Privacy

What we collect, and what never leaves your device.

Aegis ID exists so an organization can be certain who approved something. That needs less personal information than most systems, not more, and the parts that matter most never reach us at all.

Last updated 17 August 2026.

In short

The version that fits on one screen.

Your wallet keys stay on your phone

The private key behind your wallet is generated on the device, cannot be extracted from it, and is excluded from backups. We never hold it, so we cannot approve anything as you and cannot restore it for you.

No analytics, no tracking, no advertising

There is no analytics SDK in either wallet and no tracking on this site. Nothing about you is sold, shared for advertising, or used to build a profile.

Card details never reach us

Payments run through Stripe's own hosted checkout. Card numbers are entered on Stripe's page, not ours, and this application never sees or stores them.

Your organization sees its own work

An organization that issues you a credential sees that credential and the approvals it asked for. It does not see credentials from other organizations, or the list of who else you hold one from.

What is collected

Everything held, and why.

There is no other category. If something is not on this list, it is not collected.

In the wallet

An email address, and a mobile number if you chose to give one. Both are entered by you, and both exist so an organization can address an invitation to the right person. The number is optional and only used if an organization sends an invitation by SMS.

A Wallet ID is generated for your device. It is an identifier rather than a secret — it names your wallet so a credential can be issued to it.

The public half of your device key, so a signature from your wallet can be checked. The private half never leaves the device.

If you have an account on this site

Your email address, a display name, an optional phone number, and, unless your account is passwordless, a bcrypt hash of your password. The password itself is never stored.

Which sign-in methods you have enrolled, and for a passwordless account the hashes of your single-use recovery codes.

Credentials and approvals

The credentials an organization issued you, and a record of each approval and decline: what was asked, when, and what you answered.

Both answers are recorded. A decline is a real answer and is kept the same way an approval is.

The evidence chain

Actions that change who can do what — issuing, revoking, recovering, administering — are written to an append-only, hash-chained log so they cannot be quietly altered afterwards.

Values recognised as sensitive are replaced with [redacted] before an entry is written. Codes, secrets and credentials do not enter the log in the first place.

Ordinary server logs

Request logs and error diagnostics, of the kind any web service keeps to stay running and to investigate a fault.

Passkeys, if you use them

Where the wallet holds a passkey for another site, the key is generated on the device and is not extractable. Neither the key nor the list of sites it covers is sent to us.

Who else is involved

Where data goes.

Nothing is sold, and nothing is shared for advertising. Data reaches somebody other than us in exactly these cases.

  • The organization that issued your credential. It sees what it issued and the approvals it asked for.
  • Microsoft Azure, which hosts the service. Data is held in the region the deployment runs in.
  • Stripe, for subscription payments. Stripe handles card details directly; we hold a customer reference and the status of a subscription.
  • An email or SMS provider, configured by whoever runs this deployment, to deliver sign-in codes, invitations and recovery links.
  • Your own identity provider, if your organization signs you in through one. Aegis links an existing account; it never creates one from an upstream sign-in.
  • Anybody a law requires, where we are obliged to respond to a valid legal demand.

Your choices

See what is held. Your wallet's Ledger tab shows your own history. Ask us or your administrator for the rest.

Correct it. Contact details are editable in the wallet and in your account.

Delete it. Ask the organization that issued to you, or contact support. A wallet that never held a credential is erased entirely. Where one did, the credential record and its evidence entries are kept — an audit trail that could be deleted on request would not be an audit trail, and it is what protects you in a dispute as much as it protects anybody else.

Withdraw. Declining a request is always available and is recorded as your answer.

Contact

Email contact-aegis-id@vanguardcs.ca

Support and recovery help

Keeping it

How long, and what happens at the end.

While you hold a credential

Your wallet record and your credentials are kept while an organization still issues to you, and are removed on request afterwards.

Evidence entries

Kept for as long as the organization they belong to needs them, because they are the record of who approved what. Revoking or deleting a wallet does not erase the trail — that is deliberate, and a revoked wallet is exactly the case where it matters.

Children

Aegis ID is workplace software and is not directed at children. Accounts exist because an organization created one or invited somebody to hold a credential.

Changes to this policy

Material changes will be announced through the service before they take effect. This page always describes the version currently running.