Verified, never tracked.
How Cylinder proves a fact about someone without becoming a way to follow them — single-use credentials, selective disclosure, and as little data kept as possible. This explains our approach; the legal terms live in the privacy policy.
Cylinder verifies with single-use credential presentations: each time your credential is claimed it produces a fresh, unique signature and is burned on use. There is no reusable identifier to follow, so two checks can never be tied back to the same person — you are verified, and nothing else.
A verification confirms the single claim a flow needs — not the whole credential. The person shares “over 18 = true”, and the date of birth, document number, and everything else stay with them.
Nothing is collected silently. Before anything is shared, the person sees who is asking and the exact claim being requested, and confirms it in their own wallet. No approval, no data — the holder is always in the loop.
Retention is a control you own, not a promise to take on faith. Choose to keep only that a check happened, a short default window, or a custom period that matches your policy. When the window closes, the record is permanently deleted.
Where third parties are involved they are identified and governed, and there is a clear path to access, correct, or delete data. This page describes our approach; the legal terms live in the privacy policy.
Know the subprocessors
Where third parties are involved, they are identified and governed — named, not hidden.
Access, correct, delete
A clear path for privacy requests — the right to see, fix, or remove data — as required by law.
Organisation-scoped
Every record belongs to one organisation; access is checked on every read and write.
Separate from the legal policy
This explains product behaviour and intent; the formal disclosures live in the privacy policy.
See how a flow returns the decision your workflow needs while keeping the data footprint small.