1. Who We Are
AuthentiKate, Inc. ("AuthentiKate," "we," "us," or "our") is a Delaware C-corporation. We operate an anti-impersonation verification platform built on CKY (Customer Knows You): a system that allows people to confirm whether someone contacting them is genuinely who they claim to be, using a short-lived code only a verified figure can produce.
We operate two apps:
- AuthentiKate (the consumer app) — free, no account required. Used by the public to verify whether someone contacting them is a real, verified figure.
- AuthentiKate Verified (the figure app, $120/year) — used by public figures, brands, and their teams to generate verification codes, manage their verified profile, and receive impersonation alerts.
This policy also covers our website at authentikate.com. Business and enterprise use is governed by separate agreements.
Data Controller contact: privacy@authentikate.com
2. The Two Apps Have Very Different Data Profiles
2.1 AuthentiKate — Consumer App
When you use the consumer app:
- No account is created. You are not a registered user of our systems.
- Your search queries are not logged to a profile or stored in our database.
- Your verification history — the name you searched, the channel (e.g. Instagram, Phone, Email), whether it was verified, and the date/time — is stored on your device (and, on iOS, may be included in your device's own iCloud or local backups, since Apple provides no way for an app to exclude a single item from those) and is never transmitted to our servers. The code itself is never stored, on-device or otherwise.
- We receive the code you submit for validation and the claimed figure handle — these are processed in memory and the Verification record written contains only the figure's identifier, the outcome, and the claimed handle/platform. It contains no consumer identifier: no IP address, no device ID, no account reference.
- Separately — to confirm the app itself is genuine and unmodified before we act on your code — your device may complete a cryptographic attestation check (Apple App Attest on iOS; Google Play Integrity on Android). On iOS, this produces a device attestation credential that we store, Redis-only, for up to 90 days after your last use (see §6). This credential is never written to the Verification record, our database, or any consumer-identifying store, and is never linked to your search, the code you entered, or any other data. See "Device Attestation — Security, Not Tracking" below for exactly what this is and isn't.
- Abuse prevention uses short-lived, ephemeral rate-limiting checks that purge within 24 hours. These are never persisted to our database.
- We do not use any third-party analytics SDKs in this app.
- Impersonation reports you submit are fully anonymous — no reporter contact information is recorded.
In practical terms: we do not know who you are, and we have no way to find out from the data we hold.
What this is: a cryptographic check that proves your copy of the app is a genuine, unmodified installation — not a bot, an emulator, or a tampered client — before we act on a verification request. Apple calls this App Attest; Google calls it Play Integrity. Your device registers for this automatically when you install the app, and again roughly every 60 days to stay current.
What it is not:
- Not your device's advertising identifier.
- Not a hardware serial number or any Apple/Google device identifier.
- Not your Apple ID, Google account, or any account identifier.
- Not a general-purpose device fingerprint we could reuse for anything else.
What we do with it: exactly one thing — confirming the request came from a genuine copy of our app. We do not use it to track you across sessions, build a profile of your activity, target advertising to you, or share or sell it to anyone. We do not run advertising in this app and do not use third-party analytics or tracking SDKs (see §2.1).
What we cannot do with it: identify who you are, or connect your attestation credential to your search history, the code you entered, or any other person-identifying information. It is stored, Redis-only, separately from every other system in this app, and it is never joined to the Verification record described above.
2.2 AuthentiKate Verified — Figure App
This is where our substantive data-controller obligations arise. To become a verified figure, you must provide:
- Identity information: Your full name and email address.
- Government identity verification (KYC): A government-issued photo ID and a liveness/selfie check, processed by our identity verification provider Veriff. This data is collected and held by Veriff; we receive only the verification outcome and a vendor reference ID. We do not store copies of your ID documents or biometric data in our own systems.
- Social handles you declare: The external social media accounts you wish to associate with your verified profile (Instagram, X, Facebook, TikTok, Snapchat, Telegram, LinkedIn, Discord).
- Payment information: Billing details processed by Stripe. We store only your Stripe customer ID; we do not hold card numbers or bank details.
- Device and passkey data: Information about the registered devices you use to authenticate. Authentication uses passkeys (WebAuthn) — we never store passwords. Each device requires an in-person or video verification ceremony before it can access your account.
- Profile content: Display name, bio, avatar, any personalized signature or message shown to people who verify you.
- Team member information: If you add team members (managers, agents, publicists) to your account, we hold their name, email address, role, and KYC status.
- Communications with support: Messages you send us via our support platform.
2.3 Website
Our website (authentikate.com) is served from Cloudflare Pages, not our Cloud Run backend. Cloudflare keeps standard access logs for the site — IP address, browser type, and pages accessed — retained for 30 days, and separately acts as our DNS and CDN provider, processing request metadata for security and performance purposes.
The Contact and Claim Your Name forms on this website collect the name and email address you provide, plus (Contact) your company and how we can help, or (Claim Your Name) the public name you're claiming and your relationship to it, along with any free-text message you add. Submissions are relayed as a single email to our team via the Resend API — they are not written to a database.
3. How We Use Your Information
3.1 AuthentiKate Verified — Figures
- To verify your identity and create your verified profile (contract performance; GDPR Art. 6(1)(b)).
- To enable you to generate verification codes and manage your account (contract performance).
- To process your subscription payment (contract performance).
- To send transactional notifications: code-generation confirmations, impersonation alerts, account security notices (contract performance and legitimate interests).
- To detect fraud and abuse, and to maintain audit records of privileged actions (legitimate interests; GDPR Art. 6(1)(f)).
- To comply with financial record-keeping obligations (legal obligation; GDPR Art. 6(1)(c)).
- To carry out liveness verification at account creation and during account recovery, and we may carry out liveness re-verification when other security events require it (legitimate interests and contract performance).
3.2 Website Visitors
- To serve web pages and maintain site security (legitimate interests).
We do not send unsolicited marketing emails. We do not run advertising on or around our services. We do not use your data to build advertising profiles or sell data to third parties.
4. Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA), we rely on the following legal bases under GDPR Article 6:
| Processing purpose | Legal basis |
|---|---|
| Creating and operating your verified figure account | Art. 6(1)(b) — Performance of contract |
| Identity verification (KYC) via Veriff | Art. 6(1)(b) — Performance of contract; Art. 6(1)(f) — Legitimate interests (preventing fraud and impersonation) |
| Payment processing via Stripe | Art. 6(1)(b) — Performance of contract |
| Sending transactional service emails | Art. 6(1)(b) — Performance of contract |
| Audit logging of privileged actions | Art. 6(1)(f) — Legitimate interests (fraud detection, security, legal defence) |
| Financial record retention (7 years) | Art. 6(1)(c) — Legal obligation |
| Security monitoring and anomaly detection | Art. 6(1)(f) — Legitimate interests (protecting users and the platform) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights — particularly because we collect the minimum data necessary for each purpose and implement strong privacy protections by design.
5. KYC and Identity Verification Data
Identity verification for AuthentiKate Verified is performed by Veriff, our third-party KYC provider. When you undergo verification:
- Veriff collects your government-issued photo ID and captures a liveness check (a brief selfie or video). This data is processed by Veriff under their own privacy policy and data processing agreement with us.
- We receive from Veriff only: verification status (pass/fail) and a vendor reference ID. We do not receive or store copies of your identity documents or raw biometric data.
- Veriff retains source documents in accordance with their data retention policies. We encourage you to review Veriff's privacy notice for details.
- KYC verification status on your account is retained for the lifetime of the account plus a reasonable run-off period. Once your account is deleted and any applicable retention period expires, your KYC metadata is redacted.
Liveness checks are triggered by Veriff only at specific security-event moments (initial verification and account recovery). They are not performed routinely.
6. Data Retention
We retain data only as long as necessary for the purpose for which it was collected, or as required by law. Key retention periods:
| Data type | Retention period |
|---|---|
| Figure account (User record) | Active account lifetime, then redacted on deletion request; shells retained for audit integrity |
| KYC metadata (status, reference ID) | Account lifetime; redacted on verified erasure request |
| KYC source documents and biometric data | Held by Veriff only — see Veriff's privacy notice |
| Subscription and payment records | 7 years post-final transaction (IRS and financial regulations) |
| Audit event log | 7 years |
| Verification events (anonymous records) | 90 days (aggregate counters retained indefinitely) |
| Active session data | 15–30 minutes (access token); 30 days (refresh token, rotated on use) |
| Device records | Account lifetime; purged on account deletion |
| Push notification delivery records | 30 days |
| Rate-limiting hashes (consumer app) | 24 hours maximum; ephemeral, never persisted to database |
| Device attestation credential (consumer app, iOS App Attest only) | What: a per-device cryptographic public key and a counter, generated by the iPhone's secure hardware. No name, no email, no IP address, no identifier that can be traced to a person. We do not store the device's token itself — only an irreversible hash of it; the token exists only on the phone. How long: automatically deleted no more than 90 days after the last time that device uses it. Deletion is enforced by the storage layer's own expiry, not by a manual process. Stored in Redis only — never written to our database. Never linked to your account, search query, or Verification record. Android's equivalent mechanism (Google Play Integrity) does not create a comparable stored credential — see §2.1. |
| Website server logs | 30 days |
Where an account is deleted, we redact personally identifiable information (name, email, and other PII are replaced with an anonymized tombstone record). Audit log rows remain to preserve the integrity of the event record but no longer resolve to identifiable individuals. This approach satisfies GDPR Article 17 and is consistent with the legitimate-interest exception under Article 17(3)(b) for fraud detection and legal defence. The retention periods above describe our live database; data removed from it can also persist for up to 7 days in encrypted database backups taken for disaster-recovery purposes, until that backup is rotated out.
7. How We Share Your Information
We share information only in these limited circumstances:
7.1 Subprocessors
We engage third-party service providers who process data on our behalf and are contractually bound to use it only for the purposes we specify. Our current subprocessors are:
| Provider | Purpose | Data processed |
|---|---|---|
| Google Cloud Platform (GCP) | Cloud hosting, database, secret management | All Verified account data in transit and at rest. Every request that reaches our backend, including from the consumer app, is also recorded in Cloud Run's platform request log, which includes the requester's IP address and the full request URL. |
| Veriff | KYC identity verification | Government ID documents, selfie/liveness data, verification outcomes |
| Stripe | Payment processing and subscription billing | Your name and email address (used to create your Stripe customer record), plus billing information. Card details are handled entirely by Stripe and never reach us; we store only the resulting Stripe customer ID. |
| Mercury | US banking (company operations only) | Company financial data; no end-user personal data |
| Cloudflare | DNS, CDN, DDoS protection, website hosting (Cloudflare Pages) | IP addresses and request metadata for security processing |
| Google Workspace | Internal company email and operations | Emails you send us; internal communications |
| Plain | Customer support platform | Name, email, and support conversation content |
| Resend | Transactional email delivery | Email address and message content for service notifications |
| Apple (App Attest) | Device integrity check on the consumer app (iOS) | Device attestation data confirming the request comes from a genuine, untampered copy of the app; runs on device-verify requests. Does not include the content of your search. |
| Google (Play Integrity) | Device integrity check on the consumer app (Android) | Device attestation data confirming the request comes from a genuine, untampered copy of the app; runs on device-verify requests. Does not include the content of your search. |
7.2 Business Transfers
If AuthentiKate is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will provide reasonable notice before your information is transferred and becomes subject to a different privacy policy.
7.3 Legal Requirements
We may disclose information if required to do so by applicable law, court order, or valid governmental request. Where legally permitted, we will notify you before disclosing.
7.4 Protection of Rights
We may disclose information when reasonably necessary to prevent fraud, enforce our Terms of Service, or protect the safety of users or the public.
8. International Data Transfers
AuthentiKate, Inc. is based in the United States. Our primary infrastructure operates on Google Cloud Platform in the US. If you are in the European Economic Area (EEA) and use AuthentiKate Verified, your personal data is transferred to the United States for processing.
We rely on the following transfer mechanisms for EEA-to-US transfers:
- Standard Contractual Clauses (SCCs): We have executed the European Commission's approved SCCs with our subprocessors who process EEA personal data (including GCP and Veriff). These clauses contractually require those processors to maintain GDPR-equivalent protections.
- Adequacy decisions: Where available and applicable.
You may request a copy of the relevant safeguards by contacting us at privacy@authentikate.com.
9. Your Privacy Rights
Your rights depend on where you are located. We honor all of the following regardless of which legal regime applies to you.
9.1 Rights Available to All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data. Some data must be retained for legal or audit-integrity reasons (see Section 6); we will explain any such limitations.
- Portability: Receive your data in a structured, machine-readable format.
- Opt out of communications: Unsubscribe from non-essential emails at any time.
A note on verified figures and on-device history: Your on-device verification history is a personal record of your own past interactions — it is not a live connection to a figure's current profile. If a figure updates their profile, is suspended, or has their account deleted, entries already stored on your device are not updated or removed to reflect that change; they remain a snapshot of the figure's status at the moment you verified them, similar to a dated receipt. Because this history lives solely on your device and we never receive it, we have no way to reach, alter, or delete it as part of a figure's data request.
9.2 Additional Rights Under GDPR (EEA Users)
- Restriction of processing: Request that we limit processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests where your particular circumstances warrant it.
- Withdraw consent: Where we rely on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: You have the right to lodge a complaint with your national data protection authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
9.3 California Residents (CCPA/CPRA)
California residents have the following rights under CCPA/CPRA:
- Right to Know: The categories and specific pieces of personal information we collect, the sources, the purposes, and the third parties with whom we share it.
- Right to Delete: Deletion of your personal information, subject to exceptions.
- Right to Correct: Correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: We do not sell personal information and do not share it for cross-context behavioral advertising. There is nothing to opt out of.
- Right to Limit Use of Sensitive Personal Information: We use sensitive information (including KYC data) only for the specific purposes for which it was collected. We do not use it for advertising or unrelated secondary purposes.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
California residents may also designate an authorized agent to make requests on their behalf.
9.4 Other US States
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws have similar rights to access, correction, deletion, portability, and opt-out of sale. Contact us to exercise these rights.
9.5 A Note for Consumer App Users
Because the consumer app does not collect personal information about you, there is generally no personal data for us to access, correct, or delete on your behalf. You control your on-device verification history directly in the app: the History screen lets you delete a single entry or clear all history at once, on both iOS and Android. Uninstalling the app also removes it. Clearing history in the app stops it from being included in any future device backup, but does not reach a copy already captured in a backup taken before you cleared it.
9.6 Exercising Your Rights
To exercise any of the above rights, contact us at privacy@authentikate.com. We will respond within 30 days (45 days with notice if additional time is required).
10. Data Security
We take security seriously, and the architecture of our platform reflects that:
- No passwords, ever. Authentication uses passkeys (WebAuthn/passkeys) tied to device hardware security (Secure Enclave on iOS, TEE on Android). There is no password to steal or phish.
- Human-cleared access. A passkey on its own does not get anyone in. Every credential is cleared over an in-person or video call with AuthentiKate staff before it can be used to sign in, and passkeys that sync across your own Apple or Google account carry that clearance with them. Nobody can self-serve their way onto an account.
- Encryption in transit and at rest. All data is encrypted in transit via TLS (managed by Google Cloud Run and Cloudflare) and at rest on Cloud SQL (Postgres).
- No consumer PII stored. The consumer verification surface stores no personally identifiable information — there is no consumer data to breach.
- Ephemeral rate-limiting only. Abuse prevention on the consumer surface uses salted hashes that expire within 24 hours and are never written to our persistent database.
- Immutable audit trail. Every privileged action on figure accounts is recorded in an append-only audit log. Once written, an audit record cannot be modified or deleted — enforced by the database itself, not by application permissions that could later be reassigned.
- Secret management. Credentials and secrets are managed via GCP Secret Manager; they are not stored in code or environment variables.
No system is completely secure. In the event of a data breach that affects your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
11. Children's Privacy
Our services are not directed to children. We do not knowingly collect personal information from:
- Children under 13 in the United States.
- Children under 16 in the European Economic Area.
If you believe we have inadvertently collected information from a child under the applicable age threshold, please contact us at privacy@authentikate.com and we will delete that information promptly.
The AuthentiKate Verified app requires identity verification through Veriff, which includes age verification. It is not accessible to minors.
12. Do Not Track
There is no widely accepted technical standard for "Do Not Track" browser signals. We do not respond to DNT signals. However, we do not engage in cross-site tracking of any kind, and the consumer app contains no tracking technology whatsoever.
13. Links to Third-Party Services
Our website and apps may contain links to third-party services (for example, social platforms associated with verified figures). This Privacy Policy does not apply to those services. We encourage you to review the privacy policies of any third-party services you use.
14. Enterprise and Business Use
Use of AuthentiKate by businesses, talent agencies, industry bodies, and enterprise customers is governed by separate agreements, which include applicable data processing addenda. If you are an enterprise customer or prospective partner, contact sales@authentikate.com.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the effective date at the top of this page.
- Notify AuthentiKate Verified users via email or in-app notification.
- Where required by law, obtain your consent before applying the change to your data.
We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes acceptance of the revised policy, to the extent permitted by law.
16. Contact
Privacy and data requests: privacy@authentikate.com
General inquiries: kate@authentikate.com
Mail: 8 The Green, STE R, Dover, DE 19901, USA
For users in the EEA, if you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your national supervisory authority. You may also contact us first so we have the opportunity to resolve the matter directly.