Privacy Policy for CivicOS

Effective date: 2026-07-20
Last updated: 2026-07-31

CivicOS values your privacy. This Privacy Policy explains how CivicOS handles information when you use the CivicOS mobile application and related services.

1. Overview

CivicOS is a digital identity and verified participation platform. The app includes identity onboarding features such as document scanning, MRZ capture, NFC passport reading on supported devices, and related profile and participation features.

Document and face verification media is processed on your device. Information you choose to publish, a non-reversible verification identifier, and limited verification results are sent to our servers so that verified participation features can work. Sections 3, 4, and 7 explain exactly what stays on your device, what is sent, and how long each item is kept.

2. Who We Are

Code iland AB (organisationsnummer 559393-4424), Stockholm, Sweden, is the data controller responsible for the personal data described in this policy. You can reach us using the details in section 19.

3. Information Processed on Your Device

Depending on the features you use, CivicOS processes the following categories of information on your device:

Document images, MRZ data, NFC chip data, the document portrait, live face images, facial landmarks, face mesh, and face embeddings are processed locally. These raw images and face representations are not transmitted to our servers or to a face-analysis service. Temporary copies are deleted when verification completes or is cancelled.

One face-display artifact is retained on your device after successful verification. On supported devices it consists of the 468-point face mesh, selected facial landmarks, and an encrypted face texture. If mesh extraction is unavailable, an encrypted final face photograph is retained instead. The artifact is used only to represent you visually in your CivicOS profile. It is not used for another comparison and is never transmitted. Signing out, deleting your account, or uninstalling the app removes it.

On supported devices, hardware-backed security mechanisms may be used, including the Secure Enclave on Apple devices and the Android Keystore, to store app-related secrets. Your identity information is not stored in these mechanisms.

4. What Leaves Your Device

Some information is used only on your device and never reaches our servers. Other information is sent to us so the service can function. This section explains which is which.

4.1 Never transmitted to us

The following is used locally during identity verification and is not transmitted to us:

4.2 Derived face-verification results

After the on-device checks pass, the app sends limited derived results to Code iland's backend as part of account verification. Depending on the completed flow, these results may include:

These results contain no photograph, video, face mesh, facial landmarks, or face embedding. The backend uses them only while processing the verification request. CivicOS does not write them to its database, audit records, or application logs, and discards them when the request completes. They are transmitted using encrypted HTTPS connections.

4.3 The unique verification identifier

When verification succeeds, your device derives a single value from your identity information using a keyed one-way function (HMAC) and sends only that value to us. This identifier:

Because the same person always produces the same identifier, it is a persistent pseudonymous identifier. It is linked to your activity within CivicOS, and we treat it as personal data under applicable data protection law even though it does not reveal your real-world identity.

4.4 Information you enter or send us

4.5 Technical information

Like any internet service, our servers automatically receive certain technical information when your app communicates with them, including your IP address, the time of the request, and basic device and app version information. We use this only to operate the service, diagnose faults, and protect against abuse.

The app also uses the platform's app attestation services (App Attest on iOS and Play Integrity on Android) to confirm that requests come from a genuine, unmodified copy of CivicOS. This check involves Apple or Google and does not disclose your identity to them.

5. Permissions

CivicOS requests access to the following device capabilities. Each is requested in context, at the point where the relevant feature is used, and each can be declined.

6. How We Use Information, and Our Legal Bases

Under the EU General Data Protection Regulation (GDPR) we must have a legal basis for each purpose for which we process personal data. Our purposes and bases are:

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal.

7. Biometric Data

CivicOS processes live camera frames, a final face photograph, temporary face crops, facial landmarks, a 468-point face mesh, numerical face embeddings, liveness and gaze measurements, and the similarity result of comparing the live face with the document portrait. This face data is used only to confirm that a real person is present, that the person follows the liveness and gaze prompts, and that the identity document belongs to that person. It is not used to identify you among a database of people.

Under GDPR, face data used for this purpose may be special-category biometric data. CivicOS processes it on the basis of your explicit consent under Article 9(2)(a). Before the face camera starts, the app displays the data categories, purposes, local storage, limited transfer described in section 4.2, and retention period. The scan button remains disabled until you affirm that consent. You can decline; verification will not continue and features requiring a verified account will remain unavailable.

Raw camera images, the document portrait, face mesh, facial landmarks, and face embeddings remain on your device. Face detection, mesh creation, liveness evaluation, and face comparison run locally. Only the derived verification results listed in section 4.2 are sent to Code iland's backend, where they are used for the current request and not retained. No face data is sold, used for advertising, or shared with data brokers.

Temporary face images and embeddings are deleted when verification completes or is cancelled. The encrypted profile face artifact described in section 3 remains until you sign out, delete your account, or uninstall the app. Signing out or deleting the account withdraws consent for future processing and deletes that retained artifact from the app's storage.

8. Content Moderation and Automated Processing

Content published in CivicOS passes through two moderation layers. An automated system first flags content that may be inappropriate. A human administrator then reviews flagged content and approves it, requests changes, or rejects it. Moderation decisions are therefore not made by automated means alone.

Administrators can access content that has been flagged or reported. They see the content and the pseudonymous identifier associated with it; they do not have access to your identity documents, raw face images, face mesh, facial landmarks, or face embeddings.

Eligibility verification itself is automated: your device determines whether your document meets the eligibility criteria. If you believe an outcome is incorrect, you can contact us using the details in section 19 and ask for it to be reviewed by a person.

9. Data Sharing

We do not sell your personal data, and we do not share it with advertisers, data brokers, or for third-party marketing purposes.

We share data only in the following circumstances:

We do not receive your identity documents, information extracted from those documents, face photographs, face mesh, facial landmarks, or face embeddings. Railway processes the derived results described in section 4.2 only for the duration of the backend request; those results are not sent to Supabase or retained by CivicOS.

10. Data Retention

On your device.

On our servers.

11. Deleting Your Data

You can delete your CivicOS account from within the app at Profile → Settings → Delete account.

Deleting your account removes your published content, your profile, and your verification identifier from our servers, subject to the retention periods in section 10. Signing out or deleting your account also removes the retained face artifact and other identity data from the device. Uninstalling the app removes its local data.

Because your identity is held only as a non-reversible identifier, we cannot locate your account from your name or your document. Deletion requests must therefore be made from within the app, or accompanied by information that lets us identify the account.

12. Security

We use appropriate technical and organizational measures designed to protect information and reduce unauthorized access, disclosure, misuse, or loss. These include:

No method of storage, processing, or transmission is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

13. International Transfers

We are established in Sweden. Railway and Supabase may process server data in the hosting regions configured for CivicOS and through their supporting infrastructure. Where personal data is transferred outside the European Economic Area, we rely on applicable safeguards, such as the European Commission Standard Contractual Clauses, an adequacy decision, or the EU–US Data Privacy Framework. You can request current information about hosting regions and safeguards using the contact details in section 19.

14. Children's Privacy

CivicOS is not intended for people under the age of 13, and we do not knowingly collect personal information from them.

If you believe a child has provided personal information in violation of this policy, please contact us and we will delete it.

15. Your Rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

To exercise any of these rights, contact us at info@codeiland.com. We will respond within one month, and will tell you if we need longer because a request is complex. Note the limitation described in section 11: because we hold no identifying information about you, we may need you to make the request from within the app so that we can locate the correct account.

If you are in Sweden, you can complain to Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection. If you are elsewhere in the EEA or the UK, you can complain to your local supervisory authority.

16. Users Outside the European Economic Area

CivicOS may be available in countries outside the EEA. Wherever you are, we apply the practices described in this policy. Depending on where you live, you may have additional rights under local law; contact us if you wish to exercise them. We do not sell personal data as that term is defined under United States state privacy laws.

17. Third-Party Services

CivicOS uses Railway for backend hosting, Supabase for database and file-storage infrastructure, Apple App Attest, Google Play Integrity, and the platform map services. The app also uses on-device face-detection and machine-learning components, including Google ML Kit on supported platforms and locally bundled TensorFlow models. Face images, landmarks, meshes, and embeddings are not sent to Google or another model provider.

We do not use third-party analytics or advertising SDKs.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where required, notify you in the app before the changes take effect.

19. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Code iland AB
Post Box 145361
Stockholm, Sweden
info@codeiland.com
civicos.codeiland.com/support