Privacy Policy
Last updated: June 27, 2026
TosiName provides verified digital identity services. This policy explains what we collect, why we collect it, and how we handle your information.
1. Data We Process
We process the following categories of data to provide the service:
- Account information, such as your email and authentication details.
- Identity verification information from KYC checks.
- Linked digital account handles, proof links, and Reveal Link activity.
- If you link an X account, we collect your X user ID, username/handle, display name, and profile image URL to prove account ownership and show the linked identity in TosiName.
- Basic security logs used to keep the service safe and prevent abuse.
2. Why We Process Data
- To create and secure your account.
- To verify legal identity and operate proof-of-human / proof-of-name features.
- To verify ownership of linked accounts such as X after you authorize the connection.
- To prevent fraud, abuse, and unauthorized access.
- To measure product usage and reliability (page views, time on page, and client errors).
- To comply with legal obligations.
3. Service Providers
We use trusted processors to deliver the service:
- Neon (authentication and database infrastructure)
- Didit (identity verification provider)
- Resend (transactional email delivery)
- Stripe (payments)
- PostHog (product analytics, with consent)
- Sentry (error and performance monitoring)
4. Identity Verification
TosiName provides verified identity links. To create or publish a verified identity link, we may require you to complete an identity verification process.
We use Didit as our identity verification provider. During this process, Didit may collect and process information such as your identity document, document data, selfie or liveness image, face match result, extracted legal name, country, IP address, device information, and other technical or fraud-prevention data.
TosiName does not store copies of your identity document, selfie, video, or biometric template. After a successful verification, TosiName stores only limited verification metadata needed to operate the service, such as your verification status, verified legal name, country, verification timestamp, identity verification provider, and provider session identifier.
Didit stores identity verification session data according to the retention setting configured by TosiName. We currently configure Didit's retention period to 6 months. After that period, Didit should delete the verification session data unless it is legally required to retain it for longer.
Identity verification may involve biometric data, such as facial data used for liveness detection and face matching. Where required by law, we ask for your explicit consent before this processing takes place.
Didit processes verification data on our behalf as a data processor. Didit may also process anonymized or pseudonymized data as an independent controller for fraud prevention, security, and improvement of its verification systems. You may request deletion of your TosiName account or verification data by contacting us.
5. International Data Transfers
Some of our service providers process data outside the European Economic Area. Didit states that identity verification data is primarily hosted within the EEA. Where non-EEA transfers do occur, they are governed by Standard Contractual Clauses approved by the European Commission or other recognized GDPR transfer mechanisms, which provide appropriate safeguards for your personal data.
6. Data Retention
We retain data only as long as needed for service operation, security, and legal compliance. Reveal Links are time-limited. When you close your account, access is immediately disabled and account data is scheduled for deletion after a 90-day retention period. During that period, processing is restricted to security, abuse prevention, fraud investigation, dispute handling, legal claims, accounting, and compliance purposes. We may retain limited records for longer where required by law or where necessary for the establishment, exercise, or defence of legal claims. We currently configure our identity verification provider (Didit) to retain verification session data for 6 months, after which Didit should delete the data unless legally required to retain it longer.
7. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Request export of your data
- Object to or restrict certain processing
8. Cookies and Analytics Consent
We use an analytics consent banner. If you accept, we store a consent cookie and collect limited product analytics through PostHog (such as visited pages, time spent, and key product events) to improve the service. We configure these analytics to reduce personal data exposure. If you reject, PostHog analytics collection is disabled.
We remember an accepted analytics choice for 6 months and a rejected analytics choice for 3 months. You can reopen cookie settings at any time here: .
We also use Sentry to monitor application reliability and diagnose technical failures (for example, crash and error reports). Sentry data is used for security and service operation.
9. Account Closure
You can close your account directly from the dashboard. When you close your account, we immediately disable access to the account and deactivate published proof URLs and Reveal Links. We then schedule account data for deletion after 90 days. During this retention period, we restrict processing to security, abuse prevention, fraud investigation, dispute handling, legal claims, accounting, and compliance. We may retain limited records for longer where required by law or where necessary for the establishment, exercise, or defence of legal claims.
We currently configure our identity verification provider (Didit) to retain verification session data for 6 months. After that period, Didit should delete the verification session data unless it is legally required to retain it for longer; TosiName does not control this retention.
10. Security
We use technical and organizational safeguards, including signature verification for identity verification callbacks, security headers, and abuse rate limiting. No system is perfectly secure, but we continuously improve controls.
11. Contact
For privacy requests, contact: privacy@tosiname.com
For security reports, contact: security@tosiname.com