How it works
How to get verified.
The whole thing takes one sitting. Below is every step, and then the part most companies skip: exactly what we ask for, what we keep, and what we never take in the first place.
One sitting
Start to verified. You will not be asked to come back with a document later.
Free, for you
A person never pays to be verified. Institutions license the ability to read the credential.
Once a year
The credential runs on an enforced 12 month term, then you renew. Not once per login.
The whole process
Six steps. You are verified after the fourth.
Nothing here needs a laptop, a printer, a notary or an appointment.
1
Open the app and start
No forms to fill in first. You give an email address so the credential has somewhere to live, and that is the whole setup.
Every field we ask for before the check is a field we would then have to keep. So we ask for almost nothing.
2
Photograph your ID
A driver’s licence or a passport. Incode, our identity provider, runs this check, not Fuzzy. They look at the document and confirm it is genuine.
Document checking is a specialist job with a certified stack behind it. We would rather route to people who do it properly than build a worse version.
3
Take a short live selfie
A few seconds, to prove a real person is present right now rather than a photo of one. Incode matches that against your document, at Incode. The comparison does not happen at Fuzzy and never runs against a copy we hold.
This is the step that makes the credential mean something. It is also the step where most companies quietly start a face database. We did not.
4
Your badge goes live
A page and a scannable code, at an address that is yours. Put it in an email signature, a bio, a message thread, or hold up the code in person. Anyone can check it in about a second, with no account and no app.
A credential nobody can read is not a credential. Yours has to work for the person on the other side, on the phone already in their hand.
5
Invite the people you trust
Send your badge to friends and family and ask them to get one. A credential is worth more when the person on the other side has one too, and the whole point is a network of people who can prove they are real to each other.
This step is a request, not a requirement. Nothing about your own badge depends on it. We are asking for help building the thing that makes the rest of it work.
Every person carrying one makes the next introduction easier, because the ask stops being unusual. That is not a growth tactic bolted on. It is the only way a trusted network gets built.
6
Renew once a year
The term is 12 months and it is enforced, not suggested. Coming back is a check against the credential you already have, not the whole process again.
A proof with no expiry stops being a proof. A yearly one stays true without turning your life into a checkpoint.
The handoff
Incode sees the document. We deliberately do not.
There are two companies in that flow and it matters which one holds what. The narrow thing we get back is the entire point, because a company cannot lose, leak or be compelled to hand over a field it never took.
Incode
RUNS THE CHECK
- Reads your ID document
- Runs the live selfie check
- Matches face to document, on their side
- Holds the document image and the liveness video under their own retention terms
A certified identity stack. SOC 2 Type II, ISO 27001 and FedRAMP Ready are Incode certifications, not Fuzzy’s.
What crosses to Fuzzy
A DELIBERATELY NARROW RESULT
- Your name
- City, region and country
- An 18+ signal, and nothing more precise
- The still photo, which becomes your badge photo
- Whether it cleared, and when
Not the document. Not the video. Not your date of birth.
Whoever checks you
SEES THE LEAST OF ANYONE
- That you are a verified human
- Your name and photo
- An 18+ chip, if it applies
- Nothing about your document
- No reason, ever, if a check did not clear
A category, not a document and not an image.
The middle column is the part worth pausing on. The response our provider sends can carry more than we take, including scanned fields with a name, a home address and a date of birth. Our code copies an explicit list, those fields are not on it, and a test fails the build if they ever come through. So it is not that we promise not to keep your date of birth. It is that the code that would have written it down does not exist.
Your data
The 18+ chip is the clearest example.
It is set when someone is over 18 and is otherwise simply absent. There is no list of known minors to leak, because being under 18 was never a state we recorded. A bar, a marketplace or a platform gets a yes without ever learning your birthday, and we never learned it either.
Data
What we keep. What we refuse to keep.
These are the fields people ask about most, on the member flow you just read. It is not a complete inventory, and the field-by-field list is in the technical brief instead, because a partial list published as though it were the whole one reads as a denial of everything it leaves out. We are not doing that.
What Fuzzy stores
THE FIELDS PEOPLE ASK ABOUT MOST
- Given name and family name
- An 18+ signal, established at verification
- Verification status and its dates
- City, region and country, taken from the document
- The still photo from verification, which becomes the badge photo, plus an email address
- A one-way lookup hash, so a relying party can ask about a person without naming them
On the photo, precisely. The still image from verification becomes the badge photo and the face the verified ring wraps. It is a photograph, not a faceprint: no face template is stored for a verified member, and the match runs at Incode against Incode’s own record rather than against our copy. Anyone with the badge link can load the photo, and messaging apps fetch it for link previews, which is what makes a badge readable by a person.
What Fuzzy never stores
SCOPED TO THIS VERIFICATION FLOW
- A date of birth. The column does not exist
- An ID document image or a liveness video, in our database
- A face template, from this pipeline
- Social security numbers
- Home addresses, or ID and document numbers
- A record that anyone is under 18
Two caveats we would rather state than be caught on. Database backups carry a short tail, so we will not claim a field exists nowhere on earth. And “no face templates” is true of this verification flow, not of every system this company has ever operated. The technical brief scopes both properly.
THINGS WE COULD LEAVE OUT AND ARE NOT GOING TO
DELETING YOUR ACCOUNT DOES NOT ERASE EVERY TRACE
Your identity details go. But one record per verification attempt is retained after deletion, including the identifiers our provider issued for that session. It is the basis of the categorical outcome record, and we would rather tell you it exists than let you find out. Tightening this is open engineering work, not a settled position we are defending.
WE REPORT THAT A CHECK DID NOT CLEAR, NEVER WHY
No partner, school or platform ever receives a reason. Internally, the diagnostic text our provider returns is retained on this flow, because support and dispute review need it to help someone who thinks a result was wrong. It is never surfaced on any partner or public screen, and it is never a fraud finding.
YOUR BADGE PHOTO IS PUBLIC BY DESIGN
Anyone with your badge link can load it, and messaging apps fetch it to build link previews. That is not a leak, it is the mechanism: a credential a human can read at a glance has to show a face. If you would not put the photo on a public profile, do not use it here.
WE WILL NOT TURN OFF A LIVE BADGE
Once your credential is live it stays live for its term. Where two of our own systems disagree about your status, we resolve upward or leave it alone. The single exception is ordinary expiry at the end of 12 months, and you will be told before that happens.
Reviewing us, not joining us?
There is a longer version written for security reviewers, with the field-by-field inventory, the retention detail and the parts still in progress. Ask and we will send it.