As digital identity systems evolve, the use of privacy-enhancing technologies like Zero-Knowledge Proofs (ZKPs) is growing — and with good reason. These tools offer a compelling proposition: prove something about yourself (like your age) without revealing the underlying personal information (like your date of birth).
Google’s recent announcement that it will support ZKPs within Google Wallet for age verification has drawn praise in the tech and privacy communities. At first glance, it seems like a major step forward. You can now prove you’re over 18 without revealing your birthdate — a textbook case for zero-knowledge cryptography.
But this interpretation misses a critical truth: privacy isn’t defined solely by what a third party sees. It’s also about who has systemic control — and what they do with it. And when a single company owns the entire ecosystem — from credential issuance to device software to verification interface — privacy becomes a tightly managed illusion.
Controlling the Ecosystem Means Controlling the Data
To use Google’s ZKP-based verification, you first need to upload your government-issued ID into Google Wallet. That document — your passport, driver’s license, or national ID — is then stored on your device, but managed, indexed and processed within Google’s proprietary environment.
Here’s the problem: even if your date of birth isn’t shared with a third-party website, Google still retains and processes:
- Your full personal identity credentials
- The metadata from each verification (what service you accessed, when, and how often)
- Your device identity and location
- Patterns of your interactions across apps and sites that use the verification service
In other words, the entity that issues the credential, stores the credential, and verifies the credential — is the same company. This creates a closed-loop identity system, where no data may leave the ecosystem, but all data is visible to the ecosystem owner. Moreover, the ecosystem owner can utilise that data for profit purposes such as advertising or data sharing.
When Privacy Becomes a Product, Control Becomes a Risk
Google is positioning this system as “privacy-first,” but real privacy can’t exist in a structure that demands full trust in a single private company — especially one whose business model is historically built on data collection, profiling and monetisation.
Even if data is not “shared” externally, it doesn’t mean it isn’t being collected, logged or analysed internally. Google still knows:
- Who you are
- When you performed an age check
- Which site or app prompted it
- Whether you passed or failed
- How often you verify your age — and in what contexts
This becomes a new layer of behavioural telemetry, tightly linked to your verified identity. And unlike cookies, you can’t clear this from your browser — because it lives in the infrastructure of your device and your ID.
True Privacy Requires Systemic Separation
Zero-knowledge proofs are a powerful tool, but they don’t guarantee privacy when they’re implemented in closed, centralised ecosystems. They can prevent overexposure of data to third parties, but they cannot protect you from the company that owns the system itself.
At Sedicii, we’ve taken a different path. Our patented technology allows for real-time verification of identity attributes without ever storing, transmitting or exposing the underlying data.
- We won’t store your identity credentials, except for the bare minimum needed to authenticate you as a returning user.
- We won’t hold your government documents, unless there is a legal requirement to do so, which we will tell you in advance.
- We don’t track where or when you verify your age – every visit to a Sedicii Age Assured site is done with a unique token that is forgotten after your visit ends.
- We will NEVER monetise your data
When someone needs to prove they are over 18, or that they belong to a particular jurisdiction or income group, they can do so via a Sedicii-enabled system that never sees the actual document or personal details. The verification happens securely, mathematically and privately — all without the user needing to upload or deposit anything in a digital wallet owned by a third party.
With Sedicii, nobody — not even us — sees your data. There is no central wallet, no centralised control, no behavioural tracking. Just a simple question (“Is this person over 18?”) answered securely and privately using patented zero-knowledge technology.
Privacy by Design
If the only thing standing between you and exposure is a tech company’s good intentions, you don’t have privacy — you have policy.
Privacy by design means building systems that make misuse impossible — not just undesirable. It means creating digital identity layers where even the system owner cannot see, store, or infer more than what’s strictly necessary.
Google’s approach may seem like a step in the right direction. But as long as one company controls issuance, storage and verification, it will always have full visibility — and users will never have full control.
Privacy isn’t a feature. It’s a structure. And it’s time we built it that way.
This article is part of Sedicii’s ongoing thought leadership in support of Project PHACKS, an initiative focused on building collaborative communities to address complex cybersecurity and data privacy challenges. PHACKS is funded by the European Union and brings together organisations to explore new approaches to secure data collaboration utilising privacy enhancing technologies. Through this work, Sedicii contributes its expertise in advanced cryptography, secure data collaboration and digital identity to promote safer, more transparent digital ecosystems across Europe. The views expressed herein reflect the author’s perspective and do not necessarily represent those of the European Union. Learn more about Project PHACKS.
