Privacy Policy
Identity Armor is built on a foundational commitment to creator sovereignty. This policy governs how we collect, store, protect, and handle your data — with particular care given to the biometric and digital asset data that defines your protected identity.
Effective Date: July 1, 2025 | Last Updated: July 26, 2025 | Version 1.0
1. Data We Collect
We collect only the data necessary to operate the Identity Armor platform and protect your digital identity. Categories include:
- ›Account credentials: email address, hashed password, account creation timestamp.
- ›Creator profile data: display name, public bio, social handles, publicly visible asset metadata.
- ›Vault assets (encrypted at rest): 3D rigging meshes and avatar model files, headshot and reference photo sets, voice baseline master recordings, watermark signature files, and license token payloads.
- ›Biometric-adjacent data: voice print spectral baselines and facial geometry reference sets used solely for your own watermark and ownership verification processes.
- ›Payment data: subscription tier, billing cycle, and transaction records. Raw card data is processed exclusively by our PCI-DSS compliant payment processors (Stripe). We never store full card numbers.
- ›Usage telemetry: page interactions, scanner invocations, API call counts, and feature usage — collected in aggregate and never linked to vault asset contents.
2. Vault Asset Security & Encryption
Your vault raw assets are treated with the highest level of protection we can technically provide:
- ›All vault assets are encrypted at rest using AES-256-GCM with per-user key derivation. Your encryption keys are never stored alongside your data.
- ›Assets in transit are protected by TLS 1.3 with certificate pinning enforced on all mobile clients.
- ›Vault storage is logically isolated — no cross-user access paths exist at the storage layer. Each vault namespace is segmented and access-logged.
- ›Access control is enforced via Firebase Security Rules and server-side authentication middleware. Unauthenticated principals cannot access any vault path, even partially.
- ›Biometric reference data (voice baselines, facial geometry references) is stored in a dedicated secure enclave separate from general media storage with stricter access audit logging.
3. We Do Not Train AI Models on Your Assets
Identity Armor strictly prohibits the use of your vault assets — including voice masters, 3D meshes, headshot sets, or any biometric reference data — for training, fine-tuning, distillation, or evaluation of any AI or machine learning model, whether operated by Identity Armor or any third party.
This prohibition is absolute for consumer accounts. The only exception is:
- ›Explicit B2B enterprise consent: If an enterprise-tier creator account holder formally opts in — via a countersigned B2B Data Utilization Agreement with defined scope, duration, and compensation terms — a strictly scoped and contractually bounded arrangement may be negotiated.
- ›Such opt-in is always affirmative, never passive. Pre-checked boxes, default settings, or buried toggles will never constitute consent for AI training use.
- ›Even under an active B2B agreement, only the contractually specified asset types and date ranges may be accessed. All other vault contents remain excluded.
Our internal automated systems (deepfake detection, watermark scanning, duplicate detection) process assets only in read-only ephemeral contexts. Processing results are discarded after the scan completes. No scan output is fed into model training pipelines.
4. How We Use Your Data
We use your data to operate and improve Identity Armor. Specifically:
- ›Providing the vault storage, registry anchoring, and licensing engine you signed up for.
- ›Running automated deepfake detection and watermark scanning on assets you submit for protection scans.
- ›Generating and verifying cryptographic ownership proofs tied to your identity tokens.
- ›Sending transactional communications: account alerts, license deal notifications, scan result reports, security notices.
- ›Enforcing our Terms of Service and Creator Guidelines, including takedown and infringement response processes.
- ›Improving platform reliability, performance, and security through aggregated, anonymized telemetry.
We do not sell, rent, broker, or share your personal data or vault assets with advertisers, data brokers, or analytics platforms.
5. Third-Party Processors
We engage a limited set of trusted sub-processors to operate the platform. Each is bound by data processing agreements (DPAs) consistent with this policy:
- ›Google Firebase / Google Cloud Platform — authentication, database, and cloud storage infrastructure.
- ›Stripe — payment processing and subscription management. Subject to Stripe's own PCI-DSS obligations.
- ›Cloudflare — DDoS protection, edge caching, and DNS. Does not receive vault asset contents.
- ›Postmark / Resend — transactional email delivery. Receives only the recipient address and message content necessary for delivery.
We do not integrate third-party advertising SDKs, behavioral tracking pixels, or social media embeds that would allow external parties to profile your activity on this platform.
6. Data Retention & Deletion
You own your vault. You have the right to leave and take your data with you — or have it permanently destroyed.
- ›Upon account deletion request, all vault assets (3D meshes, voice masters, photo sets, watermark files, license tokens) are permanently purged from active storage within 72 hours.
- ›Encrypted backup copies are fully overwritten and purged within 30 days of account deletion.
- ›Transaction records and license deal audit logs are retained for 7 years to satisfy legal and financial record-keeping obligations, but are stripped of vault asset references.
- ›Anonymized, aggregated usage statistics that cannot be re-linked to your account may be retained indefinitely.
- ›To request deletion, navigate to Settings > Account > Delete Account, or contact ghostrender_support@proton.me with subject line "Account Deletion Request."
7. Breach Notification
In the event of a security incident that may have exposed your personal data or vault assets, we commit to:
- ›Notifying affected users within 72 hours of confirmed breach identification via the email address on file.
- ›Providing a clear incident report detailing: what data was potentially accessed, the timeline of detection and containment, and recommended protective actions.
- ›Notifying applicable supervisory authorities as required by GDPR, CCPA, and other applicable regulations.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- ›Access a copy of all personal data we hold about you.
- ›Correct inaccurate personal data.
- ›Request deletion of your personal data ("right to be forgotten").
- ›Request restriction of processing while a dispute is pending.
- ›Data portability: receive your vault assets in their original uploaded format.
- ›Object to processing for legitimate interests.
- ›Lodge a complaint with your local supervisory authority (e.g., your EU member state's Data Protection Authority, or the California Attorney General).
To exercise any of these rights, contact us at ghostrender_support@proton.me.
Questions about this policy? Contact us at ghostrender_support@proton.me