Privacy & Security
This page describes how the app and creds.id handle your data, based on how they are built. It is not a privacy policy; see Privacy Policy & Terms.
Local-first, not serverless
Your identity and your data start on your phone. That doesn’t mean there is no server. Your public page has to reach visitors, so it is published to public Nostr relays and shown by creds.id, and the creds.id name directory maps your name to your key. The sections below say exactly what goes where.
Your identity and keys
- When you set up the app, it creates a 24-word recovery phrase on your phone. Your identity key, your Nostr key and your backup key are all derived from it.
- The phrase is kept in your phone’s keychain, and the app never writes it to its ordinary storage.
- On iPhone, a recovery copy of the phrase goes to your iCloud Keychain during setup. On a new iPhone, choose I already have an account › Restore from iCloud.
- On Android, the app currently keeps no cloud copy of your identity.
- Face ID protects sensitive actions. By default, one Face ID check covers the next five minutes, and you can choose a different mode in Settings › Security. Some actions ask every time, whatever the mode, such as resetting app data. Your device passcode always works as a fallback.
What stays on your phone
Your contacts, cards and attestations are stored on your phone, in encrypted storage. The app never sends your contacts to creds servers. Contacts leave your phone only inside an encrypted backup, if you turn backups on.
To keep saved pages up to date, the app asks public Nostr relays for the latest page of each saved contact who has one. The relays see which public keys the app asks for.
The app contains no analytics or crash-reporting software.
What is public
These are public by design, so that anyone can check them:
- Your page: your name, avatar, bio, links, the identities you list, your identity’s public ID (DID) and the time you signed the page. The app publishes it, signed, to the public Nostr relays
relay.damus.io,nos.lolandrelay.primal.net. - Your Nostr profile: it says
name@creds.idand names your identity, which is the other direction of your name check.
What creds.id stores
- The name directory stores your name, your public key, your relay list, the name’s status, timestamps, and redirect details after a rename. It also keeps a log of registrations and releases, including the signed request; log entries are deleted after 90 days. See
name@creds.id. - If you connect a passkey (during setup or in Settings › Passkeys), the app uploads an encrypted copy of your recovery phrase (and of your Nostr key, if the app stores one) to creds.id. It is encrypted with a key that only your passkey can produce, so creds.id can’t read it. creds.id stores only the encrypted copy and a storage address derived from the passkey. The app currently has no way to delete this copy.
- creds.id runs on Cloudflare, with request logging turned on. The directory uses your IP address to limit request rates and doesn’t store it in its database.
Backups
Backups are off by default. Turn them on in Settings › Backup & Recovery.
- A backup contains your cards, contacts, attestations, profile and page. It doesn’t contain your keys.
- It is encrypted (AES-256-GCM) with your backup key, which is derived from your recovery phrase.
- It goes to your own cloud storage: iCloud Drive on iPhone, Google Drive on Android. On Google Drive, the app can only access the files it created. creds never receives your backups.
- Once backups are on, the app backs up while it is open, at most every 6 hours, and keeps the last 3 backups.
Notifications
If you allow notifications, the app registers your phone’s push token with a push relay, so that notifications can reach this device.
Visitors to your page
- creds.id uses no analytics, no cookies and no third-party scripts. Fonts are served from creds.id itself.
- creds.id sends no referrer when a visitor follows a link on your page.
- The browser stores a visitor’s theme and language choice only if they change it.
- To check your page, the visitor’s browser contacts creds.id and public Nostr relays. As with any website, those servers can see the visitor’s IP address.
A page made in your browser
If you make your page at creds.id instead of in the app:
- Your browser generates the recovery phrase. It is not sent to creds.id.
- Your signing key is created so that it can’t be exported from the browser.
- If you add a passkey, a passkey-protected copy of your identity is stored in this browser.
- If you clear the site’s data, that copy is deleted, and your recovery phrase is the only way back. Write it down.
- Creating and unlocking a browser identity works only on creds.id.
Deleting data
Settings › Reset Options › Reset App Data clears the app’s data on your phone but keeps your identity keys.
Some copies are outside the app’s reach. The app can’t delete:
- backups in your iCloud Drive or Google Drive (delete them there);
- the encrypted passkey copy on creds.id;
- your name in the creds.id directory;
- pages already published to Nostr relays.