How we built privacy into the Yoti app

profile picture Yoti 4 min read

Just as the right to identity is a fundamental human right, we believe privacy is too. 

Yoti was built to give everybody a simple and secure way of proving and protecting their identity, online and in person. 

With the free Yoti app, you can create a digital ID that allows you to prove who you are in the most privacy-friendly way. It is built with data minimisation at the core and allows you to share less data to prove your identity or age. You’re in control to show only the details you need, to the businesses and people you trust. 

 

First things first

We don’t have your ID document details unless you have chosen to add them to your account. This is totally your choice. If you don’t add your ID document, you can use other features on the app such as our password manager or get an estimated age, but you do not have a digital ID.

We make sure it’s really you

When registering your account, we ask you to take a quick video to prove you’re a real human being. If you want to create a digital ID, you can upload a government-issued ID document. This is either checked automatically or sent to our team of identity verification specialists. They check your document is real and that the photo matches up with the image from your video and the information taken from your document. 

This is called a liveness test and is where we ask you to move your face according to instructions on the screen. If this test fails, you may be asked to say a few words so we can confirm you’re a real person.

We double check that you’re the one calling the shots

From your liveness test, we create a digital map of your face and encrypt it.

When we need extra confirmation that it’s you, we ask you to take a seflie, which we compare to this original image. 

We let you share less data

Unlike a physical ID document, we store your personal information as individual pieces of data. We call these attributes – individual pieces of information that identify you as you, such as your name, date of birth etc. 

By storing these attributes separately, you can share just the information required for a transaction, rather than revealing your whole identity.

If you need to prove your age, you can share the fact that you’re over 18 and nothing else.

 

Only you hold the key

When you unlock your app, you activate your master encryption key. This master key is stored on your phone and is the only way of pulling together your attributes and turning them into readable text. Yoti also encrypts your master key for extra security.

 

We use advanced biometric technology to keep you safe

We use biometric (and non-biometric) technologies to carry out anti-spoofing, fraud prevention and security checks. This is the most effective way of verifying that you are a real person and that you’re setting up a genuine digital identity. It allows us to keep our users safe and make sure that only genuine identities are on our platform.

 

We’re clear and transparent

We tell you what we’re doing and why in the app, in our privacy policy and in FAQs. Our customer support team are also incredibly friendly and super speedy at replying so you can get in touch at any point if you need any help.

 

You can always opt out

Our research and development (R&D) team use some user data to develop, test and improve our age estimation technology and our anti-spoofing, fraud prevention and security checks. We do this to keep our community safe but if you are not comfortable with this, you have the option to opt out in the app.

Go ID-free

We’ve also built age estimation technology so you don’t even need an ID document to have an estimated age on your account. This technology can be used to allow anonymous proof of age in situations such as buying age-restricted goods at self-checkouts or proving you are over a certain age to access age-restricted content online. For all the technical bits, take a read of our whitepaper.