Privacy Policy
Last updated October 7, 2026
Who we are
GenID Protocol is operated by DealDily (“GenID,” “we,” “us”). This policy covers the GenID website, the API, and the browser extension.
What we collect
Account & identity. Your name and email address, and the result of Stripe Identity verification (government ID + selfie). Stripe handles the document and selfie images directly — we store only the verification outcome and Stripe's own session identifiers, never the ID document or selfie image itself.
Content you certify. Images you generate, upload, or edit through GenID, plus the metadata that makes up a certificate: timestamps, prompts, edit history, cryptographic hashes and signatures, and (if anchored) a Polygon blockchain transaction.
Cookies. Only what's required to keep you signed in and to protect forms from forgery — a session cookie and a CSRF token. Neither is used for tracking or analytics, and GenID does not run any analytics or advertising scripts today. Because these cookies are strictly necessary for the service to function, they don't require a cookie-consent banner under GDPR/ePrivacy — we still disclose them here for clarity.
API keys. If you generate a developer API key, we store a cryptographic hash of it, never the raw key — the raw value is shown to you once and can't be retrieved again, only revoked.
How we use it
To run the certification pipeline (hash-chaining, C2PA/CAWG manifest embedding, Polygon anchoring, certificate generation), to verify your identity once at registration, to send you sign-in and registration emails, and to enforce fair-use rate limits.
Text prompts for GenID's own image-generation step are sent to OpenAI to produce the image. Images you upload or that come from an external tool are never sent to OpenAI or any other model provider — they go directly into the certification pipeline.
Who we share it with
We use a small number of subprocessors to run the product — see the full list, with what each one receives, at /subprocessors. We don't sell your data, and we don't share it with anyone else for their own marketing purposes.
The blockchain anchor is public and permanent
When a session is anchored on Polygon, the transaction — including the session's root hash — becomes part of a public, permanent blockchain record outside our control. It does not contain your name, email, or the image itself, only a cryptographic digest. We cannot remove it, including after an account deletion request (see “Your rights” below).
How long we keep it
Session and certificate records are kept indefinitely by default, since a certificate is meant to remain independently verifiable by anyone, indefinitely. Full-resolution images for steps you didn't select as final are compressed shortly after a session is finalized; the final/certified image and the certificate itself stay full-resolution.
Your rights
Export. Download a full copy of your account's data — sessions, steps, certificates, stamp history — any time from your dashboard.
Deletion. You can delete your account from the same dashboard. This deletes any session you never finalized (including its stored images), revokes your API keys, and clears your name and email from our records. It does not delete the hash-chain records or stored images behind a session you already finalized: a finalized certificate is a proof third parties may already be relying on, and because our verification check re-hashes the stored file to confirm it hasn't been tampered with, removing that file would make a legitimate certificate incorrectly report as tampered rather than simply unavailable. If you need a finalized certificate's image removed for a specific reason, contact us at the address below and we'll work through it with you individually. Nothing we delete or anonymize can be removed from the Polygon blockchain — see above.
These map to the data access and erasure rights available under GDPR, CCPA, and similar laws, regardless of where you're located.
Children
GenID requires government ID verification to register, so the service isn't directed at or knowingly used by children.
International transfers
Our subprocessors (listed at /subprocessors) are primarily US-based. If you're accessing GenID from outside the US, your data is transferred to and processed in the US.
Changes to this policy
We'll update the date at the top of this page when this policy changes, and post the new version here.
Contact
Questions or a privacy request: privacy@genid.app