The short version TL;DR
Autonymous.me collects zero identity data — by design. The entire protocol exists to eliminate the need for any party to hold your personal data. Your credentials live on your device only. No server stores your identity, your proofs, or your Source Chain. The only personal data we process at all is what you voluntarily send us via the contact form.
Data controller Identity
The data controller for the Autonymous.me project is the community maintainer acting on behalf of the open-source project.
- Contact: [email protected]
- Project: Autonymous.me — open source, non-profit, Apache 2.0
- Jurisdiction: European Union (GDPR applies)
What data is processed Data inventory
Protocol layer — zero data collected
- Identity credentials: Generated and stored exclusively on your device. Never transmitted to any server. Never accessible to Autonymous.me.
- Verifiable Presentations (VP Tokens): Sent peer-to-peer between your device and the requesting verifier. Autonymous.me never sees or processes them.
- Holochain Source Chain: Stored locally on your device. Replicated only with peers you authorise. Not accessible to us.
- Cryptographic keys (DIDs): Generated locally. Private keys never leave your device. Not transmitted to any server.
- Cookies and trackers: None. This site sets no cookies, loads no analytics, and makes no third-party tracking calls.
Contact form — limited, voluntary data
- Data collected: Name, email address, topic, and message content — only when you voluntarily submit the contact form.
- Purpose: To respond to your message. No marketing. No profiling.
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — responding to an inbound request from you.
- Processor: FormSubmit.co forwards the form data to our email inbox. FormSubmit does not retain form data beyond transmission.
- Retention: Email replies are retained only as long as necessary for the conversation, and deleted on request.
- No third-party sharing: Your contact data is never sold, shared with advertisers, or passed to third parties beyond the email delivery chain.
Your rights under GDPR Art. 15–22
Under Regulation (EU) 2016/679 (GDPR), you have the following rights regarding any personal data we hold. Because the protocol itself holds no data about you, these rights apply specifically to contact form data processed via email.
Art. 15 — Right of access
Know what we hold
You can request a copy of any personal data we hold about you (i.e. your contact emails). We will respond within 30 days.
Art. 16 — Right to rectification
Correct your data
If any data we hold is inaccurate or incomplete, you can ask us to correct it immediately.
Art. 17 — Right to erasure
"Right to be forgotten"
You can ask us to delete all contact data we hold about you. We will confirm deletion within 30 days.
Art. 18 — Right to restriction
Pause processing
You can ask us to restrict processing of your data while a dispute is being resolved.
Art. 20 — Right to portability
Export your data
You can request your data in a structured, machine-readable format (JSON or CSV). We will provide it within 30 days.
Art. 21 — Right to object
Stop processing
You can object to processing based on legitimate interest at any time. We will cease processing immediately upon request.
Note on the protocol: Because Autonymous.me stores no identity data on any server, rights of access, portability, and erasure apply automatically — there is nothing to request. Your identity data lives on your device under your sole control. You exercise these rights directly by managing your local wallet.
How to exercise your rights Contact
Send a request to our data contact. We will acknowledge within 72 hours and respond in full within 30 calendar days, free of charge.
If you believe your rights have not been respected, you have the right to lodge a complaint with your national supervisory authority. In France: CNIL (cnil.fr). Full list: EDPB members.
Privacy by design Architecture
Autonymous.me is built so that privacy is not a policy choice — it is a structural impossibility to violate. The architecture enforces data minimisation (Art. 5(1)(c) GDPR) and purpose limitation (Art. 5(1)(b) GDPR) at the cryptographic level:
- Data minimisation: Zero-knowledge proofs ensure only a boolean result is transmitted — never the underlying attribute value.
- Storage limitation: No server stores any identity data. There is no database to breach.
- Integrity and confidentiality: All credentials are cryptographically signed by issuers and encrypted at rest on the user's device.
- Accountability: Every verification action is logged on the user's own immutable Source Chain — under the user's sole control.
- Unlinkability: Context-specific DIDs prevent correlation across services. No persistent identifier is ever shared with a verifier.
External processors Third parties
- FormSubmit.co — processes contact form submissions for delivery to our inbox. Subject to their own privacy policy. No data retained after delivery.
- No analytics: No Google Analytics, no Plausible, no Matomo, no pixel trackers of any kind.
- No CDN dependencies: This site is fully self-contained. No third-party scripts are loaded at runtime.
Last updated: January 2025 · This policy will be updated when the project structure changes materially. Changes will be announced in the GitHub repository changelog. · GDPR Reg. (EU) 2016/679