Privacy Policy
What we hold about you, why we hold it, who else sees it, and how to get it back or erased. Written so that you can check it rather than take our word for it.
In force since 9 October 2026In short
This product exists to prove who somebody is, which makes personal data the whole substance of it. Six things are worth knowing before the detail.
- We never process your face unless you have asked us to, and being searchable is a second, separate switch that stays off until you turn it on.
- We keep visitor IP addresses in clear. That is a deliberate decision, and the section below explains why and what protects them.
- We never see a card number or a bank account number. Stripe holds those.
- We never tell anybody who reported them. We count distinct people and we do not name them.
- Nothing goes on your public page that you did not put there. No analytics, no report, no machine finding, no face.
- We do not sell data and we do not run advertising. There is no tracker on this site belonging to anybody else.
Who is responsible
The data controller is Stefan Mikovic, trading as WhoseID, 35 bis rue Léon Dauer, 94350 Villiers-sur-Marne, France. Our full registration details are on the legal notice.
For anything to do with your data, write to contact@whoseid.io. A person reads it.
Where an agency manages a creator’s page, that agency decides what to publish on it and is a controller for those choices. We remain the controller for everything described on this page.
What we hold, and why
One line per purpose, with the legal basis we rely on for it.
| What | Detail | Why | Legal basis |
|---|---|---|---|
| Your account | Email address, password (stored hashed, never in clear), handle, display name, profile picture. | To give you an account and let you sign back in. | Performance of the contract |
| Accounts you prove | The platform, the handle, the one-time code we generated, what we read on the profile and when, the history of attempts, any renames, and statements you make about an account. | To establish the proof, to be able to evidence it later, and to show it on your page. | Performance of the contract |
| Domains you prove | The domain name and the DNS record we asked you to publish. | To check once that the domain is yours. | Performance of the contract |
| What you publish | Posts, stories, calendar entries, links, collaborations, page settings, and the media attached to them. | To render your public page. | Performance of the contract |
| Protected media | A perceptual fingerprint of each registered image, video or sound. It is a set of numbers describing how the file looks or sounds, and the original cannot be reconstructed from it. We also keep what we found elsewhere that matched. | To find copies of your work republished by somebody else. | Performance of the contract |
| Face and identity data | A face template, a record that the face was checked live, and whether you allow it to be searched. Covered in detail in its own section below. | To prove a face is yours before anybody can register it. | Explicit consent (Art. 9(2)(a) GDPR) |
| Page audience | For each visit, outbound click and reaction on a public page: the visitor’s IP address, the browser user-agent, a first-party cookie identifier, and the time. Covered in detail in its own section below. | To give a creator the analytics for her own page, and to count distinct visitors on a promotion. | Legitimate interest in measuring a page for the person who publishes it |
| The promotion marketplace | Listings, offers, applications, the photos and videos attached to them, the link and time recorded for each part of a promotion, who marked it seen or contested and why, click and visitor counts, token balances, and the full ledger of movements. | To run the marketplace and keep an accurate account of who owes what to whom. | Performance of the contract |
| Reports about accounts | The platform, the handle reported, the reason, the free-text comment, and for reports made without an account a salted hash of the reporter’s IP address. The hash lets us count distinct people and identifies nobody. | To review reports, and to say honestly how many distinct people reported the same account. | Legitimate interest in protecting creators from impersonation, and legal obligation under the DSA |
| Your tax profile | Legal name, legal form, country, address, date of birth or registration date, tax identification number, VAT number where you have one, and the result of each check we ran against public registers and sanctions lists. When you have a Stripe payout account, your name and address are read from it to fill in the form; you check them before saving. | Required before you can sell anything paid or be paid through us, and required of us as a platform operator, who reports what you received each year. | Legal obligation (Art. 242 bis of the French tax code, DAC7, EU sanctions regulations) |
| Payments and payouts | For every payment made through us: the date and time, the amount, the VAT, what it was for, and the name, email address and country Stripe gives us for the person who paid. We also keep a copy of each message Stripe sends us about a payment, which can carry the billing details and the card brand and last four digits that Stripe attaches. For every payout: the amount, the date and the reference. Your full card number and your bank account are held by Stripe and not by us. | To take payment, run your subscription, and pay out what you earn. | Performance of the contract, and legal obligation for accounting records |
| Conversations between creators | The text of each message you send or receive in Messages, who it was between, when it was sent, and whether it has been read. When an agency manages a page, its staff read and reply for the page, and we record which account typed each message. Only text is sent: no photo, no file, no voice. Our staff do not read conversations, with one exception: when a part of a promotion is sent to us in a dispute, the member of staff who decides it reads the conversation of that promotion, and each reading is recorded. | To let two creators talk before they agree on a promotion. | Performance of the contract |
| Messages we send you | The notices raised in your account, and whether a digest of them was emailed to you and read. | To tell you when something happened that concerns your money or your page. | Performance of the contract |
| Service logs | Application errors, scheduled task runs, operational incidents, and rate-limit counters keyed by IP address. | To keep the service running and to stop abuse. | Legitimate interest in security and reliability |
Your face and your identity
A face template is biometric data, which is the most protected category the law recognises. We only process it if you explicitly ask us to, and only for the two purposes below.
What the search does with somebody else’s media
When a visitor submits an image or a video to find out whether the person in it is a verified creator, we compute a template in memory and compare it only against creators who have opted in. After that:
- the submitted media is not kept, and neither is the template computed from it;
- no record is kept of who was searched for, or by whom, because a log of that would be precisely the file this product refuses to hold;
- the result is a handle or nothing at all, never a score, never a nearest match, and never a conclusion about whether an account is genuine.
The person appearing in a submitted media has not consented to that computation. We keep it to the minimum we can, with nothing retained and nothing logged, and we would rather state it here than leave it unsaid.
Where it lives, and how to erase it
Face templates are held by our matching engine, on a dedicated server in Germany, separately from the main database. Deleting your face from your dashboard erases it at the engine first and then here. Your own account does not hold the permission to delete it directly, which is what stops the erasure from being half done.
Nothing biometric ever appears publicly. Your page shows a badge, and never a template, a capture, or the fact that a search matched.
IP addresses
When somebody visits a creator’s public page, clicks a link on it, reacts to a post or follows a promotion link, we store their IP address in clear. Not hashed, not truncated. This is the one deliberate exception to the way this product treats visitor data everywhere else, so it deserves a straight explanation.
The reason is counting. A creator needs to know how many distinct people visited rather than how many page loads happened, and both sides of a promotion judge it on distinct visitors. A hash would still let us count, but it would quietly cost us the ability to tell a real audience from a fabricated one, and creators pay each other on what that count shows.
In exchange, that table is the most closed one in the entire database.
- It has no access policy at all. No signed-in session can read a row from it, ever, not yours, not another creator’s, not an administrator’s.
- It is read only through named functions that compute totals, and not one of them returns an IP address, a user-agent or a cookie identifier to anybody.
- Nothing derived from it appears on a public page.
- It is never shared, never sold and never used for advertising.
These records are kept for as long as the page they belong to exists, so that a creator’s analytics stay complete, and they are deleted along with it. If you are a visitor and you want your records removed sooner, write to contact@whoseid.io from the connection concerned and we will remove them.
Rate-limit counters keyed by IP are a separate thing and they expire within minutes. Reports filed without an account use a salted hash rather than the address itself.
What we never hold
- Card numbers. Payment details are entered on Stripe’s pages and never reach our servers.
- Bank account numbers. Your payout account is set up with Stripe, who verify and hold it. No IBAN exists anywhere in our systems.
- Identity documents. We never ask for a passport, an ID card or a company certificate. Where something can be verified we fetch it from a public register instead, since a register answer cannot be edited in an image editor.
- Your password. It is stored hashed by our authentication provider and we cannot read it.
- The identity of anybody who reported an account. We do not hold it in a form that names them, and we would not disclose it in any case.
- Any record of who searched for whom. The face search keeps nothing.
Transfers outside Europe
Your account, your page, your media and your face template are stored in the European Union: Ireland for the database and file storage, Germany for the matching engines.
Some of the services listed above are established outside the European Economic Area, or may access data from there for support purposes. Those transfers rely on the European Commission’s standard contractual clauses, or on an adequacy decision where one covers the provider.
How long we keep things
| What | Kept for |
|---|---|
| Your account, page and proofs | Until you delete them or close your account. |
| Face template and identity check | Until you erase it from your dashboard, or close your account, whichever comes first. Live captures are discarded as soon as the check has been judged. |
| Page audience records | As long as the page exists, so that its analytics stay complete. Deleted with the page. |
| Marketplace records and token ledger | Kept as accounting records. The ledger cannot be modified or deleted by anybody, including us, which is what makes a balance trustworthy. |
| Photos and videos attached to a promotion | Deleted from our servers when the promotion ends: when the listing closes or is removed, when a booking is settled, and within a day for a file uploaded and never used. Keep your own copy. |
| Conversations between creators | As long as both pages exist, and deleted with either of them. We do not edit or remove a single message on request, because the person who received it may need it to stay readable. |
| Invoices, payments, payouts and tax profiles | Ten years, as French commercial and tax law requires. This survives closing your account and we are not permitted to delete it on request. |
| Reports and moderation decisions | As long as the case is open, and afterwards for as long as we might need to justify the decision. |
| Engine read logs and incidents | Short lived, and trimmed automatically as new ones arrive. |
| Abandoned sign-ups | Swept automatically. A sign-up you never finished does not linger. |
Your rights
Under the GDPR you can:
- ask for access to the data we hold about you, and for a copy of it;
- correct anything inaccurate, and most of it you can edit yourself;
- ask us to erase it, subject to what we are legally required to keep. Your face, your media and your page you can erase yourself, today, from your dashboard;
- restrict or object to processing we base on a legitimate interest;
- take your data elsewhere in a machine-readable format;
- withdraw consent at any time where we rely on it, in particular for your face. Withdrawing consent does not undo what was lawfully done before;
- give instructions about what happens to your data after your death, as French law provides.
Write to contact@whoseid.io and we will answer within one month. There is no charge and you do not have to justify the request.
No automated decision here produces a legal effect on you. Our engines flag, score and sort, and a person decides. A doubtful identity check goes to review rather than to a refusal, and no automated system removes content on this service.
Security
Access to data is enforced by the database itself, row by row, rather than by the code that queries it, so a mistake in a screen cannot show you somebody else’s data. The most sensitive tables, meaning tax profiles, audience records and face consent, have no access policy at all: no signed-in session can read them under any circumstances, and they are reached only through named functions that return computed answers.
Everything travels over HTTPS. Passwords are hashed by our authentication provider. Staff accounts require a second factor. Secrets are never stored in the code.
No system is perfect. If you find a vulnerability, write to contact@whoseid.io, since we would much rather hear about it from you than from somebody else. If a breach ever puts your rights at risk, we will tell you and the supervisory authority within the deadlines the law sets.
Children
WhoseID is for adults. We do not knowingly collect data about anybody under 18, and we close any account we find to belong to a minor and delete its data. If you believe a minor has an account here, tell us at contact@whoseid.io.
Changes to this policy
This policy changes as the product does, and the date at the top is when the current version came into force. Where a change widens what we do with your data we tell you by email before it takes effect, and where a change needs your consent we ask for it rather than announce it.
Contact and complaints
Write to contact@whoseid.io, or by post to 35 bis rue Léon Dauer, 94350 Villiers-sur-Marne, France.
If you are not satisfied with how we handled your request, you can complain to the French data protection authority, the CNIL, at cnil.fr, or to the supervisory authority of the country where you live.