Your wallet keys stay on your phone
The private key behind your wallet is generated on the device, cannot be extracted from it, and is excluded from backups. We never hold it, so we cannot approve anything as you and cannot restore it for you.
Aegis ID
Privacy
Aegis ID exists so an organization can be certain who approved something. That needs less personal information than most systems, not more, and the parts that matter most never reach us at all.
Last updated 17 August 2026.
In short
The private key behind your wallet is generated on the device, cannot be extracted from it, and is excluded from backups. We never hold it, so we cannot approve anything as you and cannot restore it for you.
There is no analytics SDK in either wallet and no tracking on this site. Nothing about you is sold, shared for advertising, or used to build a profile.
Payments run through Stripe's own hosted checkout. Card numbers are entered on Stripe's page, not ours, and this application never sees or stores them.
An organization that issues you a credential sees that credential and the approvals it asked for. It does not see credentials from other organizations, or the list of who else you hold one from.
What is collected
There is no other category. If something is not on this list, it is not collected.
An email address, and a mobile number if you chose to give one. Both are entered by you, and both exist so an organization can address an invitation to the right person. The number is optional and only used if an organization sends an invitation by SMS.
A Wallet ID is generated for your device. It is an identifier rather than a secret — it names your wallet so a credential can be issued to it.
The public half of your device key, so a signature from your wallet can be checked. The private half never leaves the device.
Your email address, a display name, an optional phone number, and, unless your account is passwordless, a bcrypt hash of your password. The password itself is never stored.
Which sign-in methods you have enrolled, and for a passwordless account the hashes of your single-use recovery codes.
The credentials an organization issued you, and a record of each approval and decline: what was asked, when, and what you answered.
Both answers are recorded. A decline is a real answer and is kept the same way an approval is.
Actions that change who can do what — issuing, revoking, recovering, administering — are written to an append-only, hash-chained log so they cannot be quietly altered afterwards.
Values recognised as sensitive are replaced with
[redacted] before an entry is written. Codes, secrets and
credentials do not enter the log in the first place.
Request logs and error diagnostics, of the kind any web service keeps to stay running and to investigate a fault.
Where the wallet holds a passkey for another site, the key is generated on the device and is not extractable. Neither the key nor the list of sites it covers is sent to us.
Who else is involved
Nothing is sold, and nothing is shared for advertising. Data reaches somebody other than us in exactly these cases.
See what is held. Your wallet's Ledger tab shows your own history. Ask us or your administrator for the rest.
Correct it. Contact details are editable in the wallet and in your account.
Delete it. Ask the organization that issued to you, or contact support. A wallet that never held a credential is erased entirely. Where one did, the credential record and its evidence entries are kept — an audit trail that could be deleted on request would not be an audit trail, and it is what protects you in a dispute as much as it protects anybody else.
Withdraw. Declining a request is always available and is recorded as your answer.
Keeping it
Your wallet record and your credentials are kept while an organization still issues to you, and are removed on request afterwards.
Kept for as long as the organization they belong to needs them, because they are the record of who approved what. Revoking or deleting a wallet does not erase the trail — that is deliberate, and a revoked wallet is exactly the case where it matters.
Aegis ID is workplace software and is not directed at children. Accounts exist because an organization created one or invited somebody to hold a credential.
Material changes will be announced through the service before they take effect. This page always describes the version currently running.