DO//NOT//RESURRECT← THE PROJECT

HOW IT WORKS / FOLLOW THE DATA

Your decision.
Not your identity.

A passport lets you authorise a directive without publishing your name, passport number or date of birth.

The proof is public. The passport details are not disclosed by this flow. Here is what actually happens between your phone and the record.

01 / FROM PASSPORT TO PROOF

Four stops. Different data.

  1. YOUR PHONE

    Read locally. Prove locally.

    The camera reads the printed text needed to unlock the NFC chip. The app then reads the passport’s signed chip data and generates the first cryptographic proofs on your phone, using ZKPassport’s libraries. You do not need the separate ZKPassport app.

    The camera image is processed locally. Passport details are held temporarily in memory; our app does not save them in its receipt storage or send the raw scan or private proof inputs to our server.

    STAYS LOCAL / PASSPORT DATA + PRIVATE PROOF INPUTS
  2. PROOF COMPRESSION SERVICE

    Make the proof small enough to use.

    A remote service receives intermediate proofs and their public inputs, then compresses them into a proof the contract can check. It does not receive the passport scan or the private passport inputs used to create those proofs.

    SENT / INTERMEDIATE PROOFS + PUBLIC INPUTS
  3. OUR RELAY

    Submit the decision you approved.

    Our server receives the finished proof and your directive. It checks the submission and pays the network transaction fee. Your proof is bound to the exact action you reviewed; changing the decision or conditions would require a new authorisation.

    SENT / FINAL PROOF + DIRECTIVE
  4. THE PUBLIC NETWORK

    A record anyone can verify.

    The registry stores a pseudonymous record ID, your decision, a hash and retrieval link for any conditions, and revision information. The transaction also exposes the submitted proof and its public inputs.

    Your conditions are public text, stored separately from the contract. Do not put private information in them. Updating or withdrawing changes the current directive; it does not erase its history.

    PUBLIC / DIRECTIVE + CONDITIONS + PROOF TRANSACTION

PRIVACY / WITHOUT THE SMALL PRINT

Private details.
Observable activity.

“Zero knowledge” does not mean nothing is visible. This flow does not request disclosure of your name, passport number or birth date. It still exposes an app-scoped identifier, proof metadata and a public record of your decisions.

Services you connect to may see connection information such as your IP address. Publishing a name beside your record, or sharing its receipt, can connect it to you.

The native integration has not completed an independent privacy audit. Memory handling, dependencies, logging and network traffic still need that review. These are the implementation’s data boundaries, not a promise of absolute anonymity.

02 / MAKE IT FINDABLE

The proof cannot tell them who you are.

A future reader cannot work backwards from the proof to your passport or your body. They need a connection to your record.

THE DURABLE CONNECTION

Keep the receipt.

Save the record ID and its QR lookup link with your preservation arrangements or estate documents. Someone with that receipt can read the latest directive without your passport and without a public profile.

Keep a copy of the conditions too. A surviving hash can verify the right text; it cannot reconstruct text that has been lost.

OPTIONAL / PUBLIC BY CHOICE

Give it a name.

Choose a public profile and directory listing only if you want them. Both start off. A display name or pseudonym is allowed; it is not a passport-verified identity.

Profile details live offchain, but connecting a name to the record can identify its permanent onchain history. Removing the profile cannot erase copies others kept.

Explore the directory ↗

03 / THE EDGES

A few things to know.

What does the passport proof establish?

It demonstrates knowledge of valid passport data, checks the issuer’s signature and document integrity, and binds the proof to the action you approved.

It does not independently prove that the person operating the phone is the named holder, that they are alive, or that a future reconstructed person is the same person.

Is there a government passport lookup?

There is no passport-holder lookup built into this product. The ICAO Public Key Directory distributes authentication certificates used to check passport signatures; it is not a directory of people or their passport chip data.

The native “Find my directive” flow uses a fresh proof to match the same passport to its record, without a transaction. The proof is checked against the controller and the current directive is read from the registry. This does not prove the scanner is the rightful holder. Continuity after passport renewal or expiry is not established, so keep your receipt.

About ICAO’s Public Key Directory ↗
Can I change my mind?

Yes. Updating or withdrawing requires a new passport proof and a new transaction. The current record changes once that transaction is confirmed; earlier versions remain public.

The contract does not detect death or automatically lock a directive after death.

Does this enforce my decision?

No. The registry provides a verifiable record of an instruction. It cannot enforce compliance, establish legal effect, or guarantee that resurrection will ever be possible.

Current recordings use Sepolia, a test network. Treat this as an experiment, not a permanent substitute for preservation or estate arrangements.

04 / CHECK THE WORK

Read beyond the promise.

The project’s public repository includes contracts, the specification and web code. The current native integration is not yet published there. The public repository alone therefore does not yet let you reproduce or audit every part of this iPhone build.

Publishing the complete implementation and completing independent review are still release work. A source link is not an audit.

Your terms. On record.

Get the iPhone app →