Privacy policy
We protect you, and we see as little of you as the job allows. Where that is structural, it is because of how the software is built and not because we promise to behave. Where it is not, this page says so plainly and names what we hold. On 30 August 2026 that list grew, and the section on the app has been rewritten rather than softened.
Last updated 30 August 2026.
There are two different things here
This website takes your email if you join the waiting list, subscribe, or contact us. That is a mailing list. We hold it, we can read it, and this page explains it.
The Fravash app reads the chip in your passport or ID card and keeps the result on your phone. We never receive that data. There is no account, no server copy, and no database of users. That is not a policy choice we could quietly reverse; it is what the system is made of.
Everything below is split along that line, because collapsing the two would make this document flattering and wrong.
The website
What we collect, and only when you type it in
- Waiting list: email address, and optionally your first and last name, phone number, country, and what you are interested in.
- Newsletter: email address.
- Contact form: name, email address, a category, and your message.
Each record carries the time it was created and which form it came from. Nothing else is attached to it.
Why, and on what basis
Consent, which you give by submitting the form, and which you can withdraw at any time. We use these details to tell you when Fravash opens, to answer what you asked, and for nothing else.
Where it is kept, and by whom
- Supabase, on infrastructure in the European Union, stores the list.
- Vercel serves this website and processes the requests that reach it.
Those are the only two processors. We do not pass your details to anyone else, we do not sell them, and we never will. The business model is subscriptions and per-verification fees, so advertising and data resale are not revenue we are giving up. They are revenue that would destroy the thing we are selling.
How long
Waiting list and newsletter entries are kept until you ask us to remove them or until the list has served its purpose and is deleted. Contact messages are kept while we are dealing with them and for as long as we need to answer a follow-up.
What this website does not do
These are checkable claims, not reassurances, and they are worth reading as a list of absences.
- No analytics. There is no Google Analytics, no Plausible, no Vercel Analytics, no pixel, and no third-party script measuring you. We do not know how many pages you looked at.
- No cookies at all. This site sets no cookies and writes nothing to your browser's storage. There is no consent notice because there is nothing to consent to.
- No advertising networks and no remarketing.
- No profiling and no automated decision-making. We do not build a picture of you from your behaviour, on this site or anywhere else.
IP addresses
The forms on this site are rate limited so that nobody can flood them. To do that, the server needs to tell one visitor from another. It does this by hashing your IP address together with a random value that is generated when the server starts and is never written down. The result is kept in memory for at most a minute and is never logged, never stored, and never sent anywhere. We do not keep your IP address, and we could not recover it from what we do keep.
Vercel, as the host, handles the network connection itself and keeps its own operational logs, as any host must.
The app
Updated 30 August 2026, when the app started proving that the person holding a document is the person in it. Here is exactly what that involves, what stays on your phone, and what reaches us.
- Your photograph never leaves your phone. The app reads the picture stored on your document’s chip and compares it with your face, and both the picture and your face are used on the device and then discarded. We never receive either one, and no measurement taken from your face is stored anywhere by anyone.
- The rest of the chip does reach us. When you prove you are a person, your phone sends us the chip’s security certificate and its machine-readable zone: your name, date of birth, document number, nationality, issuing country and document type. We check the issuing country’s own signature over those bytes ourselves, against the certificates of 116 states. We take nobody else’s word for it, including the app’s.
- We keep a record, and we can read it. There is one row per person. Nothing in it is stored in readable form: your details are encrypted, and the row is found by comparing codes rather than by reading anything. The keys that would decrypt it are ours, which means we could determine whether a named person has used Fravash. We say so because it is true and because a policy that claimed otherwise would be worth nothing. It exists so that a platform with a fraud problem can be answered without every service on the internet keeping its own copy of your passport.
- The face check happens on your phone, not on our servers. Nothing about your face, and no measurement taken from it, is sent anywhere or stored anywhere.
- A different account number for every site. When you prove you are a real person to a website, that site receives a number derived for that site alone. Two sites comparing notes cannot tell they are looking at the same person, and a breach at one of them does not unlock anything here. We can link them, because the numbers are derived from our record.
- A site learns that a real, unique person is present. Not your name, not your birthdate, not your document number, and not your face. If a site asks something narrower, such as whether you are over eighteen, it receives only yes or no.
- You are asked every time, and you can refuse.
Fravash is not a certified European Digital Identity Wallet and does not claim to be one.
Your rights
Under the GDPR you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to our use of it, ask for it in a portable form, and withdraw consent at any time. Withdrawing consent does not undo what was lawful before you withdrew it.
For the app, these rights have something to act on. We hold one row per person containing your name, date of birth, document number, nationality, issuing country and document type, encrypted under keys we hold.
To ask for a copy or for deletion, write to us at the address below. Because the row is found by matching codes derived from your document rather than by searching a name, the reliable way for us to identify your record is for you to tell us that you want it removed and to re-read your document in the app, which produces the same codes and names the exact row. Deleting your enrolment on your phone removes it from the device, and our row is removed separately, on request. For the mailing list, write to us and we will act on it.
You also have the right to complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
Children
This website and the waiting list are not directed at children, and we do not knowingly collect their details through it.
Who is responsible
The controller for the personal data described on this page is Fravash, Irene Vorrinkplein 4, Zaandam, Netherlands.
For anything on this page, including a request about your data, write to diktasrevan@gmail.com or use the contact form.
Changes
If this policy changes we will update the date at the top. If a change affects what we collect or why, we will say so rather than letting the date carry the news.