Privacy Policy
HideID exists to reduce how much of your personal information is exposed online — so we collect as little as possible. By default your information stays on your device; the only exception is the optional connected checks described below.
Beta policy · Last updated June 2026
What HideID stores, and where
- On your device by default. The information you enter in the app — your email address, optional phone number, optional identity-profile details, your removal requests and their evidence log — is stored locally on your iPhone (in the iOS Keychain and app storage). It stays there unless you use the optional connected checks described below.
- How it's used. Your details are used to guide broker opt-out requests you submit yourself and, where available, to check exposure. They are not sold, shared, or used for advertising.
- Keychain note. Data saved in the iOS Keychain can persist across app reinstalls until you delete it (see Deletion below).
What leaves your device
- Broker opt-out forms. When you complete a removal, you submit the broker's own opt-out form on the broker's website. That submission goes to the broker, not to HideID.
- Feedback and support email. If you contact us or send beta feedback, your email goes to support@hideid.ai and includes only what you choose to write, plus app version and device model.
- TestFlight and Apple. During the beta, Apple's TestFlight may collect crash logs, usage statistics, and feedback you choose to share, under Apple's own terms and privacy policy.
Connected exposure checks (when enabled)
HideID offers optional connected exposure checks. They are off until you sign in (with Apple or Google) and start a check, and the app will always say whether they are connected. When you use them:
- What is sent: the email address you choose to check is sent to the HideID API, which queries the Have I Been Pwned (HIBP) breach database on your behalf. The HIBP access key lives only on our servers — never in the app.
- What is stored: your checked email is stored encrypted (AES-256), together with scan results (breach names and dates). Scan records contain no other personal information.
- What is never claimed: if a check could not run, the app says so — it never reports a "clean" result it didn't verify.
- Deletion: Delete My Data in the app removes server-side records too, including your account, encrypted identifiers, and scan history.
Ongoing monitoring (periodic automatic re-checks of your email against new breaches, with an alert if something new is found) builds on the same connected-checks data and may not be active for everyone yet; this policy will be updated before any new type of data is stored. Until you use connected checks, no HideID server stores your personal data.
Analytics
The beta does not send analytics to any third-party provider. Event logging exists only in development builds and never includes personal information.
Deletion
Use Delete My Data in the app (Settings) to permanently erase everything HideID stores on your device, including Keychain entries. Because data is local-first, deletion is immediate and complete.
Contact
Questions about this policy: support@hideid.ai