Last updated: April 7, 2026
We at PersonaBlocks (Persona Blocks, referred to here as "we," "us," or "our") respect and protect the privacy of those who explore our Services ("Users") and Users who sign up for and access our Services ("Customers") (together referred to throughout this policy as "you" and "your").
This Privacy Policy describes how we collect, use, and share personal information when you explore, sign up for, or access our "Services," which include the services offered on our websites, including personablocks.io and app.personablocks.io (each a "Site" and collectively the "Sites"), or when you use the PersonaBlocks verification platform, customer portal, merchant portal, application programming interfaces ("APIs"), or third-party applications relying on such APIs (together, our "Apps") and related services.
By accessing and using our Services, you accept this Privacy Policy and its terms. It is important that you understand how we use your information. You should read this page in full, but below are the key highlights:
Key Highlights
Facts — What Does PersonaBlocks Do With Your Personal Information?
We collect the following personal information and documentation:
When you sign up for or use our Services, you voluntarily provide us with certain personal information. This includes:
When you access or use our Services, we automatically collect certain information about your device and usage, including:
We may receive personal information about you from third-party sources, including:
Some of the personal information described above may be considered sensitive under applicable laws, including biometric data, government identification numbers, and precise geolocation. We do not use sensitive personal information for the purpose of inferring characteristics about you. We process sensitive personal information only as described in this Privacy Policy and for the specific purposes of identity verification, fraud prevention, and regulatory compliance.
We use your personal information to deliver, operate, improve, and develop our Services, to provide you with a secure and efficient experience, and for legal compliance, loss prevention, and anti-fraud purposes. Below we describe our uses and the legal basis for each:
To the extent the processing of your personal information is based on your consent, you may withdraw your consent at any time. The lawfulness of our processing before you withdraw your consent will not be affected by such withdrawal.
We work with service providers, partners, and other third parties to help us provide our Services. Here is how we share your information:
We engage trusted third-party service providers to perform functions on our behalf, including:
Pinata / Filebase (IPFS Pinning)
Decentralized storage for encrypted documents. These services only receive encrypted data and cannot access your plaintext documents.
Polygon Network
Public blockchain for VIC registration, document registry, and access control. On-chain data is public and immutable by design.
Anthropic (Claude API)
AI-powered liveness and scene analysis during identity verification. Images are processed in-memory for analysis and are not retained by the provider after processing.
IP Intelligence Providers
VPN/proxy detection and IP reputation services used for fraud prevention. Only IP addresses and device metadata are shared.
When you use our Services in connection with a merchant's verification request, we may share verification results and compliance reports with that merchant. Merchants access your encrypted identity documents only with your explicit consent and through the access control mechanisms governed by our smart contracts.
Merchants receive access to specific document types (e.g., selfie, government ID, compliance report) only when approved by you or as required for regulatory compliance.
If PersonaBlocks is involved in a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
| Reason for Sharing | Does PersonaBlocks Share? | Can You Limit? |
|---|---|---|
| To process your verification, maintain your VIC, and respond to legal obligations | Yes | No |
| For sanctions screening and AML compliance | Yes | No |
| For fraud prevention and platform security | Yes | No |
| With merchants at your direction | Yes | Yes |
| For marketing purposes | No | We don't share |
| For nonaffiliates to market to you | No | We don't share |
PersonaBlocks employs a sovereign encryption model designed to give you full control over your identity data. We implement reasonable technical and organizational safeguards to protect the information we hold, and we require our service providers to do the same.
However, security risk is inherent in all internet and information technologies, and we cannot guarantee the absolute security of your personal information.
We retain your information as needed to provide our Services, comply with legal obligations, or protect our or others' interests. Retention requirements vary by data type and applicable regulations:
| Data Category | Retention Period | Basis |
|---|---|---|
| Encrypted documents (IPFS) | Indefinite — you control access through your wallet keys | User sovereignty |
| Blockchain records (VIC, hashes) | Permanent and immutable on the Polygon blockchain | Blockchain architecture |
| Compliance records (sanctions, SARs) | Minimum 5 years from creation | AML/BSA regulations |
| Biometric data | Retained in encrypted form for the period required by financial regulatory compliance | Regulatory requirement |
| Device fingerprints | Up to 2 years from collection | Fraud prevention |
| Server and technical logs | Up to 90 days | Security monitoring |
| Audit trail and access logs | Minimum 5 years | Regulatory compliance |
We may retain pseudonymized data (information with identifying details removed) to help us understand usage patterns and improve our Services. We delete information that is no longer needed for the above purposes when you close your account, when you request deletion, or as required under applicable law.
We use cookies and similar technologies to facilitate the operation of our Services:
We do not use advertising cookies or share your information with third-party advertising networks. We do not engage in interest-based advertising.
Most browsers allow you to remove or reject cookies. Please note that if you disable cookies, certain features of the Service may not function properly.
We collect and process biometric information as part of our identity verification Services. This is an important notice about how we handle this sensitive data:
By proceeding with the identity verification process, you provide informed consent to the collection and processing of your biometric data for these specific purposes. You may withdraw your consent at any time by contacting us, though this may prevent you from using the verification Services.
The Sites and Services are not directed to persons under the age of 18, and we do not knowingly request or collect any information about persons under the age of 18. If you are under the age of 18, please do not provide any personal information through the Sites or Services.
If a User or Customer submitting personal information is suspected of being younger than 18 years of age, PersonaBlocks will require the relevant User or Customer to cease using the Services and will take steps to delete the individual's information as soon as possible. If we learn that we have collected personal information from a child under 18, we will comply with applicable legal requirements to delete it. Parents or guardians with concerns should contact us at privacy@personablocks.io.
To facilitate our operations, PersonaBlocks and its third-party service providers may transfer, store, and process your personal information in the United States and other jurisdictions worldwide. Due to the decentralized nature of our infrastructure (IPFS, Polygon blockchain), your encrypted data may be replicated across nodes in multiple countries.
If you reside in the European Economic Area (EEA), Switzerland, or the United Kingdom, we rely upon appropriate legal mechanisms to facilitate international transfers of your personal data, including:
By using the Services, you acknowledge that your information may be transferred to jurisdictions that may have different data protection laws than your country of residence. We implement appropriate safeguards to protect your information regardless of where it is processed.
Depending on where you live, you may be able to exercise certain privacy rights related to your personal information. Requests can be made by contacting us at privacy@personablocks.io.
| Right | Description |
|---|---|
| Access & Portability | Request a copy of the personal information we hold about you. Your encrypted data on IPFS is inherently portable — you hold the decryption keys. |
| Rectification | Request correction of inaccurate personal information held by PersonaBlocks. |
| Deletion / Erasure | Request deletion of your personal information, subject to applicable law and legal retention requirements. |
| Withdraw Consent | Withdraw your consent at any time. The lawfulness of processing before withdrawal will not be affected. |
| Object / Restrict | Object to or restrict the processing of your personal information for certain purposes, including processing based on our legitimate interests. |
| Non-Discrimination | We will not discriminate against you for exercising any of your privacy rights. |
| Lodge a Complaint | If you reside in the EEA, Switzerland, or the UK, you have the right to lodge a complaint with your local data protection authority. |
Important Notice Regarding Blockchain Data: Due to the immutable nature of blockchain technology, on-chain records — including VIC registrations, document hashes, and access control entries — cannot be deleted or modified once created. However, without your wallet's private key, the encrypted documents referenced by these on-chain records remain permanently inaccessible to any third party. This architecture is fundamental to the sovereign, user-controlled design of our Services.
To protect your privacy and security, we may take steps to verify your identity before complying with your request and we may decline your request if we are unable to verify your identity. These rights are not absolute and may be limited where required by applicable law.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended) ("CCPA"):
We do not "sell" personal information as defined by the CCPA. We do not use or disclose sensitive personal information for purposes that California residents have a right to limit under the CCPA. We do not share personal information with third parties for interest-based advertising purposes.
To exercise your rights, email privacy@personablocks.io or write to PersonaBlocks, Attn: Privacy, at the address listed in Section 13. Under California law, you may designate an authorized agent to make requests on your behalf.
Certain Nevada consumers may opt out of the sale of "personally identifiable information" for monetary consideration as defined under Nevada law. We do not engage in such activity. However, if you are a Nevada resident, you may submit a request to opt out of any future sales by contacting us at privacy@personablocks.io.
We may need to change this Privacy Policy from time to time as we improve our Services. We post any changes to this Privacy Policy on this page and, where appropriate, we will provide you with reasonable notice of any material changes before they take effect or as otherwise required by law. The date the Privacy Policy was last updated is identified at the top of this page.
We may provide additional "just-in-time" disclosures or information about how we collect or use your information in the context of specific Services; these in-product notices may supplement or clarify our privacy practices or provide you with additional choices about how we use your information.
If you have questions or concerns regarding this Privacy Policy, if you have a complaint, or if you wish to exercise your privacy rights, please contact us:
We take all complaints seriously and will respond within a reasonable time. If you reside in the EEA, Switzerland, or the UK, you also have the right to lodge a complaint with your local supervisory authority.