1. Who We Are
AuthentiKate, Inc. ("AuthentiKate," "we," "us," or "our") is a Delaware C-corporation. We operate an anti-impersonation verification platform built on CKY (Customer Knows You): a system that allows people to confirm whether someone contacting them is genuinely who they claim to be, using a short-lived code only a verified figure can produce.
We operate two apps:
- AuthentiKate (the consumer app) — free, no account required. Used by the public to verify whether someone contacting them is a real, verified figure.
- AuthentiKate Verified (the figure app, $120/year) — used by public figures, brands, and their teams to generate verification codes, manage their verified profile, and receive impersonation alerts.
This policy also covers our website at authentikate.com. Business and enterprise use is governed by separate agreements.
Data Controller contact: privacy@authentikate.com
2. The Two Apps Have Very Different Data Profiles
2.1 AuthentiKate — Consumer App
When you use the consumer app:
- No account is created. You are not a registered user of our systems.
- Your search queries are not logged to a profile or stored in our database.
- Your verification history (which codes you entered, which figures you checked) is stored on-device only and is never transmitted to our servers.
- We receive the code you submit for validation and the claimed figure handle — these are processed in memory and the Verification record written contains only the figure's identifier, the outcome, and the claimed handle/platform. It contains no consumer identifier: no IP address, no device ID, no account reference.
- Abuse prevention uses short-lived, ephemeral rate-limiting checks that purge within 24 hours. These are never persisted to our database.
- We do not use any third-party analytics SDKs in this app.
- Impersonation reports you submit are fully anonymous — no reporter contact information is recorded.
In practical terms: we do not know who you are, and we have no way to find out from the data we hold.
2.2 AuthentiKate Verified — Figure App
This is where our substantive data-controller obligations arise. To become a verified figure, you must provide:
- Identity information: Your full name and email address.
- Government identity verification (KYC): A government-issued photo ID and a liveness/selfie check, processed by our identity verification provider Veriff. This data is collected and held by Veriff; we receive only the verification outcome and a vendor reference ID. We do not store copies of your ID documents or biometric data in our own systems.
- Social handles you declare: The external social media accounts you wish to associate with your verified profile (Instagram, X, Facebook, TikTok, Snapchat, Telegram, LinkedIn, Discord).
- Payment information: Billing details processed by Stripe. We store only your Stripe customer ID; we do not hold card numbers or bank details.
- Device and passkey data: Information about the registered devices you use to authenticate. Authentication uses passkeys (WebAuthn) — we never store passwords. Each device requires an in-person or video verification ceremony before it can access your account.
- Profile content: Display name, bio, avatar, any personalized signature or message shown to people who verify you.
- Team member information: If you add team members (managers, agents, publicists) to your account, we hold their name, email address, role, and KYC status.
- Communications with support: Messages you send us via our support platform.
2.3 Website
When you visit authentikate.com, our hosting infrastructure (Google Cloud Platform via Cloud Run) receives standard server logs including IP address, browser type, and pages accessed. Cloudflare acts as our DNS and CDN provider and processes request metadata for security and performance purposes. We use PostHog for product analytics on the website and Verified app; PostHog is configured to collect aggregate usage data only — we do not use it to build profiles of individual users on the consumer surface, and the consumer app does not include PostHog or any analytics SDK.
3. How We Use Your Information
3.1 AuthentiKate Verified — Figures
- To verify your identity and create your verified profile (contract performance; GDPR Art. 6(1)(b)).
- To enable you to generate verification codes and manage your account (contract performance).
- To process your subscription payment (contract performance).
- To send transactional notifications: code-generation confirmations, impersonation alerts, account security notices (contract performance and legitimate interests).
- To detect fraud and abuse, and to maintain audit records of privileged actions (legitimate interests; GDPR Art. 6(1)(f)).
- To comply with financial record-keeping obligations (legal obligation; GDPR Art. 6(1)(c)).
- To carry out liveness re-verification when security events require it — for example, after a biometric configuration change on a registered device (legitimate interests and contract performance).
3.2 Website Visitors
- To serve web pages and maintain site security (legitimate interests).
- To understand aggregate usage patterns in order to improve the site (legitimate interests).
We do not send unsolicited marketing emails. We do not run advertising on or around our services. We do not use your data to build advertising profiles or sell data to third parties.
4. Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA), we rely on the following legal bases under GDPR Article 6:
| Processing purpose | Legal basis |
|---|---|
| Creating and operating your verified figure account | Art. 6(1)(b) — Performance of contract |
| Identity verification (KYC) via Veriff | Art. 6(1)(b) — Performance of contract; Art. 6(1)(f) — Legitimate interests (preventing fraud and impersonation) |
| Payment processing via Stripe | Art. 6(1)(b) — Performance of contract |
| Sending transactional service emails | Art. 6(1)(b) — Performance of contract |
| Audit logging of privileged actions | Art. 6(1)(f) — Legitimate interests (fraud detection, security, legal defence) |
| Financial record retention (7 years) | Art. 6(1)(c) — Legal obligation |
| Site analytics (aggregate, no individual profiling) | Art. 6(1)(f) — Legitimate interests (improving the service) |
| Security monitoring and anomaly detection | Art. 6(1)(f) — Legitimate interests (protecting users and the platform) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights — particularly because we collect the minimum data necessary for each purpose and implement strong privacy protections by design.
5. KYC and Identity Verification Data
Identity verification for AuthentiKate Verified is performed by Veriff, our third-party KYC provider. When you undergo verification:
- Veriff collects your government-issued photo ID and captures a liveness check (a brief selfie or video). This data is processed by Veriff under their own privacy policy and data processing agreement with us.
- We receive from Veriff only: verification status (pass/fail) and a vendor reference ID. We do not receive or store copies of your identity documents or raw biometric data.
- Veriff retains source documents in accordance with their data retention policies. We encourage you to review Veriff's privacy notice for details.
- KYC verification status on your account is retained for the lifetime of the account plus a reasonable run-off period. Once your account is deleted and any applicable retention period expires, your KYC metadata is redacted.
Liveness checks are triggered by Veriff only at specific security-event moments (initial verification, account recovery, biometric configuration change on a device). They are not performed routinely.
6. Data Retention
We retain data only as long as necessary for the purpose for which it was collected, or as required by law. Key retention periods:
| Data type | Retention period |
|---|---|
| Figure account (User record) | Active account lifetime, then redacted on deletion request; shells retained for audit integrity |
| KYC metadata (status, reference ID) | Account lifetime; redacted on verified erasure request |
| KYC source documents and biometric data | Held by Veriff only — see Veriff's privacy notice |
| Subscription and payment records | 7 years post-final transaction (IRS and financial regulations) |
| Audit event log | 7 years (compressed cold storage after 12 months) |
| Verification events (anonymous records) | 90 days (aggregate counters retained indefinitely) |
| Active session data | 15–30 minutes (access token); 30 days (refresh token, rotated on use) |
| Device records | Account lifetime; purged on account deletion |
| Push notification delivery records | 30 days |
| Rate-limiting hashes (consumer app) | 24 hours maximum; ephemeral, never persisted to database |
| Website server logs | 90 days |
Where an account is deleted, we redact personally identifiable information (name, email, and other PII are replaced with an anonymized tombstone record). Audit log rows remain to preserve the integrity of the event record but no longer resolve to identifiable individuals. This approach satisfies GDPR Article 17 and is consistent with the legitimate-interest exception under Article 17(3)(b) for fraud detection and legal defence.
7. How We Share Your Information
We share information only in these limited circumstances:
7.1 Subprocessors
We engage third-party service providers who process data on our behalf and are contractually bound to use it only for the purposes we specify. Our current subprocessors are:
| Provider | Purpose | Data processed |
|---|---|---|
| Google Cloud Platform (GCP) | Cloud hosting, database, secret management | All Verified account data in transit and at rest; no consumer data |
| Veriff | KYC identity verification | Government ID documents, selfie/liveness data, verification outcomes |
| Stripe | Payment processing and subscription billing | Payment card details, billing information (we store only Stripe customer ID) |
| Mercury | US banking (company operations only) | Company financial data; no end-user personal data |
| Cloudflare | DNS, CDN, DDoS protection, Turnstile (bot prevention) | IP addresses and request metadata for security processing |
| Google Workspace | Internal company email and operations | Emails you send us; internal communications |
| Plain | Customer support platform | Name, email, and support conversation content |
| Resend | Transactional email delivery | Email address and message content for service notifications |
| PostHog | Product analytics (website and Verified app only) | Aggregate usage events; not used on consumer app; no individual profiling |
7.2 Business Transfers
If AuthentiKate is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will provide reasonable notice before your information is transferred and becomes subject to a different privacy policy.
7.3 Legal Requirements
We may disclose information if required to do so by applicable law, court order, or valid governmental request. Where legally permitted, we will notify you before disclosing.
7.4 Protection of Rights
We may disclose information when reasonably necessary to prevent fraud, enforce our Terms of Service, or protect the safety of users or the public.
8. International Data Transfers
AuthentiKate, Inc. is based in the United States. Our primary infrastructure operates on Google Cloud Platform in the US. If you are in the European Economic Area (EEA) and use AuthentiKate Verified, your personal data is transferred to the United States for processing.
We rely on the following transfer mechanisms for EEA-to-US transfers:
- Standard Contractual Clauses (SCCs): We have executed the European Commission's approved SCCs with our subprocessors who process EEA personal data (including GCP and Veriff). These clauses contractually require those processors to maintain GDPR-equivalent protections.
- Adequacy decisions: Where available and applicable.
You may request a copy of the relevant safeguards by contacting us at privacy@authentikate.com.
9. Your Privacy Rights
Your rights depend on where you are located. We honor all of the following regardless of which legal regime applies to you.
9.1 Rights Available to All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data. Some data must be retained for legal or audit-integrity reasons (see Section 6); we will explain any such limitations.
- Portability: Receive your data in a structured, machine-readable format.
- Opt out of communications: Unsubscribe from non-essential emails at any time.
9.2 Additional Rights Under GDPR (EEA Users)
- Restriction of processing: Request that we limit processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests where your particular circumstances warrant it.
- Withdraw consent: Where we rely on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: You have the right to lodge a complaint with your national data protection authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
9.3 California Residents (CCPA/CPRA)
California residents have the following rights under CCPA/CPRA:
- Right to Know: The categories and specific pieces of personal information we collect, the sources, the purposes, and the third parties with whom we share it.
- Right to Delete: Deletion of your personal information, subject to exceptions.
- Right to Correct: Correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: We do not sell personal information and do not share it for cross-context behavioral advertising. There is nothing to opt out of.
- Right to Limit Use of Sensitive Personal Information: We use sensitive information (including KYC data) only for the specific purposes for which it was collected. We do not use it for advertising or unrelated secondary purposes.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
California residents may also designate an authorized agent to make requests on their behalf.
9.4 Other US States
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws have similar rights to access, correction, deletion, portability, and opt-out of sale. Contact us to exercise these rights.
9.5 A Note for Consumer App Users
Because the consumer app does not collect personal information about you, there is generally no personal data for us to access, correct, or delete on your behalf. Your on-device verification history is controlled entirely by you through your device's app settings.
9.6 Exercising Your Rights
To exercise any of the above rights, contact us at privacy@authentikate.com. We will respond within 30 days (45 days with notice if additional time is required).
10. Data Security
We take security seriously, and the architecture of our platform reflects that:
- No passwords, ever. Authentication uses passkeys (WebAuthn/passkeys) tied to device hardware security (Secure Enclave on iOS, TEE on Android). There is no password to steal or phish.
- Device ceremony requirement. Every device must be individually verified through an in-person or video call with AuthentiKate before it can access a figure account — even if a passkey credential has been synced to it. This prevents unauthorized devices from gaining access.
- Encryption in transit and at rest. All data is encrypted in transit via TLS (managed by Google Cloud Run and Cloudflare) and at rest on Cloud SQL (Postgres).
- No consumer PII stored. The consumer verification surface stores no personally identifiable information — there is no consumer data to breach.
- Ephemeral rate-limiting only. Abuse prevention on the consumer surface uses salted hashes that expire within 24 hours and are never written to our persistent database.
- Immutable audit trail. Every privileged action on figure accounts is recorded in an append-only audit log. Application-layer database roles are denied UPDATE and DELETE permissions on this table.
- Secret management. Credentials and secrets are managed via GCP Secret Manager; they are not stored in code or environment variables.
No system is completely secure. In the event of a data breach that affects your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
11. Children's Privacy
Our services are not directed to children. We do not knowingly collect personal information from:
- Children under 13 in the United States.
- Children under 16 in the European Economic Area.
If you believe we have inadvertently collected information from a child under the applicable age threshold, please contact us at privacy@authentikate.com and we will delete that information promptly.
The AuthentiKate Verified app requires identity verification through Veriff, which includes age verification. It is not accessible to minors.
12. Do Not Track
There is no widely accepted technical standard for "Do Not Track" browser signals. We do not respond to DNT signals. However, we do not engage in cross-site tracking of any kind, and the consumer app contains no tracking technology whatsoever.
13. Links to Third-Party Services
Our website and apps may contain links to third-party services (for example, social platforms associated with verified figures). This Privacy Policy does not apply to those services. We encourage you to review the privacy policies of any third-party services you use.
14. Enterprise and Business Use
Use of AuthentiKate by businesses, talent agencies, industry bodies, and enterprise customers is governed by separate agreements, which include applicable data processing addenda. If you are an enterprise customer or prospective partner, contact sales@authentikate.com.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the effective date at the top of this page.
- Notify AuthentiKate Verified users via email or in-app notification.
- Where required by law, obtain your consent before applying the change to your data.
We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes acceptance of the revised policy, to the extent permitted by law.
16. Contact
Privacy and data requests: privacy@authentikate.com
General inquiries: kate@authentikate.com
Mail: 8 The Green, STE R, Dover, DE 19901, USA
For users in the EEA, if you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your national supervisory authority. You may also contact us first so we have the opportunity to resolve the matter directly.