Draft: this wording is still being reviewed, and a few business details are yet to be filled in.
Biometric Data Policy
Last updated 2026-10-01
How MakeItLit! collects, uses, keeps and destroys biometric data, which only happens when you choose to verify your selfie. [COMPANY LEGAL NAME] is responsible for it. Questions: privacy@makeitlit.app.
What we collect, and why
Only if you choose to verify your selfie, and agree first: a few live selfies, each doing a move we ask for (like turning your head or smiling). Amazon Web Services checks each move and compares the face in them with the face in your main profile photo. That comparison measures facial features (face geometry), which is biometric data.
Once you’ve agreed, we also check that your main photo shows a face, and keep only the yes or no.
Why: to show other members the Solid badge (your selfies matched your photos), and to stop fake profiles. Never for advertising, and never to recognize you anywhere else.
We don’t collect biometric data from anyone who hasn’t agreed, and we never compare one member’s face with another’s.
Who it’s shared with
Amazon Web Services does the checking for us, as our service provider, under contract.
We never sell, lease or trade biometric data, or otherwise profit from it, and we don’t share it with anyone else unless the law requires it (for example, a valid court order).
How long we keep it
- Verification selfies: deleted as soon as the check is done. If a check never runs, within 1 day.
- Face measurements: never stored. They exist only while the check runs.
- To tune the check, our technical log keeps, for 7 days, how far your head turned, whether each move was seen, and the match scores (numbers out of 100). None of it can be used to recognize anyone.
- What we keep, which isn’t biometric data: whether you passed (the Solid badge) and when, whether your main photo shows a face, and the record that you agreed (which wording, and when). These stay with your account and are deleted with it.
Destroying it
Biometric data is permanently destroyed at the earliest of: when the purpose it was collected for is done (for verification, the end of the check); 24 months after you last used MakeItLit!; or 45 days after we find it’s no longer needed. In any case, never later than 3 years after your last interaction with MakeItLit!.
Destroying means deleting the files and every copy we control.
Once a year we check that we hold no biometric data we don’t need, and destroy anything we find within 45 days.
Taking back your consent
Write to privacy@makeitlit.app from the email address on your account. We stop comparing your face and the Solid badge comes off; there’s nothing else to delete, since we don’t keep the measurements. You keep your account, without what verifying unlocks.
Keeping it safe
Selfies go over an encrypted connection straight into private, encrypted storage that isn’t on the public web, and are deleted after the check.
We have a written plan for responding to a security incident that could affect biometric data, which includes telling the people affected, and the authorities, as the law requires.