history, security records, device binding and sign-in credentials are removed. See Delete Your Account for the full list and for what to do if you no longer have your old phone.
How we protect it
Honest Keys and security answers are end-to-end encrypted. Traffic is encrypted in transit, and data is encrypted at rest. Your account is bound to a single attested device and unlocked with your device biometrics. Access to production data is limited to those who need it. No service can promise perfect security, but the design goal here is that a breach of our servers would not hand anyone the secrets that matter.
Your rights
Under UK and EU data protection law you have the right to access, correct, export, delete or restrict the use of your personal data, to object to processing we base on legitimate interests, and to withdraw consent where we rely on it. To exercise any of these, email support@honestid.io. We respond within one month and we do not charge for it.
If you are not satisfied with our response, you can complain to the Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EU.
Children
HonestID is not directed to children and is not intended for use by anyone under 16. If we learn that we hold data about someone under 16, we delete it.
Changes to this policy
We may update this policy from time to time. The “Last updated” date above always reflects the current version. Before a material change takes effect we will take reasonable steps to tell you, by email or in the app.
Contact
Questions about this policy or your data? Email support@honestid.io, or write to Honest Identity Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.