Last updated: 30 August 2026
By using the Sealfie website, mobile applications, and your account, you agree that your data is processed according to this policy. This document complements our Terms of Service.
The Service is operated by Inkan.link SAS ("the Company"), a company incorporated under French law. Processing is subject to the General Data Protection Regulation (GDPR).
Your biometrics never leave your phone. The fingerprint or face recognition that unlocks Sealfie is processed by your operating system, inside the device's secure element (Secure Enclave on iPhone, StrongBox/TEE on Android). It only authorises the use of a cryptographic key that stays confined to that element and cannot be extracted from it. We never receive, process or store any biometric data, and a device without that secure element is refused rather than downgraded.
What we do collect: account identifiers (phone number, email); the photo taken at the moment of a verification, kept as a timestamped visual record attached to the file — we extract no template from it and run no facial recognition, identity being established by the signature of your device's key rather than by your face; technical device information (hardware fingerprint, used to detect a compromised or swapped device); and billing information necessary to pay for the subscription.
We never resell your data and never use it for advertising purposes.
To provide the Service, we rely on the following subprocessors, each limited to the data necessary for its role:
Supabase — database hosting, authentication, and server functions for the application. Processes account data and verification results.
Stripe, Inc. — subscription payment processing. Processes billing and card data; Sealfie does not store card numbers. Stripe, Inc. is established in the United States: this processing involves a transfer of data outside the European Union, governed by the contractual commitments in place with that provider.
ShareID — identity verification provider. It is involved at two specific points, and only those: when your account is created, for the initial identity check against an official document, and in organisations that have chosen the process configuration including a ShareID step. The everyday verification flow does not involve ShareID. The processing ShareID performs at those steps is described in its own privacy policy, available from them.
Processing of verification data is based on the performance of the contract between the Client company and Sealfie (providing the identity verification Service). Processing of billing data is based on the performance of the subscription contract. Processing of support requests is based on Sealfie's legitimate interest in resolving incidents and improving the Service.
Account data and the verification log are retained for the duration of the subscription, then archived as required by legal and accounting obligations. You may request deletion of your account at any time via support@sealf.ie.
Under the GDPR, you have the right to access, rectify, erase, object to the processing of, and port your data. To exercise these rights, write to the data protection officer: dpo@inkan.link. For questions about how the service works, support@sealf.ie remains the contact point.
You also have the right to lodge a complaint with the CNIL, the French supervisory authority (cnil.fr), or with your local authority.
We only disclose your data in response to a binding legal obligation from the competent French authorities, after reviewing the validity of the request.
This policy may be reviewed periodically. Users who have enabled notifications will be informed of substantial changes.
For any questions about this policy, contact: support@sealf.ie