Privacy policy
Effective 9 August 2026 · Last updated 9 August 2026
This policy covers two groups. Clients are the organisations that hold a Facenition account and call the API. End users are the people whose faces are presented to the service through a client's application. What we hold about each is very different, so both are set out separately.
Contents
1. The face, in full 2. What we collect from clients 3. How that information is used 4. No sale, no sharing, no third parties 5. How long anything is kept 6. Roles under data protection law 7. Your rights 8. Security 9. Where the service runs 10. Legal disclosure 11. Changes 12. Contact1. The face, in full
Facenition exists to verify a person without building a biometric database. Because that involves a camera and a face, this section comes before everything else and says exactly what happens.
What happens during a call
- A live face is captured by the client's application and sent to the API over an encrypted connection.
- It is combined with the user-controlled inputs and the client's scope to derive an identity token.
- The token is returned to the client, which stores it against the account. The face is discarded.
- The derivation is one way. A token cannot be turned back into a face, and on its own it reveals nothing about a person's appearance.
What is never stored
- No face images. Not on our servers, not in any log, not as a thumbnail or a preview.
- No video, and no frames taken from video.
- No face templates, face geometry, face maps, embeddings or biometric identifiers of any kind.
- No searchable library of faces, because nothing is written to search.
- No copy of the tokens we return. They are derived, sent to the client, and not retained by us.
This is a property of how the product is built, not only an undertaking about what we choose to keep. Neither we nor anyone who compromised us can produce an image of an end user's face, because none was ever written down. That is the whole point of the design, and it is why a breach of Facenition cannot expose the people who used a client's application.
Consent and the client's role
The camera is opened by the client's application, under wording the client controls. Clients are responsible for having a lawful basis, for telling their end users what is happening, and for offering a workable route through for anyone who cannot or will not present a face.
2. What we collect from clients
Unlike end users, account holders do leave a record with us. It is short.
- Name
- Email address
- Phone number, which is used to confirm the account at registration
- Organisation, where given
- API tokens issued to the account, and the record of when they were issued or rotated
- Technical records of API calls: the time, the endpoint, the originating address, and whether the call succeeded
- Correspondence you send us
Registration asks for an email address and a phone number because both are confirmed before an account is issued, one by emailed code and one by text message. That is the only reason a phone number is held.
3. How that information is used
- Issuing and rotating API tokens, and authenticating calls made with them
- Confirming an account at registration
- Counting usage, and enforcing the limits that apply to an account
- Securing the service, identifying abuse and investigating faults
- Answering support requests and sending notices about the service itself
It is not used for advertising, for profiling, or for building any picture of a person beyond running the service they asked for.
4. No sale, no sharing, no third parties
We do not sell, rent, trade or otherwise disclose personal information to anyone. We do not share it with advertisers, data brokers or partners.
There is no third-party analytics on this site or in the service. No Google Analytics, no product analytics, no session recording, no heat maps, no advertising pixels, no social widgets, no error reporting service. There are no behavioural tracking cookies. Cookies are used only where one is needed to operate the service, and for nothing else.
Fonts, scripts and the verification engine are served from infrastructure we operate, so loading a page or making a call does not tell a third party that you were here.
5. How long anything is kept
- Face captures are not retained at all, at any point, as set out in section 1.
- Derived tokens are not retained by us. The client holds the only copy.
- Account information is kept while the account is open, and removed when it is closed.
- API call records are kept for as long as they are useful for billing, security and fault investigation, and then deleted.
- Correspondence is kept while it is relevant to supporting the account.
6. Roles under data protection law
For anything concerning an end user, the client decides why a verification happens and Facenition acts on that client's instructions. The client is responsible for the lawful basis, for informing its own users, and for handling requests from them.
For client account information, Facenition decides how it is handled and is answerable for it directly.
Because no face image and no reusable biometric is stored, there is no biometric record for either party to disclose, correct or erase. There is nothing to hand over, because nothing was kept.
7. Your rights
Subject to the law where you are, you may ask to see the information held about you, correct it, have it deleted, receive a copy, withdraw consent, or object to how it is handled.
End users should approach the organisation whose application asked them to verify, since that organisation holds the account and the token. Clients can contact us directly at the address below.
8. Security
- Encryption in transit for every call
- API tokens stored only as hashes, and replaceable by the account holder at any time
- Face captures held in memory for the duration of a call and never written to disk
- Restricted administrative access, firewalling and monitoring
- Accounts showing malicious or abusive behaviour are blocked
No system connected to the internet can be guaranteed secure, and we do not claim otherwise. What we can say is narrower and more useful: the material people most fear losing in a breach of a face verification service is not held here to lose.
9. Where the service runs
Our servers are located in Australia. Using the service from elsewhere means the information described in this policy is handled there.
10. Legal disclosure
We disclose information only where we are required to comply with the law, to answer a valid legal request, to protect our rights, or to prevent fraud or a threat to safety. In every one of those cases there is no face image and no biometric record to disclose, because none exists.
11. Changes
We may update this policy. Material changes will be posted here and, where appropriate, emailed to account holders.
12. Contact
Facenition
Email: office@facenition.com
Website: facenition.com
In plain terms
- No photograph of anyone's face is stored, at any point, by anyone.
- What comes out of a verification is a token that cannot be turned back into a face, and we do not keep a copy of it either.
- If you hold an account with us, we have your name, email, phone number and the record of your API calls. Nothing more.
- We do not sell anything, we do not share anything, and we run no analytics or trackers of any kind.
- Close your account and what little we hold goes with it.