Privacy Policy
Last updated: May 2026
Short version: We store your encrypted identity and signed messages so you can use the app across devices. We never see your private key. We don't sell your data. We don't run ads.
Who we are
It's the Real Me ("the app", "we", "us") is a cryptographic identity and message verification service available at itsthereal.me.
What we collect and why
Account information
When you create an identity, we collect your email address and a display name (which can be any name or nickname). Your email is used to log in and recover your account. We never show your email to other users.
Your cryptographic identity
The app generates a unique key pair (public + private key) on your device. Your private key is encrypted with your password before it ever leaves your device — we store only the encrypted version. We have no way to read or use your private key. Your public key is stored and shared openly so others can verify your messages.
Signed messages
When you sign a message or photo, the signed content is stored in our database so that recipients can verify it by tapping the link. Messages you sign are readable by anyone with the link. If you want a message removed, contact us.
Photos
When you sign a photo, it is uploaded to our cloud storage and given a public URL included in the verification link. Photos are publicly accessible to anyone with the link.
Profile information
Your display name and profile picture (if you set one) are publicly visible on your profile page. You can change or remove them at any time from within the app.
Trusted contacts
Contacts you save are stored in your account and are only visible to you.
How we store your data
All data is stored using Supabase, which runs on AWS infrastructure. Data is encrypted at rest and in transit. Your private key is additionally encrypted client-side before storage, so even a database breach would not expose it.
Third parties
- Supabase — database, authentication, and file storage. Their privacy policy.
- Netlify — app hosting and CDN. Their privacy policy.
We do not use advertising networks, analytics trackers, or sell your data to any third party.
Deleting your data
You can delete your identity at any time from within the app (Home → Delete my identity). This removes your keys, profile, and contacts from our servers. Previously signed messages that others have already received will remain verifiable, but cannot be traced back to an active account.
Children
This app is not directed at children under 13. We do not knowingly collect data from children under 13.
Changes to this policy
We may update this policy as the app evolves. We'll note the date of the last update at the top of this page.
Contact
Questions? Email us at privacy@itsthereal.me