"One stores ciphertext: encrypted blobs created with a key held by the user. Never the underlying identity data. This includes government ID and selfie data, as well as the verified email associated with the account. "
Why does it need to store even encrypted data after the result is +18, for example? Does ONE need to keep validating against the same documents every time?