Skip to main content
FaceSign processes biometric data during verification sessions and retains only what is necessary for future recognition. This page documents what data is captured, what is retained, and how you and your users can exercise data rights.

Processor vs. controller

FaceSign operates as a data processor. Your organization is the data controller. FaceSign does not independently decide to collect, use, or share biometric data. All processing occurs at your direction, for the purpose of the verification session you initiated.

What IS processed during a session

During a verification session, FaceSign processes the following biometric and behavioral signals in memory:
Video frames are processed in memory and discarded at session end. Raw media is never written to persistent storage unless you explicitly opt in for audit purposes. See Security Architecture for the full data flow.

What IS retained after a session

After the session ends, FaceSign retains only:

What IS NOT retained

  • Raw video — discarded at session end
  • Raw audio — discarded at session end
  • Unprocessed biometric frames — never written to storage
  • Any media that could reconstruct the original recording — not retained by default
  • Raw photos — biometric fingerprints are hashed, not raw photos. Matching requires a live session plus liveness detection, which blocks replay and rainbow attacks.
Session media (video and screenshots) are retained only if you explicitly opt in for audit purposes. Recognition against hashed fingerprints only occurs if the user’s consent allows it and your deployment has opted in. Defaults lean toward minimum retention.

What you control

You choose:
  • Whether to retain session media for audit or attribution
  • Whether to store biometric fingerprints for cross-session recognition
  • Whether to pass any user identifiers from your system into the session context
  • Whether to enable document scan retention
All choices are configurable per integration.

Retention periods

FaceSign applies two retention thresholds: After deletion, the data cannot be recovered. FaceSign does not maintain backup copies of purged biometric data.

Right to delete

Data subjects (end users) can request deletion of their biometric data. As the data controller, you handle these requests and relay them to FaceSign:
1

User submits a deletion request

The user requests deletion through your organization’s standard privacy process.
2

You verify the request

Confirm the request is valid under the applicable regulation (GDPR, CCPA, or your local law).
3

You submit a deletion request to FaceSign

Send the request via the API or by contacting privacy@facesign.ai.
4

FaceSign deletes the data

Deletion completes within 30 days. This includes the biometric fingerprint, session metadata, and any tokenized features associated with that user.

Right to access

Data subjects can request a copy of the data FaceSign holds about them. FaceSign supports access requests by providing:
  • Confirmation of whether biometric data exists for the subject
  • Session history and metadata (dates, outcomes, risk scores)
  • AI transcripts from verification sessions
  • A description of the biometric fingerprint (not the fingerprint itself, which is a one-way hash and not human-readable)
The biometric fingerprint is a one-way tokenized representation. It cannot be reversed to reconstruct the original face or voice. Access requests receive a description of what is stored, not the raw token.

Consumer rights by regulation

FaceSign does not sell, share, or use biometric data for any purpose beyond the verification session you initiated. There is no secondary use.

Next steps

Security Architecture

HSM tokenization, encryption standards, and zero raw video retention.

Compliance

GDPR, CCPA, BIPA, SOC 2, and ISO 27001 regulatory details.

Coercion Detection

How FaceSign detects when users act under duress.