Ultrapass® Privacy Policy

Private Identity LLC

Effective Date: Sept 1, 2026


This privacy policy (“Application Privacy Policy”) sets out how Private Identity LLC (“Private Identity,” “we,” “our” or “us”) collects, uses, maintains and discloses Personal Data about you when you use the Ultrapass FIDO authenticator application and any Private Identity verification services accessed through it (together, the “App”). This Application Privacy Policy is one of the product-specific privacy policies referenced in the privacy policy for our website at privateid.com (the “Site Privacy Policy”). The Site Privacy Policy governs the Site; this Application Privacy Policy governs the App. “Personal Data” has the meaning given in the Site Privacy Policy, and includes, without limitation, biometric information where applicable law treats it as such.


A. Scope and Roles

The App is a standards-based FIDO2 / WebAuthn authenticator that lets you create and use passkeys and, for supported workflows, verify your identity, age, or other attributes to an organization that has asked you to do so (each, a “Relying Party” or “Organization”), such as your employer, bank, healthcare provider, or an online service.

Your Organization is responsible for its own services, decisions, and privacy practices, which are governed by its own privacy policy. Where the App performs a verification because an Organization requested it, Private Identity generally processes any resulting information as a service provider (or, in the EU/EEA/UK, a processor) acting on the Organization’s documented instructions.

A defining feature of the App is that most processing of your information happens on your own device rather than on our systems. Where information is processed only on your device and is never transmitted to us, we do not receive, hold, or control it.


B. Our Approach: On-Device by Design

  • Biometric matching is always performed on your device. The comparison between your live face (or voice) and your enrolled reference never occurs on Private Identity systems.
  • Biometric templates and embeddings never leave your device. Your enrollment reference is a protected, irreversible on-device biometric template conforming to ISO/IEC 24745 and ISO/IEC 30136. It is not transmitted to Private Identity, to your Organization, or to anyone else, under any circumstance.
  • Raw captures are transient. Camera frames and audio captured for biometric matching are processed in memory and discarded; they are not written to your photo library or transmitted for matching.
  • Liveness is checked fresh. Each biometric verification requires a new live capture with on-device presentation-attack detection.
  • Nothing leaves your device without your consent for that Organization. Verification results are released only for the specific Organization and workflow you approved, and contain outcomes, not biometric content.
  • Two narrow, consent-gated exceptions involve images (never templates): identity-document images for document verification (Section D.1), and, in the EU/EEA/UK, images sent for human review if you contest an automated decision (Section D.2). Both occur only with your explicit consent at the point of use.

C. Face Data and Biometric Information

C.1 What we process

When you start face enrollment or verification in the App, the App captures live images of your face using your device camera, with your consent, at the point of use. These images are processed entirely on your device to (a) check liveness and image quality, producing transient signals that are discarded when the session ends, and (b) create or compare against a protected, irreversible biometric template (ISO/IEC 24745; ISO/IEC 30136) stored only on your device as your enrollment reference for one-to-one verification. Raw camera images are deleted from memory immediately after on-device processing and are never saved to your device storage or photo library and are never transmitted for biometric matching.

C.2 How face data is used

Face data is used only to enroll you on your own device, confirm liveness, and verify that you are the enrolled user when you sign in or complete a verification that you or your Organization initiated. We do not use face data for advertising, marketing, analytics, profiling, or model training, and we do not use it for any purpose other than the security function you requested.

C.3 Where face data is processed and stored

All biometric processing and matching occurs on your device. Your protected template is stored only on your device, in the App’s private storage protected by the operating system’s security features, with cryptographic keys held in device secure hardware where available.

C.4 What leaves your device

When a verification completes, the Organization you are authenticating to receives a cryptographic assertion and/or an encrypted result (for example, verification succeeded or failed, an age-threshold result, or a policy result, delivered as an encrypted result object such as a JWE under RFC 7516). That result contains no facial image, no template or embedding, and no biometric measurement. Where your Organization’s policy requires additional signals (for example, a coarse location result or device-integrity result), the App discloses the minimum result needed (such as a yes/no or coarse value), not the underlying raw data, as described in Section E.

C.5 Retention and deletion

Raw face images exist only for the duration of the active capture session. Your protected on-device template is retained until you delete your enrollment in the App, re-enroll, or uninstall the App, any of which removes it from your device. Because Private Identity does not receive your face data in the App’s biometric matching flows, there is nothing for us to retain or delete on our servers for those flows.

C.6 Voice data

Where you choose voice verification, a short prompted phrase is captured only while the voice screen is open. The audio is processed on your device into a protected, irreversible on-device template in the same manner as face data; raw audio is discarded after processing and is not transmitted for voice matching. Transient speech-recognition output used to confirm you read the prompted phrase is consumed in memory and not saved.

C.7 Your device’s built-in biometrics

To unlock your passkeys, the App uses the authentication built into your device operating system (for example, the device’s face or fingerprint unlock, or your device passcode) through the device’s local-authentication interfaces. The App receives only a success or failure result; it never receives, and cannot access, the operating system’s biometric data.


D.1 Identity document verification

Some Organizations require verification of a government-issued identity document (for example, a driver license, national ID card, or passport) to establish higher identity assurance. In those workflows, and only with your explicit consent given at the point of use, images of your identity document (and, where you choose chip scanning, data read from the document’s NFC chip) may be transmitted to Private Identity systems to validate the document’s authenticity, extract the data needed for the verification (such as name and date of birth), and complete the verification the Organization requested.

  • Purpose limitation. Document images and extracted data are used solely to perform the verification you requested and are not used for advertising, marketing, or any unrelated purpose.
  • Matching stays on-device. Any comparison between your live face and the portrait on your document is performed on your device; your live biometric template is not transmitted with, or derived from data on, our systems.
  • Disclosure. Verification results, and where the Organization’s workflow and your consent require it, extracted document data or document images, are provided to the requesting Organization as part of the verification you initiated.

Retention: document images and extracted data are retained only for the period necessary to complete the verification and thereafter as required by the requesting Organization’s agreement with us and applicable law, and are then deleted.

If you do not consent, the document-verification step will not proceed; your Organization determines what alternatives, if any, are available.

D.2 Human review of automated decisions (EU/EEA/UK)

Verification decisions in the App (for example, a face match result, a liveness result, or an age-threshold result) are made by automated means. If you are in the European Union, the European Economic Area, or the United Kingdom and an automated decision produces legal or similarly significant effects for you, you have the right to obtain human intervention, to express your point of view, and to contest the decision (GDPR Article 22(3)).

If you exercise that right, then with your explicit consent given at that time, the relevant image or images (for example, the selfie image captured for the contested check and/or the document images involved) may be transmitted to a human verification service so that a person, not an algorithm, re-examines the decision. Only images are transmitted for this purpose; your biometric templates and embeddings are never transmitted.

  • Who performs the review. The review is performed by Private Identity personnel, or an authorized human-review service acting under contract and confidentiality obligations, or by the Organization, depending on the workflow.

Retention: images transmitted for human review are used only for that review and are deleted when the review is complete, except where a longer period is required by law or by the Organization’s documented instructions.

If you do not consent, the automated result stands, and you may pursue other remedies your Organization offers through its own channels.


E. Other Information We Process in the App

  • Profile information. A display name you enter and a backup PIN you choose are stored on your device; the PIN is stored in protected form and is not transmitted to us.
  • Passkeys and credentials. Passkey key pairs are generated on your device. The private key is device-bound, and never leaves your device. By design of the FIDO2/WebAuthn standards, the corresponding public key, a credential identifier, and signed assertions are shared with the Organization you register with. Where you enable your platform’s credential sync or backup, passkey material may be synchronized by your operating-system provider under its own terms.
  • Policy signals requested by your Organization. Where an Organization’s policy requires it and you consent, the App may evaluate signals such as a one-time coarse location (disclosed as a coarse grid or in-zone yes/no result rather than raw coordinates), device-integrity attestation results, or time-window results, and disclose only the minimum result to the Organization.
  • Service and technical data. We receive limited technical information needed to operate and secure the service, such as App version and configuration, error and diagnostic codes, and security event records. This service data does not include biometric content.

F. How We Use Personal Data; Lawful Bases

Where the EU/UK General Data Protection Regulation (“EU/UK GDPR”) applies, we process Personal Data only where we have a valid legal basis. The table below sets out the principal categories, purposes, and lawful bases:

CategoryPurpose of processingLawful basis
Face and voice data processed on your device (Section C)Enrollment, liveness, and one-to-one verification on your deviceYour explicit consent (Art. 9(2)(a) where applicable); performance of a contract
Identity-document images and extracted data (Section D.1)Document authenticity validation and identity verification requested by your OrganizationYour explicit consent; performance of a contract; compliance with legal obligations (e.g., KYC)
Images transmitted for human review in the EU/EEA/UK (Section D.2)Human intervention in a contested automated decisionYour explicit consent; compliance with GDPR Art. 22(3)
Verification results and assertionsDelivering the outcome of the verification to the Organization you approved; fraud prevention; auditPerformance of a contract; our and the Organization’s legitimate interests (security, fraud prevention)
Service and technical dataOperating, securing, and improving the AppOur legitimate interests (service operation and security)

Automated decision-making: verification outcomes in the App are produced by automated means. Section D.2 describes your rights in the EU/EEA/UK, including the right to human intervention.


G. When We Disclose Personal Data

We do not sell Personal Data, and we do not share your information with third parties for their direct marketing purposes. Face data is never used for, or disclosed for, advertising or marketing. We may disclose Personal Data only in the following circumstances, and only to the extent permitted by applicable law:

  • To the Organization you are verifying with — verification results and, in the document workflows described in Section D.1, the consented document data, as part of the verification you initiated.
  • With your consent or at your request.
  • With service providers and vendors who perform functions on our behalf and under our instructions (for example, hosting and infrastructure, and the human-review service described in Section D.2), bound by contractual confidentiality and data-protection obligations.
  • To comply with legal or regulatory obligations, including, without limitation, valid legal process, and to protect legal rights and safety.
  • In connection with a business transaction, subject to steps to ensure any recipient respects the security and confidentiality of your Personal Data in accordance with applicable law.

The App contains no third-party advertising, analytics, or data-broker software development kits.


H. How We Secure Personal Data

The App’s primary security control is architectural: biometric matching, templates, and embeddings remain on your device, so they cannot be exposed by a breach of our systems. Information transmitted in the consent-gated flows described in Section D is encrypted in transit and at rest. We take reasonable technical and organizational precautions to protect the confidentiality, security and integrity of all data; however, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.


I. Our Retention of Personal Data

DataWhere it livesRetention
Raw camera frames and audio for biometric matchingYour device (volatile memory)Active capture session only; discarded after on-device processing
Protected, irreversible biometric templateYour device onlyUntil you delete the enrollment, re-enroll, or uninstall the App
Passkey private keysYour device (and platform sync where you enable it)Until you delete the passkey or uninstall the App
Identity-document images and extracted data (D.1)Private Identity systemsPeriod necessary to complete verification, then as required by the Organization’s agreement and law.
Images for EU/EEA/UK human review (D.2)Authorized human-review serviceDuration of the review; deleted on completion as soon as permitted by law or regulation.
Verification results and audit recordsPrivate Identity and/or Organization systemsAs required by the Organization’s agreement and applicable law
Service and technical dataPrivate Identity systemsLimited operational period (90 days)

J. Minors and Children Privacy

The App is not directed to children under the age of 13, and we do not knowingly collect Personal Data from children under 13 through the App. If you are a parent or guardian and believe a child under 13 has provided Personal Data through the App, contact us at compliance@privateid.com so we may take appropriate action.


K. Jurisdiction and Cross-Border Transfers

We are headquartered in the United States. Where information is transmitted to us under Section D, it may be transferred to, stored in, or accessed from the United States or other jurisdictions where our service providers are located. Where required under applicable law (including, without limitation, the EU/UK GDPR), we ensure appropriate safeguards for international transfers, which may include, without limitation, the European Commission’s Standard Contractual Clauses and/or the UK International Data Transfer Agreement or Addendum. You may request further information about these safeguards by contacting us at compliance@privateid.com.


L. Your Rights

Because most information the App uses lives only on your device, many rights are self-service: you can delete your face or voice enrollment in the App at any time, delete individual passkeys, or uninstall the App to remove the App’s data from your device. For information we hold (Sections D and E), you may exercise the rights available under the law of your state or country — including, depending on your residence, the rights to know, access, correct, delete, restrict, object, port, and withdraw consent — as described in the Site Privacy Policy, by contacting us at compliance@privateid.com. Where we act as a service provider or processor for your Organization, we may direct your request to that Organization or assist it in responding. If you are in the EU/EEA/UK you also have the rights described in Section D.2 regarding automated decisions, and the right to lodge a complaint with your supervisory authority or the UK ICO. We do not discriminate against anyone who exercises these rights.


M. Changes to this Application Privacy Policy

We may update or modify this Application Privacy Policy from time to time. If we make material changes, we will revise the Effective Date above, post the updated policy, and, where required, provide additional notice in the App. We encourage you to review this policy regularly.


N. How to Contact Us

Email Private Identity LLC: compliance@privateid.com

Was this page helpful?