Biometric Retention and Destruction Policy
Last updated: September 2026
This is the written biometric retention and destruction schedule that our Privacy Policy refers to. It applies to everyone who starts the face check in the World Republic Service, wherever they are. It is published so that you can hold us to it, and so that the laws that require a public schedule of this kind are met.
1. What this policy covers
The face check creates two kinds of biometric data, both held by Amazon Web Services (AWS) in its EU (Ireland) region on our behalf:
- A reference facial image from your face-check session, stored in Amazon S3.
- A facial vector (template) derived from that image, stored in an Amazon Rekognition collection and linked to your account. The collection is what lets us check that the same face is not used to verify a second account.
"Biometric data" in this policy means both of these, together with the internal records in our database that point at them (the session records of your face checks).
It does not cover the outcome of a check. Whether your account is verified, and a reviewer's decision if your face matched another account, are ordinary account records and are handled as described in the Privacy Policy.
2. When biometric data is destroyed
We keep biometric data only as long as it is needed to verify that you are a unique, live person and to prevent duplicate voting accounts. It is permanently destroyed at the earliest of the following:
- When you delete your account. Deletion in the Service destroys your reference images and your facial vector immediately, as part of the deletion itself. If the destruction cannot be completed at that moment, your account is still deleted and the destruction is recorded as owed and retried automatically every day until it succeeds.
- When you withdraw consent or ask us to delete it. Requests to the contact in the Privacy Policy are handled the same way.
- Three years after your last interaction with the Service. Three years after the last interaction our records show — a vote, a WDD movement, a verification attempt, an edit to a party you founded, a basic-income claim, accepting an updated Terms of Service or Privacy Policy when you sign in, or a session that is still signed in — an automated job destroys your biometric data and removes your verification. Signing in and out on its own is otherwise not recorded. Your account, balance and past votes are not affected. If you come back, you can verify again with a new face check.
- Earlier if the law requires it.
We do not keep biometric data longer than three years after your last interaction.
3. How destruction works
Destruction means deleting the data, not marking it as unused:
- The reference images are deleted from Amazon S3, under every face-check session of yours.
- The facial vector is deleted from the Amazon Rekognition collection, and the account's entry in that collection is removed with it.
- The internal records that pointed at them are deleted from our database. The one exception is the record of a reviewer's decision that your face matched another account, which, if your account is still open, is kept as an account record with its image reference removed; on account deletion it is deleted with the rest.
If any step fails, the account is flagged and the job retries it daily. A face check whose data was destroyed on the inactivity schedule also loses its verification at the same moment, so that no account can vote on the strength of a face that the duplicate check can no longer see.
Independently of the schedule above, the same daily job removes every facial vector that is no longer linked to an account, so that nothing survives in the collection by accident.
4. Human review images
If your face appears to match another account, a small number of authorised reviewers may compare the two reference images before a decision is made. Those images are the same reference images described above and are destroyed on the same schedule. Reviewers see them through short-lived access links.
5. Service providers
AWS stores and processes biometric data on our behalf and on our instructions, as described in the Privacy Policy. Our face-check sessions are configured so that AWS keeps no audit images from them.
Where an identity-document check with our escalation provider (Didit) has been used, Didit holds the data it processes under its own retention terms, which are named in the Privacy Policy. Deleting your account in the Service does not currently send a deletion instruction to Didit; requests about data held by Didit go through the contact address in section 7.
6. Changes to this policy
If we change the retention period or the destruction method, we will update this page and the "Last updated" date above before the change takes effect. A shorter period may be applied immediately; a longer one will not be applied to data already collected without notice.
7. Contact
Questions about this policy and requests concerning your biometric data go to the contact address in the Privacy Policy.