Last updated: June 2026

Privacy Policy

At FaceSign, we take your privacy seriously. This policy describes how FaceSign, Inc. ("FaceSign," "we," "us") collects, uses, and protects personal information in connection with our identity verification and trust-decisioning services (the "Services") and our websites. It works together with our Terms of Service and, for enterprise customers, any executed Data Processing Agreement (DPA).

Scope & Roles

How we handle your data depends on your relationship with us:

  • End Users — individuals who complete a verification session at the request of one of our enterprise customers (a "Customer"). For verification data, the Customer is the data controller and FaceSign acts as a data processor on the Customer's behalf and instructions. The Customer's own privacy notice governs why you are being verified.
  • Customers — for account, billing, and security information of Customer personnel, FaceSign acts as a data controller.
  • Website visitors — for data collected on facesign.ai, FaceSign acts as a data controller.

Information We Collect

When you use FaceSign's Services, we may collect the following categories of information:

  • Identity data: Facial biometric data, voice patterns, and behavioral signals collected during verification sessions.
  • Device data: Device type, operating system, browser information, IP address, and geolocation.
  • Session data: Verification timestamps, session duration, conversation transcripts, interaction patterns, and verification outcomes.
  • Account data: Information provided by Customers to facilitate verification (e.g., name, email, account identifiers) and information Customer personnel provide when registering for or administering an account.
  • Website data: Pages visited, referral source, and similar usage data collected when you browse our websites.

How We Use Information

We use collected information for the following purposes:

  • Providing identity verification and trust-decisioning services as instructed by our Customers.
  • Detecting and preventing fraud, including deepfakes, synthetic identities, and coercion.
  • Securing and operating the Services, including authentication, abuse prevention, and audit logging.
  • Improving the accuracy and reliability of our verification technology, using de-identified, aggregated data that does not include biometric data.
  • Complying with legal obligations and regulatory requirements.
  • Managing Customer accounts, billing, and support.

We do not sell personal information. We do not use personal information for advertising. We do not use biometric data to train our models.

Biometric Data

FaceSign processes biometric data (facial geometry, voice patterns) solely to verify identity and detect fraud during a discrete, consented verification session — never for surveillance, tracking, or any other purpose. Consistent with biometric privacy laws, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act, and the GDPR, biometric data is:

  • Collected only after the Customer provides notice and obtains the consent required by applicable law, as set out in our Terms of Service.
  • Encrypted in transit and at rest using industry-standard AES-256 encryption.
  • Retained no longer than the schedule described in Data Retention below, encrypted at rest, and deleted on request or when the purpose of collection is fulfilled.
  • Never sold, leased, traded, or used for advertising, and never disclosed except to the contracting Customer, our subprocessors as needed to provide the Services, or as required by law.

AI Processing

Verification sessions are conducted by an AI avatar and analyzed by automated systems for liveness, deepfake detection, facial matching, and behavioral signals. You will always know you are interacting with an AI. The output is a probabilistic risk assessment delivered to the Customer that requested the verification — FaceSign does not itself make decisions about your access, eligibility, or accounts. Under our Terms of Service, Customers must apply meaningful human review before making decisions with legal or similarly significant effects. If you believe a verification outcome is wrong, contact the Customer that asked you to verify; we will support their review.

Data Retention

Session video and images are used to perform the verification and are retained only briefly. By default, captured media is automatically deleted within approximately 24 hours. Where recording, extended analysis, or cross-session recognition is in use, session recordings, biometric templates, and related records are retained for the period set in the Customer agreement and deleted on request or when the purpose is fulfilled, unless longer retention is required by law. Account and billing data is retained for the life of the Customer relationship plus any period required by law. Upon termination of a Customer agreement, we delete or return Customer data in accordance with the DPA and our Terms of Service.

Sharing & Subprocessors

We share personal information only with:

  • The contracting Customer — verification results, transcripts, and session reports for sessions they initiate.
  • Subprocessors — vetted service providers (e.g., cloud infrastructure) bound by data protection obligations consistent with this policy and applicable DPAs. A current subprocessor list is available on request to privacy@facesign.ai.
  • Legal authorities — where required by valid legal process, after challenging overbroad requests where appropriate.
  • Successors — in connection with a merger or acquisition, subject to this policy's commitments.

International Transfers

FaceSign currently processes and stores verification data in the United States. Where personal data, including data originating in the EU or UK, is transferred across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.

Data Security

We implement industry-standard security measures to protect your data, including:

  • End-to-end encryption for all verification sessions.
  • AES-256 encryption at rest for stored data.
  • Regular third-party security audits and penetration testing.
  • Strict access controls and audit logging.

If we become aware of a breach affecting your personal data, we will notify affected Customers and authorities as required by applicable law.

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Portability: Request your data in a structured, machine-readable format.
  • Objection & restriction: Object to or restrict certain processing of your personal data.
  • Consent withdrawal: Withdraw consent to biometric processing at any time, without affecting processing already performed.

If you are an End User, the Customer that initiated your verification is the controller of your verification data — we will forward your request to them and assist with its fulfillment. For data FaceSign controls, contact us directly using the information below. We will not discriminate against you for exercising your rights.

Children's Privacy

The Services are not directed to children, and Customers may not initiate verification sessions for individuals under the age of majority without verifiable parental or guardian consent where required by law, as set out in our Terms of Service. If we learn that biometric data of a minor was collected without required consent, we will delete it.

Cookies & Website Data

Our websites use cookies and similar technologies that are necessary for the site to function and, where you consent, to understand site usage and improve our content. We do not use cookies for cross-site advertising. Verification sessions use only the cookies and local storage necessary to operate the session.

Changes to This Policy

We may update this policy from time to time. For material changes, we will update the date above and provide notice on this page or by email before the changes take effect. Prior versions are available on request.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at privacy@facesign.ai.