Privacy Policy - App
As of: March 12, 2026
Controller
Overview
SecureID is a digital identity wallet app for secure building access, biometric signatures, and contactless payments. This privacy policy explains which data the app processes and how we protect your privacy.
Processed data
Data TypePurposeStorage LocationSharingDisplay NameIdentification of the credential holderServer (Supabase)NoBiometric featuresTransaction authorizationOnly on the device (Secure Enclave / Android Keystore)NoCryptographic keysDigital signatures (ECDSA P-256)Only on the device (Hardware Security Module)No — only public keys are transmittedCamera imagesQR code scanning during registrationNot stored — real-time processingNoNFC dataBuilding access (Tap-to-Open)Not storedOnly to the local door stationPayment authorizationsContactless payment confirmationServer (transient, in-memory)NoX.509 certificatesProof of identityServer + DeviceNo
What we do NOT do
We do not use analysis or tracking SDKs.
We do not run ads.
We do not share data with third parties.
We do not store biometric data on servers — it never leaves your device.
We do not collect location data.
Cryptography and Security
All private keys are generated and stored in your device's hardware security module (Secure Enclave on iOS, Android Keystore on Android). Private keys cannot be extracted or exported. Each signature requires biometric confirmation.
All network communication is conducted via HTTPS (TLS 1.2+). Plain text HTTP is used exclusively for local network addresses (LAN).
Data Storage and Deletion
Your ID data record is stored on the server as long as your account is active. Upon revocation of an ID, the associated certificates are invalidated. You can request the deletion of your data at any time by contacting us at privacy@saltlock.de.
Your Rights (GDPR)
As a user in the EU, you have the following rights:
Access — What data is stored about you
Rectification — Correction of incorrect data
Erasure — Deletion of your personal data
Data portability — Export of your data
Objection — To certain processing
Email: hello@secureid.app
Legal basis
The processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR (performance of contract — provision of identity wallet functions) as well as Art. 6 Para. 1 lit. f GDPR (legitimate interest — system security).
Changes
We may update this privacy policy. The current version is always available at this URL.




