Privacy Policy

Last updated 10 August 2026.

ReFineID applications run on your own device. We operate no servers that receive personal data. There are no accounts, no analytics, no tracking and no telemetry.

What the applications process

Your identity card carries your name, personal identity code and certificates. ReFineID reads them from the card to show you whose card is in the reader, to let you sign in to services and to sign documents. This data is processed on your device. ReFineID sends none of it to us. Your certificate goes only where you take it: to a service when you sign in, or into a document when you sign.

Network connections

When you sign in to a service, that service receives what you present to it, as in any login. That traffic is between you and the service. None of it comes to us. ReFineID itself opens no connections for card use. Reading the card and managing PINs contact no network. Only signing a document with an attested time and long-term evidence makes ReFineID's own network requests:

These services see your IP address, as any internet connection does, and are governed by their operators' own privacy policies. We receive nothing.

Retention

We retain nothing, because nothing reaches us. The applications store on your device only your settings and what you explicitly choose to store. That data stays in the device's protected storage. It is deleted by the applications' own forget actions or by removing the applications.

Diagnostics

Production builds write no diagnostics. The operating system may keep its own local records of smart-card use, as it does for any hardware. Those stay on your device under its rules, and nothing is sent to us.

Contact

Petri Koistinen, petri.koistinen@refineid.fi.