9 July, 2026
Version 1.0 | Last Updated
Privacy
Alien App Privacy Policy explains what information the App needs to function and how it’s handled. Only the minimum necessary is collected to give you the best service possible, and you stay in full control of your data.
This Privacy Policy (“Policy”) outlines how Alien (“we,” “us,” or “our”) handles your personal information when you: (1) utilize our mobile application (the “App”), and (2) interact with us through various channels including email, messaging platforms, or face-to-face meetings (collectively, “Interactions”). This Policy should be read in conjunction with our Terms of Use, which govern your use of the App.
1. To use the App, you share the following information
The App is designed to connect users on the Alien network. We process data you voluntarily submit while using the App’s features. Additionally, device-specific data is processed to enable App functionality. Information shared during direct Interactions is also processed.
Here’s what you share with us: your name and selfie image, your mobile phone number, phone numbers from your device contact list (with your permission, as described in Section 3), and any other contact details you want to share, logs of how you interact with the App, and any other content you choose to provide while using the App or communicating with us.
Here’s what the App collects automatically: device type, operating system, unique device identifiers, advertising identifiers (such as IDFA or Advertising ID), and diagnostic data such as crash logs. This data helps keep the App secure, stable, and supports advertising as described in Section 7.
2. Biometric Data Consent and Usage
The App uses video recordings to create facial recognition identifiers and to train machine learning models. You have control over how your biometric data is used:
2.1 If You Do Not Provide Consent for Biometric Data Retention
If you choose not to consent to biometric data retention, your video recordings will be processed solely to create your facial recognition identifier. Once the identifier is generated, the video recordings will be immediately and permanently deleted. Only the facial identifier (not the raw video data) will be retained for App functionality.
2.2 If You Provide Consent for Biometric Data Retention
By providing explicit consent, you allow Alien to collect, store, and process your video recordings for the following purposes:
Training and improving machine learning models for video-based face recognition
Developing and refining our facial recognition technology
Your biometric video data is protected according to applicable biometric privacy laws and data protection standards. Video recordings will be retained for a maximum period of one (1) year from the date of collection, after which they will be permanently deleted unless you provide renewed consent or legal obligations require extended retention.
2.3 Withdrawal of Consent
You may withdraw your consent at any time by contacting us at the email address provided in Section 14. Upon withdrawal of consent, your video recordings will be deleted within thirty (30) days, subject to any legal retention requirements. Your facial recognition identifier will remain to maintain App functionality unless you request full account deletion.
3. Contact Data and Social Graph Verification
The App requests access to your device contact list to support the Collaborative Human Verification Protocol (CHVP) — an open protocol for verifying that each user on the Alien network is a unique human being on an ongoing basis. Verification requires a complete social graph built from contact relationships across the network. You can learn more about CHVP at alien.org/blog/chvp-1.
3.1 What We Collect
When you grant the App permission to access your contacts, we collect only phone numbers from your device contact list. We do not collect contact names, email addresses, physical addresses, photos, or any other contact fields.
3.2 How Contact Data Is Protected
Your contact data is stored in encrypted form and is never publicly accessible. Phone numbers from your contact list are also converted into irreversible cryptographic hashes, each tied to a unique key specific to your account. The original phone numbers cannot be recovered from these hashes.
All social graph processing takes place inside Frame Private Compute — Alien’s infrastructure built on Trusted Execution Environments (TEEs). A TEE is an isolated, hardware-secured environment where data remains shielded from access or modification, even by the owners of the underlying hardware. The system is designed so that no person or entity — including Alien’s developers, operators, and infrastructure providers — has access to your raw contact information.
The code running inside each Frame is publicly verifiable: its hash is registered on-chain and signed by a trusted auditor. You can independently verify Frame attestations at alienscan.org.
On the blockchain, only cryptographic hashes are recorded — never raw phone numbers. The contact data itself is kept in encrypted storage accessible only within the TEE. Outside the TEE, only cryptographic proofs are available, not the underlying data.
3.3 Withdrawal and Deletion
You may revoke the App’s access to your contacts at any time through your device settings. You may also request deletion of your contact data by contacting us at the email address provided in Section 14. Upon such a request, encrypted contact data will be deleted within thirty (30) days, subject to any legal retention requirements. Cryptographic hashes recorded on the blockchain cannot be removed due to the immutable nature of blockchain technology; however, these hashes are irreversible and cannot be used to recover the original phone numbers. Note that revoking contact access or deleting contact data may affect the App’s ability to verify your uniqueness on the network.
4. Card Service Data
If you request the Alien Card, some of your data is processed so the card can be issued and operated. In plain language: the card is issued by our partner Wirex, so verifying you and running your card involves sharing certain data with Wirex and its providers.
Identity verification (KYC). To issue a card, Wirex must verify your identity. Verification is performed by Wirex through its verification provider, Sumsub. Alien receives the outcome and status of that verification (for example, whether you passed, or a date after which a card is blocked because a document expired) — Alien does not receive or store your underlying identity documents.
Contact details. To set up and run your card, we also share the contact details you gave us — your email address and the phone number you verified when you signed up — with Wirex. Wirex uses them to manage your card account, confirm it’s you, send you security codes (for example, the one-time code to approve a payment), and contact you about your card.
What is shared and with whom. For the card service, the following may be shared between Alien, Wirex, the regional card issuer, the Visa network, and Sumsub: your identity and verification data, your contact details (email and verified phone number), your card and transaction data, and device information. This data is used to issue the card, process and authenticate payments, prevent fraud, and meet legal, anti-money-laundering, and card-scheme obligations.
Retention. Where identity verification is performed by Wirex, Wirex retains the associated verification data in line with its legal obligations. Card and transaction data are retained as required for the card service and by law.
Cross-border. Card data may be processed outside your country, including by Wirex’s entities. Wirex processes personal data as an independent controller under its own Privacy Policy; Sumsub processes verification data under its policy notice.
5. Information Processing Methods
Your data reaches us through three channels: (1) direct submission when using the App or engaging in Interactions; (2) automated capture via technological tools during App usage; and (3) external sources.
Direct Submission: Data is processed when you input information into the App, establish an account, utilize our features, access content, or engage in Interactions.
Automated Processing: During App usage, information may be automatically processed through tracking technologies and system logs.
External Sources: Data is obtained from partner organizations, public databases, and vendors supporting our operations.
6. Data Usage Purposes
Your personal data enables the App to:
Deliver and administer App features and services
Enable account registration and access
Address inquiries and resolve complaints
Establish communication channels with you
Execute and support transactions and services
Safeguard accounts through security measures like two-factor authentication
Detect and prevent policy violations and security threats
Protect accounts and the Alien network from fraudulent or abusive activity
Evaluate user patterns and App performance metrics for optimization
Share relevant product information and promotional opportunities, including third-party offers where you’ve granted permission
Fulfill legal obligations, protect our rights, and respond to legal proceedings when required
Deliver targeted advertising: device identifiers may be used to measure ad performance and deliver relevant advertising through third-party advertising partners
Send one-time SMS verification codes to the phone number provided during registration solely to confirm account access. These messages are transactional and are never used for promotional purposes
Build and maintain a social graph from contact relationships to verify that each user is a unique human being through the Collaborative Human Verification Protocol (CHVP), as described in Section 3
Enable issuance and operation of the Alien Card, including identity verification, payment authentication, and fraud prevention, through our partner Wirex and its providers
Anonymized, aggregated, or de-identified information may be utilized for any lawful purpose. For details on your control over data usage, refer to Section 9.
7. Information Sharing Practices
Your information is disclosed only under these circumstances:
Authorized Disclosure: Information sharing occurs with your explicit consent, obtained through written agreements, digital acceptance, App terms acknowledgment, verbal authorization, or other consent mechanisms.
Corporate Transactions: Data may be transferred during business events such as mergers, acquisitions, joint ventures, corporate restructuring, asset sales, or in cases of insolvency, bankruptcy, or receivership proceedings.
Service Partners: Information is shared with external organizations that facilitate App functionality and business operations, including brand collaborators, internet infrastructure providers, advertising platforms, analytics services, operating systems, social platforms, and vendors providing customer support, marketing, technical maintenance, and security services.
Legal Requirements: Data may be disclosed to comply with legal obligations, regulations, legal proceedings, or governmental demands, and when we reasonably believe such disclosure is necessary to: (1) enforce our agreements; (2) safeguard our interests, assets, or the safety of others; (3) address claims or disputes; and (4) protect the App’s integrity.
Advertising Partners: Device identifiers (such as Advertising ID and IDFA) are shared with Meta Platforms, Inc. for advertising purposes, including ad delivery, and optimization.
Card Partners: where you use the Alien Card, identity, card and transaction data is shared with Wirex, the regional card issuer, the Visa network, and the identity-verification provider (Sumsub), so the card can be issued, operated, authenticated, and kept compliant with law and card-scheme rules.
Contact data is never shared with third parties. Social graph processing occurs exclusively within the Trusted Execution Environment as described in Section 3.
8. Third-Party Services
The App may connect with external websites and services provided by third parties (“Third-Party Services”) operating independently with their own terms and privacy practices. Users should review the applicable policies governing Third-Party Services before submitting data. This Policy applies solely to the App, not to Third-Party Services.
9. User Rights and Controls
9.1 Account Management
You may review, modify, or delete information through your account settings or by contacting us at the email provided in Section 14. Identity verification may be required. Note that certain information will be retained as necessary for legal compliance, dispute resolution, and agreement enforcement.
9.2 App Controls
Tracking Signals: We do not respond to “Do Not Track” browser signals. Additional information available at http://www.allaboutdnt.com
App Access: You can halt all data collection by uninstalling the App.
9.3 Communication Preferences
Email Communications: Opt out of promotional messages by clicking unsubscribe links in emails or contacting us with “UNSUBSCRIBE” in the subject line. Transactional emails regarding your account, services, or business relationship cannot be opted out of.
Push Alerts: If enabled, push notifications can be disabled through device settings or by uninstalling the App.
Opt-out preferences apply to the specific email address, device, or phone number used and don’t affect future subscriptions.
Phone numbers collected for account verification are not used to send promotional SMS messages.
10. Age Restrictions
The App targets adult users and is not designed for minors. We do not knowingly collect information from individuals under thirteen years of age.
11. Data Protection
Your data is protected by commercially reasonable security measures appropriate to your data’s sensitivity, in accordance with applicable legal and regulatory standards.
12. Data Retention: Only With Your Permission
Information is retained for the duration necessary to fulfill collection purposes, meet business requirements, and satisfy legal and regulatory obligations.
Biometric Video Data:
• With your permission: Video recordings are kept for up to one year from collection, as detailed in Section 2
• Without your permission: Video recordings are immediately deleted after creating your facial recognition identifier.Facial Recognition Identifiers: Kept as long as your account is active to make the App work.
Selfie Images: Kept as long as your account is active.
Contact Data: Encrypted contact data is kept as long as your account is active to support ongoing uniqueness verification. Raw phone numbers are never exposed outside the Trusted Execution Environment. Upon account deletion or your request, encrypted contact data is deleted within thirty (30) days. Cryptographic hashes on the blockchain are permanent but irreversible — they cannot be used to recover the original phone numbers.
Everything Else: Kept only as long as needed for the purposes described in this Policy.
Data Storage Location and Sharing: Biometric data (including selfie images, video recordings, and facial recognition identifiers) is stored on secure servers in the United States. Selfie images are stored locally on your device. Biometric data is never shared with third parties for any purpose. For users in the European Union, data transfers comply with applicable data protection frameworks including Standard Contractual Clauses to ensure GDPR compliance.
Data disposal follows secure protocols appropriate to the information type.
13. Security Warnings
Alien maintains no partnerships with entities claiming to provide customer support via email or social media in exchange for payment. If you encounter suspected fraud, phishing, or scam activity impersonating Alien, immediately contact support@alien.org
14. Contact Information
This Privacy Policy may be modified at our discretion. Users will receive notification of significant changes, and we recommend periodic Policy review for minor updates. Modifications typically result from operational, legal, or regulatory developments.
For inquiries regarding this Privacy Policy, contact us at: support@alien.org
We raised $7.1M from Initialized, Finality and others. Read more