Leak Cleaner is not a law firm. We do not give legal advice, we do not tell you what your contract means, and we do not choose an attorney for you. Here is exactly what we do instead.

DRAFT — ATTORNEY REVIEW REQUIRED BEFORE PUBLISHING

Mandatory page. Strategy §8.4: the absence of a publicly posted schedule is an independent per-plaintiff violation under 740 ILCS 14 § 15(a). Counsel to confirm: the characterization of perceptual hashing as non-biometric, the identity-vendor arrangement and whether directing a vendor to collect attaches liability here, the 1-year destruction trigger against both BIPA and Texas CUBI, and the third-party-in-image position. Do not run a first scan until this page is live. Note for counsel: §3 now describes a capability that is not in operation. Nothing described there is collected or computed today.

What we do with biometric data, and when we destroy it.

Illinois' biometric privacy law (740 ILCS 14) requires any private entity in possession of biometric identifiers to make a written retention and destruction schedule publicly available. Texas has a parallel requirement under its own statute.

We post this whether or not we are covered, because a schedule that only exists when somebody sues for it is not a schedule.

§1 — The short version

We do not collect a scan of your face or hand geometry. We do not collect voiceprints, fingerprints, retina or iris scans.

We also do not hold your content and we do not compute or store a fingerprint of it. There is no image-matching system here today. Ownership is verified from links to your own posts and the dates they went out.

§2 — What we do not collect

  • No scan of face geometry, at any point, on any tier, for any purpose.
  • No scan of hand geometry.
  • No voiceprint.
  • No fingerprint.
  • No retina or iris scan.
  • No biometric template of any person appearing in any leaked image we examine.

We also do not build, buy, licence, or query any database that identifies people by their bodies.

If that ever changes, this page changes first, with a dated version history, and the consent screen described in §5 comes before a single collection.

§3 — Image matching, if it is ever built

Nothing in this section runs today. It is here so the schedule is posted before the capability exists rather than after it, and so you can see in advance what we would and would not do.

If we build matching, it would use perceptual image hashing — PDQ for still images and TMK+PDQF for video. Both are open source from Meta, both are free, and both are from the same family of techniques StopNCII uses.

The software looks at a picture and produces a number. Similar pictures produce similar numbers. The same picture, resized or recompressed or reposted, produces a number close enough to match. A different picture produces a different number.

The number would describe the picture, not the person in it. Two different people photographed in the same pose produce different numbers. The same person in two different photographs produces two different numbers. It is not a way to recognise a person and it could not be used as one.

The number cannot be reversed into an image. None of it exists yet, and this page changes, with a dated version history, before any of it does.

§4 — Identity verification, and why we never hold the document

We verify that a client is the person depicted. That check runs entirely on a specialist vendor's systems, FOUNDER: identity vendor.

What the vendor holds: the document image and the selfie, for a maximum of 24 hours, under a written contract that requires destruction and written confirmation of it.

What we receive: three things. A pass or fail. A name-match result. An over-18 boolean.

We never receive the document. We never receive the selfie. We do not have a copy to destroy, because we never had one.

Where the vendor route fails, a live session is required and one person views the document on screen. That session runs about 90 seconds, nothing is downloaded, nothing is captured, and the session is logged.

§5 — If a biometric identifier is ever collected

Not today, and not without this sequence first, in this order.

  1. A separate consent screen at /onboarding/identity, unbundled from the terms of service and unbundled from the service agreement. Not a line in a longer document.
  2. Written notice on that screen stating the specific biometric being collected, the specific purpose, and the specific retention term.
  3. Your express written release, executed before any collection occurs.
  4. The record stored timestamped and immutable.

Consent is never a pre-ticked box here, never bundled with anything else, and never a condition of using a service that does not require it.

§6 — The retention and destruction schedule

This is the schedule required by 740 ILCS 14 § 15(a).

ItemWho holds itRetentionDestruction trigger
Government ID imageFOUNDER: identity vendor, never usMaximum 24 hoursCompletion of the check. Written destruction confirmation required by contract.
Selfie or liveness captureFOUNDER: identity vendor, never usMaximum 24 hoursCompletion of the check. Written destruction confirmation required by contract.
Pass or fail result, name match, over-18 booleanUsContract term plus 30 daysAccount closure, or a deletion request
Perceptual hashes (PDQ / TMK+PDQF)Not collected todayIf ever collected: contract term plus 30 daysAccount closure, a deletion request, or revocation of your authorization
Reference content originalsNot collected today. We do not ask for your content.None heldNothing to destroy, because nothing is taken
Full-File Retention, opt-in onlyNot available todayIf it ever ships: contract term, revocable at any timeOne email, started the same working day, confirmed in writing
Any biometric identifier or biometric information, if ever collectedUsThe earlier of: the purpose being satisfied, or 1 year from your last interaction with usImmediate destruction on the trigger, with a Certificate of Destruction issued to you

There is no portal on day one. Until it ships, every request on this page runs by email. One line to FOUNDER: privacy email, no call and no questions, and we start it the same working day. When the portal ships it becomes one button.

On that 1-year term. Illinois' statute sets an outer limit of 3 years from the last interaction. We commit to 1 year, which matches the stricter Texas position and is shorter than either requires.

The full retention table for everything else we hold →

§7 — Other people in the images we examine

Leaked images frequently contain people other than our client. Those people have no relationship with us, gave us nothing, and consented to nothing.

We never build, derive, or store a biometric template of any of them. We do not run image comparison at all today. Where any process touches an image containing a third party — a page capture of an infringing URL — it is held as evidence under the schedule on /trust/, and nothing about that person is derived or persisted. That handling is documented internally and dated.

§8 — We do not profit from any of it

We do not sell, lease, trade, or otherwise profit from any biometric identifier or biometric information. There is no exception, no anonymized-data carve-out, and no research programme.

We do not disclose, redisclose, or disseminate any of it without your consent, except where disclosure is required by law or by a valid warrant or subpoena. Where we receive one of those and are permitted to tell you, we tell you.

§9 — If you are in Illinois or Texas

You have specific rights under your state's statute. Use the data request form and say which state you are in.

Request my data →

§10 — Changes to this schedule

Any change to this schedule is published here with an effective date before it takes effect. Every prior version is archived and available on request. We do not silently shorten or lengthen a retention term.

Effective EFFECTIVE_DATE. Version VERSION.