Issue 01 · Identity and age verification · 16 June 2026

You proved you were real.
Where did the proof go?

To open an account, watch a video, or start a job, you hand your face and your ID to a company you never chose. Here is what they keep, why 'we delete it' is a claim you can't check, and what a regulator found when it looked.

The box you used to tick

You used to tick a box that said you were over 18, and that was that. Now the camera comes on. You hold up your passport, or you turn your head slowly while your phone works out whether you are a real person, and then the video plays or the account opens.

It takes half a minute, so it feels like nothing much. What happened is that your face and your document went to a company you did not choose, and that company now knows you were at that particular door, on that day.

Where the check came from

Proving who you are to a company is not new. It used to happen in a branch, with a person looking at a document. The online version arrived through banks. After 2001, US law required every bank to verify the identity of anyone opening an account and to keep a record of what it used to check; the rule took effect in October 2003. The UK put the same duty into its money-laundering rules. That is the world "know your customer" comes from: a bank, a passport, and a file the bank keeps for years because the law says so.

Age checks came next, and they spread by law. In the UK, the Online Safety Act means that since 25 July 2025 any service that allows pornography has to run what the regulator calls highly effective age assurance, and other services have to keep children away from content that could harm them, which has meant checks on forums and social apps too. In the US, more than twenty states passed laws of their own, and in June 2025 the Supreme Court upheld the Texas one, so the checks are staying.

Then the checks moved past what the law asks. A dating app asks for a selfie to prove you are the person in your photos. A marketplace asks for an ID before you can sell. A forum asks for a face scan to lift a restriction. Some of these are required by law, and many are the company's own choice, made to cut fraud, spam or liability. Either way, the same handful of verification companies sells the check to all of them.

That is where the risk sits. A bank keeps its copy of your passport under rules written for banks. The verifier behind a dating app or a video site is a company you never chose, holding your document and your face alongside everyone else's, for every site that pays it. The check is the same each time. The difference is who holds the proof afterwards.

What the check takes

Depending on how it is done, the check can take:

  • a photo of your ID, with everything printed on it: name, date of birth, address, document number, expiry
  • a selfie or a face scan, turned into a template, which is a map of your face precise enough to recognise you again
  • a few seconds of liveness video, you blinking or turning your head, to prove you are not a photo
  • your device, roughly where you were, and which site sent you

The yes-or-no answer about your age is the smallest part of it. What gets stored is your face, your document and the door you were standing at.

The company behind the button

The site you came for almost never runs the check itself. It hands you to a verification company, and that company often hands part of the job on again. You picked the site, not the verifier, and you probably never caught its name.

A few of these companies now sit behind a lot of doors: the video site, the forum, the dating app, the betting page. Every time one of them checks you, it sees another door you walked up to. If you want the long version of what this industry's own policies allow, we keep one here.

How the check travels

You
ID document the photo page
Your face a scan, turned and blinked
Dating app asks for the check
Video site asks for the check
Forum asks for the check
Marketplace asks for the check
Lanterna ID the verifier, a company you never chose

You hold up your ID.
The raw image leaves your phone.

The dating app asks for a scan of your document and your face. Both go out through the app, to a place you did not pick.

1 / 5

Step through it.

"We delete it right after"

Every company in this trade says a version of the same thing: the photo of your ID and the selfie go as soon as the check is done. Some keep the images anyway, and you are never told. The promise is the whole basis for handing anything over, and you have no way to check it from outside.

Now and then one of them gets caught. Tea, a women's safety app, told users their verification photos were deleted straight after the check. In July 2025 about 72,000 images were pulled out of an unsecured storage bucket, roughly 13,000 of them selfies paired with government IDs, sitting there with no password on them. They belonged to people who signed up before February 2024, and Tea had stopped asking for IDs in 2023. A separate flaw days later exposed around 1.1 million private messages. Class actions followed, including one under Illinois's biometric law.

Tea's promise was the same one every verifier makes. The difference is that its storage was open to whoever had the address, so anyone could see what it had kept. Everywhere else the same sentence sits in the same place in the policy, and you take it on trust.

A regulator's view of what gets kept is worth more than the promise. Spain's data protection authority, the AEPD, went through Yoti, one of the big face-check providers, and fined it €950,000. There was no hack. The largest part was for processing face data unlawfully. The rest was about keeping: location data held for five years, face data kept so people could recover accounts, ID documents flagged as fraudulent kept to train Yoti's own software, liveness videos held for a month, and a consent box for internal research ticked by default, which the AEPD said was not real consent.

Discord said the scan of an ID is deleted once verification passes, and the ID photos of around 70,000 people leaked anyway. They were sitting in an appeals queue run by an outside support vendor, a part of the chain nobody shows you, rather than on the automated path that does the deleting. AU10TIX, which runs checks for some of the largest platforms in the world, left an admin login exposed for about eighteen months. In each case "deleted" described what happened when everything worked.

"It doesn't identify you"

The other reassurance is that your face becomes a template, a string of numbers that is supposed to be abstract and harmless. Yoti argued exactly that to the AEPD: the biometric data authenticates you, it does not identify you. The regulator threw it out. A face template is biometric data either way, its purpose is to identify you, and it sits in the most protected class of personal data under the GDPR.

The same goes for "anonymised". What companies usually mean is de-identified: the name comes off, the rest stays, and it can be traced back to you. Truly anonymous data cannot be tied to anyone, and that is rare. We went into it here.

Why this data is worth holding

The record that ties your real-world identity to your online life is one of the most valuable things a company can have, and the firms best placed to collect it are the ones you are now required to pass through. Verification pages carry the same advertising and analytics trackers as the rest of the web. Verifiers name credit bureaus and data brokers among the parties they pass information to. And the check itself gets stretched into wider checks: exposed front-end code from Persona showed it screening people against adverse-media lists while it was at it.

If it leaks, you can't reissue your face

A leak here hands someone your government ID and the face that proves it is yours, next to a list of where you used it: the adult site, the political forum, the health community, the dating app. The pairing is a ready-made identity kit, and the list on its own says plenty about you. You can change a password on a bad afternoon; your face stays the same.

The Electronic Frontier Foundation put it this way:

"If age verification requirements become law, you'll have to be lucky every time you are forced to share your private information. Hackers will just have to be lucky once."

What you can do

You cannot opt out of being asked. While the law and the platforms want the check, it happens. What is left to you is to hand over the least you can and keep track of what you handed over.

  • Hand over the least. Where a site gives you a choice, a method that answers yes or no, or one that runs on your own phone, leaves less behind than uploading a passport to a stranger.
  • Ask the site that made you verify. Send it a deletion request for what the check collected, and ask it to pass that on to whoever ran it. Two companies hold this: the one you dealt with, and the one behind the button.
  • Keep what comes back. The date, the site, and their own words about what they kept.

Whatever they say is their claim, and nobody outside the company can check it, us included. It still beats the policy, because it is about your data, dated, with their name on it.

That last part is what we take off you. You add the company, we work out what it likely holds, and we write the request, worded and ready to send. You send it from your own inbox, their reply lands in yours, and we keep the list and the dates.

The same clauses sit under every privacy policy, and the same reasons mean deletion is rarely the clean moment it sounds like. Start your record →

More from the blog

ISSUE No. 02

Post 16 Jun 2026

De-identified does not mean what it used to

Every privacy policy lets a company pass on what it holds once your name is off it. The law allowed that because putting a name back took an expert, days and money. It now takes an AI model and a few seconds, and years of messages and profiles went out under the old assumption.

ISSUE No. 03

Post 23 Sept 2026

What dating apps keep, and how the way you write can name you

A dating or matrimony profile holds your face, your faith, who you're drawn to and years of private messages. Some of that has already been shared, sold, scraped, handed to an AI company and leaked. Taking your name off doesn't hide you, because AI can now work out who wrote a text from the way it's written. Here's what these apps hold, where it has gone, and what to ask for.

The Fine Print Identity Verification: how the industry handles your data
The Fine Print Adult Entertainment: how the industry handles your data
The Fine Print Social Media: how the industry handles your data