Legal

Privacy Policy

This policy explains the little we do handle, why, and the one thing about a blockchain that no privacy policy can change.

Last updated: Aug 13, 2026

Our approach: collect as little as possible

Mask.ID is built to need almost nothing from you. We do not require your real name, an email address, a phone number, a social login, or any identity documents. You can use a pseudonym — a made-up name is fine and encouraged. This policy explains the little we do handle, why, and the one thing about a blockchain that no privacy policy can change.

Two ideas run through everything below:

  1. We are responsible for the information we collect and store. We minimise it, and you can delete most of it.
  2. We are not the operator of the PIVX blockchain, and we never hold your keys. The blockchain is a public, permissionless ledger that no one controls. Your wallet keys live only on your device. Some information relates to you in places we do not control — and, importantly, you put it there by transacting or by choosing to link an identity.

1. Information you provide, that we store

This is the information under our control. You choose to give all of it.

What Why we have it Public?
Mask ID (your PIVX wallet address) Your account's identifier — you sign in with it, and it keys everything the app stores about you Yes — public on-chain (§4)
Display name Shown on your profile (any name — real or invented) Yes
Username / handle Your profile address on Mask.ID Yes
Bio / "About me" Free text you write about yourself Yes
Country, languages, time zone You self-select these; shown on your profile Yes
Profile & banner images Avatar and header you upload Yes
Linked social accounts Handles you connect (X, GitHub, Reddit, YouTube, Nostr…) Yes
Referrals given & received The trust graph — who vouches for whom See §5
Referral answers & private notes Your assessments when you vouch for someone No — §5
Preferred contact link An optional link to how you'd like to be reached Yes
Feedback you submit To answer and fix issues — includes any name or reply contact you add No
System notifications Short messages Mask.ID sends to your in-app inbox — nobody else can mail you here, and you can delete them any time No — only you
Connected Sites authorizations When you verify your Trust Index with a third-party site (§8), we record the site, your account identifier on that site, the reference code we minted for it, which data you approved, and your signed approval — so we can honor, enforce, and let you revoke that sharing. Revoking purges your account identifier and the signed approval; only the minimal record (site, approved data, dates) remains No

We store this so the service works. You can edit or delete it in your profile, and deleting your profile removes it (see §9).

2. What we deliberately do not collect

  • Your IP address is never stored and never written to our logs. We use it only for a moment, in memory, to rate-limit abuse — then it is gone. We do not keep it, and we do not use it to guess your location.
  • No email, phone number, real name, social login, or identity documents.
  • No third-party analytics or advertising trackers, and no tracking cookies. No third-party scripts load from other servers — everything runs from our own domain. The in-browser wallet uses the open-source PIVX wallet-kit, which we self-host; the only outside service it contacts is the PIVX explorer (see §8).
  • No location lookup. You tell us your country and time zone; we don't infer them.

3. Your keys, your seed, self-custody

Your identity on Mask.ID is your wallet. This is not something we manage for you — it is something you hold.

  • We never receive your private keys or recovery seed. They are generated and kept in your browser, on your device. This is by design: they are never transmitted to us, so we could not hand them over even if compelled.
  • We cannot recover your wallet, reset your access, or restore a lost profile. There is no “forgot password.” If you lose your recovery seed and your device, access to that Mask ID is gone.
  • You are responsible for backing up your recovery seed and keeping your device secure. Anyone with your seed, or with access to your unlocked device, can act as you.

4. Information recorded on public blockchains

Your Mask ID is a PIVX blockchain address. When you receive tips, send payments, or otherwise transact, those transactions are recorded on the public PIVX blockchain.

  • This data is public, permanent, and outside our control. We did not put it there — your own transactions did.
  • We cannot change, delete, hide, or erase anything recorded on a blockchain. No one can.
  • We may read public blockchain data to show balances and verify payments (see §8), but we do not store or mirror your transaction history.

If you want blockchain activity that isn't publicly linkable to your address, PIVX offers shielded (private) transactions. Linking a public social account to your address makes the connection durable — see §7.

5. How the trust graph and referrals work

Referrals (who vouches for whom): New referrals default to private. A private referral is hidden from the public trust graph and connection diagrams, and cannot be used to trace a connection path between people. You choose, per referral, whether to make it public. Either person in a relationship can keep it private — it only appears publicly if both leave it public.

Referral answers (your assessment of someone): When you vouch for someone, your individual answers and any private note are never shown to anyone — not even the person you're vouching for. They contribute only to an aggregate score, and only once a profile has at least 10 referrers, so no single person's answers can be inferred. Your answers are your own factual statements or honest opinions, and they are deleted if you revoke the referral or delete your profile.

Your private note on a referral goes further: it is encrypted on your device with a key only you hold (derived from your wallet), so we store only ciphertext and cannot read it — not for a subject request, not for a legal order, not at all. If you lose your recovery seed, your notes can't be recovered either (see §3).

6. Free-text fields and acceptable use

Bios, referral notes, and feedback are free text. Please don't include information you don't want stored or shown, other people's personal information, or sensitive details (health, religion, political views, and similar). If someone posts personal information about you, contact us at Contact@Mask.ID and we will remove it.

7. Linking your identities (and what it means)

Connecting a social account to your Mask ID is optional and member-initiated. Its purpose is to publicly link that identity to your Mask ID — that's the reputation you're building.

The verification statement you publish on the other platform contains only a one-time code, your @username, and your random short code — never your wallet address. The public tie between that account and your Mask ID lives on your Mask.ID profile, and deleting your profile removes it.

Be aware: a social account is tied to your permanent blockchain address. If you later want to break that link, the only complete way is to stop using the address entirely — move funds to a shielded address, delete your Mask.ID profile, and never reuse the same wallet, address, or recovery seed anywhere else. We show you this warning when you link an account. The “Show Connection Path” feature can reveal how two members are connected, using only public referral edges; private referrals are never traversed.

Your profile links. Your permanent share link is a random code (Mask.ID/i/…), not your wallet address — sharing it never reveals your address, and no one can find your profile from it. Separately, you may opt in to let people reach your profile from your Mask ID address (Mask.ID/a/…); this is off by default, and when on it only ever redirects to your public profile.

8. Services we read from and share with

We keep this list short. None of it involves selling your data, and anything that ever joins this list will follow the same rule.

  • PIVX blockchain explorer (explorer.pivx.org). Your browser queries it to display balances and confirm payments. This sends your (already public) address to that service. We do not send it anything else.
  • Nostr relays. To verify a linked Nostr identity or Vector status, Mask.ID reads public Nostr events (such as a published verification note or status) from public relays. Those events are public by nature and are not ours to control or delete. We do not read anyone's private messages.
  • Vector. When you submit feedback, we store the submission (listed in §1; kept for the period in §12) and also relay it to our team over Vector so we can respond. That includes any first name and reply contact (a platform and handle) you choose to add — both are optional, both are stored with the feedback, and both travel in the Vector message. New-member notifications include a display name and country. Vector states that its messages are end-to-end encrypted — so message content on relays is encrypted, not public. For how Vector itself handles your data, see Vector's own privacy policy at vectorapp.io/privacy-policy.

We do not sell your data, and we do not share it with advertisers.

Sharing you direct: verifying your Trust Index with other sites. You can prove your reputation to a third-party site through the “Verify Trust Index” flow. Only you can start it, you approve each category of data separately before anything is sent, and your wallet signs the approval. The site receives your Trust Index and the categories you approved — drawn from your profile and reputation, with sensitive quantities expressed as ranges, never exact amounts or dates — under a random reference code minted for that site alone. It never receives your Mask.ID username, profile, or wallet addresses, and no two sites can link their reference codes to each other. The full catalog of what can and can never be shared is published on the app's API page. You can revoke any site's access at any time in Settings → Connected Sites; it takes effect immediately for everything after that moment. One honest limit, in the same spirit as the rest of this policy: data already delivered to a site while your approval stood is that site's copy, governed by its privacy policy — revoking stops all future access but cannot recall it. Paying us never buys anyone access to anything you kept private.

9. Your rights

You can see and edit your profile information at any time in the app, and delete your profile — which removes your profile data, linked accounts, the referrals you gave and received, your uploaded images, and your notification inbox — including any Connected Sites authorizations (§8).

You can also revoke any third-party site's access to your Trust Index at any time, per site, in Settings → Connected Sites — no reason needed, effective immediately (§8).

One boundary, in the same spirit as the rest of this section: a notification already delivered to another member's inbox that happens to mention you (for example, “New referral from @your_name”) is their copy of something they were told at the time — like an email they received. Deleting your profile removes everything you hold, but does not rewrite other members’ inboxes.

The blockchain limit: deleting your Mask.ID profile removes what we hold. It cannot erase transactions already recorded on the public PIVX blockchain, data on public Nostr relays, or a link that others already observed. This is a property of public, decentralized systems, not a choice we make. Because identity on Mask.ID is proven by your wallet key, we may ask you to sign a message to verify a request. Where a request concerns information another member provided about you, we may provide it in aggregated form or without identifying the other member, to protect their privacy too. Region-specific rights are in §14.

10. Cookies and local storage

Mask.ID sets exactly one cookie: _mask_id_key, the session cookie.

  • It exists only to keep you signed in — session, authentication, and CSRF protection (blocking forged requests). Nothing in it tracks you, and it is never used for analytics or advertising.
  • It is tamper-proof (signed), unreadable by page scripts (HttpOnly), sent only to Mask.ID (SameSite), HTTPS-only, and expires after 90 days. Signing out invalidates it immediately, server-side.
  • There are no third-party cookies — our security policy prevents third-party scripts from loading at all.

Why there is no cookie banner: the EU ePrivacy rules require consent only for cookies that are not strictly necessary — tracking, analytics, advertising. A login/session cookie is the textbook “strictly necessary” cookie, explicitly exempt from the consent requirement. Virtually every site with a login sets one, banner or not. Few people know about the exemption, so to be clear: we name our one cookie out of transparency — having it without a consent banner is exactly what the law provides for. If we ever added a cookie that did require consent, we would ask first. We just don’t plan to have one.

  • Your wallet lives in your browser's local storage on your device — see §3. We never receive your private keys or recovery seed.

11. Children

Mask.ID is not intended for anyone under 18. We collect no date of birth and no identity documents, so we have no way to verify anyone's age — using Mask.ID is your representation that you meet the age requirement. If you believe a child is using Mask.ID, contact us at Contact@Mask.ID.

12. Retention

We keep profile information for as long as your profile exists. Feedback is kept for 12 months. Deleting your profile removes the data described in §9. Blockchain records and public relay data are permanent and outside our control.

Abandoned, never-used profiles are cleaned up automatically. A profile is deleted as abandoned only when it was never used at all: no sign-in for 90 days and nothing ever added (no linked accounts, referrals, tips, or images) and a zero wallet balance. Doing anything at all with your profile keeps it out of this cleanup, for as long as you like.

Connected Sites authorizations (§8) are kept while they stand. Revoking one immediately purges your account identifier on that site and your signed approval; the minimal record of the authorization (the site, what you approved, and when) is kept so the history in your Settings stays truthful. Deleting your profile removes it all.

Three things outlast a profile deletion: feedback you previously submitted isn't linked to your profile, so it isn't removed automatically — contact us to have it deleted; recent encrypted backups may still contain your data until they rotate out (12 months); and data already delivered to a Connected Site while your approval stood is that site's copy, under its own policy (§8).

13. Legal requests and law enforcement

If we receive a lawful, binding request, here is the honest picture of what we can and cannot provide:

  • We can be compelled to disclose the off-chain profile information we actually hold (§1) — for example, a profile's public fields.
  • We cannot provide what we do not have: your private keys or recovery seed (they never reach us — §3), and your IP address (we do not store it — §2).
  • We have no control over public systems. Blockchain transactions and public Nostr relay data are already public to everyone; we could not remove or alter them for anyone, including ourselves.

14. Your regional rights

Mask.ID is not incorporated — it is run directly rather than through a company, so nothing sits between you and the people accountable for your data. Requests reach us at Contact@Mask.ID. Which of the frameworks below formally binds us depends on where you live and where we operate from; rather than argue that line, we honour the rights described in all of them, for everyone. Once an operating entity is formed, it will be named here along with its governing jurisdiction.

European Economic Area / UK (GDPR): We process the data in §1 to provide the service (contract), to keep it safe from abuse (legitimate interest), and, for anything optional, with your consent. You have the right to access, correct, delete, restrict, object to, and port your data, and to lodge a complaint with your local supervisory authority. Note the blockchain and public-relay limits in §9 — for data outside our control, erasure is technically impossible, not withheld.

California (CCPA/CPRA): We do not sell your personal information and do not share it for cross-context behavioural advertising. You have the right to know what we hold, to delete it, and to correct it, and we will not discriminate against you for exercising those rights.

Brazil (LGPD): We process the minimum data described here, do not sell it, and honour access, correction, deletion, and portability requests.

15. Changes and contact

We'll post any changes here and update the date above. Questions, requests, or complaints: Contact@Mask.ID — that address reaches the people who run Mask.ID. There is currently no incorporated entity; once an operating entity is formed, it will be named here and this policy updated with its jurisdiction.

Free · No subscriptions · Reputation can’t be bought

Get your Mask.ID — free.

Create your Mask See a live profile

Contact Us

Or message the developer directly on Vector.