# Concordium

> Concordium is a blockchain startup building trust infrastructure for the internet, where I lead the design department. This case study is its ID app: letting people prove things about themselves online while giving away nothing more than necessary, and making that privacy something non-technical people can actually feel.

**Question:** How do you make privacy something people can feel?  
**Tags:** Service Design, Research, Identity  
**Focus:** Design Lead  
**Case study:** https://www.sebastian-nause-blueml.com/concordium.html  
**External:** https://www.concordium.com

---

## Cover

**Concordium**

**Privacy you can feel.**

Designing Concordium's ID app so ordinary people trust it: proving who they are online while giving away nothing more than the moment needs.

*Cover image: A person sitting with a laptop, glancing at their phone, an everyday online moment.*

## At a glance

- **Project:** Concordium ID: privacy-preserving online identity verification
- **My role:** Design Lead: ran the design department, guiding several designers across all design work
- **Scope:** Early concept to launch (0 to 1)
- **Research:** London, non-technical people, not crypto
- **Built with:** AI-made prototypes, tested then shipped
- **The challenge:** Make a provably private app feel private, and trustworthy
- **Outcome:** Launched to the community, and growing since

## The brief

### The maths was private. The feeling had to be designed.

The app can prove a fact about you, over 18, a citizen, a real person, while revealing nothing else, provably. But provable is not believable. Feeling private is bound up with trust, and trust is easily lost.

**The real question:** Not "is it private?" but "will people believe it is?"

*Image caption: The people who'd use it: ordinary, non-technical, online.*

## The research

### Built with AI in days, tested with real people the same week.

I built the prototypes fast with AI, then took them to London, to non-technical people who owed the claim nothing, and watched them try to prove who they were.

*Image caption: Testing the prototype with ordinary people in London: passports, not wallets.*

## What we learned, 1

### Privacy you can see beats privacy you're promised.

People don't weigh a privacy claim. They watch what the app does. So the screen shows exactly what's shared, and nothing else.

*Screen caption: Before you approve, you see exactly what leaves your hands.*

*Screen detail: The approval screen shows a request from a wine shop, "Only this information will be shared: Over 18 Years Old, Country," above an Approve button.*

## What we learned, 2

### Explaining "zero-knowledge proofs" spent trust, not built it.

An unfamiliar term reads as something to take on faith, the opposite of feeling shown. So we showed instead: a plain promise and a simple visual.

*Screen caption: Three screens, not a definition: your data exposed, then covered, then proven without giving it away.*

*Screen detail: Three onboarding screens run left to right as a before and after. First, "Common online verification exposes your data", an ID card with every field revealed and flagged as shared, stored on remote servers, and vulnerable to leaks. Then, "Concordium ID keeps you safe", as the app card slides over the ID and turns those risks green. Last, "Verify and stay anonymous", a single "Over 18" proof with no personal data shared, not exposed, and not in the cloud.*

## What we learned, 3

### What feels appropriate is set by the moment, not the feature.

The same disclosure felt safe in one context and intrusive in another. So each proving moment asks only for what it genuinely warrants.

*Screen caption: A proof always begins in someone else's context: a checkout, a sign-up, an age gate.*

*Screen detail: The verification start screen shows a QR code to scan with a supported mobile or browser app to begin a private verification.*

## What happened

**0 to 1**

From early concept to a launched app the community keeps using.

Once the prototypes had earned their answers, I led the design team in turning them into the real product, holding the line on the research the whole way: privacy felt, shown rather than asserted, and tuned to each moment. It shipped to the community by the end of the year, and has been growing ever since.

**The hard part:** Not shipping. Holding the line on "show, don't assert" all the way through the build.

## The quote

> "I worked with Sebastian from day one at Concordium, where he was our Lead Service Designer ... He brings clarity to complex problems, facilitates great conversations, and challenges ideas in a thoughtful, constructive way."

**Dario Peric**
Reported to Sebastian at Concordium

## Looking back

### What I'd carry forward

My first instinct was to explain the mechanism. Surely if people understood zero-knowledge proofs, they'd trust it. They didn't; explaining quietly cost trust. Some early AI mockups had the opposite flaw: privacy that read beautifully in a demo but skipped the moment someone actually decides to believe it.

Both got fixed by testing with people who owed the claim nothing. Next time I'd trust "show, don't tell" from the start.
