Prove you're old enough — without proving who you are.
EroPass is a device-bound, privacy-first age verification system. It's built to satisfy age-gating requirements for online content without forcing people to repeatedly upload ID, or forcing platforms to become custodians of sensitive identity data.
The core product is EroPassID, an iOS app that verifies a person's age once, then issues a reusable, cryptographically signed proof of age that can be presented to participating apps and websites on demand.
01 The problem we're solving
Age-verification laws for online content are expanding quickly, and most implementations force an uncomfortable choice: sites either do nothing, or they collect and store government ID scans, selfies, and birthdates directly — creating large, centralized troves of sensitive identity data that become high-value targets for breaches, leaks, and misuse.
EroPass exists to remove that trade-off. Verification should happen once, be portable, and reveal nothing more than the minimum fact required: is this person old enough, yes or no.
02 What EroPass does
EroPass separates identity verification from proof of age. A person verifies their age once, through a vetted third-party verification step. EroPass then issues a short-lived, cryptographically signed credential bound to that person's device. Sites and apps that need to gate age-restricted content can request proof of that credential — and get a signed yes/no answer — without ever learning the person's name, birthdate, or seeing their identity documents.
This is designed for use by adult content platforms, age-gated marketplaces, and any online service with a legal or policy obligation to verify age before granting access.
03 How it works
The user completes an identity/age check through a vetted third-party verification provider. EroPass does not perform this check itself and is designed so that it never receives or stores the underlying ID images, document numbers, or full birthdate — only a pass/fail result.
On success, the EroPassID app generates a private key inside the device's Secure Enclave and receives a short-lived, cryptographically signed age credential (an ECDSA-signed, JWT-based token) tied to that specific device. The private key never leaves the device.
When a participating site or app needs to confirm age, EroPassID presents its signed credential — via an in-app handshake or a QR-based cross-device linking flow — proving the device holds a valid, unexpired age attestation. The relying site learns only "yes, verified" or "no," never the person's identity.
Credentials are time-bound and expire on a schedule, so a revoked or stale verification can't be used indefinitely. Renewal requires re-establishing the credential rather than a one-time, permanent bypass.
EroPass issues and validates age credentials; it does not see which sites, apps, or content a credential is used with.
04 Privacy Policy
Who we are
EroPass is developed by Paradigm Net Media ("EroPass," "we," "us," or "our"). This policy explains what information EroPass collects, why, and the choices you have.
Our privacy commitment
EroPass is built on a data-minimization principle: we aim to collect and retain the least amount of information necessary to issue and validate a proof-of-age credential, and no more. Where possible, sensitive verification data is handled by specialized third parties and never touches EroPass's own servers at all.
Information we collect
- Age/identity verification data: the initial check is performed by a vetted third-party identity verification provider under its own privacy terms. EroPass is designed to receive only the outcome of that check (verified / not verified, and an expiry), not the underlying documents, images, or full date of birth.
- Device-bound cryptographic keys: EroPassID generates a private signing key inside your device's Secure Enclave. This key is never transmitted to EroPass or to any third party.
- Ephemeral session and linking tokens: short-lived tokens (JWT-based) used to complete the verification handshake and cross-device QR linking flow. These are used only to complete the transaction and are not retained beyond what's needed for that purpose.
- Basic technical/security logs: like most online services, our infrastructure keeps minimal, short-retention logs (such as IP address and timestamp) for security, abuse prevention, and reliability purposes.
We do not collect
- Your name
- Government ID photos or numbers
- Home address
- Full birthdate (beyond what a provider needs momentarily to verify age)
- Which sites or apps you use your credential with
- Biometric data — Face ID/Touch ID never leaves your device
We do collect (minimally)
- Verification result (pass/fail + expiry)
- Short-lived session/linking tokens
- Basic security logs (IP, timestamp)
Third-party verification providers
EroPass relies on a third-party provider to perform the underlying identity/age check. We have not yet finalized which provider we will launch with; once selected, we will name that provider here and link to its own privacy policy. We select and contract with verification providers on the basis of strong data-minimization and security commitments.
How we use information
Information collected is used solely to: issue, validate, and expire age-verification credentials; maintain the security and integrity of the verification system; prevent fraud and abuse; and comply with applicable law.
Data retention
Ephemeral session and linking tokens are deleted once the verification handshake completes. Your private signing key remains on your device only and is removed if you delete the EroPassID app or revoke your credential in-app. Security logs are kept only as long as needed for security purposes, then deleted.
Data sharing
We do not sell personal data. We do not share verification results with relying sites or apps beyond the minimum cryptographic yes/no attestation required to complete age verification. We may disclose limited information if required to comply with applicable law, regulation, or legal process.
Children's privacy
EroPass is not directed at children, and its entire purpose is to help prevent access to age-restricted content by people who are underage. We do not knowingly collect personal information from children. If a verification attempt indicates the person does not meet the required age, no identity data from that attempt is retained beyond what's needed to return the result.
Your rights
Depending on where you live, you may have rights to access, correct, or request deletion of personal information we hold about you. Because EroPass is designed to retain very little information by default, most requests can be resolved quickly. To exercise these rights, contact us using the details below.
Security
EroPass uses device-level hardware security (Secure Enclave-backed key storage), cryptographic signing (ECDSA) for credentials, and encryption in transit (TLS) for any network communication. We do not store verification documents in plaintext, and our architecture is designed to avoid storing them at all.
Changes to this policy
We may update this policy as EroPass develops, particularly as we finalize our verification provider and launch publicly. Material changes will be reflected on this page with an updated effective date.
Contact us
Questions about this policy or your data can be sent to telly@paradigmnetmedia.com.
05 Contact
Paradigm Net Media
Email: telly@paradigmnetmedia.com
Web: eropass.com