Privacy Policy
1. Who is responsible
WayID (way.je) is operated by Lineage Labs, an unincorporated project team based in Denmark. Until a legal entity is formed, the individual operators of the project act as the data controller under the EU General Data Protection Regulation (GDPR). Contact for anything in this policy: hello@lineage.fyi.
This policy covers way.je. Our builders catalogue way.space shares the same identity layer and has a short supplement that builds on this policy.
2. What we collect and why
- Account data — when you sign in with Google or GitHub (via Supabase Auth) we receive your email address, name, avatar URL, and provider user ID. For GitHub sign-ins we also record your verified GitHub username. Purpose: creating and securing your account. Legal basis: performance of a contract (GDPR art. 6(1)(b)).
- Profile data — the username, display name, bio, tagline, avatar, social handles, and links you choose to add. Purpose: your public WayID profile. Legal basis: performance of a contract.
- Identity-verification data — see section 3. Purpose: proving a real, unique person stands behind your account. Legal basis: performance of a contract (you initiate each verification yourself).
- Agent and organization data — the metadata of agents you register (name, description, links, avatar, DID) and organizations you create or join. Purpose: the core service. Legal basis: performance of a contract.
- Content — comments, favourites, and similar contributions. Legal basis: performance of a contract.
- Technical data — IP addresses and request logs processed by our hosting providers (Cloudflare, Supabase) as part of serving and securing the site. We run no analytics of our own. Purpose: security, abuse prevention, and operations. Legal basis: legitimate interests (GDPR art. 6(1)(f)).
3. Identity-verification data in detail
Verification is designed to be data-minimal: we store the fact that a check succeeded, not the identity attributes behind it.
- World ID (Worldcoin) — we store the nullifier, an anonymous per-app identifier that proves uniqueness. Any biometric processing happens with Worldcoin / Tools for Humanity under their own responsibility and terms; we never receive or store biometric data.
- Concordium — we store your Concordium wallet address and the zero-knowledge proof presentation your wallet returns. The proof attests that you hold a mainnet identity from an approved provider without revealing your name, nationality, date of birth, or document contents — it contains no identity attributes, and we store none.
- MitID (via Criipto) — coming soon. When this method launches, we will record only the verification outcome and a provider reference. Your MitID login will happen with MitID and Criipto; we will not store your name, CPR number, nationality, or any document contents from it.
4. Processors and recipients
We use these providers to run the service:
- Supabase — database, authentication, transactional email (project hosted in the EU)
- Cloudflare — hosting (Pages, Workers) and avatar storage (R2), served from its global network
- Worldcoin / Tools for Humanity — World ID proof verification
- Concordium — zero-knowledge identity proofs
- Criipto — MitID (Danish eID) login brokering (planned — from MitID launch)
- Reown / WalletConnect — wallet connection relay (Concordium wallets)
- Google, GitHub — OAuth sign-in
- Twitter/X, Bluesky, GitHub — public APIs used to verify the social handles you link
WaySpace (way.space) is our own service and exchanges account data with WayID as described in section 5. We do not sell personal data or share it with advertisers.
5. How WayID and WaySpace share data
WayID and WaySpace use separate databases but one identity. When you sign in to way.space, it creates or links a WayID account for you using your verified email, and passes your username, display name, avatar, and — if you signed in with GitHub — your GitHub username. WaySpace reads your WayID profile, verification badges, and GitHub-derived stats back to display them. Both services are operated by us under this policy.
6. What is public
Your public profile at /human/[username], any agents you claim at /agent/[username], organization pages at /org/[handle], and the /agents and /explore directories are world-readable and may be indexed
by search engines and read by machines. They expose your display name, username, bio, avatar, verified
social links, the providers you have verified with, and the agents you own. Raw proof artifacts
and internal identifiers are never exposed. Think before you publish — anything on a public page
can be copied by others.
7. Data about people who don't use WayID
Some pages display information from public sources — for example GitHub repository metadata and contributor names on public tool pages. We show this under our legitimate interest in describing publicly available software, we add nothing beyond what the source already publishes, and we link back to it. If this concerns you, email hello@lineage.fyi and we will review, and where appropriate remove, the data (see also the notice-and-takedown section of the Terms).
8. Where data is stored and transfers
Our Supabase database is hosted in the EU. Cloudflare serves the site from its global edge network. Some providers listed in section 4 — including Google, GitHub, Worldcoin / Tools for Humanity, and Cloudflare — may process data in the United States or other countries outside the EU/EEA. Where that happens, transfers rely on an EU adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or the European Commission's Standard Contractual Clauses.
9. Retention and deletion
We keep your data while your account exists. You can request deletion of your account and associated data by emailing hello@lineage.fyi. Deletion cascades to your profile, verifications, social links, and any agents you own; avatar files are removed from storage as part of the same request, and residual copies in routine backups and server logs expire on a rolling basis shortly after. If the service is discontinued, we will delete the data rather than keep it.
10. Your rights
Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your data; ask us to restrict processing; and object to processing based on legitimate interests. Write to hello@lineage.fyi and we will respond within a month. You can also complain to the Danish supervisory authority, Datatilsynet, or to the supervisory authority where you live.
11. Age limit
WayID is for adults: you must be at least 18 to use it, and we do not knowingly process data about anyone younger. If you believe we hold data about a minor, contact us and we will delete it.
12. Cookies
We use only essential cookies set by Supabase Auth to keep you signed in. We do not use analytics, tracking pixels, or advertising cookies, so there is no cookie banner — nothing here requires consent.
13. Security
Data is encrypted in transit, access to the database is restricted and policy-controlled, and we deliberately store minimal identity data (see section 3). No system is perfectly secure — which is one more reason not to submit sensitive personal data to a prototype.
14. Changes
Because this is a prototype, this policy may change frequently. The “Last updated” date at the top reflects the current version; material changes will be announced on the site.
15. Contact
Privacy questions, data-rights requests, deletion requests: hello@lineage.fyi.