New Age ID
Privacy Policy
Last updated 21 June 2026
Who we are
New Age ID (“New Age ID”, “we”, “us”) provides identity verification and a wallet for verifiable credentials. This policy explains what personal data we collect, why, and the rights you have over it. We are the data controller for the personal data described here and process it in line with UK data protection law (UK GDPR and the Data Protection Act 2018).
Our commitment
Your identity is yours. We collect the minimum needed to verify you once, we delete raw identity media as soon as verification is complete, and we never sell your personal data. Verified credentials are issued to you and held on your device — we do not track where or to whom you present them.
Information we collect
- Account details. Your email address and authentication details, managed through our sign-in provider (WorkOS).
- Identity verification data. Images of a government identity document (such as a passport), a selfie/face capture, and a short voice sample. These are collected solely to confirm you are a real, unique person and that the document is genuine.
- Biometric data. Your face and voice are processed to create a secure biometric match key. Biometric data is special category data under UK GDPR and is processed only with your explicit consent, given when you start verification.
- Credentials. The verifiable credential we issue to you (for example, a verified-identity credential) and the minimal record that it was issued.
- Device & usage data. Device identifiers, app version, and diagnostic and usage events used to keep the service secure and reliable.
Verify once — how we handle raw identity media
Verification happens once. The document images, selfie, and voice sample you provide are used to verify you and are then deleted shortly after processing (within minutes). We retain only an encrypted biometric match key and the minimal result of the check (for example, that verification succeeded) — never the raw media. The match key lets you unlock and re-prove your verified identity later without re-submitting documents.
Verifiable credentials
When you are verified, we issue a cryptographically signed credential that is held by you on your device. You choose when and to whom to present it. We sign and can revoke a credential where required (for example, on confirmed fraud), but we do not receive a record of each time you use it.
Why we process your data
- Consent — for processing biometric (special category) data. You can withdraw consent at any time by deleting your account.
- Performance of a contract — to verify your identity and provide the credential service you asked for.
- Legitimate interests — to prevent fraud, secure the service, and keep it working reliably.
- Legal obligation — where we must retain limited records to comply with applicable law.
Data retention
Raw identity media (document images, selfie, voice sample) is deleted shortly after verification completes. The encrypted match key and minimal verification records are kept for as long as your account is active, and only as long as needed for the purposes above or to meet a legal obligation. When you delete your account, your personal data is permanently removed from our systems, except where we are legally required to retain it.
Service providers we use
We rely on the following providers to operate New Age ID:
- Onfido — document and biometric identity verification.
- WorkOS — account sign-in and authentication.
- Convex — secure backend and data storage.
- Amazon Web Services — cloud hosting and key management (KMS) for credential signing.
- Stripe — payment processing, if you purchase a paid plan.
- Resend — transactional email (such as sign-in and account notices).
- PostHog — product analytics to improve the service.
Each provider acts on our instructions under a data processing agreement and only receives the data needed for its function.
International transfers
Some providers process data outside the UK. Where they do, we rely on appropriate safeguards (such as UK adequacy regulations or standard contractual clauses) to protect your data.
Your rights
You have the right to access, correct, or delete your personal data, to withdraw consent to biometric processing, to object to or restrict processing, and to data portability. To exercise any of these, email us at privacy@new-age-id.com. The easiest way to remove your data is to delete your account in the app.
Children
New Age ID is intended for adults (18+). We do not knowingly collect personal data from anyone under 18. If you believe a minor has used the service, contact us and we will delete the data.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above, and where appropriate we will notify you in the app.
Contact
Questions or requests about your privacy? Email privacy@new-age-id.com. If you are in the UK and are unhappy with our response, you can complain to the Information Commissioner’s Office at ico.org.uk.