How Unidy works

The detail behind the idea: what you keep, what leaves, what expires and what we are still building.

Three things, and that is the whole idea

Keep it. Show a piece of it. Change it once.

  1. Everything in one place, locked

    Your identity documents, your cards, and the details that keep changing. Your Unidy is sealed with an encryption key of its own, held on different machines from the information itself, and none of it is reachable from the open internet.

    • Passport
    • Driving licence
    • Insurance
    • Address
    • Phone
  2. They see one piece, never the rest

    You choose what leaves your Unidy, field by field, who it goes to and for how long. A gym gets your name and that you are over 18, not your passport. You can take it back at any moment.

    • Field by field
    • For a set time
    • Revocable
  3. Change it once, not thirty times

    You move house, you change your address here. Everyone you authorised reads the new one from you, instead of writing to the place you left two years ago.

    • One change
    • Everyone you authorised
    • Never out of date

The first two are yours from the first day. The third grows as organisations connect to Unidy.

A real example

Share what is needed. Nothing more.

A gym needs your name, proof that you are over 18, sometimes an address. It does not need a permanent copy of your passport, driving licence or any other ID.

Your passport

What the gym receives

NameAlex C.

Alex C.

Over 18Verified

Verified

Expires12 Mar 2031

12 Mar 2031

Passport number••••••••

Not shared

Date of birth••••••••

Not shared

Document image••••••••

Not shared

Copy made for ABC Gym · 20 Sep 2026 · access expires in 15 minutes

  • You choose field by field what leaves your Unidy.
  • They receive a copy marked with their name and the date, never your original document.
  • Access expires by itself, and you can revoke it at any time.

If someone already downloaded a copy, revoking access cannot erase it from their computer. That is why every copy carries the name of who received it, and when.

Show a QR code, or read out a short code. The other person needs no app and no account.

Being built

Share what they need. Never your original.

A cloud-storage link gives someone the file you uploaded. With an identity document, that means handing over everything on it: your photograph, your document number, your date of birth, your signature, whatever else the page happens to carry.

Unidy works the other way round. Your original stays inside your Unidy, and no link ever points at it. When you authorise something, Unidy makes a new document at that moment, holding only what you chose to disclose, addressed to one recipient.

The link never points to your original document.

A passport held inside a sealed case on one side, and on the other a separate document made for one gym, carrying its name, an expiry and its own reference.

Look at what the link is

A cloud-storage link is an address for a file that already exists. A Unidy link is a request: it asks for a document to be made for whoever is standing in front of you.

  • Google Drive

    drive.google.com/file/d/1A2b3C4dE5fG6hI7jK8lM/view

    Opens the file you uploaded. Anyone holding the address sees the whole passport.

  • Dropbox

    dropbox.com/s/9qz1x2c3v4b5n6m/passport.jpg

    Same thing, and the name of the file often says what it is before anyone opens it.

  • Unidy

    unidy.me/7F3K29

    Points at no file. It asks Unidy for the version made for this recipient, and it stops working when you say so.

What happens when you share

  1. Your original stays put

    The document you uploaded stays inside your Unidy. It is never the file that gets sent, and never what a link opens.

  2. You choose what to disclose

    A few fields, a version with the rest blacked out, or a plain verified answer such as “over 18”. You decide, for this recipient, for this reason.

  3. Unidy makes a version for them

    A new document, made when it is asked for, carrying who it is for, why, when it was made, when it stops working, and a mark that belongs to that recipient alone.

The difference, in one picture

A cloud-storage link

  1. Your stored file
  2. A link to that file
  3. They receive the whole document

Unidy

  1. Your original, protected
  2. You choose what may be seen
  3. Unidy makes a version for that recipient
  4. They receive only that version

Side by side

Cloud-storage linkUnidy
What is sharedThe stored file, or a full copy of itA version made for the occasion
Your originalDelivered, or downloadableNever shared
What it disclosesEverything on the documentOnly what you authorised
Who it was forNot usually visible in the fileWritten into the version itself
Visible watermarkNot normally tied to a recipientNames the recipient
ExpiryCan be set on the linkBelongs to the version and the access
If it turns up elsewhereHard to tell which copy travelledThe version points back to who it was made for
Access historyDepends on the plan and how the link was madePart of how sharing works

Every version knows where it came from

A generated document is tied to the Unidy who authorised it, the recipient it was made for, the stated purpose, what it contains, when it was made, when it expires, and its own identifier. Each time it is opened through Unidy is recorded against it.

  • A watermark that names the recipient, visible on the page.
  • An identifier carried inside the file.
  • A record of when it was opened.

If a version turns up where it should not, its markings say which recipient it was made for. That is not the same as proving who passed it on: anyone with that version in their hands could have. What it removes is the anonymous copy that could have come from anywhere.

Calling it back

You can stop a version working from now on, and your original is never at risk either way, because nothing ever pointed at it. What we cannot do is reach into somebody’s computer: a version already downloaded or photographed stays downloaded. That is exactly why it carries their name.

This is not a complaint about cloud storage

Drive, Dropbox and OneDrive are good at what they are for. A link can need a password, expire next week, or be withdrawn. What none of them can do is make the file itself say less: the thing being delivered is still the whole document. They are not built to share an identity document without exposing the file you stored.

Secure delivery is not the same as safe disclosure.

The parts of life this is actually about

You move.
Change your address once, not thirty times.
Someone asks for your ID.
Share the two facts they need, not the document.
A company needs your details.
Give permission instead of giving up control.
Your documents expire.
Unidy warns you months ahead.
Someone needs to reach you.
Give them your Unidy, not five different numbers.

Move once. Update once.

Change it in one place.

Change your address, phone number or email in your Unidy. The organisations you have authorised take the new value from you, instead of you repeating the same paperwork dozens of times.

  1. 1

    You change your address

    Once, in your Unidy.

  2. 2

    You choose who is told

    Your bank and your insurer, not the shop you used once.

  3. 3

    They read the new value

    From you, when they need it. No forms, no phone calls.

Being builtThis is the second way of sharing: not a document handed over once, but a detail that stays correct by itself. It grows as organisations connect to Unidy, so it is the model we are building rather than something that works everywhere today.

A single change to an address travelling outward to the few organisations the person authorised.

Privacy architecture

One lock each. Keys kept elsewhere.

Every Unidy is encrypted with a separate key of its own, and no master key exists that opens everybody’s. The keys are not stored beside the information: they live in a separate system, on separate machines.

One key per person

Take our entire database and you face one separate lock per person, not one door.

Keys kept apart

Your information lives on one machine. The keys that open it live on another.

Not for sale

Your personal information is not sold, rented or handed over in readable form.

What a thief would find
Steal the database and you get scrambled text, locked separately for every single person, and not one key to open it with.
Why two systems
The keys sit in their own vault, with its own credentials and its own audit log. Reading anything means breaking into two independent systems, not one.

What we will not tell you: that we could never read anything. We hold the keys, because a key that exists only on your phone dies with your phone. What we can promise is that no single key opens everybody’s information, and that the keys are kept away from it.

What this protects you from, and what it does not →
Two sculpted halves of one whole, held apart by a gap: the left cradles a person’s documents, the right holds the mechanism that opens them.

What this turns into

The same idea, applied to more of the paperwork in your life.

In the first release

Documents and expiry dates

Passport, ID, licence, insurance, cards. In one place, with a warning months before anything runs out.

In the first release

Sharing with a QR code

At a counter, in seconds, with only the fields you picked.

In the first release

Signing in with your Unidy

A standard sign-in button for websites, showing exactly what each one receives.

Being built

Update once

A new address or phone number reaches the organisations you authorised.

Where this goes

Answers instead of data

“Over 18: verified” instead of your date of birth. A shipping price without the shop learning where you live.

Where this goes

If you are no longer here

Decide in advance who may reach what, so your family is not left searching for months.

Going further

Two places carry the parts that matter most, in full.