Last Updated: July 7, 2026
At NumID, we believe your privacy is fundamental. This policy explains exactly what data we collect, how we use it, and how we protect it.
NumID collects only the minimum data necessary to provide our service:
Database: Supabase (PostgreSQL hosted on AWS) in the us-east-1 region. Data is encrypted at rest.
Vault Encryption: Your vault items are encrypted client-side using AES-256 before leaving your browser. Only you can decrypt them—NumID servers never have access to the plaintext keys.
Email Forwarding: Cloudflare Email Routing handles your incoming emails. Email headers are processed by Cloudflare's servers; we do not store the email content.
Avatars: Stored on Cloudflare R2 (AWS S3-compatible) with public read access so your profile picture displays on your public directory page.
In Transit: All communication between your browser and NumID servers uses TLS 1.3 encryption. We use HTTPS everywhere.
Data Export: You can download all your data (profile, audit logs, vault metadata) in JSON format from your dashboard.
Account Deletion: You can permanently delete your account and all associated data. After deletion, there is a 30-day grace period before permanent removal from backups.
Right to Be Forgotten: Under GDPR and similar regulations, you have the right to request erasure of your personal data. See our GDPR/Data Rights page for details.
Correction: You can update your email, name, avatar, and social profiles at any time from your account settings.
NumID relies on the following third-party services. We are not responsible for their privacy practices; please review their policies:
We only use essential cookies for:
We do not use analytics services, pixels, or third-party cookies.
NumID is committed to compliance with:
See our GDPR/Data Rights page for more information on exercising your rights.
If you have privacy questions, data requests, or concerns, contact us at:
Email: privacy@numid.dev
We commit to responding within 30 days to any privacy inquiry.