Privacy Policy
Last updated: September 18, 2026
ID Oracle ("we," "us," or "our") operates the ID Oracle mobile application and website (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described below.
1. Information We Collect
Information you provide: email address, password (hashed), and business or team details you enter when setting up a team or multi-location account.
Identity document data: when you scan an ID, we process an image of the document to extract the name, date of birth, and address shown on it. Document images are stored in private, access-controlled storage and are never made publicly accessible.
Public records search data: the name and address extracted from the ID are used to query public records databases to help assess whether the document is genuine.
Scan history: the results of each verification scan are stored in your account so you can review them later. You can disable scan history storage or purge past scans at any time from Settings.
Location data: for team and multi-location accounts, we use device GPS coordinates to verify that scans are performed near an authorized venue. Location is used only for this geofence check and is not stored long-term.
Device information: a device fingerprint is generated to help prevent abuse of the free trial across multiple accounts. We also collect standard technical data such as IP address, browser type, and operating system.
Usage data: pages viewed, actions taken, and other analytics events that help us improve the Service.
2. How We Use Your Information
- To provide the identity verification and fake-ID detection features of the Service.
- To create and manage your account, including team memberships and multi-location access.
- To enforce scan limits, geofencing, and free-trial eligibility.
- To process payments and manage subscriptions.
- To send service-related emails such as verification codes and account notifications.
- To detect, prevent, and address fraud, abuse, and security issues.
- To analyze and improve the Service and develop new features.
3. What This App Does NOT Do
ID Oracle is a fake-ID detection tool. It does not perform background checks, criminal record searches, credit checks, or employment verification. It does not access government motor vehicle or DMV databases. Results should be used as a screening aid, not as a definitive determination of identity.
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area, we process your personal data under the following legal bases: performance of a contract (providing the Service you requested), consent (for optional data like location), legitimate interests (security and abuse prevention), and compliance with legal obligations.
5. Data Sharing and Third Parties
We do not sell your personal information. We share data with the following categories of service providers:
- Cloud infrastructure & authentication — the Base44 platform that hosts the app, stores data, and manages user accounts and email verification.
- Payment processing — our payment provider handles checkout and subscription billing. We do not store your full card number.
- Public records providers — third-party databases queried with the name and address extracted from the ID. The specific provider is not disclosed.
- Device fingerprinting — FingerprintJS is used to generate a device identifier for abuse prevention.
- Analytics & advertising — Google Ads and analytics tools that help us measure performance and show relevant ads. See the Cookies section below.
We may also disclose information when required by law or to protect our rights, safety, or property.
6. Google Ads and Cookies
We use Google Ads to measure ad performance, including conversion tracking. Google may set cookies or use device identifiers to track conversions from ads you interact with. You can opt out of personalized advertising by visiting Google Ads Settings or aboutads.info. For more information about how Google uses data, see Google's Privacy & Terms.
7. Data Retention
Scan history is retained according to the retention preference you choose in Settings (daily, weekly, monthly, or indefinite). If you disable scan history storage, new scans are not saved. Document images are stored in private storage and may be deleted by deleting the associated scan record or your account. Account data is retained for the life of your account.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data or your entire account (available in Settings).
- Object to or restrict certain processing.
- Withdraw consent for optional processing such as location.
- Export your data in a portable format where applicable.
To exercise any of these rights, contact us using the information in section 10.
9. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Contact Us
If you have questions about this Privacy Policy or your data, you can reach us through our Contact page.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date above.