Terms and conditions
Effective 9 August 2026 · Last updated 9 August 2026
These terms apply between Facenition and the organisation or person holding an account and using the API. Requesting a token or making a call means accepting them.
Contents
1. What the service does, and does not do 2. Your account and your API token 3. Your data is yours to keep 4. Your obligations to your end users 5. Acceptable use 6. Blocking and suspension 7. Availability 8. Commercial terms 9. Intellectual property 10. No warranty 11. Limits of liability 12. Indemnity 13. Ending the agreement 14. Changes to these terms 15. Governing law 16. Contact1. What the service does, and does not do
Facenition derives an identity token from a live face combined with user-controlled inputs and your scope, and later confirms whether a presented face and those same inputs reproduce that token. No face image or template is stored at any point.
The service establishes that the person presenting themselves matches a token your application already holds. It does not establish who that person is in the world, that they are who they claim to be, that documents they hold are genuine, that they are of any particular age, or that they are acting for themselves and not under duress. It is one signal among the controls you use, and it should not be the only control on a decision that matters.
The service returns a score and a decision against thresholds. Like every biometric system it can fail a genuine person and can be defeated by a sufficiently determined attack. Section 10 is not boilerplate, and you should read it before you design a flow around this.
2. Your account and your API token
- You are responsible for everything done through your account and with your token.
- Your API token belongs on your server. Publishing it in a web page, an app bundle, a public repository or a client-side script is a breach of these terms, and any use that follows it is yours.
- Tell us promptly if you believe a token has been exposed. You can rotate it yourself at any time.
- One organisation per account. Do not share account credentials.
- The details you give at registration must be accurate, and the email address and phone number must be ones you control.
3. Your data is yours to keep
This section matters more here than it would with an ordinary API, so it is stated plainly rather than buried.
The identity token we return to you is not retained by us. You hold the only copy. There is no shadow copy on our side to fall back on, no export to request, and no support request that can recover one, because the design that protects your end users is the same design that leaves us with nothing to give back.
- Storing, backing up and protecting the tokens issued to you is entirely your responsibility.
- If you lose a token, the enrolment it represents is gone. The affected person must enrol again.
- The same applies to any record you keep of verifications, scores or decisions. We do not maintain a copy of your operational data on your behalf.
- Test your restore path before you rely on it in production, not after.
We accept no responsibility or liability for any loss, corruption or unavailability of data held by you, however it arises.
4. Your obligations to your end users
You are the one asking a person to present their face. These obligations are yours, not ours.
- Have a lawful basis for asking, wherever your end users are.
- Tell them what is happening in your own privacy notice, and keep any consent wording you show accurate.
- Offer a workable alternative for anyone who has no camera, refuses permission, or cannot complete a verification. Nobody should be shut out of your service because of this.
- Do not use the service on people you know to be children where the law where they are does not permit it.
- Do not present a result as identity verification, age verification, or proof of anything it does not establish.
- Handle requests from your end users about their own information. They are your users, and you hold the token.
5. Acceptable use
You may not use the service, or attempt to use it, to:
- Identify, track, profile or match people without their knowledge, or combine results with other data for that purpose
- Run verifications on people covertly, or through an interface designed to obscure that a camera is opening
- Build or populate a biometric database, whether from your own captures or from anything the service returns
- Submit images of a person who has not agreed to it, or images obtained from a third party for that purpose
- Reverse engineer, probe, load test without agreement, or interfere with the service, or attempt to produce a passing result without a live person present
- Resell access, or place the service behind your own API for third parties, without a written agreement with us
- Exceed the limits applying to your account, or work around them using multiple accounts
- Break any law, or facilitate anything unlawful
6. Blocking and suspension
We block malicious use. Where an account, a token or a source of traffic is abusing the service, attacking it, attempting to defeat a verification, or breaching section 4 or section 5, we may block or suspend it, in whole or in part, immediately and without notice where the circumstances require it.
We will tell you why where it is reasonable and lawful to do so, and we will restore access once the cause is resolved. Blocking to protect the service, its clients or the people using it is not a breach of these terms by us, and no refund or compensation is payable for a suspension brought about by your own breach.
7. Availability
We aim to keep the service running continuously, and we do not promise that it will be. Maintenance, faults, capacity limits, network conditions and events outside our control can interrupt it. There is no uptime guarantee and no service level commitment unless one is set out in a separate written agreement signed by us.
Design your own flow so that an unavailable verification does not break your application. Decide in advance whether the action waits, falls back to another control, or proceeds with a flag for review.
8. Commercial terms
Pricing, allowances, invoicing and payment terms are those set out in the plan or written agreement applying to your account. Fees are payable in advance unless agreed otherwise and are not refundable in part, except where the law requires it. We may change pricing on reasonable notice, taking effect at your next renewal.
9. Intellectual property
The service, the API, the derivation method, the documentation and everything in them remain ours, along with the Facenition name and registered trademark. You receive a non-exclusive, non-transferable right to use the API within your own applications for as long as your account is open, and nothing more. Tokens derived for you, and the data you hold, remain yours.
10. No warranty
The service is provided as it is and as it is available. To the extent the law allows, we exclude all warranties, conditions and representations, whether express or implied, including any implied warranty of merchantability, fitness for a particular purpose or non-infringement.
In particular, we do not warrant that the service will identify every genuine person correctly, that it will reject every attempt to defeat it, that it will be uninterrupted, that it will be free of faults, or that any result is accurate or fit for the decision you use it in. Face verification raises the cost of impersonation. It does not eliminate it, and we say so here rather than in a footnote.
11. Limits of liability
To the extent the law allows, neither party is liable for indirect, incidental, special or consequential loss, nor for lost profits, lost revenue, lost business, lost goodwill, or loss or corruption of data, however caused.
To the extent the law allows, our total aggregate liability arising out of or in connection with the service, in any twelve month period, is limited to the fees you paid us in that period. Where no fees were paid, our liability is limited to resupplying the service.
We are not liable for any decision you make on the strength of a result, for any consequence of a genuine person being rejected or an impostor being accepted, or for any loss of data held by you.
Nothing in these terms excludes, restricts or modifies any right, guarantee or remedy that cannot lawfully be excluded, including under the Australian Consumer Law. Where a guarantee applies and cannot be excluded, our liability is limited, at our option, to resupplying the service or paying the cost of having it resupplied.
12. Indemnity
You will indemnify us against claims, losses and costs arising from your use of the service in breach of section 4 or section 5, from your handling of your end users' information, from claims by your end users about how or why a verification was presented to them, and from any loss of data held by you.
13. Ending the agreement
You can close your account at any time. We may end or suspend an account for a breach of these terms, for non-payment, or if we cease offering the service, on reasonable notice except where a breach or a threat to the service requires immediate action.
When an account closes, your tokens stop authenticating and the account information we hold is removed. Tokens you have stored on your side are unaffected and remain yours. Sections 3, 9, 10, 11, 12 and 15 survive the ending of this agreement.
14. Changes to these terms
We may update these terms. Material changes will be posted here and emailed to account holders before they take effect. Continuing to use the service after that means accepting them.
15. Governing law
These terms are governed by the laws of New South Wales, Australia, and both parties submit to the exclusive jurisdiction of the courts of that state.
16. Contact
Facenition
Email: office@facenition.com
Website: facenition.com
The three that catch people out
- Back up your tokens. We hold no copy. Lose one and that enrolment is gone for good.
- It proves a match, not an identity. Do not build a flow that treats a pass as proof of who someone is.
- Keep the API token server side. Anything done with an exposed token counts as done by you.