Security and data handling
What we store, for how long, where it is hosted, who else processes it, and how we protect it.
The binding terms are in our Data Processing Agreement and our Privacy Policy. This page summarizes them.
Who is responsible for the data
The business that requests a verification is the data controller. ProofAge (IT Brains SASU) is the processor and acts only on that business's documented instructions.
We don't sell verification data or use it for advertising.
Private and Protected modes
Each workspace runs in one of two modes. Private mode keeps nothing it doesn't need once the decision is made. Protected mode remembers faces and devices so you can block repeat accounts: banned users and duplicate accounts. The price is the same in both modes.
- EUDI Wallet age verification (beta) always runs in Private mode: there is no photo or document to keep.
- Facial age estimation and Age verification by ID run in either mode.
- Identity verification (KYC) always keeps data: it runs in Protected mode only.
| Topic | Private (nothing remembered) | Protected (remembers, to protect) |
|---|---|---|
| What is stored | Nothing. Photos and video are deleted right after the decision. | Photos, video and verification data for 30 days. A face template and a device fingerprint hash for 12 months. |
| What you get | The decision. With Age verification by ID, also first name, last name and date of birth by API. Nothing is kept afterwards. | The answer, plus duplicate detection and blocking by face and by device. |
| Good for | Age-gated stores and content, where keeping as little data as possible matters most. | Dating, marketplaces, communities and any platform that bans users. |
You choose the mode for each workspace.
How long we keep data
Retention depends on the mode of the workspace.
| Data | Private mode | Protected mode |
|---|---|---|
| Selfie, video frames and document images | Deleted right after the decision | 30 days |
| Verification data: data read from the document (with Identity verification (KYC), every field on it, including the address when present), face match result, verification result, IP address and approximate location | To be confirmed (see the note below) | 30 days |
| Face template (a mathematical vector that cannot be turned back into a photo) | Not kept | 12 months |
| Device fingerprint hash | Not kept | 12 months |
| Consent record | To be confirmed | As long as the law requires |
To be confirmed: whether Private mode keeps a decision record (approved or declined, with a timestamp), and for how long.
- Periods run from the verification. At the end of each period, data is deleted automatically and permanently.
- You can ask for shorter retention for your workspaces, or delete a verification's data sooner.
- A user can withdraw consent or ask for their data to be deleted by writing to privacy@proofage.net with their verification reference.
- When your contract ends, we delete your verification data. Copies in backups disappear as the backups expire, within 7 days.
Where data is hosted
- Google Cloud EU regions by default. Storage and the main processing, including the AI models that analyse images and documents, run there.
- US regions on request, agreed in writing.
- Certified liveness runs on AWS in an EU region.
Subprocessors
A summary. The full list, with the data each one receives and the transfer safeguards, is in Annex III of the DPA.
| Provider | What for | Used |
|---|---|---|
| Google Cloud | Hosting, storage, backups, face and document analysis | Always |
| Sentry | Error monitoring, set up not to collect personal data by default | Always |
| Ably | Tells the open verification page that its status changed. No images, names or document data. | Always |
| ipapi.co, IPinfo | IP geolocation for fraud prevention. They receive the IP address only. | Always |
| Amazon Web Services | Certified liveness, in an EU region | Only when certified liveness is used |
| Anthropic, OpenAI | Backup AI models for anti-spoofing and fraud review | Only when the primary EU-hosted models are unavailable or can't complete an analysis, or a verification needs a second review |
| FingerprintJS | Device intelligence for fraud prevention | Only in Protected mode, and only where it is enabled |
We give 30 days' notice by email before adding or replacing a core subprocessor, and you can object. Backup and optional providers are listed in the DPA before they receive any data.
How we protect it
Data is encrypted in transit and at rest.
| Area | What we do |
|---|---|
| In transit | TLS 1.2 or higher for all traffic to and from the services. |
| At rest | AES-256 for databases, file storage and backups. Verification images are reachable only through authenticated requests or short-lived signed links. |
| Access control | Least-privilege, role-based access for our staff. Access to production data is limited to named people and logged. Two-factor authentication and passkeys for dashboard accounts. |
| Customer isolation | Every record belongs to one customer and workspace. API requests are signed with per-workspace keys, and webhooks are signed so you can check they came from us. |
| Backups | Daily, encrypted, kept 7 days. |
| Development | Code review and automated tests before every release. Secrets kept out of source code. Dependencies kept up to date. |
What we commit to in the DPA
Breach notice
If a breach affects your data, we tell you by email without undue delay, and within 48 h of becoming aware of it.
International transfers
Where data leaves the EEA, the EU Standard Contractual Clauses apply, with the UK Addendum for UK transfers.
Audit rights
We answer a reasonable security questionnaire and share our security documentation. If that is not enough, you can audit us, or have an independent auditor do it, on the terms in section 12 of the DPA.
Model training
We don't use verification photos, documents or face data to train models.
Status and availability
Our target for the API is 99.9% availability each month, as set out in our Terms.
The public status page shows the current state of the services and any incidents.
Report a vulnerability
Found a security issue? Write to security@proofage.net with the steps to reproduce it. Please don't access other people's data or disrupt the service while testing.
Our contact details for researchers are also published in security.txt.
ProofAge has no SOC 2 or ISO 27001 certification yet. If your review needs evidence, we answer security questionnaires and share our documentation.
Check it on your own users
500 live verifications free, no time limit, no card. The binding terms are in the DPA.