Witness privacy policy
Effective 9 September 2026.
Witness proves that the video on a live call comes from a
specific enrolled camera belonging to a passport-verified person. Most of
what makes that work never leaves your machine. This page says what does,
who else touches it, and for how long we keep it.
Who we are
Witness is operated by Apertrue Ltd (staging), 124-128 City Road, London, England, EC1V 2NX
Privacy questions and requests: support@apertrue.photo.
A person reads these and answers.
The short version
- Your camera's fingerprint, the frames of your calls, your passport
and the face comparison all stay on your own devices. What reaches
us is proof, plus a small sealed picture of your face for the person
you are calling, which we cannot open.
- We hold your email address, the public half of your passkeys, a
pseudonymous identifier derived from your passport, the name your
passport states, and the labels your devices give themselves.
- Call records are sealed on disk. Their keys are destroyed after the
retention period below, so old server backups cannot open them.
Receipts already saved by a viewer or filed for a sponsor remain readable.
- We do not sell data, run advertising or profile anyone. There are
no analytics scripts on any page.
- You can export everything and delete your account from the account
page, without asking us.
What stays on your device
- Your camera's sensor fingerprint and the enrolment
derived from it are stored on your Mac and never transmitted. The
registry we run holds a cryptographic commitment to it, a Poseidon2
hash, which reveals nothing about the fingerprint.
- Every frame of your calls. Frames are checked on
your machine, inside the camera extension. No video or frames are
sent to us. The one image that leaves your Mac is the small picture
of your face described under Calls below, and it leaves sealed under
a key we never hold.
- Your face. When the face check is enabled for you,
the comparison between your passport photo and your camera runs on
your Mac. The photo and the measurements stay there.
- Your work sign-in. To prove a work address, the
Mac app signs you in with Google and turns the signed token into a
proof on your machine. The token, and the address inside it, never
reach us. We receive the domain after the @ and the proof.
What we hold, and why
Account
Your email address, the public half of each passkey and when it was
registered, and, if you use Google sign-in, the identifier Google gives us
for you. No passwords exist. Sign-in tokens are stored only as digests we
cannot reverse, and they expire after 30 days.
Identity
A passport-derived pseudonymous identifier (a nullifier), your name as
your passport states it, and commitments to your enrolled devices with the
labels they give themselves ("Jamie's MacBook Pro"). The name is the point
of the product: it is what a call's viewers see verified, and you choose on
each call whether to show it. We never see or store your passport document,
photo, number, date of birth or machine-readable zone; the check produces a
proof, the identifier and the disclosed name. The identifier is hashed per
organisation, so two organisations you verify with cannot correlate you.
Work address
If you prove a work address, we hold the domain of that address and a
proof that a valid Google-signed token for an address at that domain
existed when you proved it. Not the address, not the token. The domain is
shown on a call only when you choose to show it.
The face check
When enabled, the reference photo is read from your passport's chip by
your phone and sent to your Mac sealed to your Mac's key. It passes through
our server as ciphertext we cannot open, and is deleted the moment your Mac
collects it, or after 24 hours if it never does. On the service we hold a
digest of the document number and the outcome of the check as a short
status. The comparison and the photo stay on your Mac.
Organisations
If you create or join one: its name, your membership and role,
invitations (the invited address and status; invitation tokens are stored
as digests and expire after seven days), API key labels and digests, the
seat count, and the organisation's billing status and trial dates.
Sponsored verification
If an organisation invited you to verify your calls at its request, the
invitation says so before you accept. While the sponsorship is active we
file the receipt of each verified call you make, together with the
organisation's name and its stated reason, against that sponsorship for the
organisation to read and download. The organisation sees those receipts and
nothing else about your account. Your calls carry a line naming the sponsor
while it is active. Either side can end it at any time. We hold the
receipts for 90 days after it ends, then delete them.
Billing
Payments are handled by Stripe. We store your Stripe customer and
subscription identifiers, your plan, and any prepaid balance. Card details
never reach us. Stripe is a separate controller for payment data.
Email
Verification and notification mail is sent through Postmark. Message
content is limited to what the mail itself shows you.
Rooms
Rooms are off. Witness does not match meeting attendees or exchange picture
keys between Macs through rooms.
Calls
You need an account to start a call; the service keeps no call without an
account. When the last app using your camera lets go of it, Witness stops
showing your picture and holds the call for ten minutes, then shows it as
ended. Your next call has a new code. An overlapping handover between two
apps is not a camera break. If the camera stays on, Witness also pauses to
ask whether you are still on the same call, at least every hour.
A call's verification record contains checkpoints, proof receipts and any
identity claims you chose to share, but no video or sensor fingerprint.
Call records, their proof files and call-specific action rows are sealed at
rest under a separate key for each call. The service holds that key in
memory only; your Mac keeps its copy in its device-only keychain. The small
readable envelope includes an expiry rounded up to the hour, not exact call
times. After a restart the service needs the sender's Mac to unlock the
record; until then the page shows a generic reconnecting status.
Records are normally available for 24 hours after the call ends so viewers
can save receipts. The Mac destroys the key 24 hours after the latest of the
recorded end, the ten-minute hold deadline, or eleven minutes after its last
accepted post. The service's expiry is no later than that key deadline. Once
both copies of the key are gone, sealed records in server backups are
unreadable. This protects stored records, not against an operator of the live
service, which reads them in memory. The promise does not hold against
someone with both the sender's Mac and a backup of that Mac made while the
key still existed.
Sponsor receipt documents, members' last-call times and account-level
action rows are organisation records and stay readable on disk and in
backups. Sponsor receipts follow their separate retention period above;
ordinary action rows are kept for 24 hours, while an account's latest call
revocation marker remains to prevent old backups restoring stopped calls.
A viewer's browser keeps received receipts locally, including across reloads;
a saved receipt remains until its holder deletes it. Witness cannot erase
copies someone else saved.
The sealed picture
While a verified call runs, the camera extension cuts a small picture
of your face, 128 pixels square, from the very frames it checked, a few
times a second while a face is in frame. Each picture is encrypted on your
Mac under a key derived from the call's code, which we never hold, and
sent to us sealed. We keep the sealed pictures in memory only, never on
disk, for the most recent stretch of the call (about ten minutes), and
they are gone the moment the call ends or the service restarts. Only a
person holding the call's code or link can open them, in their own
browser; we cannot. Your Mac deletes each picture the moment it is sent
and discards any older than ninety seconds. The pictures exist so the
person you are calling can compare the face on their call with the face
your camera actually produced.
The call code
The twelve-letter code you read out is minted on your Mac and never
sent to us. We hold a one-way lookup derived from it, which finds the
call when the other person types the code at our address, and nothing
else: we cannot recover the code from it, and we cannot open a picture
with it. The other person's browser derives the picture key from the
code they typed, and the code never leaves their browser either.
Receipts you save
A saved call receipt is a file on your own device, or your
counterparty's. We do not hold it and cannot delete it. It is yours, or
theirs.
Transparency log
Enrolments, revocations and recoveries append entries to a public,
append-only log, so changes to identities cannot happen silently. Entries
are blinded: they contain no email, name or fingerprint. The log is
permanent by design; see deletion below.
Calendar
The Witness app reads your calendar on your machine to know when
meetings start. Event titles and attendees are processed locally and never
reach us.
Who else touches it
Our servers run in London. A short list of other companies process
data for us, each for one job: hosting, email, payments, and, on
deployments that switch it on, error reporting. The list, with what each
one receives and where it runs, is on the
sub-processors page. Nobody outside that
list receives anything, and we update it before adding a name, not
after.
Where error reporting is switched on, a report carries the error and
where in our own code it happened, the release, the browser or macOS
version, and a request identifier that matches a line in our logs. It
never carries your address, your IP address, anything about a call, any
link or any frame; a report whose text mentions any of those is discarded
rather than trimmed. Nothing is ever sent from the verification page.
Some of those companies process data outside the United Kingdom.
Where they do, the transfer rests on the mechanism their own data
processing terms state: the UK extension to the EU-US Data Privacy
Framework, or the UK's international data transfer addendum to the
standard contractual clauses.
What we do not do
We do not sell data, run advertising, build profiles, or move data
beyond what is listed here. There are no analytics or tracking scripts on
any Witness page. A counterparty checking your call gets a cryptographic
answer and the sealed picture, not your identity document. We receive
nothing from your meeting app: no meeting identifiers, no tokens from
Zoom, Meet or Teams, nothing about who else is on the call.
How long we keep things
Your rights, and how to use them without asking
- See and export everything we hold about your
account: the Export button on the account page produces a file.
- Delete your account from the account page. It
needs your passkey, not just a signed-in session.
- Withdraw from the face check by removing the
reference from your Mac; the digest and status on the service go
with your identity when it is deleted.
- Ask us anything else, including correction,
restriction or objection, at
support@apertrue.photo.
We answer within a month, as UK data protection law requires.
- Complain to the Information Commissioner's Office
(ico.org.uk) if you think we have handled your data wrongly. We
would rather hear it first, but that is your right either way.
Deletion, precisely
Deleting your account removes your email, passkeys, Google linkage,
sessions and billing linkage at once. The identity layer is severable by
design: deleting an account strands no cryptographic material and keeps no
link to who you were. Entries already published to the transparency log
are append-only and cannot be erased, but they are blinded and identify
nobody; an erasable integrity log would protect nobody. An organisation
you solely administer must first hand its admin role to someone else, or
dissolve if you are its only member, which happens automatically. Your
enrolment lives on your own Mac: uninstalling the app and the camera
extension removes it.
Changes
This page is dated at the top. When it changes in a way that matters,
we email account holders before the change takes effect. The page is kept
in the same repository as the code, so a change to what the service holds
and a change to this page happen together.