Legal

Privacy Policy — LutraID Wallet

LutraID Wallet is a local-first digital identity wallet. Your credentials, keys, and personal data live on your device — not on our servers.

Effective date: 2026-08-06 · Provider: Lutra Labs (info@lutralabs.io) · Application: LutraID Wallet (iOS + Android)

This policy covers the LutraID Wallet mobile app; for the id.lutralabs.io website, which does use self-hosted analytics, see the website privacy notice.

1. What we collect on our servers

Nothing.

Lutra Labs does not operate any backend that receives, stores, or processes data from the LutraID Wallet app. We do not run analytics, crash-reporting telemetry, advertising SDKs, or remote logging. The app does not phone home.

2. What the app stores on your device

All data lives in encrypted on-device storage and never leaves the device unless you explicitly initiate a credential issuance or presentation flow.

WhatWhereEncrypted by
Verifiable credentials (SD-JWT VC, mdoc)Askar encrypted SQLite databaseAskar key derived from a device secret
Cryptographic keys (issuance + presentation key pairs)iOS Secure Enclave / Android Keystore (hardware-backed where available)OS keystore
App settings (language, locale)App sandbox preferencesApp sandbox isolation
Wallet unlock stateOS keychainOS keychain

You can delete all of this at any time by uninstalling the app. There is no “delete my data” request to file with us, because we never had it.

3. Camera

The app uses the device camera solely to scan QR codes for OpenID for Verifiable Credentials (OID4VC) flows — credential offers from issuers, presentation requests from verifiers, and similar.

  • The camera frame buffer is processed on-device only.
  • Frames are not recorded, not uploaded, and not retained beyond the moment of decoding.
  • We do not access the camera in the background.
  • The decoded QR string (a URL like openid-credential-offer://...) is then handled by the OID4VC flow. See §5.

You can revoke camera permission at any time in your device’s system settings; the app will simply prompt you again next time you try to scan.

4. Biometrics (Face ID / Touch ID / fingerprint)

The app uses biometric authentication to unlock your wallet. Biometric data is handled entirely by the operating system (iOS Face ID / Touch ID, Android BiometricPrompt). The app never sees, receives, or stores fingerprint scans or face templates — it only receives a yes/no signal from the OS that authentication succeeded.

5. Network communication during OID4VC flows

When you choose to receive a credential or present one, the app communicates directly with the issuer or verifier you chose — not with Lutra Labs. We are not a relay.

These flows are governed by open standards:

  • OpenID for Verifiable Credential Issuance (OID4VCI) — when receiving a credential.
  • OpenID for Verifiable Presentations (OID4VP) — when presenting a credential.
  • SD-JWT VC and ISO mdoc credential formats.
  • Self-Issued OpenID Provider v2 (SIOPv2) — for some authentication flows.

What happens during these flows:

  • The app sends and receives data only with the URL embedded in the QR code or deep link you scanned/clicked. You see this URL before any data is exchanged.
  • The data exchanged is the credential payload, cryptographic proofs, and protocol metadata required by the standards above. It is whatever the issuer/verifier requested and you approved.
  • Lutra Labs has no visibility into these requests or responses.

Each issuer and verifier has its own privacy policy, governed by its own jurisdiction. You are the data subject and you control what information you approve before it is sent.

6. Network communication outside OID4VC flows

The app also performs the following non-flow network requests:

  • Trust list / metadata fetches — to validate that an issuer or verifier is on a recognized trust list. These requests go directly to the trust-anchor URL configured in the app, not to Lutra Labs.
  • Operating system requests — push notification registration, app update checks, etc. — handled by the OS, not the app.

The app does not make requests to ad networks, analytics providers, or third-party SDKs.

7. Third-party services

The app does not bundle any third-party analytics, crash-reporting, or advertising SDKs. The only “third parties” you interact with are issuers and verifiers that you choose, by scanning their QR code or following their deep link.

The app’s underlying open-source components are software libraries, not data processors.

8. Children

LutraID Wallet is not directed at children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect data from children. Because we collect no data at all, this section is largely a formality, but the app is intended for users old enough to manage their own digital identity.

9. Your rights

Because we do not collect or process your personal data on our servers, most rights granted by GDPR, CCPA, and similar laws (access, rectification, erasure, portability, objection) are technically inapplicable — there is no Lutra Labs–held data to exercise them against.

For data on your device:

  • Access / portability — your credentials are exportable via the app’s UI (where issuers permit it).
  • Erasure — uninstalling the app removes all locally stored data. There is no cloud copy held by us.
  • Rectification — credential contents are issued by issuers; corrections must be requested from the relevant issuer.

To exercise rights against an issuer or verifier you interacted with, contact them directly — we cannot act on their data on your behalf.

10. Security

The app uses:

  • Hardware-backed cryptography (Secure Enclave on iOS, StrongBox / TEE on Android where available) for credential signing keys.
  • Encrypted local storage (Askar) for credentials.
  • Biometric unlock (optional) layered on top of OS-level device unlock.
  • TLS for all outbound HTTPS connections to issuers and verifiers.

We follow modern OpenID Foundation and IETF specifications for OID4VC, including issuer authentication, holder binding, and DPoP/proof-of-possession where required.

No system is perfectly secure, and we cannot guarantee that your device, OS, or the issuers/verifiers you choose to interact with are free of vulnerabilities.

11. Changes to this policy

We may update this policy as the app evolves (new features, new credential formats, new platform integrations). Material changes will be reflected in the Effective date at the top and announced in the in-app changelog when relevant. The current version is always available at the URL listed in the Play Store and App Store listings.

12. Contact

Questions, concerns, or rights requests:

Lutra Labs
Email: info@lutralabs.io

We aim to respond within 30 days.