Documentation

Privacy

Privacy policy

Effective date: 17 June 2026

Operator: KNOWDYN LTD. Product: Ensan ID. Support: projects@knowdyn.co.uk. Security, abuse, and disputes: ipcontrol@knowdyn.co.uk.

Privacy principle

Ensan ID is designed to make public identity verification useful without becoming a private identity database.

The private `.ensan` capsule is created and controlled by the holder. Ensan ID does not require the private capsule to be uploaded during normal use.

Data we process

Ensan ID may process:

  • Public resolver data.
  • Ensan hash and public commitment.
  • Controller public key.
  • Selected self-declared public claims.
  • Public binding receipts.
  • GitHub and ORCID account identifiers needed for binding.
  • Hashed provider account identifiers where public hashing is configured.
  • DNS TXT and reciprocal-link challenge records.
  • Dispute and revocation records.
  • Admin audit records.
  • Operational security metadata such as timestamp, request context, hashed IP address, and hashed user-agent values.
  • Email and SMTP configuration entered by the operator during installation.

OAuth data

GitHub and ORCID OAuth are used to verify account-control bindings. OAuth access tokens are used to complete the callback and retrieve account identity needed for the binding. Ensan ID is designed not to store long-lived OAuth tokens by default.

Public data

Resolver pages, resolver JSON, binding JSON, selected declarations, and verified public binding receipts are intentionally public. They may be indexed by search engines, crawlers, AI systems, archives, and third-party verifiers.

Do not publish information in a resolver unless you intend it to be public.

Private capsule

Your private `.ensan` capsule may contain sensitive identity material. Keep it outside public upload paths. Ensan ID support will never ask for your private capsule, private key, passphrase, or recovery material.

Purposes

We process data to:

  • Publish public resolvers.
  • Verify public account-control and domain-control bindings.
  • Compute public trust status.
  • Provide resolver and verifier functionality.
  • Detect abuse, impersonation, and security threats.
  • Respond to disputes and support requests.
  • Maintain audit trails for system integrity.

Retention

Public resolver and binding data may remain available until revoked, suspended, deleted, or otherwise removed under operator policy. Audit records, dispute records, and security records may be retained as needed for operational integrity, fraud prevention, legal compliance, and abuse handling.

International context

The service is operated by KNOWDYN LTD and may involve users, infrastructure, counterparties, or disputes connected to the United Kingdom, the United States, Saudi Arabia, or other jurisdictions. Users are responsible for ensuring that their publication of public identity declarations complies with laws and obligations that apply to them.

Your choices

You may choose which claims to publish. You may revoke or hide supported bindings where the product flow allows. Hidden bindings should not count toward public trust level. Public resolver data may already have been indexed by third parties before removal.

Contact

Privacy, security, abuse, and dispute requests should be sent to ipcontrol@knowdyn.co.uk. General support requests should be sent to projects@knowdyn.co.uk.