Worldcoin announces Personal Custody, which saves biometric data captured by the Orb on users' personal devices, and plans to open source the Orb's software
Today marks a significant milestone for our team, and me - we're thrilled to announce that we're open-sourcing the Orb Software! …
Context & Ripple Effects
Worldcoin had already tied World ID verification to Orb hardware in Germany through an identity-protocol rollout, while coverage of the project’s origins emphasized the privacy and policy questions surrounding eye scans. Personal Custody and the release of Orb software address the two most sensitive parts of that model: where biometric data resides and how the capture device can be examined.
The move matters because Worldcoin’s token rollout made Orb verification a gateway to participation; shifting storage to users’ devices changes the trust model without removing the hardware-based verification step.
First-order effects
- Orb users can keep biometric data captured during enrollment on their own devices rather than relying on Worldcoin-held storage under the new Personal Custody feature.
- Open-sourcing the Orb software gives external researchers and integrators a basis to inspect the software used by Worldcoin’s biometric capture hardware.
Second-order effects
- Worldcoin must turn those technical commitments into understandable consent, recovery, and device-loss experiences; user-held data can reduce centralized exposure while making local-device handling more consequential.
- Other proof-of-personhood providers face greater pressure to explain both their biometric-data custody model and the auditability of their verification hardware and software.
Third-order effects
- If adopted broadly, biometric proof-of-personhood systems may compete increasingly on user-controlled credentials and independently inspectable capture stacks, not solely on enrollment scale.
- The remaining trade-off is unresolved: decentralizing custody can improve data minimization, but dependable identity recovery and fraud controls may still require carefully governed service layers.
The trend: This is one data point in the shift toward privacy-preserving, user-controlled proof-of-personhood infrastructure for online services.