Identity Verification

The industry files

The brand on the screen rarely runs the check: your document and face route to a verification company, and when the images are deleted the result stays. Fraud exceptions store the rest, and your face can train the next model.

The read at a glance

Tracking priority High

The verifier holds your document and your face, the two things about you that you cannot change.

If it leaks Severe

A leak exposes your government ID and your face next to a log of the sites you tried to enter.

Expect it kept Indefinitely

Documents flagged as fraudulent, and data kept to "improve" the check, can be held with no end date.

Identity demanded Full KYC

The service exists to take your ID and face: document, selfie, and a liveness video.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

A verifier holds the passport scan and the face that proves it is yours, and archives of exactly that pairing have leaked before. You can replace a stolen document number. You cannot reissue your face.

What repeats in the policies

Who runs the check

The brand on the screen rarely runs the check

Your ID and face commonly pass through a chain you never chose: the platform picks a verifier, the verifier passes work to vendors of its own, and each link keeps a copy under its own rules. People at outsourcing firms on another continent can review your document, and requests about your data are sent back to the platform that ordered the check.

When you delete

The images go, the result stays

Deletion typically removes the images and keeps what was made from them. Results and check records are commonly kept for good, and face maps and document codes feed shared fraud databases matched against strangers' future checks. How long all of that stays is often set by the verifier's business customer, and the clock can run from their contract rather than from your check.

The reuse

Your face can train the next model

Across the sector, improve means train: policies keep verification images to sharpen the recognition systems sold to the next customer, and a regulator has already fined a verifier for keeping ID documents to train its software. The consent screen often does legal work too, sometimes carrying an arbitration clause and a promise not to sue.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Identity DocumentsPhotos & Biometrics Contact Info · maybeAccount Profile · maybeLocation · maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Your face and voice Highly likely

A face template matches you for life.

Where you go Possible

Which sites checked you builds a picture of where you go online.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Identity and age-check records They set it as long as they choose

To prove they checked your age or identity and to block known fraud, sometimes held by a separate verification company.

Fraud-prevention markers They set it about 2 to 6 years

To flag suspected fraud, often on a shared industry database you cannot reach through the company.

Identity / anti-money-laundering records Law sets it about 5 years

Money-laundering rules require ID and transaction records after an account closes.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

The checks themselves are the training data and the fraud network behind the product, and vendors advertise models refined on millions of them. The breach record is documented: archives of ID images and selfies have leaked repeatedly, from verifiers and from their support vendors, and email-based age checks read advertising-broker files to guess your age.

Sold or shared Possible

Sold as a trust product; the data itself trains the vendor's systems.

AI training High

Your face and document train the vendor's age and identity models, sometimes via a pre-ticked box.

Even anonymised, this can still be you

There is nothing to anonymise: a biometric template is you, and a leaked face or ID cannot be reissued like a password.

Name, date of birth, postcode Typical

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Face and voice Typical

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“we process this information on behalf of the business that requested the check”

“we process this information on behalf of the business that requested the check”

The verifier holds your face and your documents and answers only to its business customer. Requests sent straight to the verifier are commonly routed back to the platform, or refused on arrival.

The move Aim the request at the platform that ordered the check. A reply that names the verifier and what it received turns the chain into a list.

“images are not stored once the check is complete, except for fraud prevention purposes”

“images are not stored once the check is complete, except for fraud prevention purposes”

The exception is the storage system. For fraud reasons they keep face maps, document codes and results in matching databases on timetables of their own, and compare them against strangers' future checks.

The move A deletion request naming what they made from your images reaches past them: face maps, codes, fraud entries. Their reply should say what stayed and why.

“we may use verification data to improve and develop our services, including machine learning”

“we may use verification data to improve and develop our services, including machine learning”

Improvement means training. Your images and face measurements refine the vendor's next model, usually with the business customer's permission rather than yours, and a model already trained does not unlearn.

The move A written objection makes them name a reason to keep training. Their reply should say what already went in.

From the blog

ISSUE No. 01

Post 16 Jun 2026

You proved you were real. Where did the proof go?

To open an account, watch a video, or start a job, you hand your face and your ID to a company you never chose. Here is what they keep, why 'we delete it' is a claim you can't check, and what a regulator found when it looked.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.