Overview
Inspekt.ID reads and verifies the electronic chip in biometric passports and identity cards. This policy explains what happens to your document data, what we store on your device, and the limited, anonymous analytics we collect to keep the app reliable.
The short version: your document is processed entirely on your iPhone. Inspekt.ID does not operate a server that receives your document data, and no part of the verification process — camera image, MRZ text, or chip contents — is transmitted anywhere. The one exception is entirely up to you: if you use the share button to export a scan, see "Exporting Scans" below.
Document Data
When you scan a document, Inspekt.ID uses your device's camera to read the Machine Readable Zone and your device's NFC reader to communicate with the document's chip. This includes personal data stored on the chip, such as your name, date of birth, document number, and photo, along with the cryptographic material used to verify the chip's authenticity.
All of this — reading, decoding, and verification — happens locally on your device using the open-source GMRTD library. None of it is sent to Inspekt.ID, to the library's maintainers, or to any other server.
Scan History
Each scan is automatically saved to a history on your device so you can review it later. Saved scans are protected by iOS's built-in file encryption and, like your document data, are never transmitted anywhere.
You can delete individual scans from the Scan History screen, or clear your entire history from Settings, at any time.
Exporting Scans
From a scan result, you can use the share button to export that document's data — for example, to Files, Mail, or another app on your device. Exported files are not encrypted by Inspekt.ID, so once exported, handle them with the same care you would the original physical document.
Analytics
Inspekt.ID sends anonymous usage analytics via Firebase Analytics to help us understand reliability and fix problems. These events are limited to things like:
- Document type (e.g. passport or ID card)
- Scan duration
- Error codes, when something goes wrong
These events never include your name, date of birth, document number, photo, or any other data read from your document.
Third-Party Services
Chip reading and verification are performed using GMRTD, an open-source implementation of the ICAO 9303 standard that runs entirely on-device and does not transmit data on its own.
Anonymous usage analytics are processed by Firebase Analytics (Google), under Google's own privacy terms, limited to the non-identifying event data described above.
Data Retention & Deletion
Scan history remains on your device until you delete it, either scan-by-scan or all at once from Settings. Uninstalling Inspekt.ID removes all locally stored scan data along with the app.
Children's Privacy
Inspekt.ID is not directed at children, and since no document data ever leaves your device, we do not collect or have access to any personal information — from children or anyone else — through the app's use.
Changes to This Policy
If this policy changes, we'll update the effective date above and post the new version at this same address.
Contact Us
Questions about this policy or how Inspekt.ID handles data? Email support@inspekt.id.