01 ·
Biometric data is treated as regulated PII
Your face produces a 512-dimension embedding — a numeric signature, not a reconstructable image. The embedding is what we store, search against, and purge.
Original reference photos and liveness frames live in encrypted object storage, keyed per user, with signed URLs that expire. Nothing is publicly listable.
Illinois BIPA sets the floor for how we handle this data: explicit consent before collection, three-year retention cap, and a purge-on-delete obligation. By policy, we apply it to every user — not only Illinois residents.