DRAFT — ATTORNEY REVIEW REQUIRED BEFORE PUBLISHING
Mandatory page. Strategy §8.4: the absence of a publicly posted schedule is an independent per-plaintiff violation under 740 ILCS 14 § 15(a). Counsel to confirm: the characterization of perceptual hashing as non-biometric, the identity-vendor arrangement and whether directing a vendor to collect attaches liability here, the 1-year destruction trigger against both BIPA and Texas CUBI, and the third-party-in-image position. Do not run a first scan until this page is live. Note for counsel: §3 now describes a capability that is not in operation. Nothing described there is collected or computed today.
What we do with biometric data, and when we destroy it.
Illinois' biometric privacy law (740 ILCS 14) requires any private entity in possession of biometric identifiers to make a written retention and destruction schedule publicly available. Texas has a parallel requirement under its own statute.
We post this whether or not we are covered, because a schedule that only exists when somebody sues for it is not a schedule.
§1 — The short version
We do not collect a scan of your face or hand geometry. We do not collect voiceprints, fingerprints, retina or iris scans.
We also do not hold your content and we do not compute or store a fingerprint of it. There is no image-matching system here today. Ownership is verified from links to your own posts and the dates they went out.
§2 — What we do not collect
- No scan of face geometry, at any point, on any tier, for any purpose.
- No scan of hand geometry.
- No voiceprint.
- No fingerprint.
- No retina or iris scan.
- No biometric template of any person appearing in any leaked image we examine.
We also do not build, buy, licence, or query any database that identifies people by their bodies.
If that ever changes, this page changes first, with a dated version history, and the consent screen described in §5 comes before a single collection.
§3 — Image matching, if it is ever built
Nothing in this section runs today. It is here so the schedule is posted before the capability exists rather than after it, and so you can see in advance what we would and would not do.
If we build matching, it would use perceptual image hashing — PDQ for still images and TMK+PDQF for video. Both are open source from Meta, both are free, and both are from the same family of techniques StopNCII uses.
The software looks at a picture and produces a number. Similar pictures produce similar numbers. The same picture, resized or recompressed or reposted, produces a number close enough to match. A different picture produces a different number.
The number would describe the picture, not the person in it. Two different people photographed in the same pose produce different numbers. The same person in two different photographs produces two different numbers. It is not a way to recognise a person and it could not be used as one.
The number cannot be reversed into an image. None of it exists yet, and this page changes, with a dated version history, before any of it does.
§4 — Identity verification, and why we never hold the document
We verify that a client is the person depicted. That check runs entirely on a specialist vendor's systems, FOUNDER: identity vendor.
What the vendor holds: the document image and the selfie, for a maximum of 24 hours, under a written contract that requires destruction and written confirmation of it.
What we receive: three things. A pass or fail. A name-match result. An over-18 boolean.
We never receive the document. We never receive the selfie. We do not have a copy to destroy, because we never had one.
Where the vendor route fails, a live session is required and one person views the document on screen. That session runs about 90 seconds, nothing is downloaded, nothing is captured, and the session is logged.
§5 — If a biometric identifier is ever collected
Not today, and not without this sequence first, in this order.
- A separate consent screen at /onboarding/identity, unbundled from the terms of service and unbundled from the service agreement. Not a line in a longer document.
- Written notice on that screen stating the specific biometric being collected, the specific purpose, and the specific retention term.
- Your express written release, executed before any collection occurs.
- The record stored timestamped and immutable.
Consent is never a pre-ticked box here, never bundled with anything else, and never a condition of using a service that does not require it.
§6 — The retention and destruction schedule
This is the schedule required by 740 ILCS 14 § 15(a).
| Item | Who holds it | Retention | Destruction trigger |
|---|---|---|---|
| Government ID image | FOUNDER: identity vendor, never us | Maximum 24 hours | Completion of the check. Written destruction confirmation required by contract. |
| Selfie or liveness capture | FOUNDER: identity vendor, never us | Maximum 24 hours | Completion of the check. Written destruction confirmation required by contract. |
| Pass or fail result, name match, over-18 boolean | Us | Contract term plus 30 days | Account closure, or a deletion request |
| Perceptual hashes (PDQ / TMK+PDQF) | Not collected today | If ever collected: contract term plus 30 days | Account closure, a deletion request, or revocation of your authorization |
| Reference content originals | Not collected today. We do not ask for your content. | None held | Nothing to destroy, because nothing is taken |
| Full-File Retention, opt-in only | Not available today | If it ever ships: contract term, revocable at any time | One email, started the same working day, confirmed in writing |
| Any biometric identifier or biometric information, if ever collected | Us | The earlier of: the purpose being satisfied, or 1 year from your last interaction with us | Immediate destruction on the trigger, with a Certificate of Destruction issued to you |
There is no portal on day one. Until it ships, every request on this page runs by email. One line to FOUNDER: privacy email, no call and no questions, and we start it the same working day. When the portal ships it becomes one button.
On that 1-year term. Illinois' statute sets an outer limit of 3 years from the last interaction. We commit to 1 year, which matches the stricter Texas position and is shorter than either requires.
The full retention table for everything else we hold →
§7 — Other people in the images we examine
Leaked images frequently contain people other than our client. Those people have no relationship with us, gave us nothing, and consented to nothing.
We never build, derive, or store a biometric template of any of them. We do not run image comparison at all today. Where any process touches an image containing a third party — a page capture of an infringing URL — it is held as evidence under the schedule on /trust/, and nothing about that person is derived or persisted. That handling is documented internally and dated.
§8 — We do not profit from any of it
We do not sell, lease, trade, or otherwise profit from any biometric identifier or biometric information. There is no exception, no anonymized-data carve-out, and no research programme.
We do not disclose, redisclose, or disseminate any of it without your consent, except where disclosure is required by law or by a valid warrant or subpoena. Where we receive one of those and are permitted to tell you, we tell you.
§9 — If you are in Illinois or Texas
You have specific rights under your state's statute. Use the data request form and say which state you are in.
§10 — Changes to this schedule
Any change to this schedule is published here with an effective date before it takes effect. Every prior version is archived and available on request. We do not silently shorten or lengthen a retention term.
Effective EFFECTIVE_DATE. Version VERSION.