Privacy
Privacy Policy for Kantega Lommebok
This policy covers the Kantega Lommebok app for Android and iOS.
Last updated: 11 September 2026
In short
Kantega Lommebok is a demonstration app. It is not certified, and the credentials in the app are not valid identification. Do not enter real personal data into the app.
Everything the app stores stays locally on your own device. Kantega AS operates no server that receives your credentials, activity log or PIN. We cannot see them and we cannot retrieve them.
Who is responsible
Kantega AS is responsible for the app. Contact: lommebok@kantega.no.
What the app stores on your device
- Credentials you receive, including the attributes they contain (for example name, date of birth and other attributes). Cryptographic keys are held in the device's secure key store (Android Keystore).
- The name you enter during onboarding, used to create a local demo credential.
- Your PIN, stored as a one-way hash — never in clear text.
- An activity log of what you have received and shared, when, and with whom.
- A diagnostics log of technical protocol events, for troubleshooting.
- Settings, such as language and toggles.
None of this is sent to Kantega. Cloud backup is disabled, so the contents are not copied to Google Drive either.
What leaves your device, and when
Data leaves the device only when you initiate an action:
- When you obtain a credential, the app contacts the issuer you received an offer from.
- When you share a credential, you see who is asking and which attributes they request, and you choose whether to share. If you do, the selected attributes are sent to that recipient — and only to them.
All such traffic is encrypted (HTTPS/TLS).
Who receives the data
The recipient is the issuer or verifier you choose. In this demo that is usually the European Commission's public test environments (issuer.eudiw.dev, verifier.eudiw.dev) or test environments at the Norwegian Digitalisation Agency. They process what you send under their own terms — not Kantega.
This is another reason not to enter real personal data: you would be sending it to a test environment, not to an operated service.
Camera
The app uses the camera to read QR codes. Images are processed in real time within the app. No images are stored and no images are transmitted.
Bluetooth
The app requests Bluetooth permissions because proximity sharing (ISO 18013-5) is planned. The feature is not in use today, and no data is shared over Bluetooth.
Tracking and analytics
The app contains no analytics, no crash reporting and no advertising. It does not use an advertising ID. We collect no usage statistics.
Retention
For as long as you keep it. You delete individual credentials inside the app, and you delete everything by clearing the app's data in the device settings, or by uninstalling the app.
Because nothing is stored with us, there is nothing at Kantega to request access to or deletion of. If you have sent data to a test environment by sharing a credential, such a request must be directed to whoever operates that environment.
Your rights
You have the rights granted by the GDPR, including access, rectification and erasure. Since Kantega stores no data from the app, these apply in practice towards the recipients you have shared with. If you have questions, contact us at the address above.
Changes
If we change what the app stores or transmits, we will update this policy and the date at the top.
