Privacy at a Glance
1. Introduction
This Privacy Policy describes how Apparent Logic, LLC ("we," "us," or "our") handles data in connection with the Check ID mobile application (the "App") and our website, checkidapp.com.
By using the App, you agree to this Privacy Policy. If you do not agree with this policy, please do not use the App.
Check ID is designed with privacy as a fundamental principle. We believe the best way to protect your privacy is to not collect your data in the first place.
Check ID is offered as a free app, a one-time individual upgrade (Check ID Pro), and a paid business subscription (Check ID for Teams). Except where a section is specifically labeled for Teams, this policy describes the free and individual tiers, where your scan history and guest lists stay on your device and in your private iCloud. Check ID for Teams stores certain team data on our servers — see “Check ID for Teams (Business Accounts)” in Section 2.
2. Information We Collect
We never keep an ID's personal details — no name, birth date, or ID number. On the free and individual tiers your scan history and guest lists are never sent to our servers; what we do receive is described below under “Messages, Sign-Ups and Accounts” and “Usage Analytics.” On Check ID for Teams we store the account and team data described below under “Check ID for Teams (Business Accounts),” including a one-way cryptographic pass-back code that is deleted after the repeat-entry window and, by itself, can't be used to reconstruct a name, birth date, or ID number.
ID Scanning (Barcode and NFC)
Check ID scans multiple types of identification documents:
- Physical IDs: Driver's licenses and state IDs via PDF417 barcode scanning
- Mobile Driver's Licenses: Digital IDs from Apple Wallet
- ePassports and National ID Cards: International documents via NFC scanning on supported iPhones
For all scan types: Scanning happens on your device, and an ID's personal details — name, birth date, ID number — are never stored. Alongside the document facts listed below, Team accounts keep a pass-back code: the device makes a one-way cryptographic code from the scanned ID, and our server keeps only a keyed version of it. It contains no name, birth date, or ID number, and it's built so that a breach of our servers alone can't be turned into a list of your patrons — recovering an identity from it would require also having the original ID to check against. Our server deletes it after the repeat-entry window (4 hours by default). On every plan, while repeat-entry alerts are on (the default), the device also keeps its own one-way code for each barcode scan, on that device only; codes older than 7 days are cleared at the first scan after the app restarts.
What the app reads and shows. To perform a check, the app reads what the document encodes and shows it to your staff member so they can compare the document to the person presenting it. Depending on the document, that can include name, date of birth, address, expiry date, document number, and the photograph held on a passport chip or returned by a mobile ID. It is held in memory only, discarded when the app is closed or the next document is scanned, and never written to storage or transmitted to us.
What a completed check keeps. Where a record is kept at all — the scan history described below, or the compliance record on Check ID for Teams — it contains the outcome and the staff member’s decision, the age in whole years, the issuing jurisdiction and country, the document type, the scan method (barcode, chip or mobile ID), the REAL ID indicator exactly as the document encodes it (on Check ID for Teams, and in the App’s own scan history from version 3.0), for Apple Wallet IDs the minimum age that was checked, a confidence score from the App’s barcode checks, which checks failed if any, whether the person was on a guest list, whether the scan raised a pass-back alert, and the time. On Check ID for Teams it also records the venue, device and, unless the door is set to anonymous, the staff member who performed the check, and carries a per-row cryptographic signature over the verification facts. Each exported row states exactly which of its fields that signature covers.
What no record ever contains. A name, date of birth, address, document number, or any image of the document. Part of this is enforced in code rather than by policy alone: our server refuses to start if a field whose name matches a personal-data pattern — a date of birth, a personal name, a licence, document or passport number, an SSN or a street address — is added to the signed scan record or to the exported compliance log. The venue, device and staff names above are our customer’s own operational labels, not the ID holder’s details.
The one exception, named plainly. A guest list is a list your team builds. If a staff member adds or confirms a name on it, that name is stored as part of your guest list, described below. A scan never adds anyone to a guest list on its own.
Digital wallet IDs (mobile driver's licenses presented from Apple Wallet) are verified cryptographically at the moment of presentation, but they do not participate in pass-back detection. A wallet ID is bound to its holder's device and protected by that device's own biometrics, so the scenario pass-back detection guards against — one physical card being handed back through a line to let someone else use it — doesn't practically apply to a wallet credential.
Scan History
Check ID keeps a 7-day scan history. It is on by default, and you can turn it off in Settings. While it is on:
- A record of each scan is stored on your device and syncs through your own iCloud (see “Your Private Data” below), containing the facts listed above under “What a completed check keeps” plus an internal identifier for that scan
- It never contains a name, date of birth, address, ID number or photo
- Entries older than 7 days are cleared when the app opens
- You can clear the history in Settings. Turning recording off stops new entries; entries already recorded stay until they are cleared or reach 7 days
Your Private Data (On Your Device and in Your iCloud)
On Check ID Free and the individual Check ID Pro upgrade, the following information stays on your device or in your private iCloud container. We can't read it. Apple encrypts iCloud data in transit and on its servers, but not end-to-end (see Section 6):
- Scan History: described above. It syncs through your private iCloud container to your other devices.
- Guest Lists: For each personal guest list, you choose whether it stays on this device only or syncs through your private iCloud container. A list holds the names you type in, import, or choose to add from a scan. (Check ID for Teams works differently — see “Check ID for Teams (Business Accounts)” below.)
- App Preferences: Your settings and preferences (such as minimum age thresholds) are stored on your device only. They are not synced through iCloud.
Check ID for Teams (Business Accounts)
The commitments above — on-device scanning, and scan history and guest lists kept on your device or in your private iCloud — describe Check ID Free and the individual Check ID Pro upgrade. Check ID for Teams is a paid subscription for businesses, and it works differently: to support multiple staff, shared devices, compliance reporting, and cross-device sync, certain data is stored on our servers (“Check ID Cloud”) rather than only on your device. If your organization uses Check ID for Teams, the following also applies.
What a Teams account stores on Check ID Cloud:
- Account information: the email address and sign-in identifiers (such as passkeys or Sign in with Apple) used to create and access the account. Check ID for Teams is passwordless — we do not store passwords.
- Organization & venue details: the business or organization name and venue information you provide.
- Team members: staff names and roles, and (for shared-device check-in) optional staff PINs stored only as one-way hashes.
- Registered devices: records of the shared devices your organization activates.
- Scan events: the date, time, result (approved or rejected), method, and the staff or device attribution of each ID check. Alongside those we keep a small set of facts about the document, because a compliance report is not much use without them: the age in whole years, whether your minimum-age threshold was met, the issuing state and country, the document type, the REAL ID indicator as the document encodes it, a confidence score for the read, whether the person was on a guest list, and which checks failed if any.
What is never stored: the cardholder’s name, date of birth, address, photo, or ID/document number. None of it is written to the scan record, and none of it appears in an export. The age is kept in whole years rather than as a birth date. - Guest list entries: the names, tags, and notes your team chooses to add to shared guest lists. Unlike the personal guest lists described above, Teams guest lists are stored on Check ID Cloud, not your private iCloud — they're organization-scoped and deletable by the account owner at any time. This is information your team enters — not data extracted from scanned IDs.
- Passback detection: privacy-preserving one-way hashes used to detect the same physical ID being re-used within a short time window. These hashes cannot be reversed to reveal the name, birth date, or ID number they were derived from, and are deleted after the window. By default, none are kept for venues in New Hampshire, the EU and EEA, and every country outside the US, Canada, the UK and Australia; owners and managers can change this per venue. Digital wallet IDs do not participate in passback detection — see “ID Scanning (Barcode and NFC)” above.
- Audit logs: records of team-management actions (inviting a member, registering a device, changing settings, editing a guest entry) for accountability and compliance.
Roles and responsibilities. For data your organization enters or generates through Check ID for Teams (team members, guest lists, scan events, audit logs), your organization is the data controller and Apparent Logic, LLC acts as a data processor on your behalf. If your organization needs a data processing agreement, contact us at support@checkidapp.com.
Retention. Scan events are kept for your organization’s configured retention period (two years by default; the owner can choose from 30 days to about ten years) and then deleted. Audit logs are kept for the life of the team. Guest list entries persist until your team deletes them; a deleted entry is purged once it has gone untouched for your retention period, and an owner can erase all guest data immediately. Passback hashes are deleted after the configured detection window. Deleted data can stay in our backups for about a week, until they age out.
Even on Check ID for Teams, we never store an ID's personal details — no name, birth date, photo, or ID number. From the ID itself, a scan record keeps only the document facts listed above. The one-way cryptographic pass-back code contains none of those details and is deleted after the repeat-entry window.
Messages, Sign-Ups and Accounts
We also receive the following, on any plan, when you choose to send it:
- Support messages, feedback and newsletter sign-ups: when you use the support form on our website, or send feedback or sign up for our newsletter in the App, we receive your message and email address (optional for feedback in the App), plus technical details such as your browser’s user agent from the website, or your app version, device model and operating system version from the App. We delete them from our database after 180 days. A copy of each is also delivered to our internal inbox in Slack (see Section 5).
- The Check ID for Teams updates and interest list: when you join it on our website, we keep your email address and any organization name, region, number of venues or note you give us, together with any preview preference you previously provided, and use them to email you about Check ID for Teams. If you arrive through a guide, we also keep its public topic with your request to understand which guides produce interest. We do not put your email or note in website analytics. These requests aren’t deleted automatically: reply to any of our emails, or contact us, to be removed.
- A Check ID account: from version 3.0, you can sign in to the App with a Check ID account. You don’t need one to use the App on your own; if you sign in, we store your email address and sign-in identifiers, as described for Teams accounts above.
Usage Analytics
We collect limited, pseudonymous usage analytics to monitor the health and performance of the App. This helps us identify bugs and performance issues. They are grouped under a random identifier for the app installation, which changes every six months (see Section 4).
What we DO collect:
- Feature usage statistics (e.g., which features are used most often)
- Performance metrics (e.g., how long a session lasts)
- Device model, operating system and app version, language and time zone settings, and connection type (for compatibility testing), and whether the App has Pro or Check ID for Teams
- Coarse facts about each scan: the result, the age (in whole years in version 2.5.1; from version 3.0, an age range such as 21–24), the state or country that issued the ID, a score from the App’s barcode checks and how many failed, for a repeat entry how long ago the earlier scan was, and, from version 3.0, the REAL ID indicator as the ID encodes it
What we DO NOT collect:
- Stored IP addresses — website analytics keep only a hashed code that changes daily
- Customer identifiers or account information
- A name, date of birth, ID number, address, or photograph from a scanned ID
- Names, addresses, or any data from guest lists
- Location data
- Your name or email address
From version 3.0, also:
- App Store ad attribution: we ask Apple which App Store ad, if any, led to an install. We keep Apple’s answer, and link in-app purchases to it, under a separate install ID that doesn’t change. It carries no scan data.
- Document format details: each scan also sends the ID’s format details, such as the barcode standard version and issuer code, but none of its personal details. We store them without the sender.
- Usage figures for signed-in Pro users: we keep usage figures, such as total scans, with the account to answer App Store refund requests.
The name, date of birth, address, ID number and photo read from an ID are never sent to us, and no scan record keeps them. Check ID for Teams keeps the scan record facts listed above and, for the repeat-entry window, a one-way cryptographic pass-back code. On the free and individual tiers, guest lists stay on your device or in your private iCloud container, where we can't read them; on Check ID for Teams, guest list data is stored on Check ID Cloud (see Section 2).
3. How Your Information is Used
ID Scanning
When you scan an ID (via barcode or NFC), the App processes the information locally to:
- Display the cardholder's age and verify against your minimum age setting
- Show relevant ID information for visual verification
- Record scan activity in your 7-day scan history, which is on by default and syncs through your own iCloud (no name, date of birth, address, ID number or photo)
Your Private Data
Data stored on your device and in your private iCloud container is used exclusively for the App's functionality:
- Guest list information helps you manage entry control and track attendees
- Preferences customize the App to your specific needs
- iCloud sync allows your data to be available across all your devices
Usage Analytics
Usage analytics are used solely to:
- Improve app performance and reliability
- Understand which features are most valuable to users
- Ensure compatibility across different devices and iOS versions
From version 3.0, App Store ad attribution is used to see which of our App Store ads lead to installs and purchases, and usage figures kept with a signed-in Pro account are used to answer App Store refund requests.
Your personal data is never sold or rented, and never shared with advertisers, data brokers, or trackers. The limited service providers we use to run the service (see Section 5) process data only on our instructions.
4. Analytics, Tracking & Advertising
Check ID uses only its own pseudonymous analytics. Zero advertising. No cross-app tracking.
What We Use
We collect pseudonymous usage analytics to monitor app health and performance. This is limited to basic feature usage statistics, performance metrics and coarse scan statistics—never a name, date of birth, address, ID number or photograph.
Analytics are grouped under a random identifier for the app installation, which changes every six months and is never connected to your name, email, or account. We use it to understand how features are used—for example, how many people reach a screen, or where a flow is abandoned—and nothing else. It is never sold, shared, or used for advertising.
Where a scan produces a statistic, version 2.5.1 records the age in whole years; from version 3.0, the App records only an age range (such as 21–24) instead, alongside the yes/no answer to the age check itself. We never record a name, date of birth, ID number, address, or photograph in analytics. Mobile driver's licences are excluded from age statistics entirely.
Raw analytics events are deleted after 180 days; only aggregate counts are kept beyond that. Website analytics events are deleted after 7 days.
From version 3.0, we also ask Apple which App Store ad, if any, led to an install, and keep Apple’s answer, linked to in-app purchases, under a separate install ID that doesn’t change; and for signed-in Pro users we keep usage figures, such as total scans, with the account to answer App Store refund requests (see Section 2).
What We DO NOT Use
- Google Analytics or similar services — Never
- Facebook Pixel or social media trackers — Never
- Third-party analytics frameworks — Never
- Data brokers or data sharing networks — Never
- Advertising networks or SDKs — Never, apart from Apple’s own App Store ad attribution from version 3.0 (above). No advertising SDKs and no advertising identifier
- Behavioral profiling for advertising or resale — Never
- Tracking tied to your name, email, or account — Never. Our analytics aren’t linked to an account. From version 3.0, a signed-in Pro user’s usage figures are kept with the account, for refund requests (above)
- Storing your IP address — Never. Website analytics keep only a hashed code of it that changes daily
- Cross-app tracking — Never
There are NO advertisements in Check ID. Your attention is not for sale.
5. Third-Party Services
We never sell or rent your data, and never share it with advertisers, data brokers, or trackers. To run the service — especially Check ID for Teams — we rely on a few trusted providers (“sub-processors”) that handle data only on our instructions.
The App and service connect to:
- Apple iCloud: On the free and individual tiers, your scan history, and any guest lists you keep in iCloud, are stored in your private iCloud container, governed by Apple's privacy policies.
- Apple App Store: App downloads, updates, and in-app purchases — including Check ID for Teams subscriptions bought in the App Store, which Apple bills — and, from version 3.0, App Store ad attribution (see Section 4).
- Sign in with Apple: if you choose it to sign in to a Check ID account.
- Check ID Cloud (our servers): usage analytics for all users; messages and sign-ups you send us (see Section 2); for Check ID for Teams accounts, the account and operational data described in Section 2, including team guest lists. No name, date of birth, address, ID number or photo read from a scanned ID is stored here. What is kept from a scan is described in Sections 2 and 4: the document facts in Teams scan records, a one-way pass-back code deleted after the repeat-entry window, coarse scan statistics in analytics and, from version 3.0, document format details.
- Hosting & infrastructure: Check ID Cloud runs on DigitalOcean, which hosts our servers, database and web console.
- Network and backup storage: Cloudflare is the network in front of our servers and this website. All traffic to them, including Teams scan uploads, passes through it. It also stores an encrypted copy of our nightly database backups, which only we can decrypt.
- Email: Amazon Web Services (SES) sends account emails such as sign-in links and team invitations, and owner summaries with scan totals.
- Payments (Business accounts): If your business pays for a subscription on the web, payment is handled by Stripe, which processes your billing contact and card details directly. We never receive or store full card numbers.
- Internal messaging: Slack is our internal inbox for support messages, app feedback, purchase notices and service alerts.
We do NOT integrate with, share data with, or connect to:
- Google or Facebook services
- Third-party analytics platforms
- Advertising networks, other than Apple’s App Store ad attribution from version 3.0
- Data brokers or marketing platforms
- Social media integrations
6. Data Security
We take data security seriously and implement multiple layers of protection:
Your Private Data
- iCloud Encryption: On the free and individual tiers, your scan history, and any guest lists you keep in iCloud, are stored in your private iCloud container, where we can't read them. Apple encrypts them in transit and on its servers, but not end-to-end, even with Advanced Data Protection on, because Check ID doesn't use CloudKit's encrypted fields
- Device Security: Data on your device (including scan history) is protected by iOS encryption, passcodes, and biometric authentication
- No ID Details Transmitted: The name, date of birth, address, ID number or photo read from an ID (barcode, NFC or mobile ID) is never transmitted—we never receive them. Team accounts send the scan record facts listed in Section 2 and a one-way code for pass-back detection; our server keeps only a keyed version of that code, for the repeat-entry window, and discards it at venues where repeat-entry hashing is off
- Local Processing: Reading the ID and the age and expiry check happen on your device. On Check ID for Teams, repeat-entry matching across a venue's devices happens on our servers
Analytics
- Analytics are transmitted over encrypted connections
- No name, date of birth, ID number, address, or photograph is included in analytics—scan statistics use the age in whole years in version 2.5.1, and an age range from version 3.0
- Analytics are grouped under a rotating per-installation identifier that is never linked to your name, email, or account
While no system is 100% secure, we never keep the name, date of birth, address, ID number or photo read from an ID, so a breach couldn't expose them. What we do keep, including account details, Check ID for Teams scan records and team guest lists, is described in Section 2. The pass-back code is built so a breach of our servers alone can't be turned into a list of your patrons, and it is deleted after the repeat-entry window.
7. Your Rights & Control
You have complete control over all your personal data stored by the App:
- Access: View all your guest lists and settings directly in the App at any time
- Modify: Edit or update any information you've entered
- Delete: Remove individual entries or clear all data through the App's settings
- Export: Your data is included in your iCloud backups and standard iOS device backups
For your guest lists, scan history and settings, you do not need to contact us—you have direct control through the App interface. For data on our servers, such as a Check ID account or a message you’ve sent us, email support@checkidapp.com to ask for a copy or for deletion. From version 3.0, you can also delete your account in the App’s account settings; our Security page explains what that deletes. Check ID for Teams data is controlled by the organization that uses it (see Section 2).
When you delete the App, all local data is removed. Your iCloud data persists in your iCloud account and can be managed through iCloud settings.
8. Children's Privacy
Check ID is intended for use by adults (18+) in professional age verification and access control contexts. The App is not directed at children under 13.
We do not knowingly collect personally identifiable information from children under 13. Our usage analytics never include a name, birth date, address, ID number or photo, and they aren't linked to an account.
9. Legal Compliance
We handle requests to access or delete personal data as described in Section 7.
Because we don't keep an ID's personal details, we have no name, birth date, or ID number read from an ID on file to provide in response to legal requests, subpoenas, or court orders. We do hold the data described in Section 2, such as account details and, for Check ID for Teams, scan records, team guest lists and audit logs. What we keep that is derived from an ID is described in Sections 2 and 4: the document facts in Teams scan records, coarse scan statistics in analytics, from version 3.0 document format details, and a one-way cryptographic pass-back code that is deleted after the repeat-entry window; on its own that code cannot be turned back into a name, birth date, or ID number.
Our analytics carry no name, email, or account reference, only a random per-installation identifier, so we cannot look them up by a person's name, email or account in response to a legal request, subpoena, or court order.
10. Important Disclaimers
Please read these disclaimers carefully:
Limitation of Verification
Check ID reads and displays information from ID barcodes and NFC chips (for ePassports and National ID cards). The App does NOT verify the authenticity of IDs or detect fraudulent documents. It is a tool to assist with age verification, not a guarantee of ID validity. Users are responsible for visually inspecting physical IDs and using their own judgment.
Compliance Responsibility
While Check ID is designed to assist with age verification compliance, users are solely responsible for complying with all applicable federal, state, and local laws and regulations. The App is provided as a tool only and does not constitute legal advice or guarantee compliance.
No Warranty
THE APP IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. WE MAKE NO REPRESENTATIONS OR WARRANTIES REGARDING THE ACCURACY, RELIABILITY, OR COMPLETENESS OF ANY INFORMATION PROVIDED BY THE APP.
Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, APPARENT LOGIC, LLC SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS OR REVENUES, WHETHER INCURRED DIRECTLY OR INDIRECTLY, OR ANY LOSS OF DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES ARISING FROM YOUR USE OF THE APP.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this page.
Material changes will be communicated through:
- App Store update notes
- In-app notifications
- This website
Your continued use of the App after changes are posted constitutes acceptance of the updated Privacy Policy.
The current version is always available at: checkidapp.com/privacy
12. Contact Information
If you have questions about this Privacy Policy or Check ID's privacy practices, please contact us: