A service needs to know you're over 18. It doesn't need your birthday.

Bisotun Wallet is built around selective disclosure: sharing only the specific facts a service asks for, instead of a whole document. Here is what that means in practice, what each party sees, and where the limits are.

How it worksRead the privacy policy

Selective disclosure, by example

Imagine your university has issued you a diploma card with five items on it:

  • Name: Sara Ahmadi
  • Date of birth: 14 March 1999
  • Institution: (your university)
  • Degree: MSc Civil Engineering
  • Final grade: 17.2

A job portal asks for institution and degree. Your wallet shows you exactly those two items and asks whether you want to share them. You tap Share.

What the job portal receivesWhat it does not receive
Institution and degreeYour name, date of birth and grade
Proof that the university signed these valuesA copy of the certificate or the rest of the card
Card type and issuer ("Diploma card from your university")Any other card in your wallet
The week the card was issued and the week it expiresYour PIN, your wallet's account ID

If the portal also needs your name, it has to ask for it, and you see that before deciding. The proof still shows that all the shared items come from the same genuine card.

(The diploma card is an illustration. Such cards appear when universities issue them on Bisotun; today each existing card holds a single item, so the "part of a card" benefit shows once richer cards are issued.)

You decide, every time

  • Nothing is shared automatically. Each request opens in your wallet, shows who is asking and what they want, and waits for you. You can decline.
  • Your PIN protects every use. Your wallet cannot share anything until it has been unlocked with your PIN, and that PIN is checked by Bisotun's keyshare server, not just on the phone.
  • Choices are yours. If a service accepts alternatives (say, a student card or a membership card), you pick which one to show. Optional items are marked, and you can leave them out.
  • You keep a record. The app's Activity tab lists every card you received and every piece of data you shared, with whom and when. It is stored on your phone only.

Proving a fact without the underlying data

Selective disclosure works on the items an issuer puts on the card. So the most privacy-friendly cards contain ready-made answers:

Age

An age card with "over 16: yes" and "over 18: yes" lets a shop check your age without ever seeing your date of birth.

Student status

"Enrolled: yes" plus the institution is enough for a student discount. Name and student number stay on your phone.

Membership

"Member level: gold" gets you the partner offer. Your member number stays private.

Bisotun cannot calculate "over 18" from a date of birth at the moment you share; the issuer includes such answers on the card. These cards are examples of what organizations can issue.

Identity cardIssued by a trusted organization
  • Full namenot shared
  • Date of birthnot shared
  • ID numbernot shared
  • Addressnot shared
  • Over 18Yes

An online shop asks: “Are you over 18?”

The shop receives only this

Over 18: yes

Issuer signature valid

Illustrative example A card with five items; only “Over 18: yes” is shared, the rest stays on the phone.

No tracking number in the cryptography

Every time you show a card, your wallet creates a new, randomized proof. Two services, or the same service on two occasions, cannot tell from the proof itself that it came from the same card.

Be aware of what can still connect you:

  • The values you share. Your email address is the same everywhere, so services that receive it can recognise you by it.
  • Your wallet's account ID. It is a fixed random number, the same for every service that asks for it. Share it only where being recognised is fine, such as logging in to an account you already have.
  • Card dates. The issue and expiry weeks of a card are always part of the proof.

Bisotun is private, not anonymous: what you choose to share can identify you.

What Bisotun itself sees

We think you should know exactly what passes through our servers.

Your cards: not with us

Cards and their contents are stored on your phone only. There is no central database of your cards and no cloud copy.

Keyshare server: when, not what

To protect your wallet, a part of every proof is made together with our keyshare server after it checks your PIN. It therefore records that and when your wallet was used and your PIN checks. It does not learn what you shared or with whom. You can view this log in My Bisotun.

Session server: briefly, in memory

Our session server checks each proof on behalf of the website and passes the verified result on. It therefore handles the values you share, keeps the result in memory for up to five minutes so the website can collect it, and does not keep a record of what you shared.

Issuers: not informed

Using a card does not contact the organization that issued it. Your university does not learn where you show your diploma.

The app itself contains no advertising, no crash reporting and no analytics or tracking. It connects only to Bisotun's servers and to the service you are sharing with. Screens are hidden from screenshots and from the app switcher unless you change that in Settings.

Know who is asking

Any website can send a request to your wallet. Bisotun does not yet verify the names of organizations, so every requester is shown by its web address, with a notice that it is not a known organization. Check that address before you share, just as you would check the address bar before typing a password.

Privacy you can check for yourself.

Download for AndroidSecurity explained