VNTXID

The VNTX ID privacy promise

Ventryx runs VNTX ID as infrastructure, not as a data business. This page describes exactly what we store, and what we refuse to store.

What we store about you

Email
to identify your account
Display name
shared with apps only if you approve the profile scope
Password
scrypt hash, never plaintext, never recoverable
App grants
which apps you approved and which scopes
Tokens
SHA-256 hashes only (not the tokens themselves)
Security events
metadata like “login happened”, purged after 30 days

What we never store

  • IP addresses: not a single one, not even in logs
  • Browser fingerprints, cookies for analytics, tracking pixels
  • Third-party requests of any kind (no CDN fonts, no external assets)
  • Where you came from or where you go after sign-in
  • Your real email: when an app requests email, it receives a per-app alias

Pairwise anonymity

Every app that you sign in to receives a different pseudonymous ID (and, if unmasked is off, a different email alias). Even a malicious pair of relying parties comparing databases can never link your two accounts. This is structural; apps cannot opt out of pairwise IDs.

Your rights

From your dashboard you can download everything we hold about you as JSON, or delete your account permanently, which instantly revokes every app's tokens. No emails to send, no forms to fill, no retention games.