Your credentials never leave your phone
Most apps that store your credentials store them on their servers. Trust doesn't. Here is exactly how the architecture works, in plain English.
The short version
Trust stores your credentials — license numbers, expiration dates, scanned card images, CE certificates — only on the iPhone where you added them. That data is written to your device's encrypted local storage, backed by the Secure Enclave, and unlocked with Face ID or your device passcode. Trust does not operate a server-side database of clinician credentials. There is no copy of your wallet sitting on our infrastructure, and no admin view where anyone at Trust could look up your records.
Nothing about your credentials leaves your phone. The app does not run analytics SDKs and does not transmit license numbers, card images, or usage of individual features back to us. The only thing we collect from the app is anonymous crash reporting through Apple's first-party tools, which tells us whether the app crashed and on what type of device — not who you are or what you stored. When you tap a renewal button, Trust opens the regulator's own portal directly in your browser; we do not sit in the middle of that transaction and cannot see what happens on the other side of it.
This marketing website is a separate system from the app. It may record anonymous page-view analytics after you opt in through the cookie banner, the same as most websites. That has nothing to do with your credential data, which never touches this website at all.
Deletion is simple because there is nothing centralized to delete: removing a credential in the app removes it from your device immediately. Deleting the app removes your entire wallet, unless it is captured in your personal iPhone or iCloud backup — the same backup that covers your photos and messages, which Trust does not control. If you'd rather keep an independent copy first, you can export any credential to PDF at any time before deleting.
None of this depends on Trust as a company staying in business. Because your wallet lives on your device rather than on our servers, your records outlast us by construction, not by promise.
Storage is on-device.
Every credential (license number, expiration, scanned card image, CE certificate) is written to your iPhone's encrypted storage, backed by the Secure Enclave. Trust never holds a copy. Trust is iPhone only.
Authentication uses Face ID or a Passkey.
There is no Trust password to lose or reuse. Your device authenticates you. If you reset your phone, the credentials reset with it — you restore from your encrypted device backup, the same way you restore everything else.
Renewal links are direct.
When you tap a renewal button, Trust opens the regulator's own portal in your browser. We do not proxy the transaction. The board takes your payment, not us.
Telemetry is crash logs only.
We collect anonymous crash reports through Apple's first-party tools. The app runs no analytics SDKs. We cannot tell you which credentials you have added, or when you last opened the app. This marketing site may record anonymous page views after you opt in; the app does not.
If Trust shut down tomorrow, your data wouldn't.
Because the wallet lives on your device, our continued existence is not a precondition for your records' continued existence. Export to PDF is available at any time.
The formal version of these commitments is our Privacy Policy.