In development

Prove you're old enough — without proving who you are.

EroPass is a device-bound, privacy-first age verification system. It's built to satisfy age-gating requirements for online content without forcing people to repeatedly upload ID, or forcing platforms to become custodians of sensitive identity data.

The core product is EroPassID, an iOS app that verifies a person's age once, then issues a reusable, cryptographically signed proof of age that can be presented to participating apps and websites on demand.

01 The problem we're solving

Age-verification laws for online content are expanding quickly, and most implementations force an uncomfortable choice: sites either do nothing, or they collect and store government ID scans, selfies, and birthdates directly — creating large, centralized troves of sensitive identity data that become high-value targets for breaches, leaks, and misuse.

EroPass exists to remove that trade-off. Verification should happen once, be portable, and reveal nothing more than the minimum fact required: is this person old enough, yes or no.

02 What EroPass does

EroPass separates identity verification from proof of age. A person verifies their age once, through a vetted third-party verification step. EroPass then issues a short-lived, cryptographically signed credential bound to that person's device. Sites and apps that need to gate age-restricted content can request proof of that credential — and get a signed yes/no answer — without ever learning the person's name, birthdate, or seeing their identity documents.

This is designed for use by adult content platforms, age-gated marketplaces, and any online service with a legal or policy obligation to verify age before granting access.

03 How it works

1
One-time age verification

The user completes an identity/age check through a vetted third-party verification provider. EroPass does not perform this check itself and is designed so that it never receives or stores the underlying ID images, document numbers, or full birthdate — only a pass/fail result.

2
Device-bound credential

On success, the EroPassID app generates a private key inside the device's Secure Enclave and receives a short-lived, cryptographically signed age credential (an ECDSA-signed, JWT-based token) tied to that specific device. The private key never leaves the device.

3
Presenting proof of age

When a participating site or app needs to confirm age, EroPassID presents its signed credential — via an in-app handshake or a QR-based cross-device linking flow — proving the device holds a valid, unexpired age attestation. The relying site learns only "yes, verified" or "no," never the person's identity.

4
Expiry & renewal

Credentials are time-bound and expire on a schedule, so a revoked or stale verification can't be used indefinitely. Renewal requires re-establishing the credential rather than a one-time, permanent bypass.

5
No visibility into usage

EroPass issues and validates age credentials; it does not see which sites, apps, or content a credential is used with.

04 Privacy Policy

Effective date: September 7, 2026  ·  Applies to: EroPass, the EroPassID application, and eropass.com

EroPass is currently in development. This policy describes the data-handling architecture we are building EroPass around, and it will be kept current as the product evolves and as our third-party verification partner is finalized.

Who we are

EroPass is developed by Paradigm Net Media ("EroPass," "we," "us," or "our"). This policy explains what information EroPass collects, why, and the choices you have.

Our privacy commitment

EroPass is built on a data-minimization principle: we aim to collect and retain the least amount of information necessary to issue and validate a proof-of-age credential, and no more. Where possible, sensitive verification data is handled by specialized third parties and never touches EroPass's own servers at all.

Information we collect

We do not collect

  • Your name
  • Government ID photos or numbers
  • Home address
  • Full birthdate (beyond what a provider needs momentarily to verify age)
  • Which sites or apps you use your credential with
  • Biometric data — Face ID/Touch ID never leaves your device

We do collect (minimally)

  • Verification result (pass/fail + expiry)
  • Short-lived session/linking tokens
  • Basic security logs (IP, timestamp)

Third-party verification providers

EroPass relies on a third-party provider to perform the underlying identity/age check. We have not yet finalized which provider we will launch with; once selected, we will name that provider here and link to its own privacy policy. We select and contract with verification providers on the basis of strong data-minimization and security commitments.

How we use information

Information collected is used solely to: issue, validate, and expire age-verification credentials; maintain the security and integrity of the verification system; prevent fraud and abuse; and comply with applicable law.

Data retention

Ephemeral session and linking tokens are deleted once the verification handshake completes. Your private signing key remains on your device only and is removed if you delete the EroPassID app or revoke your credential in-app. Security logs are kept only as long as needed for security purposes, then deleted.

Data sharing

We do not sell personal data. We do not share verification results with relying sites or apps beyond the minimum cryptographic yes/no attestation required to complete age verification. We may disclose limited information if required to comply with applicable law, regulation, or legal process.

Children's privacy

EroPass is not directed at children, and its entire purpose is to help prevent access to age-restricted content by people who are underage. We do not knowingly collect personal information from children. If a verification attempt indicates the person does not meet the required age, no identity data from that attempt is retained beyond what's needed to return the result.

Your rights

Depending on where you live, you may have rights to access, correct, or request deletion of personal information we hold about you. Because EroPass is designed to retain very little information by default, most requests can be resolved quickly. To exercise these rights, contact us using the details below.

Security

EroPass uses device-level hardware security (Secure Enclave-backed key storage), cryptographic signing (ECDSA) for credentials, and encryption in transit (TLS) for any network communication. We do not store verification documents in plaintext, and our architecture is designed to avoid storing them at all.

Changes to this policy

We may update this policy as EroPass develops, particularly as we finalize our verification provider and launch publicly. Material changes will be reflected on this page with an updated effective date.

Contact us

Questions about this policy or your data can be sent to telly@paradigmnetmedia.com.

05 Contact

Paradigm Net Media
Email: telly@paradigmnetmedia.com
Web: eropass.com