ONE WALLET · SIX FACES · ZERO OVERSHARING

Every service meets
a different you.

No passwords, no forms, no shared email. Each app gets its own identity and only the answer it needs — and you can cut any one of them loose without touching the rest.

S
Store
Needs a payer, not a person.
SEES YOU AS
user_8F3A
V
Streaming
Knows your plan is active. Never your name.
SEES YOU AS
user_91B2
F
Forum
Asks 18+. Gets a proof, not a birth date.
SEES YOU AS
user_21CD
E
Employer
Verifies your credential. Keeps no copy.
SEES YOU AS
user_44E7
B
Bank
Full KYC where it is required — nowhere else.
SEES YOU AS
user_7C05
C
Clinic
Reaches you privately. No phone number.
SEES YOU AS
user_D3A1
DRAG SIDEWAYS TO SPIN THE DECK6 FACES · 1 WALLET

What changes for you

Three things are true every time you connect to a service through U-net, in this order.

01

Every connection gets its own identity

Demo Supermarket and Issuer Example each see a different, unrelated U-net identity for you. Neither can tell the other exists, and neither can piece together a profile from the other's side.

02

Approval happens on your device

When a sign-in or check arrives, you approve it locally with a tap or biometric. Your private keys never leave your phone, and no approval is silent or automatic.

03

You can see and revoke everything

Every connected service, notification category, and issued attestation is listed in the app. Disconnect any one of them without disturbing the rest.

What actually happens when a service asks you something

Say a miniapp needs to confirm you're old enough to continue. Here's the whole exchange.

STEP 1

A specific question arrives

“Is this holder age-eligible?” — not a request for your ID, birthdate, or name.

STEP 2

You approve locally

A biometric or device unlock confirms it's you. Nothing about the request leaves your phone yet.

STEP 3

A proof goes out, not a document

The service receives a verified yes — never the ID, the birthdate, or a way to look either up again.

The boundary, plainly

This is the actual line between what's yours and what a service ever sees.

Stays on your device
Your private keys and device approval
Your push token and global device identity
Every other service's scoped identity for you
Shared, scoped to this relationship
A scoped identity for this one relationship
The specific proof a check asked for, nothing wider
Permission and notification state you granted, reversible anytime

Curious what this looks like from the other side?

See how developers integrate the same check, or what it solves for a company deciding whether to ask for one at all.