Privacy policy · evID

evID reads your document. It keeps nothing.

evID works on your device and almost entirely offline. It has no accounts, no advertising and no tracking, and ALBeID OÜ collects no personal data through it. evID itself never sends the data read from a document to ALBeID OÜ or anyone else, and stores nothing about you or the documents it reads.

Version 1 · In force since 9 October 2026

In short

Personal data collected by ALBeID OÜ
None
Document data stored
None
Data shared or sold by ALBeID OÜ
None
Passed to other apps
Only to ALBeID apps on the same device, with your approval each time
Tracking or advertising
None
Third-party code
Only Google ML Kit, on Android, for the optional camera scan
Account required
No
Stored on the device
Only the trust lists you download or import

What evID is

evID is a utility app for reading and validating the electronic chip of identity documents (passports and ID cards) that follow ICAO Doc 9303, also known as eMRTDs. It reads only the electronic content stored on the chip, through a reader built into or attached to the device it runs on.

evID is published by ALBeID OÜ, registry code 16874333 in the Estonian e-Business Register. It runs on Android, iOS, iPadOS, macOS, Linux and Windows.

How a document is read

A document chip opens only with an access key printed on the document itself: the machine-readable zone (MRZ) or the card access number (CAN). You can type the key in, or scan the MRZ with the device camera. Scanning is optional on every platform, and typing always works. evID uses the camera image only to read those characters, and does not itself save it or send it anywhere. How the characters are recognised depends on the platform:

  • iOS, iPadOS and macOS: Apple's Vision framework, the text recognition built into the operating system.
  • Windows and Linux: Tesseract, an open-source recognition engine included in the app, which works entirely offline.
  • Android: Google's ML Kit text recognition. ML Kit sends Google technical data about its own use, such as the device model, operating system version, app name and version, installation identifiers, performance metrics and error codes, for diagnostics and usage analytics. Google's disclosure does not list the camera image or the recognised text among this data. Each time you choose to scan, evID first shows a notice explaining this and offers you the option to type the key instead. If you type it, no scan takes place.

Anything the operating system itself does with the camera is governed by its maker's privacy policy, as it is for every app that uses the camera.

On Android, the camera scan relies on your consent, given each time in the notice shown before scanning (Article 6(1)(a) GDPR). You can withdraw it at any time by simply typing the key instead. The data ML Kit sends goes to Google LLC, which processes it under its own privacy policy and may transfer it to the United States under the EU–US Data Privacy Framework. ALBeID OÜ never receives it. Questions or requests about that data can also be addressed to Google.

evID then reads the data the issuing authority stored on the chip. Depending on the document, this can include the holder's name, nationality, date of birth, document number, validity dates and facial image. This data is kept in the device's memory only while it is displayed and validated. It is never written to storage. evID itself never sends it to ALBeID OÜ or anyone else, except by handing it to another app at your request, as described below. It is discarded when the reading session ends.

Validation

evID checks the chip's content and signatures according to the ICAO Doc 9303 specifications and the technical guidelines of the German Federal Office for Information Security (BSI). It follows these specifications but does not endorse them, and it does not claim certification by ICAO, the BSI or any other body. The result is a technical check of the chip's content. How you use it is at your sole discretion.

The only two connections outside your device

Apart from ML Kit on Android, described above, evID communicates with something outside the device in exactly two cases, and in both only with your permission.

1. Downloading trust lists

To verify the signatures on a chip, the app needs the certificates of the Country Signing Certificate Authorities (CSCAs) and their certificate revocation lists (CRLs). ALBeID OÜ assembles these lists and publishes them on its website. When you allow it, evID downloads them over HTTPS. The request contains no personal data and no data from any document. The website's server may keep standard technical logs of the request, as described in the website privacy policy.

The downloaded lists are stored on the device so that they do not have to be downloaded again each time. Trusting them is your decision: you can replace them at any time with lists you obtain from sources you trust.

2. Acting as a proxy for another device

A device without a suitable reader can ask another device running evID to read a document on its behalf. The device asked to help acts only if its user allows it. The two devices connect over a secured Bluetooth connection, with no internet involved. The access key is entered on the requesting device, which opens the encrypted session with the chip itself. The helping device only passes the requesting app's commands to its reader and the chip's responses back. These exchanges are encrypted between the requesting app and the chip, so the helping device cannot read them, and it does not store anything it relays.

evID makes no other connections. Apart from ML Kit's technical data on Android, it sends no usage statistics and no crash reports.

Reading on behalf of another app

evID can read a document on behalf of another app published by ALBeID OÜ and installed on the same device, such as a digital identity wallet. Only apps signed by ALBeID OÜ and belonging to the same app group can make such a request, and the app group enforces this restriction. The request is made with your consent in the requesting app, and evID asks for your approval again each time before reading. evID then passes the data read from the chip directly to that app, within the device. Because the receiving app is published by ALBeID OÜ itself, the data does not go to a third party. evID itself still stores nothing and sends nothing over the internet. What the receiving app does with the data, including any verification with a server, is governed by that app's own privacy policy.

Reading someone else's document

If you use evID to read a document that belongs to another person, for example at a reception desk or in an office, the app still keeps nothing. What you do with the data shown on your screen, however, is your responsibility. If your use falls under data protection law, you are the one who needs a lawful basis for it and who must inform the document holder.

Permissions

evID asks only for the permissions it needs, each for one purpose:

  • NFC or smart-card reader (USB or built-in): to read the document chip.
  • Camera, optional: to scan the MRZ instead of typing it. On Android, the scan uses Google ML Kit, as described above.
  • Bluetooth, optional: only for the proxy connection between two devices running evID.
  • Network: only to download trust lists.

You can refuse or withdraw any of these permissions at any time in your device's settings. The app keeps working for everything that does not depend on the permission withdrawn.

What is stored, and how to delete it

The only things evID stores are the trust lists you download or import. Nothing about you or the documents you read is stored. There is no account, so there is no account to delete. Uninstalling the app removes everything it stored.

App stores and operating systems

Apple, Google, Microsoft and Linux distributions handle app downloads and updates under their own privacy policies. If you have chosen in your device settings to share diagnostic data with app developers, the store may pass ALBeID OÜ anonymous crash reports. evID adds nothing to them.

Children

evID is not directed at children. Since it collects no personal data from anyone, it collects none from children either.

Security

The strongest protection is not to collect data at all. Beyond that, the chip is accessed through the protocols defined by ICAO, trust lists are downloaded over HTTPS, and the proxy connection between two devices is secured. Through the proxy, the chip's data stays encrypted end to end between the requesting app and the chip.

Your rights

Under the General Data Protection Regulation (GDPR) you have the right to access the personal data held about you, and to ask for it to be corrected, erased or restricted, or to object to its processing. ALBeID OÜ holds no personal data from evID, so there is normally nothing to return or delete, but you are always welcome to ask. ALBeID OÜ answers every request within one month. No automated decision-making or profiling takes place. You may also lodge a complaint with the supervisory authority of the country where you live or work, or with ALBeID OÜ's lead authority, Estonia's Data Protection Inspectorate (Andmekaitse Inspektsioon).

Contact

evID is published by ALBeID OÜ, registry code 16874333. Its registered address is public in its entry in the Estonian e-Business Register. For any privacy question about evID, write to [email protected].

Changes to this policy

Every change to evID is described in the app's release notes. If a change to the app requires a change to this policy, the new policy is published as a new version, numbered and dated, and the earlier versions remain available from this page. The release notes state which version of the policy applies to each version of the app.

You are never asked to accept a new policy in order to keep the app you have. If you do not agree with a new version, you can choose not to install that update and keep using your current version of evID, under the policy you accepted.