Privacy notice

What we collect, why, and when it's deleted.

Plain English, no legalese maze. The short version: we collect what a verification needs, we keep it for as short a time as the law allows, and we never sell it.

Last updated: July 26, 2026

Privacy notice

What we collect on this website

When you visit idcheck.now (this marketing site, the docs, and the free tools), we collect:

  • Your IP address and basic request metadata
  • A device fingerprint — browser, hardware, and browser-signal data
  • Basic usage metadata — pages viewed and interactions
  • Free-tool uploads — photos you upload or scan with the free PDF417 decoder tool, plus the barcode payload decoded from them. (Text you paste into that tool is decoded locally in your browser and is never sent to us.)

We use this for fraud prevention and product analytics, to evaluate and improve the verification pipeline, and to keep the service secure. Device data is retained only as long as needed for those purposes and is never sold.

What we collect in the verification flow

When an end user completes an identity verification through our hosted flow (on our domain, embedded in a merchant's product), we collect what the check requires:

  • Document images — photos of the front and back of the ID, and the data decoded from its PDF417 barcode
  • Selfie capture — a short live video/photo sequence used for liveness and face matching
  • Biometric data — a 512-dimensional face embedding derived from the selfie and document portrait
  • Consent records — the checkboxes you agreed to, the policy version, timestamp, IP address, and user agent
  • Session metadata — device and capture-integrity signals used for fraud detection

Because capture runs on our hosted flow, this data goes to us — not to the merchant. The merchant receives the decision and the fraud-check detail, not your biometrics.

Consent comes before the camera

The verification flow presents two affirmative checkboxes — a biometric release and a recording consent — before any camera or microphone access is requested. Nothing is captured until you agree. The consent policy text is versioned, and the version hash is stored with your consent record in a hash-chained audit log.

How long we keep it

Retention is split by data type. Raw media and biometrics have short lives; decision records are kept longer because anti-money-laundering rules require it.

Data Retention
Raw media + biometrics 30–90 days after the decisionHard legal ceilings: 3 years (Illinois BIPA), 1 year (Texas CUBI), 24 months (Colorado)
Decision records + audit trail 5 yearsAML record-keeping obligation
Marketing-site device data Only as long as neededFraud prevention and product analytics

What we don't do

  • We never sell your data — not the marketing-site device data, and certainly not verification data or biometrics.
  • We don't run biometrics through third-party APIs. Face matching and liveness run on our own GPU infrastructure; biometric data never leaves our environment.
  • We don't use verification data for advertising. It exists to make a decision and stand behind it, nothing else.

Subprocessors

We use a small number of service providers to operate the platform — infrastructure hosting, object storage for media, and transactional email. Each processes data only on our instructions and only for the service they provide to us. Biometric inference itself is self-hosted on our own hardware and is not subcontracted. Enterprise customers can request the current subprocessor list as part of due diligence.

Your rights and deletion requests

You can request access to, correction of, or deletion of your personal data. Where a retention obligation applies (for example, the 5-year AML window on decision records), we'll tell you what we must keep and why, and delete everything we can. Biometric data is destroyed at the end of its retention window as described above — earlier where the law requires it.

Questions, access requests, and deletion requests: privacy@idcheck.now. We respond within one business day.

Changes to this notice

If we change what we collect or how long we keep it, we'll update this page and the "last updated" date at the top. Material changes to the consent language shown in the verification flow ship as a new versioned policy — consent records always name the version you agreed to.

Privacy questions, answered by a human.

Email us and a real person replies within one business day.