Security and data handling

What we store, for how long, where it is hosted, who else processes it, and how we protect it.

The binding terms are in our Data Processing Agreement and our Privacy Policy. This page summarizes them.

Who is responsible for the data

The business that requests a verification is the data controller. ProofAge (IT Brains SASU) is the processor and acts only on that business's documented instructions.

We don't sell verification data or use it for advertising.

Private and Protected modes

Each workspace runs in one of two modes. Private mode keeps nothing it doesn't need once the decision is made. Protected mode remembers faces and devices so you can block repeat accounts: banned users and duplicate accounts. The price is the same in both modes.

Private and Protected modes compared
Topic Private (nothing remembered) Protected (remembers, to protect)
What is stored Nothing. Photos and video are deleted right after the decision. Photos, video and verification data for 30 days. A face template and a device fingerprint hash for 12 months.
What you get The decision. With Age verification by ID, also first name, last name and date of birth by API. Nothing is kept afterwards. The answer, plus duplicate detection and blocking by face and by device.
Good for Age-gated stores and content, where keeping as little data as possible matters most. Dating, marketplaces, communities and any platform that bans users.

You choose the mode for each workspace.

How long we keep data

Retention depends on the mode of the workspace.

Retention periods in Private and Protected mode
Data Private mode Protected mode
Selfie, video frames and document images Deleted right after the decision 30 days
Verification data: data read from the document (with Identity verification (KYC), every field on it, including the address when present), face match result, verification result, IP address and approximate location To be confirmed (see the note below) 30 days
Face template (a mathematical vector that cannot be turned back into a photo) Not kept 12 months
Device fingerprint hash Not kept 12 months
Consent record To be confirmed As long as the law requires

To be confirmed: whether Private mode keeps a decision record (approved or declined, with a timestamp), and for how long.

  • Periods run from the verification. At the end of each period, data is deleted automatically and permanently.
  • You can ask for shorter retention for your workspaces, or delete a verification's data sooner.
  • A user can withdraw consent or ask for their data to be deleted by writing to privacy@proofage.net with their verification reference.
  • When your contract ends, we delete your verification data. Copies in backups disappear as the backups expire, within 7 days.

Where data is hosted

  • Google Cloud EU regions by default. Storage and the main processing, including the AI models that analyse images and documents, run there.
  • US regions on request, agreed in writing.
  • Certified liveness runs on AWS in an EU region.

Subprocessors

A summary. The full list, with the data each one receives and the transfer safeguards, is in Annex III of the DPA.

Summary of ProofAge subprocessors
Provider What for Used
Google Cloud Hosting, storage, backups, face and document analysis Always
Sentry Error monitoring, set up not to collect personal data by default Always
Ably Tells the open verification page that its status changed. No images, names or document data. Always
ipapi.co, IPinfo IP geolocation for fraud prevention. They receive the IP address only. Always
Amazon Web Services Certified liveness, in an EU region Only when certified liveness is used
Anthropic, OpenAI Backup AI models for anti-spoofing and fraud review Only when the primary EU-hosted models are unavailable or can't complete an analysis, or a verification needs a second review
FingerprintJS Device intelligence for fraud prevention Only in Protected mode, and only where it is enabled

We give 30 days' notice by email before adding or replacing a core subprocessor, and you can object. Backup and optional providers are listed in the DPA before they receive any data.

How we protect it

Data is encrypted in transit and at rest.

Security measures
Area What we do
In transit TLS 1.2 or higher for all traffic to and from the services.
At rest AES-256 for databases, file storage and backups. Verification images are reachable only through authenticated requests or short-lived signed links.
Access control Least-privilege, role-based access for our staff. Access to production data is limited to named people and logged. Two-factor authentication and passkeys for dashboard accounts.
Customer isolation Every record belongs to one customer and workspace. API requests are signed with per-workspace keys, and webhooks are signed so you can check they came from us.
Backups Daily, encrypted, kept 7 days.
Development Code review and automated tests before every release. Secrets kept out of source code. Dependencies kept up to date.

What we commit to in the DPA

Breach notice

If a breach affects your data, we tell you by email without undue delay, and within 48 h of becoming aware of it.

International transfers

Where data leaves the EEA, the EU Standard Contractual Clauses apply, with the UK Addendum for UK transfers.

Audit rights

We answer a reasonable security questionnaire and share our security documentation. If that is not enough, you can audit us, or have an independent auditor do it, on the terms in section 12 of the DPA.

Model training

We don't use verification photos, documents or face data to train models.

Status and availability

Our target for the API is 99.9% availability each month, as set out in our Terms.

The public status page shows the current state of the services and any incidents.

Report a vulnerability

Found a security issue? Write to security@proofage.net with the steps to reproduce it. Please don't access other people's data or disrupt the service while testing.

Our contact details for researchers are also published in security.txt.

ProofAge has no SOC 2 or ISO 27001 certification yet. If your review needs evidence, we answer security questionnaires and share our documentation.

Check it on your own users

500 live verifications free, no time limit, no card. The binding terms are in the DPA.