Who we are and when this policy applies
Alethic is a community project. This policy covers its website, business console, APIs and capture integrations. For privacy questions or complaints, use the help center and your authenticated workspace support inbox when available. The contact page explains access requirements and current availability.
The public website is available for information and integration review. Live checks and payment collection are not open yet. Visiting this website does not submit a face, document or payment. The processing described below applies when the relevant service is made available and you choose to use it.
The requesting business and your choice
A business that asks you to complete a check decides its purpose, the information it needs and how it will use the result. That business must give you an appropriate notice and obtain the consent or other lawful basis required for its use. Alethic processes submitted information to provide the requested service and separately handles account, security, billing and support administration.
Read the notice shown by the requesting business before submitting. You can stop before submission and ask that business for an alternative. Do not submit another person's information without the necessary authority and permission. The current service is intended for authorized adult business users and adult verification subjects, not children.
Information we may process
Account information includes your business or workspace name, contact email and business phone, sign-in identity, workspace membership and permission settings. Google sign-in, where offered, uses basic account identity information. It does not request access to your Gmail inbox or Google Drive.
Depending on the selected check, input can include a face photograph, document image, name, date of birth, document reference, vehicle registration or business registration details. Face processing can involve biometric-related information. Results can include provider responses, extracted fields, confidence, warnings and comparison outcomes.
We also process consent records, request IDs, timestamps, access and error records, credit and charge records, payment references, and messages you send for support. Payment-card credentials are handled through the payment provider's checkout, not an Alethic card-entry form. Please do not send card details, passwords, API secrets or full identity-document numbers in support messages.
Why information is used
We use the information to perform the requested check or extraction, return its result to the authorized business, manage access, maintain billing and original-request recovery, investigate faults or abuse, and respond to support or privacy requests. Registry matching, face presence, liveness and OCR each have a limited scope; none is a general guarantee of identity.
Separate Test environments use synthetic scenarios and test credits. Use fictional inputs there. A Test result does not establish real identity, eligibility or a provider decision. This website does not use advertising cookies or third-party advertising trackers in its current implementation.
Aadhaar and sensitive input
An uploaded Aadhaar image or text extracted from it is not UIDAI authentication or proof of a valid Aadhaar. Alethic does not claim to be an authorized Aadhaar authentication agency. The particular result must identify what was actually checked. Use a masked Aadhaar image where it is suitable for the requested lawful purpose; do not provide a full number merely for convenience.
The text-extraction response is designed to mask Aadhaar-format numbers and return only a last-four field. That does not mean an uploaded image, a provider's copy or other submitted information has been erased. The requesting business remains responsible for lawful collection, required consent and appropriate alternatives.
Providers and access to results
Netlify hosts and delivers this public website and can process technical request information needed to serve and secure it, such as IP addresses, browser information and requested URLs. The backend uses Amazon Web Services for API hosting, authentication and storage; document OCR uses AWS Textract when enabled. Cashfree performs selected verification or registry checks, and Razorpay handles payment collection once enabled. Google is involved when its sign-in option is selected. Dedicated transactional email, if activated, uses AWS. These providers process information under their applicable terms and privacy policies.
Results are available to the requesting business and its authorized workspace members. Authorized Alethic operators may access information needed for support, security, billing or business review. We may disclose information where legally required or necessary to investigate misuse or protect rights. The requesting business controls any copies or further use in its own systems. We do not promise that every provider processes information exclusively in India.
Retention and deletion
The verification storage configuration targets deletion of uploaded images after one day and private provider evidence, including detailed OCR and vehicle-record results, after seven days. Object lifecycle deletion is asynchronous, so these periods are not a promise of deletion at an exact hour. Provider retention and copies held by the requesting business are separate.
Identity details submitted as expected values, such as names, birth dates and some document references, can remain in session and attempt records beyond the image period. Account, consent, financial, request-identity, security, business-review and support records can also be retained separately for their operational purpose, dispute handling and applicable legal duties. The image lifecycle must not be understood as deletion of every related record.
If dedicated email is activated, the configured targets are seven days for original received email and thirty days for parsed and outgoing message bodies; metadata and delivery records are separate. Dedicated email is not currently an available contact channel. Use the authenticated workspace support inbox when available.
Privacy requests are reviewed manually. A recorded request or ticket means we received it, not that deletion is complete. We explain any information needed to locate the record and any applicable retention restriction; financial and verification audit records may need to remain. Do not provide full identity documents in support messages to make a request.
Access, correction, consent and complaints
To ask about access, correction, deletion or withdrawal of consent, contact the business that requested the check and use the Alethic workspace support inbox for information controlled by this service. Use a safe account, ticket or request reference. We may need to verify your identity and authority using proportionate information before acting.
Withdrawing consent does not undo completed processing. We will consider your request and explain the outcome, including any legal or transaction-related reason for retaining a record. You retain rights and complaint routes provided by applicable law. This policy does not claim that every provision of a future or phased legal requirement is already operational.
Cookies, browser storage and your choices
Alethic uses local storage and session storage for the purposes described here. The current website does not install analytics or advertising trackers. Optional preferences are off until you choose Allow preferences or save them in Cookie preferences. Necessary sign-in and transaction recovery remain available with either choice.
- Necessary sign-in and security: temporary access tokens, the PKCE sign-in transaction and selected workspace are kept in this browser tab. Short-lived capture-session tokens can be saved with an original verification request so it can be recovered. These scoped tokens can grant access to that session; protect this browser on shared devices. Long-lived business API secrets are not saved by the portal.
- Necessary request recovery: original request and order IDs, exact quote references and payload hashes help avoid duplicate checks, replies or charges. Some payment-recovery records use local storage until the original transaction is resolved. Rejecting optional preferences does not delete these records, support messages, account information or server records.
- Your privacy choice: a small versioned record in local storage remembers whether you allowed preferences, when you decided and its expiry, for up to 180 days. It contains no account identity and is not sent to an analytics service. An expired or invalid choice is treated as necessary only.
- Optional appearance and intro preferences: after permission, local storage remembers light, dark or system appearance. Session storage can help avoid repeating the introduction in this tab. Without permission, appearance and intro state stay in page memory. Withdrawing permission removes only these optional keys on this origin. Other open tabs apply the change when they receive it or become active.
Reopen Cookie preferences in the footer to allow or withdraw optional storage at any time. If your browser blocks storage, optional preferences remain off and your choice may be requested again. Browser settings can also remove stored data, but removing necessary recovery records can make unfinished requests harder to recover.
AWS Cognito and Google manage sign-in on their own domains and may use their own cookies. Payment checkout, when enabled and opened, is also operated by its provider. This control does not delete those providers' cookies, end Google sign-in, or disable the technical server logs used to deliver and protect the website.
Protect your device and server credentials and sign out on shared devices. Access controls and bounded data handling reduce risk, but no online service can promise perfect security. Use the support inbox if you suspect unauthorized access. Material changes to this policy will be reflected in the updated date and, when appropriate, communicated through an available account channel.