Built so you share less, not more.
NoStrangers helps two people establish trust before meeting for the first time. This page explains what we collect, who processes it, how long we keep it, and what the other person actually sees.
This page is maintained by NoStrangers. It describes controls that are enabled in the app today and is not an independent security certification.
Verification providers
We do not run identity checks ourselves. Government ID checks and biometric matching are handled by specialist providers under their own security programs.
Veriff receives the ID document and selfie directly from your device. NoStrangers only receives the decision (pass/fail), the verified fields you approve (e.g. name, date of birth), and, where applicable, the reference selfie used for later face matches.
What we store
- Your account (email, plan, timestamps).
- Verification status and expiry — not the raw ID document.
- For Photos Verified: your approved album, kept in a private storage bucket with signed, short-lived read URLs.
- The Trust Requests you create or receive and the specific fields you toggled to share.
- Approximate location derived server-side from the network request (city / region / country). We never store your raw IP address and never ask the browser for GPS.
What the other person sees
Only the fields you explicitly toggle on before sending or returning a Trust Request. Everything else stays private, even if it is on your account.
Trust Request codes are single-use and expire 15 minutes after creation. A completed request cannot be replayed.
How it is protected
- Encrypted in transit (HTTPS/TLS) between your device, our backend, and every provider.
- Row Level Security on our database — each user can only read and write their own rows.
- Verification-sensitive fields on your profile can only be updated by our server, never directly by the browser.
- Album photos live in a private bucket. Access requires a short-lived signed URL scoped to the specific request.
- Face matching runs server-side against AWS Rekognition; the similarity threshold and both scores are recorded for the interaction.
Retention & expiry
- Live face confidence expires after 24 hours (Free) up to 90 days (Premium). A fresh liveness check is required after that.
- Government ID reference selfies are retained for up to 90 days to support face matching, then removed.
- Guest verification data is cleared shortly after the interaction completes.
- Completed Trust Requests keep only the fields you chose to share, so both people can still see the interaction on their history.
Your controls
- Replace or delete your verified photos from the Account page at any time.
- Delete your account to remove your profile, verification status, and album. Interaction records are anonymised for the other party.
- Contact us for a full data export or a deletion request.
Reporting a security issue
If you believe you have found a security or privacy issue, please contact us before disclosing it publicly so we can investigate and fix it.
Provider names and logos are trademarks of their respective owners and are shown here to describe the services we use.