Biometric Retention & Destruction Policy
- Version
- 1.0
- Effective
- August 15, 2026
- Last updated
- August 15, 2026
Policy Statement
TRUSTTICA maintains a policy governing retention and permanent destruction of biometric identifiers and biometric information under applicable law. This policy draws a deliberate line between two things that are easy to conflate: the verification record that proves a check occurred, and the raw biometric material used to perform that check. TRUSTTICA is built to keep the former and minimize the latter.
Retention Architecture
Each category of information processed during identity verification has its own retention rule — none of them is retained merely because a verification record needs to exist.
A. Government Identification
Government ID images are retained only for the period necessary to complete identity verification, resolve verification disputes, satisfy legitimate security or legal requirements, or meet an applicable provider or legal retention obligation. They are not kept indefinitely merely because an Evidence Vault record exists.
B. Selfie / ID-Hold Photograph
The selfie or ID-hold image is retained only for the legitimate verification/security period established by TRUSTTICA and its identity-verification processor. When that retention purpose expires, it is securely deleted according to the applicable retention schedule.
C. Liveness Information
Raw liveness information is retained only as necessary to:
- complete liveness verification
- prevent replay/identity fraud
- investigate verification abuse
- satisfy applicable legal requirements
D. Facial Geometry / Biometric Template
This is the most important rule in this policy: TRUSTTICA's Evidence Vault does not store reusable facial geometry or biometric templates merely to prove that a verification occurred. If a processor temporarily generates a mathematical representation, facial geometry, embedding, template or comparable biometric identifier for matching or liveness purposes, it is destroyed according to the applicable biometric retention requirement once its legitimate purpose has expired. The Evidence Vault retains the result, not an unnecessary reusable biometric template.
What the Evidence Vault Keeps
The Evidence Vault preserves the verification record needed to establish what occurred — not more biometric data than necessary to prove it. A typical verification record includes:
- verification ID
- internal user identifier
- verification type
- identity status (verified / failed / pending)
- document status
- liveness status (passed / failed)
- verification provider reference (a non-sensitive reference, not raw biometric data)
- consent version and consent timestamp
- verification timestamp
- presence confirmation, where applicable
- Trust Token identifier
- relevant security/audit events
- record integrity metadata
In short: the Evidence Vault preserves proof that verification occurred — not more biometric data than necessary to prove it. Evidence Vault retention is never used to justify retaining raw biometric templates indefinitely.
Retention & Destruction Schedule
| Data | Primary purpose | TRUSTTICA policy |
|---|---|---|
| Biometric template / face geometry | Matching / liveness | Not generated or stored by TRUSTTICA — face matching and liveness are performed by our identity verification processor, which returns only a match decision and confidence score, not a reusable template |
| Raw liveness information (e.g. liveness capture frames) | Liveness / fraud detection | Deleted automatically 90 days after capture, together with the selfie |
| Selfie | Identity verification / dispute / security | Deleted automatically 90 days after capture |
| ID-hold photograph | Identity verification | Deleted automatically 90 days after capture |
| Government ID image | KYC / identity verification | Deleted automatically 90 days after capture |
| Verification result | Proof of verification | Retained approximately 3–5 years as evidence of the verification outcome |
| Trust Token | Verification evidence | Retained approximately 3–5 years, matching verification-result retention |
| Consent record | Legal / compliance evidence | Retained approximately 3–5 years to demonstrate consent/compliance |
| Presence confirmation | Verification evidence | Retained approximately 3–5 years, matching verification-result retention |
| Security / audit log | Security / fraud / compliance | Retained approximately 3–5 years |
Critical engineering rule: Evidence Vault retention is never used as justification for retaining raw biometric templates indefinitely.
Destruction Standard
When biometric information reaches the end of its authorized retention period, TRUSTTICA or the applicable processor securely destroys or permanently deletes it so that it is no longer reasonably recoverable through ordinary systems. Deletion propagates, according to technically appropriate lifecycle procedures, to primary storage, derivative biometric records, caches where applicable, processing environments, and backups according to backup-expiration schedules.
Where technically feasible, an auditable destruction event is generated for each stage:
- BIOMETRIC_RETENTION_EXPIRED
- BIOMETRIC_DELETION_INITIATED
- BIOMETRIC_DELETION_COMPLETED
The deleted biometric material itself is never placed inside the deletion audit record.
Statutory Benchmark
Where Illinois's Biometric Information Privacy Act (BIPA) applies to covered biometric data, its statutory benchmark for destruction is when the initial purpose is satisfied or within three years of the individual's last interaction, whichever occurs first, subject to the statute's provisions. Where Texas law applies, covered biometric identifiers must be stored, transmitted and protected using reasonable care and at least as protectively as TRUSTTICA protects other confidential information. TRUSTTICA's actual retention periods, once confirmed, will not exceed what applicable law permits.
Third-Party Identity-Verification Providers
TRUSTTICA may use authorized third-party identity-verification and liveness providers to perform parts of the verification process. Those providers may process identity documents, photographs, selfies, liveness information or related verification information according to their contractual obligations, applicable law, and their role in providing the TRUSTTICA verification service. TRUSTTICA contractually requires applicable providers to maintain appropriate safeguards and retention/deletion practices. The specific production provider and its confirmed processing/retention behavior are listed on the Subprocessors / Service Providers page once integration is confirmed — it is never guessed or substituted here.
Account Deletion
Deleting a TRUSTTICA account triggers a retention evaluation covering biometric and related verification information. See the Account Deletion page for how information is categorized as eligible for immediate deletion, scheduled deletion, or legally required retention.
Questions About This Policy
For questions about how a specific category of biometric information is retained or destroyed, contact support@trusttica.com.