How long we keep different kinds of data, and the exact order things are removed when an account is deleted.
Effective date: September 4, 2026
We keep data only as long as it serves the purpose it was collected for — running a verification, supporting a dispute, or meeting a legal or regulatory obligation — and no longer. Where a retention period isn't yet fixed by a specific regulation that applies to your institution, we default to the periods below and will tighten them as clearer legal requirements are confirmed.
Only one canonical face embedding is kept per enrolled person at any time. When a new enrollment replaces it, the prior embedding is moved to an internal audit table rather than kept as an active, searchable record. On account deletion, the active canonical embedding is removed first — before the rest of the profile is soft-deleted — as a hard precondition, not a background cleanup job that might lag behind.
Registry numbers are stored as a lookup hash plus an application-layer-encrypted value used only for masked display. These are retained while the account is active and, after deletion, for the same audit window as verification logs (below), since a registry link is part of the record of what was verified.
Every face comparison, match outcome, and 1:N identification is logged with its confidence score, outcome, and context. These logs are retained beyond account deletion to support disputes, fraud investigation, and regulatory audit — this is a deliberate exception to immediate deletion, since a log's value is largely in outlasting the account it describes. We are actively scoping a fixed maximum retention window for these logs against applicable regulatory guidance, rather than treating "indefinite" as a permanent default.
Name, phone, email, and preferences are soft-deleted on account deletion (marked inactive, excluded from normal product use) and are not permanently purged immediately, to preserve referential integrity with historical verification logs. Hard purge on a fixed schedule is a planned follow-up, tracked separately from this policy's current defaults.
Branch, staff, and billing records for an institution are retained for the duration of the institution's relationship with FaceTrust AI, plus a reasonable period after termination for billing reconciliation and dispute resolution, consistent with our Data Processing Agreement.
Questions about this document? Contact info@facetrustai.com. See also our Privacy Policy, Data Retention Policy, and Data Subject Request form.
Talk to us about a pilot, or dig into the API reference to see exactly how it fits your stack.