Last updated · June 2026
Privacy Policy
This Privacy Policy explains how Known Technologies, Inc. ("Known", "we", "us") collects, uses, stores, shares, and protects information when you use known.id and any related services (the "Service"). By creating an account you agree to this Policy and to our Terms of Service. If you do not agree, do not use the Service.
Known is operated as a personal-data controller for account and profile data. For verification artifacts (ID images, selfies, phone numbers, voice recordings, social profile pages), we act as a controller for the verification result and as a joint or independent controller with the verification providers listed below for the underlying biometric and identity data they collect on our behalf.
1. Information we collect
Account & profile data you provide:
- Email address, password hash, authentication identifiers, and OAuth tokens (Google sign-in).
- Display name, username, profile photo, short bio, category, location text, and links you choose to publish.
- Linked social profile URLs (e.g. X, Instagram, LinkedIn, GitHub) that you submit for cross-platform verification.
Verification artifacts:
- Government ID & live selfie: document images, selfie frames, liveness video, document type, issuing country, name, date of birth, and a biometric face template — captured and processed by Veriff Operations OÜ ("Veriff") on our behalf.
- Phone number: your full E.164 phone number, transmitted to Twilio Inc. ("Twilio") to deliver a one-time verification code via Verify API.
- Voice recording: a short audio + video clip (≤15 seconds) of you reading a randomized phrase, sent to our AI provider for accent classification and face-match against your profile photo. The raw recording is not stored; only the derived result (accent region label and a "verified" timestamp) is retained.
- Social verification: public HTML of the social profile URLs you submit, fetched server-side via Firecrawl to confirm handle consistency and account age.
Automatically collected usage data:
- Profile view, share, and link-click counts (aggregate counters, not per-visitor logs).
- Truncated IP address and request metadata used for rate limiting and abuse prevention.
- Error and performance telemetry sent to Sentry (no request bodies, no PII payloads).
2. Biometric information notice
Live selfies, liveness video frames, and voice recordings constitute biometric information under laws such as Illinois BIPA, Texas CUBI, Washington H.B. 1493, and similar regimes. By initiating a verification flow you provide express written consent for Known and its verification providers to collect, process, and (in the case of Veriff) retain such information for the limited purpose of confirming your identity and producing the trust signals shown on your public profile.
- Veriff retains ID images, selfies, and the face template per its own retention schedule (typically up to 3 years, or shorter where required). Known stores only the decision result and your document's issuing country — never the document images.
- Voice recordings are transmitted to our AI provider, used only for the single classification request, and discarded. Known does not persist the audio or any voiceprint.
- You may withdraw consent and request deletion at any time (see Section 9).
3. How we use information
- To verify that you are a real, unique human and to issue the verified trust signals on your profile.
- To render your public profile at known.id/<username> and serve it to anyone with the link.
- To prevent fraud, impersonation, sybil accounts, SMS pumping, and abuse of the Service.
- To send transactional email (password reset, account changes). We do not send marketing email without separate opt-in.
- To debug, monitor, and improve the Service (Sentry error telemetry, aggregate analytics).
4. Legal bases (GDPR / UK GDPR)
- Contract: account creation, profile hosting, verification delivery.
- Explicit consent: processing of biometric data (selfie, voice), SMS delivery, social profile scraping.
- Legitimate interests: fraud prevention, rate limiting, security telemetry — balanced against your rights.
- Legal obligation: responding to lawful requests and complying with regulator orders.
5. How we share information
We do not sell personal data. We share with the following processors strictly to operate the Service:
- Lovable Cloud (Supabase / Cloudflare) — application hosting, database, edge functions, object storage.
- Veriff Operations OÜ — identity document and live-selfie verification.
- Twilio Inc. — SMS one-time-code delivery (Verify API).
- Google LLC — Sign-in with Google (OAuth identity only).
- Our AI provider (via Lovable AI Gateway) — voice/accent analysis and face-match for the voice signal.
- Firecrawl — server-side fetching of public social profile pages you submit.
- Sentry — error and crash reporting.
We may disclose information when legally required (subpoena, court order, lawful government request), to enforce our Terms, or to protect the rights, safety, and property of Known, our users, or the public.
6. Public vs. private fields
Your public profile (name, username, photo, bio, category, location text, linked social handles, and the boolean "verified" signals) is intentionally visible to anyone with the link and is indexed by search engines. Phone numbers, email addresses, raw ID data, biometric templates, voice audio, and account settings are never shown publicly.
7. International transfers
Known is operated from the United States. Our processors operate in the US, EU, and other regions. Where we transfer personal data out of the EEA or UK, we rely on Standard Contractual Clauses or equivalent safeguards.
8. Data retention
- Account and profile data: retained until you delete your account.
- Verification results (boolean signals + timestamps + issuing country for ID): retained for the life of the account so we can display them on your profile.
- SMS one-time codes: held by Twilio only long enough to validate, then expired.
- Voice recordings: discarded after the single classification request.
- Veriff-side document images and biometric templates: per Veriff's retention schedule.
- Aggregate counters and rate-limit records: auto-expire on a rolling window.
- Backups: rolling 30-day backups; deletions propagate as backups age out.
9. Your rights
Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, and similar), you have the right to access, correct, export, restrict, or delete your personal data, to object to processing based on legitimate interests, and to withdraw consent for biometric processing. You can:
- Edit profile fields and disconnect signals from Settings.
- Permanently delete your account from Settings → Danger Zone. Deletion removes your profile row, uploaded files, and authentication record, and instructs our processors to delete what they hold on our behalf.
- Email privacy@known.id for any other request. We respond within 30 days.
California residents: we do not sell or share personal information for cross-context behavioral advertising. You have the right not to be discriminated against for exercising your privacy rights.
10. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Database access is gated by row-level security; only owners can read their private profile fields. Webhooks are HMAC-signed and replay-protected. Rate limits guard OTP, voice, and social verification endpoints. No system is perfectly secure — report vulnerabilities to security@known.id.
11. Children
Known is not directed to children under 13 and we do not knowingly collect personal data from them. Some verifications (e.g. government ID) require you to be of legal age in your jurisdiction.
12. Cookies
We use first-party cookies and local storage strictly for authentication and session management. We do not use advertising or cross-site tracking cookies.
13. Changes
We may update this Policy. Material changes will be announced in-product or by email. Continued use after the effective date constitutes acceptance.
14. Contact
Privacy questions: privacy@known.id. Security: security@known.id. General: hello@known.id.