Witness privacy policy

Effective 9 September 2026.

Witness proves that the video on a live call comes from a specific enrolled camera belonging to a passport-verified person. Most of what makes that work never leaves your machine. This page says what does, who else touches it, and for how long we keep it.

Who we are

Witness is operated by Apertrue Ltd (staging), 124-128 City Road, London, England, EC1V 2NX

Privacy questions and requests: support@apertrue.photo. A person reads these and answers.

The short version

What stays on your device

What we hold, and why

Account

Your email address, the public half of each passkey and when it was registered, and, if you use Google sign-in, the identifier Google gives us for you. No passwords exist. Sign-in tokens are stored only as digests we cannot reverse, and they expire after 30 days.

Identity

A passport-derived pseudonymous identifier (a nullifier), your name as your passport states it, and commitments to your enrolled devices with the labels they give themselves ("Jamie's MacBook Pro"). The name is the point of the product: it is what a call's viewers see verified, and you choose on each call whether to show it. We never see or store your passport document, photo, number, date of birth or machine-readable zone; the check produces a proof, the identifier and the disclosed name. The identifier is hashed per organisation, so two organisations you verify with cannot correlate you.

Work address

If you prove a work address, we hold the domain of that address and a proof that a valid Google-signed token for an address at that domain existed when you proved it. Not the address, not the token. The domain is shown on a call only when you choose to show it.

The face check

When enabled, the reference photo is read from your passport's chip by your phone and sent to your Mac sealed to your Mac's key. It passes through our server as ciphertext we cannot open, and is deleted the moment your Mac collects it, or after 24 hours if it never does. On the service we hold a digest of the document number and the outcome of the check as a short status. The comparison and the photo stay on your Mac.

Organisations

If you create or join one: its name, your membership and role, invitations (the invited address and status; invitation tokens are stored as digests and expire after seven days), API key labels and digests, the seat count, and the organisation's billing status and trial dates.

Sponsored verification

If an organisation invited you to verify your calls at its request, the invitation says so before you accept. While the sponsorship is active we file the receipt of each verified call you make, together with the organisation's name and its stated reason, against that sponsorship for the organisation to read and download. The organisation sees those receipts and nothing else about your account. Your calls carry a line naming the sponsor while it is active. Either side can end it at any time. We hold the receipts for 90 days after it ends, then delete them.

Billing

Payments are handled by Stripe. We store your Stripe customer and subscription identifiers, your plan, and any prepaid balance. Card details never reach us. Stripe is a separate controller for payment data.

Email

Verification and notification mail is sent through Postmark. Message content is limited to what the mail itself shows you.

Rooms

Rooms are off. Witness does not match meeting attendees or exchange picture keys between Macs through rooms.

Calls

You need an account to start a call; the service keeps no call without an account. When the last app using your camera lets go of it, Witness stops showing your picture and holds the call for ten minutes, then shows it as ended. Your next call has a new code. An overlapping handover between two apps is not a camera break. If the camera stays on, Witness also pauses to ask whether you are still on the same call, at least every hour.

A call's verification record contains checkpoints, proof receipts and any identity claims you chose to share, but no video or sensor fingerprint. Call records, their proof files and call-specific action rows are sealed at rest under a separate key for each call. The service holds that key in memory only; your Mac keeps its copy in its device-only keychain. The small readable envelope includes an expiry rounded up to the hour, not exact call times. After a restart the service needs the sender's Mac to unlock the record; until then the page shows a generic reconnecting status.

Records are normally available for 24 hours after the call ends so viewers can save receipts. The Mac destroys the key 24 hours after the latest of the recorded end, the ten-minute hold deadline, or eleven minutes after its last accepted post. The service's expiry is no later than that key deadline. Once both copies of the key are gone, sealed records in server backups are unreadable. This protects stored records, not against an operator of the live service, which reads them in memory. The promise does not hold against someone with both the sender's Mac and a backup of that Mac made while the key still existed.

Sponsor receipt documents, members' last-call times and account-level action rows are organisation records and stay readable on disk and in backups. Sponsor receipts follow their separate retention period above; ordinary action rows are kept for 24 hours, while an account's latest call revocation marker remains to prevent old backups restoring stopped calls. A viewer's browser keeps received receipts locally, including across reloads; a saved receipt remains until its holder deletes it. Witness cannot erase copies someone else saved.

The sealed picture

While a verified call runs, the camera extension cuts a small picture of your face, 128 pixels square, from the very frames it checked, a few times a second while a face is in frame. Each picture is encrypted on your Mac under a key derived from the call's code, which we never hold, and sent to us sealed. We keep the sealed pictures in memory only, never on disk, for the most recent stretch of the call (about ten minutes), and they are gone the moment the call ends or the service restarts. Only a person holding the call's code or link can open them, in their own browser; we cannot. Your Mac deletes each picture the moment it is sent and discards any older than ninety seconds. The pictures exist so the person you are calling can compare the face on their call with the face your camera actually produced.

The call code

The twelve-letter code you read out is minted on your Mac and never sent to us. We hold a one-way lookup derived from it, which finds the call when the other person types the code at our address, and nothing else: we cannot recover the code from it, and we cannot open a picture with it. The other person's browser derives the picture key from the code they typed, and the code never leaves their browser either.

Receipts you save

A saved call receipt is a file on your own device, or your counterparty's. We do not hold it and cannot delete it. It is yours, or theirs.

Transparency log

Enrolments, revocations and recoveries append entries to a public, append-only log, so changes to identities cannot happen silently. Entries are blinded: they contain no email, name or fingerprint. The log is permanent by design; see deletion below.

Calendar

The Witness app reads your calendar on your machine to know when meetings start. Event titles and attendees are processed locally and never reach us.

Who else touches it

Our servers run in London. A short list of other companies process data for us, each for one job: hosting, email, payments, and, on deployments that switch it on, error reporting. The list, with what each one receives and where it runs, is on the sub-processors page. Nobody outside that list receives anything, and we update it before adding a name, not after.

Where error reporting is switched on, a report carries the error and where in our own code it happened, the release, the browser or macOS version, and a request identifier that matches a line in our logs. It never carries your address, your IP address, anything about a call, any link or any frame; a report whose text mentions any of those is discarded rather than trimmed. Nothing is ever sent from the verification page.

Some of those companies process data outside the United Kingdom. Where they do, the transfer rests on the mechanism their own data processing terms state: the UK extension to the EU-US Data Privacy Framework, or the UK's international data transfer addendum to the standard contractual clauses.

What we do not do

We do not sell data, run advertising, build profiles, or move data beyond what is listed here. There are no analytics or tracking scripts on any Witness page. A counterparty checking your call gets a cryptographic answer and the sealed picture, not your identity document. We receive nothing from your meeting app: no meeting identifiers, no tokens from Zoom, Meet or Teams, nothing about who else is on the call.

How long we keep things

WhatHow long
Account, passkeys, identity, devices, organisation membership Until you delete them
Sign-in sessions30 days, or until you sign out
Sealed call records, proof files and call action rows Normally 24 hours after the call ends; key deadline and backup limits above
Members' last-call times and account-level action rows Readable organisation records; action rows 24 hours, latest call revocation marker retained
Sponsored-call receipts held for the sponsor 90 days after the sponsorship ends
Organisation invitations7 days, or until accepted
Face reference in transit, as ciphertext Until your Mac collects it, and at most 24 hours
Sealed pictures, as ciphertext we cannot open In memory only, the most recent stretch of the call; gone when the call ends or the service restarts
Transparency log entriesPermanent, and blinded

Your rights, and how to use them without asking

Deletion, precisely

Deleting your account removes your email, passkeys, Google linkage, sessions and billing linkage at once. The identity layer is severable by design: deleting an account strands no cryptographic material and keeps no link to who you were. Entries already published to the transparency log are append-only and cannot be erased, but they are blinded and identify nobody; an erasable integrity log would protect nobody. An organisation you solely administer must first hand its admin role to someone else, or dissolve if you are its only member, which happens automatically. Your enrolment lives on your own Mac: uninstalling the app and the camera extension removes it.

Changes

This page is dated at the top. When it changes in a way that matters, we email account holders before the change takes effect. The page is kept in the same repository as the code, so a change to what the service holds and a change to this page happen together.