This Privacy Policy and Notice covers Seventh Sense AI's own processing of your personal data in operating the SenseCrypt Authenticator App and Portal. Where you sign in to a Relying Party's service through the App, that Relying Party's own privacy notice governs how it processes your data as data controller.
1. Introduction
1.1 We are Seventh Sense Artificial Intelligence Private Limited, a company incorporated in Singapore with our registered office at 36 Robinson Road, #20-01, Singapore 068877 (“Seventh Sense AI”, “we”, “us” or “our”). We develop and operate the SenseCrypt Authenticator — a biometric authentication platform consisting of:
- A consumer mobile application (“App”) available on Android and iOS;
- A cloud-hosted SaaS portal (“Portal”) available at https://app.sensecrypt.com/ through which users register and manage their OIDC and SAML authentication clients; and
- A Face-Token Minter (“Minter”) that can be hosted by Seventh Sense AI.
1.2 This Privacy Policy and Notice (“Policy”) explains how we collect, use, store, share, and protect personal data when you use the App or the Portal, and sets out your rights under applicable data protection law.
1.3 By downloading, installing, registering for, or using the App or the Portal, you acknowledge that you have read and understood this Policy. If you do not agree, you must cease using our services and, where applicable, delete your account and uninstall the App.
1.4 This Policy is accessible at any time from the Settings screen of the App. It covers Seventh Sense AI's own processing of your personal data. Where you sign in to a Relying Party's service through the App, that Relying Party's own privacy notice governs how the Relying Party processes your data as data controller.
2. Legal and regulatory framework
2.1 This Policy has been adopted in accordance with our obligations under applicable privacy and data protection law, including:
- EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”);
- UK General Data Protection Regulation and UK Data Protection Act 2018 (“UK GDPR”);
- Singapore Personal Data Protection Act 2012 (“PDPA”);
- California Consumer Privacy Act 2018 as amended by the California Privacy Rights Act 2020 (“CCPA/CPRA”), for California residents; and
- Other applicable national and regional data protection laws in jurisdictions where the App is made available.
3. Your regulatory responsibilities
3.1 If you integrate SenseCrypt Authenticator to authenticate others (a “Relying Party” or “RP”), you are the data controller for all personal data processed through your integration. Seventh Sense AI acts solely as your data processor, whether or not self sign-up is enabled and whether your users are employees or consumers.
3.2 Whether an end-user privacy notice is required depends on whether you enable self sign-up for your application, not on whether your users are employees or consumers:
Self sign-up enabled: your end-users register themselves through the App. You must provide them with a privacy notice and terms of service, and register those URLs in your application settings so they are shown at the consent step (see Section 5). This applies regardless of whether those users are consumers or employees.
Self sign-up disabled: users are provisioned by you and the legal basis for processing is established through your existing relationship with them (for example, an employment or service agreement). A separate consent notice at registration is not collected through the App.
3.3 In all configurations, you remain the data controller and are responsible for obtaining any required consents or establishing another valid legal basis under applicable data protection law, including for biometric processing, before enabling authentication for your users.
3.4 IF YOU ARE UNSURE OF YOUR DUTIES AS DATA CONTROLLER, YOU SHOULD SEEK COMPETENT LEGAL ADVICE. WE ARE A TECHNOLOGY SERVICES PROVIDER AND CANNOT PROVIDE LEGAL ADVICE TO ASSIST YOUR COMPLIANCE EFFORTS.
4. Eligibility and age restriction
4.1 The App is intended for users who are 16 years of age or older. By registering for and using the App, you represent and warrant that you are at least 16 years old. We do not knowingly collect personal data from individuals under the age of 16.
4.2 If we become aware that we have inadvertently collected personal data from a person under the applicable minimum age, we will take immediate steps to delete that data and disable the relevant account. Please contact dpo@seventhsense.ai if you believe a minor has registered without proper consent.
5. Personal data we collect
We process only what is necessary to provide and secure authentication services.
A. Mobile App — end-user authentication data
| Data element | How it is stored / processed | Retention |
|---|---|---|
| Email address (login_hint) | Stored transiently in OAuthSession row (TTL 300 s); copied to ActivityEvent audit log on session termination. | OAuthSession: hard-deleted within 300 s. ActivityEvent: until you or the RP requests deletion. |
| Live face image | Captured on-device. Processed in device memory only to perform liveness detection and to decrypt the face_token. Never written to disk or transmitted to Seventh Sense AI or any third party. | Zero — discarded from device memory immediately after the authentication attempt. |
| Face-Token (sealed CBOR) | AEAD-encrypted opaque ciphertext fetched from the Portal. Used on-device as a decryption target only. The SaaS cannot decrypt it. Contains no biometric data. | Hard-deleted from OAuthSession within 300 s. |
| Expected nonce hash (SHA-256) | Stored in OAuthSession for nonce verification only. Plaintext nonce never exists on the server. | Hard-deleted with OAuthSession within 300 s. |
| Device public key (ECDSA-P256) | Stored in device_keys table. Used for request signature verification only. | Deleted on account deletion. |
| Device UUID (client-generated) | Stored in devices table. Not linked to any hardware identifier. | Deleted on account deletion. |
| Push notification token (fcm_token, push_platform) | Stored in devices table. Used to deliver authentication and security notifications to your device via Google Firebase Cloud Messaging (FCM). | Deleted on account deletion. |
| Authentication events (event type, fail reason, latency, email) | Stored in append-only activity_events audit log. | Until you or the RP requests deletion (see Section 9). |
B. Mobile App — registration and self sign-up data
The App collects your email address to create and identify your account. Email is the only profile field the App requires for its own purposes.
Where a Relying Party enables self sign-up, the App may present additional registration fields and a consent step. Those fields are configured, determined, and governed by the Relying Party as data controller — not by Seventh Sense AI. The App displays the Relying Party's own terms of service and privacy notice at the consent step, records your acceptance on the Relying Party's behalf, and transmits the information you provide to the SaaS for the Relying Party. What is collected in that flow, and how it is used, is described in the Relying Party's privacy notice, which is shown to you before you provide any such information. We act only as a processor for that data.
| Data element | How it is stored / processed | Retention |
|---|---|---|
| Email address | Stored in identities table. Used as the sole account identifier. | Deleted on account deletion. |
| Relying Party self sign-up fields and consent record | Where a Relying Party enables self sign-up, the App relays the fields the Relying Party has configured and records your acceptance of the Relying Party's terms and privacy notice, together with the version accepted, on the Relying Party's behalf. These fields are governed by the Relying Party's privacy notice. We process them only as a processor. | Deleted on account deletion or per the Relying Party's instruction. |
| Registration / restore tokens | Short-lived tokens (TTL 300 s). Hard-deleted by sweeper after expiry. | 300 s maximum. |
| PIN codes (6-digit OTP) | Stored as a hash; delivered by email via Amazon SES. TTL 600 s. Consumed on first use. | 600 s maximum. |
| Device restore notification | Email sent via Amazon SES when an identity is restored on a new device. | Not stored in our database. |
6. Special notice: biometric data
6.1 The SenseCrypt Authenticator uses facial biometrics as the authentication factor. This section explains how face data is handled at every stage.
How the App processes your face
When you authenticate, the App activates your device camera to capture a live facial image. This image is processed entirely in memory on your device by the SenseCrypt mobile SDK, which performs liveness detection and uses the image as a cryptographic decryption key to unlock a sealed authentication token (the face_token) fetched from the Portal. Once the decryption attempt is complete — whether successful or not — the live face image is immediately discarded from device memory. It is never written to disk, never stored, and never transmitted to Seventh Sense AI or any third party.
The face_token is an AEAD-encrypted opaque ciphertext. It flows from the Portal to your device — your face is used to open it on-device, not to generate something sent to a server. No biometric data, biometric template, facial geometry, or facial feature vector is transmitted in any direction.
Where your face image is processed depends on how you enrol
SenseCrypt converts a face image into a sealed authentication token (the face_token) using the Face-Token Minter, a firewalled service operated by Seventh Sense AI. The Minter detects a single face in the image and generates the sealed token, which is cryptographically bound to the relevant organisation and contains no reconstructable biometric data. The Minter keeps no database of its own.
Self-enrolment through the App. When you enrol yourself through the App, your face image is captured and the token is minted on your own device. Only the sealed token is uploaded — your face image is not transmitted to Seventh Sense AI and never leaves your device.
Administrator provisioning. When a company administrator provisions your account by uploading a reference photo through the management portal, that image is transmitted to Seventh Sense AI's Minter solely to generate the sealed token. It is processed in memory only, is never written to disk, and no face image is stored by Seventh Sense AI. Only the resulting sealed token is retained.
In both cases, Seventh Sense AI stores no face image, biometric template, or facial-feature data — only the sealed token, which cannot be reversed to reconstruct a face.
Summary
| Question | Answer |
|---|---|
| Is the live face image (from the App) retained? | No. Processed in device memory only and discarded immediately. Never written to disk or transmitted. |
| Is the live face image transmitted to Seventh Sense AI? | No. It never leaves your device. |
| When you self-enrol through the App, does any face image reach SSAI? | No. The token is minted on your device and only the sealed token is uploaded. |
| When an administrator provisions you by uploading a photo, is that image stored? | No. It is processed in memory only to generate the sealed token, is never written to disk, and no face image is retained. |
| What is the face_token? | An AEAD-encrypted opaque ciphertext. Contains no raw biometric data and cannot be reverse-engineered to reconstruct facial features. |
| Do any third parties receive face data? | No. Neither the live face image nor the reference face image is shared with any third party. |
| Is face data used for profiling, surveillance, or recognition? | No. Used solely for the single authentication attempt and discarded immediately. |
6.2 Seventh Sense AI does not sell, lease, trade, or otherwise profit from biometric data.
6.3 Where biometric data is processed, the RP as data controller is responsible for obtaining valid consent or establishing an appropriate legal basis under applicable data protection law before enabling authentication for their end-users.
7. How we use personal data
We process personal data only for the purposes below and only to the extent necessary to provide authentication services.
| Purpose | Data categories | Legal basis (GDPR) |
|---|---|---|
| Identity registration and device enrolment | Email address, device UUID, device public key, registration tokens, PIN codes | Art. 6(1)(b) — Performance of contract |
| Relaying self sign-up fields and consent on the RP's behalf | RP-configured fields; consent acceptance and version | Processing on behalf of the RP; the RP's own legal basis as data controller |
| Biometric authentication (per login attempt) | Live face image (on-device only, not transmitted); face_token; expected nonce hash; login_hint | Art. 6(1)(b) — Performance of contract; Art. 9(2)(a) — Explicit consent obtained by the RP |
| Authentication and security notifications | Push notification token (fcm_token, push_platform) | Art. 6(1)(b) — Performance of contract; Art. 6(1)(f) — Legitimate interests (security) |
| OTP and transactional email delivery | Email address (transmitted to Amazon SES for dispatch only) | Art. 6(1)(b) — Performance of contract |
| Audit logging of authentication outcomes | Email address, event type, fail reason, latency | Art. 6(1)(f) — Legitimate interests as instructed by the RP |
| Portal account management | Email, full name, company name, password hash | Art. 6(1)(b) — Performance of contract |
| Compliance with legal obligations | Minimum data as required by law | Art. 6(1)(c) — Legal obligation |
CCPA/CPRA (California residents): we do not sell personal information and do not share personal information for cross-context behavioural advertising.
PDPA (Singapore residents): we collect, use, and disclose personal data for the purposes described in this Policy.
8. App permissions
The App requests only the permissions strictly necessary to provide authentication services:
| Permission | Why it is needed | Does data leave your device? |
|---|---|---|
| Camera | To scan the QR code displayed by the RP's sign-in page and to capture a live facial image for on-device biometric authentication. | No. The live face image is processed in device memory only and discarded immediately. Only the authentication result is transmitted to the Portal. |
| Notifications | To deliver authentication and security notifications, such as sign-in approval prompts and account security alerts. | The notification token is transmitted to enable delivery via Google Firebase Cloud Messaging. |
| Internet | Required for network communication with the SaaS Portal. | Yes — signed authentication messages only. No biometric data is transmitted. |
No other device permissions are requested. You may manage permissions at any time through your device operating system settings.
9. Data retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy. All personal data tied to an account is deleted upon the controlling organisation actioning your erasure request on your behalf.
| Data type | Retention period |
|---|---|
| Live face image (App authentication) | Zero — processed in device memory only, discarded immediately. Never written to disk or transmitted. |
| Reference face image (RP enrolment via Minter) | Zero — processed in Minter memory only to generate the face_token; the SaaS stores no face image. |
| Face-Token (sealed CBOR) and nonce hash | 300 seconds. Hard-deleted by session sweeper. |
| PAR session | 300 seconds. Hard-deleted by sweeper. |
| Auth code | 60 seconds. |
| ID token | 600 seconds (10 minutes). |
| Access token | 3 600 seconds (1 hour). |
| Registration / restore tokens | 300 seconds. Consumed on first use. |
| PIN codes (OTP) | 600 seconds. Consumed on first use. |
| Portal session (JWT) | 1 800 seconds (30 minutes). Stateless — not persisted. |
| OAuthSession row (including login_hint) | 300 seconds. Hard-deleted by session sweeper. |
| Self sign-up fields and consent record | Until your account is deleted or per the controlling organisation's instruction. |
| Push notification token | Until your account is deleted. |
| Sign-in records (email, event type, outcome) | Retained until the controlling organisation instructs deletion or your erasure request is actioned on its behalf. |
| Identity, device, and device-key records | Deleted when the controlling organisation actions your erasure request. |
| Firebase crash reporting data | 90 days within Google's infrastructure. |
The organisation that provides your SenseCrypt access is the data controller for your account. To have your data erased, submit your request to that organisation. As its processor, Seventh Sense AI will action the deletion on its instruction, removing your identity, device, device-key, push token, self sign-up, consent, and sign-in records.
10. Third-party sub-processors
We engage the following third-party sub-processors, each bound by appropriate data processing agreements. No biometric data is shared with any sub-processor.
| Provider | Service | Data involved |
|---|---|---|
| Amazon Web Services — Simple Email Service (SES) | Transactional email — OTP codes and device-restore alerts | Email address and OTP code only. No biometric data. |
| Google LLC — Firebase Cloud Messaging (FCM) | Push notification delivery — authentication and security notifications | Push notification token and notification payload. No biometric data. |
We do not share personal data with third parties for advertising or data brokerage purposes. We do not sell personal data.
11. Cross-border data transfers
11.1 Our SaaS infrastructure is hosted on Amazon Web Services (AWS) in the European Union ([specify region — e.g. eu-central-1, Frankfurt]). Personal data you provide is processed and stored in the EU, including transactional email via Amazon SES. Certain limited personal data is also processed by the following sub-processors, which may process it in the United States or globally:
- Google LLC — Firebase Cloud Messaging: sign-in push notifications; processes your device push token.
11.2 Because our infrastructure is in the EU, personal data of EEA and UK users is not transferred outside the EEA or UK for hosting. Where limited data is transferred to a sub-processor in the United States (Google), we rely on the EU Standard Contractual Clauses and, for UK data, the UK IDTA or Addendum. For users outside the EEA or UK (for example, Singapore), personal data is processed and stored in the EU under contractual safeguards consistent with PDPA transfer-limitation obligations. Device-integrity checks (Apple App Attest and Google Play Integrity) transmit limited technical signals to Apple and Google as platform providers solely for anti-fraud verification; these are not used for tracking or advertising.
11.3 You may request details of the relevant transfer mechanism from the organisation that provides your SenseCrypt access, or from dpo@seventhsense.ai.
12. Your rights
SenseCrypt Authenticator verifies you on behalf of the organisation that provides your access — your employer, or the service where you signed up. For your personal data, that organisation is the data controller and Seventh Sense AI acts as its data processor. You therefore exercise your rights with that organisation, and we support it in fulfilling your request. Its privacy notice — shown to you at sign-up where self-registration is used — tells you how to contact it.
| Right | How to exercise |
|---|---|
| Access, rectification, erasure, restriction, portability, objection | Submit your request to the organisation that provides your SenseCrypt access (the data controller). As its processor, Seventh Sense AI will act on that organisation's instruction — including deleting your identity, device, and sign-in records on an erasure request. |
| Withdraw consent (biometric) | The controlling organisation manages consent for biometric processing. You may withdraw at any time via that organisation, and you may stop using and uninstall the App. |
| CCPA/CPRA rights (California) | Submit requests to the business you interact with (the controller). Seventh Sense AI acts as its service provider and does not sell or share personal information. |
| PDPA rights (Singapore) | Contact the controlling organisation. Seventh Sense AI acts as its data intermediary and assists with access and correction. |
If you are unsure who your controller is, or you have a question about how Seventh Sense AI processes data as a processor, contact dpo@seventhsense.ai and we will direct your request to the right organisation.
13. Security of personal data
Key technical safeguards include:
- AEAD encryption of the face_token with AAD binding to the recipient — the token cannot be re-used for a different identity;
- ES256 signed ID tokens; Argon2id hashing for client secrets and Portal User passwords;
- No face image or biometric template is stored by the SaaS; only the sealed face_token is retained;
- We verify that the App is genuine and unmodified before processing authentication requests, to prevent abuse. This check does not retain a device identifier and is not used to track you;
- All data in transit is protected by TLS 1.2 or higher; and
- Exact redirect_uri matching to prevent OAuth redirect attacks.
We have procedures in place to detect, investigate, and report personal data breaches. Where required by law we will notify the relevant supervisory authority and affected data subjects within the legally required timeframe.
15. Cookies
The Portal uses a signed HTTP-only cookie for session management (HS256 JWT, TTL 1 800 s). This is a strictly necessary cookie required for Portal login. The mobile App does not use browser cookies.
16. Children's privacy
The App and Portal are not directed to children under the age of 16. We do not knowingly collect personal data from children. Contact dpo@seventhsense.ai if you believe a minor has registered without proper parental consent.
17. Changes to this privacy policy
We may update this Policy from time to time. When we make material changes we will notify you by displaying a prominent notice within the App and updating the Effective Date. Continued use of the App or Portal after a revised Policy comes into effect constitutes acceptance of the changes.
18. Contact information and complaints
For any queries, rights requests, or complaints, please contact our Data Protection Officer:
Seventh Sense Artificial Intelligence Private Limited
36 Robinson Road, #20-01, Singapore 068877
Email: dpo@seventhsense.ai | Website: www.seventhsense.ai
- EEA and UK Users: you may lodge a complaint with your local supervisory authority. The UK supervisory authority is the ICO at ico.org.uk (telephone: 0303 123 1113).
- Singapore Users: you may lodge a complaint with the PDPC at pdpc.gov.sg.
- California Users: you may contact the CPPA at cppa.ca.gov or email dpo@seventhsense.ai.
Google Play Store — data safety disclosure summary
All data is collected solely to provide biometric authentication services. No data is collected for advertising or sold to third parties. No biometric data is shared with any third party.
| Data type | Collected? | Shared? | Purpose | Deletion |
|---|---|---|---|---|
| Email address | Yes | Yes — AWS SES (OTP dispatch only); ActivityEvent accessible to RP | Authentication; account management; OTP delivery | Delete account in App settings |
| Name | Yes — if RP enables self sign-up | No | Self sign-up profile (on RP's behalf) | Delete account in App settings |
| Phone number | Yes — if RP enables it in self sign-up | No | Self sign-up profile (on RP's behalf) | Delete account in App settings |
| Physical (postal) address | Yes — if RP enables it in self sign-up | No | Self sign-up profile (on RP's behalf) | Delete account in App settings |
| User IDs (device UUID, device public key) | Yes (client-generated) | No | Device binding; authentication | Delete account in App settings |
| Photos / Images (live face) | No — processed in device memory only; never stored or transmitted | No | N/A | N/A |
| App activity / auth events | Yes | Yes — accessible to RP as data controller | Authentication audit | Delete account in App settings |
| Financial info | No | No | N/A | N/A |
| Location | No | No | N/A | N/A |
| Advertising identifiers | No | No | N/A | N/A |
Push notifications: the App uses Google Firebase Cloud Messaging to deliver authentication and security notifications. The notification token is a device messaging identifier, not an advertising identifier, and is not used for tracking.
Security practices: data is encrypted in transit using TLS 1.2+. The live face image is processed in device memory only and is never stored or transmitted. The face_token is AEAD-encrypted opaque ciphertext containing no biometric data. Users can delete all personal data by deleting their account in App settings.
Apple App Store — privacy nutrition label summary
Data used to track you
None. SenseCrypt Authenticator does not track you across applications or websites owned by other companies and does not use personal data for targeted advertising. No advertising identifiers are collected.
Data linked to you
| Apple category | Specific data | Purpose |
|---|---|---|
| Contact Info | Email address | Authentication; account management; OTP delivery |
| Contact Info | Name (if RP enables self sign-up) | Self sign-up profile, on the RP's behalf |
| Contact Info | Phone number (if RP enables it in self sign-up) | Self sign-up profile, on the RP's behalf |
| Contact Info | Physical address (if RP enables it in self sign-up) | Self sign-up profile, on the RP's behalf |
| Identifiers | Client-generated device UUID; device public key | Authentication; device binding |
| Identifiers | Push notification token | Delivery of authentication and security notifications |