FIELD-LEVEL DATA MINIMIZATION

Collect only what this application currently needs.

Inventory version 2026-08-01. Every entry states scope, purpose, access, retention, and deletion. The current flow collects no face template, inferred age or sex, ethnicity, emotion, identity, network address, device fingerprint, or raw representative-authority document.

18+

Current minor-applicant policy

The current Digital Citizen application pilot accepts individuals age 18 or older based only on a self-declared birth date. The site does not infer age from a selfie and collects neither guardian data nor a minor's selfie. Because no guardian-consent path is live, minors cannot currently save or submit this application. This limit applies to the Digital Citizen application, not as site-wide age verification.

account_emailAll application paths
Purpose
Tie the application to the verified account and send service notices.
Access
Applicant and authorized support or reviewers
Retention
While the account or an auditable credential record remains active.
Deletion
Removed with eligible account data; a one-way audit reference may remain after issuance.
legal_nameC, B and G applications
Purpose
Identify the declared person, entity, or public institution for authorized review.
Access
Applicant and authorized reviewers
Retention
Until withdrawal, deletion approval, or the end of an applicable credential audit period.
Deletion
Deleted with an unissued application; issued records retain only the minimum auditable claim.
country_or_regionAll application paths
Purpose
Apply regional policy and route an authorized review.
Access
Applicant and authorized reviewers
Retention
Same period as the application or minimum credential record.
Deletion
Deleted with eligible application data.
birth_dateC applications only; self-declared
Purpose
Enforce the current adult-only pilot and support authorized review; never inferred from a face.
Access
Applicant and authorized reviewers
Retention
Until withdrawal, approved deletion, or an applicable credential audit period ends.
Deletion
Deleted with an unissued application and excluded from public credentials.
legacy_birth_month_gender_phoneNot collected by the current application
Purpose
No current purpose; legacy columns are retained only for safe migration compatibility.
Access
Not shown in the current application response
Retention
Cleared when an existing draft is next saved; no new values are accepted.
Deletion
Cleared on save or eligible application deletion; never inferred from a selfie.
entity_registration_and_roleB and G applications
Purpose
Route a future authorized institution and representative-authority review.
Access
Applicant and authorized institutional reviewers
Retention
While the application or minimum institution credential audit record remains active.
Deletion
Deleted with an unissued application; no raw authority document is stored in D1.
authority_referenceB and G applications; bounded metadata only
Purpose
Point an authorized reviewer to a public or official authority reference.
Access
Applicant and authorized institutional reviewers
Retention
Same period as the institution application.
Deletion
Deleted with eligible application data; confidential or raw evidence must not be entered.
selfie_imageOptional until submission; separately consented
Purpose
Support authorized review and, where available, a browser-only face-presence check.
Access
Applicant and authorized reviewers through private storage
Retention
Until consent withdrawal, application withdrawal, approved deletion, or the documented review need ends.
Deletion
The applicant can delete it independently; no face template or demographic inference is retained.
face_presence_statusSubmission capture metadata
Purpose
Record only whether the browser saw a face or routed capture to manual review.
Access
Applicant and authorized reviewers
Retention
Same period as the application review record.
Deletion
Reset when the selfie is deleted; never treated as identity verification.
consent_receiptEvery application-data or selfie consent
Purpose
Prove the policy version, purpose, grant time, and withdrawal time shown to the applicant.
Access
Applicant and privacy-authorized staff
Retention
Kept as a minimal consent audit record after application withdrawal where permitted.
Deletion
Contains no selfie or application field values; handled through the Privacy Request Center.

Your data and consent remain under your control

After sign-in, download a versioned consent receipt or request access, correction, export, deletion, or consent withdrawal.