Back to Home

PersonaBlocks Global Privacy Policy

Last updated: April 7, 2026

We at PersonaBlocks (Persona Blocks, referred to here as "we," "us," or "our") respect and protect the privacy of those who explore our Services ("Users") and Users who sign up for and access our Services ("Customers") (together referred to throughout this policy as "you" and "your").

This Privacy Policy describes how we collect, use, and share personal information when you explore, sign up for, or access our "Services," which include the services offered on our websites, including personablocks.io and app.personablocks.io (each a "Site" and collectively the "Sites"), or when you use the PersonaBlocks verification platform, customer portal, merchant portal, application programming interfaces ("APIs"), or third-party applications relying on such APIs (together, our "Apps") and related services.

By accessing and using our Services, you accept this Privacy Policy and its terms. It is important that you understand how we use your information. You should read this page in full, but below are the key highlights:

Key Highlights

Facts — What Does PersonaBlocks Do With Your Personal Information?

Why? Identity verification companies must collect and process personal information to verify your identity, comply with anti-money laundering (AML) and know-your-customer (KYC) regulations, and provide secure services. Federal and international laws require us to tell you how we collect, share, and protect your personal information.
What? The types of personal information we collect depend on the service you use. This information can include: government identification documents, biometric data (facial geometry), wallet addresses, device information, and sanctions screening results.
How? All identity verification platforms need to process personal information to operate. Below, we describe the reasons we collect your information, how we use it, and your choices regarding our use of your data.

Contents

1. What Information We Collect

We collect the following personal information and documentation:

Information You Provide to Us

When you sign up for or use our Services, you voluntarily provide us with certain personal information. This includes:

  • Identity verification data: Government-issued identification documents (e.g., passport, driver's license, national ID), selfie photographs for facial verification, and video recordings for liveness detection.
  • Extracted document data: Name, date of birth, document number, nationality, and other information parsed from your identification documents.
  • Biometric data: Facial geometry data extracted from your selfie and video, including 3D face reconstructions, used for identity verification and liveness detection.
  • Blockchain and wallet data: Ethereum/Polygon wallet addresses, cryptographic public keys derived from wallet signatures, and on-chain transaction data related to VIC creation and document storage.
  • Communications: Information you provide when you contact us for support, submit feedback, or otherwise communicate with us.
Information Collected Automatically

When you access or use our Services, we automatically collect certain information about your device and usage, including:

  • Device and technical data: Device fingerprint characteristics (canvas, WebGL, screen, and system attributes), IP address, browser type and version, operating system, device type, screen resolution, and language settings.
  • Usage data: Pages or screens viewed, time spent on pages, navigation paths, access times, and interactions with the Service.
  • Geolocation data: General location information inferred from your IP address, such as city, state, or country.
  • Cookies and similar technologies: Information collected through cookies, web beacons, and similar technologies as described in Section 6.
Information We Obtain from Third Parties

We may receive personal information about you from third-party sources, including:

  • Identity verification providers: Results from third-party identity verification services used to validate your documents and identity.
  • Sanctions and watchlist databases: Screening results from OFAC, United Nations, European Union, Canadian, and other international sanctions lists.
  • IP intelligence services: Fraud risk data, VPN/proxy detection, and IP reputation information.
  • Blockchain data: Publicly available on-chain data from the Polygon network related to your wallet address and transactions.
  • Merchant partners: Information provided by merchants who request identity verification on your behalf, including merchant-specific screening lists.

Sensitive Personal Information

Some of the personal information described above may be considered sensitive under applicable laws, including biometric data, government identification numbers, and precise geolocation. We do not use sensitive personal information for the purpose of inferring characteristics about you. We process sensitive personal information only as described in this Privacy Policy and for the specific purposes of identity verification, fraud prevention, and regulatory compliance.

2. How We Use Your Information

We use your personal information to deliver, operate, improve, and develop our Services, to provide you with a secure and efficient experience, and for legal compliance, loss prevention, and anti-fraud purposes. Below we describe our uses and the legal basis for each:

Data Use Necessary to Perform Our Contract with You
  • Verify your identity and create your Verifiable Identity Certificate (VIC)
  • Process your identification documents through our verification pipeline
  • Encrypt and store your identity documents on IPFS for your sovereign access
  • Register your VIC and document hashes on the Polygon blockchain
  • Facilitate identity verification requested by merchants you choose to transact with
  • Enable you to access, manage, and share your verified identity through the customer portal
  • Provide customer support and respond to your requests
Data Use to Comply with Our Legal Obligations
  • Perform sanctions screening against OFAC SDN, UN Security Council, EU Financial Sanctions, Canadian CASL, and other applicable watchlists
  • Generate and file Suspicious Activity Reports (SARs) with appropriate regulatory authorities when required
  • Fulfill anti-money laundering (AML) and know-your-customer (KYC) obligations
  • Respond to lawful requests from law enforcement and regulatory authorities
  • Maintain records as required by applicable financial regulations
Data Use for Our Legitimate Interests
  • Detect and prevent fraud through device fingerprinting, IP intelligence, and behavioral analysis
  • Protect the security and integrity of our platform and Services
  • Improve our verification processes, algorithms, and platform reliability
  • Analyze usage patterns to optimize the user experience
  • Enforce our terms of service and acceptable use policies
  • Develop new features and services
Data Use Based on Your Consent
  • Collect and process your biometric data for identity verification and liveness detection
  • Send you communications about our Services, updates, and relevant information
  • Share your verified identity data with merchants at your direction

To the extent the processing of your personal information is based on your consent, you may withdraw your consent at any time. The lawfulness of our processing before you withdraw your consent will not be affected by such withdrawal.

3. How and Why We Share Your Information

We work with service providers, partners, and other third parties to help us provide our Services. Here is how we share your information:

Third-Party Service Providers

We engage trusted third-party service providers to perform functions on our behalf, including:

Pinata / Filebase (IPFS Pinning)

Decentralized storage for encrypted documents. These services only receive encrypted data and cannot access your plaintext documents.

Polygon Network

Public blockchain for VIC registration, document registry, and access control. On-chain data is public and immutable by design.

Anthropic (Claude API)

AI-powered liveness and scene analysis during identity verification. Images are processed in-memory for analysis and are not retained by the provider after processing.

IP Intelligence Providers

VPN/proxy detection and IP reputation services used for fraud prevention. Only IP addresses and device metadata are shared.

Merchants and Business Partners

When you use our Services in connection with a merchant's verification request, we may share verification results and compliance reports with that merchant. Merchants access your encrypted identity documents only with your explicit consent and through the access control mechanisms governed by our smart contracts.

Merchants receive access to specific document types (e.g., selfie, government ID, compliance report) only when approved by you or as required for regulatory compliance.

Professional Advisors, Authorities, and Regulators
  • We may disclose your personal information to professional advisors (lawyers, auditors, insurers) where necessary in the course of the professional services they render to us.
  • We may disclose your personal information to law enforcement, government authorities, and regulators to comply with applicable laws, respond to lawful requests and legal process, or protect our rights, privacy, safety, or property.
  • When a sanctions match is identified with a confidence score of 0.85 or higher, we are required to file a Suspicious Activity Report (SAR) with the Financial Crimes Enforcement Network (FinCEN) or applicable regulatory authority.
Asset Transfer or Company Acquisition

If PersonaBlocks is involved in a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

Summary of Information Sharing

Reason for Sharing Does PersonaBlocks Share? Can You Limit?
To process your verification, maintain your VIC, and respond to legal obligations Yes No
For sanctions screening and AML compliance Yes No
For fraud prevention and platform security Yes No
With merchants at your direction Yes Yes
For marketing purposes No We don't share
For nonaffiliates to market to you No We don't share

4. How We Protect Your Personal Information

PersonaBlocks employs a sovereign encryption model designed to give you full control over your identity data. We implement reasonable technical and organizational safeguards to protect the information we hold, and we require our service providers to do the same.

However, security risk is inherent in all internet and information technologies, and we cannot guarantee the absolute security of your personal information.

5. How Long We Retain Your Personal Information

We retain your information as needed to provide our Services, comply with legal obligations, or protect our or others' interests. Retention requirements vary by data type and applicable regulations:

Data CategoryRetention PeriodBasis
Encrypted documents (IPFS) Indefinite — you control access through your wallet keys User sovereignty
Blockchain records (VIC, hashes) Permanent and immutable on the Polygon blockchain Blockchain architecture
Compliance records (sanctions, SARs) Minimum 5 years from creation AML/BSA regulations
Biometric data Retained in encrypted form for the period required by financial regulatory compliance Regulatory requirement
Device fingerprints Up to 2 years from collection Fraud prevention
Server and technical logs Up to 90 days Security monitoring
Audit trail and access logs Minimum 5 years Regulatory compliance

We may retain pseudonymized data (information with identifying details removed) to help us understand usage patterns and improve our Services. We delete information that is no longer needed for the above purposes when you close your account, when you request deletion, or as required under applicable law.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to facilitate the operation of our Services:

We do not use advertising cookies or share your information with third-party advertising networks. We do not engage in interest-based advertising.

Most browsers allow you to remove or reject cookies. Please note that if you disable cookies, certain features of the Service may not function properly.

7. Biometric Data Notice

We collect and process biometric information as part of our identity verification Services. This is an important notice about how we handle this sensitive data:

By proceeding with the identity verification process, you provide informed consent to the collection and processing of your biometric data for these specific purposes. You may withdraw your consent at any time by contacting us, though this may prevent you from using the verification Services.

8. Children's Personal Information

The Sites and Services are not directed to persons under the age of 18, and we do not knowingly request or collect any information about persons under the age of 18. If you are under the age of 18, please do not provide any personal information through the Sites or Services.

If a User or Customer submitting personal information is suspected of being younger than 18 years of age, PersonaBlocks will require the relevant User or Customer to cease using the Services and will take steps to delete the individual's information as soon as possible. If we learn that we have collected personal information from a child under 18, we will comply with applicable legal requirements to delete it. Parents or guardians with concerns should contact us at privacy@personablocks.io.

9. International Data Transfers

To facilitate our operations, PersonaBlocks and its third-party service providers may transfer, store, and process your personal information in the United States and other jurisdictions worldwide. Due to the decentralized nature of our infrastructure (IPFS, Polygon blockchain), your encrypted data may be replicated across nodes in multiple countries.

If you reside in the European Economic Area (EEA), Switzerland, or the United Kingdom, we rely upon appropriate legal mechanisms to facilitate international transfers of your personal data, including:

By using the Services, you acknowledge that your information may be transferred to jurisdictions that may have different data protection laws than your country of residence. We implement appropriate safeguards to protect your information regardless of where it is processed.

10. Your Privacy Rights and Choices

Depending on where you live, you may be able to exercise certain privacy rights related to your personal information. Requests can be made by contacting us at privacy@personablocks.io.

RightDescription
Access & Portability Request a copy of the personal information we hold about you. Your encrypted data on IPFS is inherently portable — you hold the decryption keys.
Rectification Request correction of inaccurate personal information held by PersonaBlocks.
Deletion / Erasure Request deletion of your personal information, subject to applicable law and legal retention requirements.
Withdraw Consent Withdraw your consent at any time. The lawfulness of processing before withdrawal will not be affected.
Object / Restrict Object to or restrict the processing of your personal information for certain purposes, including processing based on our legitimate interests.
Non-Discrimination We will not discriminate against you for exercising any of your privacy rights.
Lodge a Complaint If you reside in the EEA, Switzerland, or the UK, you have the right to lodge a complaint with your local data protection authority.

Important Notice Regarding Blockchain Data: Due to the immutable nature of blockchain technology, on-chain records — including VIC registrations, document hashes, and access control entries — cannot be deleted or modified once created. However, without your wallet's private key, the encrypted documents referenced by these on-chain records remain permanently inaccessible to any third party. This architecture is fundamental to the sovereign, user-controlled design of our Services.

To protect your privacy and security, we may take steps to verify your identity before complying with your request and we may decline your request if we are unable to verify your identity. These rights are not absolute and may be limited where required by applicable law.

11. Privacy Notice for United States Residents

California Residents

If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended) ("CCPA"):

We do not "sell" personal information as defined by the CCPA. We do not use or disclose sensitive personal information for purposes that California residents have a right to limit under the CCPA. We do not share personal information with third parties for interest-based advertising purposes.

To exercise your rights, email privacy@personablocks.io or write to PersonaBlocks, Attn: Privacy, at the address listed in Section 13. Under California law, you may designate an authorized agent to make requests on your behalf.

Nevada Residents

Certain Nevada consumers may opt out of the sale of "personally identifiable information" for monetary consideration as defined under Nevada law. We do not engage in such activity. However, if you are a Nevada resident, you may submit a request to opt out of any future sales by contacting us at privacy@personablocks.io.

12. Changes to This Privacy Policy

We may need to change this Privacy Policy from time to time as we improve our Services. We post any changes to this Privacy Policy on this page and, where appropriate, we will provide you with reasonable notice of any material changes before they take effect or as otherwise required by law. The date the Privacy Policy was last updated is identified at the top of this page.

We may provide additional "just-in-time" disclosures or information about how we collect or use your information in the context of specific Services; these in-product notices may supplement or clarify our privacy practices or provide you with additional choices about how we use your information.

13. How to Contact Us

If you have questions or concerns regarding this Privacy Policy, if you have a complaint, or if you wish to exercise your privacy rights, please contact us:

Persona Blocks

Email: privacy@personablocks.io

Website: https://www.personablocks.io

We take all complaints seriously and will respond within a reasonable time. If you reside in the EEA, Switzerland, or the UK, you also have the right to lodge a complaint with your local supervisory authority.