Privacy Policy
CAGE is designed to know as little as possible.
Here is what we collect, what we refuse to collect, and what partner platforms receive when they use CAGE.
Last updated: March 2026
What we collect
- Email address, used for magic-link login and never shared with partners
- Age verification result: 18+ or 21+, never exact age or birthday
- Verification timestamp and expiration date
- Anonymous per-partner identifiers
What we never collect
- Government ID images
- Full legal name
- Date of birth
- Facial biometric data
- Browsing history or location data
- IP addresses, except for in-memory rate limiting
No name. No address. No government ID images. No biometric data stored by CAGE.
Third-party services
Veriff
Handles identity document verification. CAGE never receives or stores the document images or selfie data.
Neon
Hosts the PostgreSQL database. Data is encrypted at rest.
Upstash
Stores temporary session and auth-code data.
Resend
Sends magic-link emails and processes email addresses for delivery.
Vercel
Hosts the frontend and may process standard CDN request logs.
Railway
Hosts the backend API infrastructure.
How long we keep data
What partners receive
- An anonymous ID unique to that partner
- A boolean age_verified claim
- An age_floor value of 18 or 21
Partners do not receive your email, name, birthday, document, or a cross-site identifier.
Your rights
You can delete your account from your dashboard at any time. Deletion removes your verification result, partner connections, and session data. For privacy questions, email privacy@cageid.app.
Browser extension
- The extension stores your session token locally in chrome.storage.local on your device only
- It does not track your browsing history
- It only activates when a partner site initiates a CAGE OAuth flow
- No data is sent to CAGE servers except during active OAuth flows
Changes to this policy
We will update this page if anything changes. Major changes will be communicated by email to registered users.