Biometric Retention and Destruction Policy
Last updated: 13 September 2026
This is the written biometric retention and destruction schedule that our Privacy Policy refers to. It applies to everyone who starts the face liveness check in the Service, wherever they are. The Service is the World Republic application and website, including the same application where it is served under the name Raised by Humanity. Section 1 of the Privacy Policy sets out which sites the Service covers, and this policy uses the same meaning. This policy is published so that you can require us to keep to it, and so that the laws that require a public schedule of this kind are met.
1. What this policy covers
The face check — the face liveness check described in Section 4 of the Privacy Policy — creates two kinds of biometric data, both held by Amazon Web Services (AWS) in its EU (Ireland) region on our behalf:
- A reference facial image from your face-check session, stored in Amazon S3.
- A facial vector (template) derived from that image, stored in an Amazon Rekognition collection and linked to your account. The collection is what lets us check that the same face is not used to verify a second account.
"Biometric data" in this policy means both of these, together with the internal records in our database that point at them (the session records of your face checks).
It does not cover the outcome of a check. Whether your account is verified, and the record that your face matched another account and verification was refused (which account, and the similarity score), are ordinary account records and are handled as described in the Privacy Policy.
2. When biometric data is destroyed
We keep biometric data only as long as it is needed to verify that you are a unique, live person and to prevent duplicate voting accounts. It is permanently destroyed at the earliest of the following:
- When the account is deleted. This covers a deletion you make in the Service, and a closure we make ourselves, by hand — under the Terms of Use, or because we learn that the account holder is under 18. What differs between the two is how the destruction starts. A deletion you make in the Service starts it automatically: it destroys your reference images and your facial vector as part of the deletion itself — at once, or, if a test election you voted in closes within the next fourteen days, when that election closes. An election that closes more than fourteen days after you act does not hold the destruction at all; the reason is set out in Section 4.5 of the Privacy Policy. A closure we make by hand has no screen in the Service that starts it, so we record the destruction as owed ourselves, and that can make it slower to begin. Once a destruction is recorded as owed, it is carried out automatically, and it is retried automatically every day until it succeeds. That is true of a deletion you make and of a closure we make. It is also what happens if the destruction cannot be completed at the moment you delete your account: your account is still deleted, and the destruction is recorded as owed.
- When you withdraw consent or ask us to delete it. Requests to the contact in the Privacy Policy are handled the same way, with one difference: if a pending destruction has not yet run and you complete a new face check, the new check is a new consent and the pending destruction is cancelled. A deletion is never cancelled this way.
- Three years after your last interaction with the Service. Three years after the last interaction our records show — a vote, a WDD movement, a verification attempt, an edit to a party you registered, a basic-income claim, accepting updated Terms of Use or an updated Privacy Policy when you sign in, or a session that is still signed in — an automated job destroys your biometric data and removes your verification. Signing in and out on its own is otherwise not recorded. Your account, balance and past votes are not affected. If you come back, you can verify again with a new face check.
- When the purpose it was collected for is satisfied. That purpose is to verify that you are a unique, live person and to keep the same face from verifying a second account. It lasts while the account does, because the facial vector is the only thing that can see a second account being opened with the same face. When the purpose ends, the data is destroyed.
- Earlier if the law requires it.
We do not keep biometric data longer than three years after your last interaction.
Three years is the same period for everyone, and some laws set a shorter maximum. Colorado requires biometric data to be destroyed no later than 24 months after your last interaction. We do not ask where you live, so the automated job described above cannot apply a shorter period to you by itself. You do not have to wait for that job. You can destroy your biometric data yourself at any time, without deleting your account — Section 4.4 of the Privacy Policy says where to do that in the Service — and you can ask us to destroy it at the address in Section 7.
3. How destruction works
Destruction means deleting the data, not marking it as unused:
- The reference images are deleted from Amazon S3, under every face-check session of yours.
- The facial vector is deleted from the Amazon Rekognition collection, and the account's entry in that collection is removed with it.
- The internal records that pointed at them are deleted from our database. The one exception is the record that your face matched another account and verification was refused (which account, and the similarity score), which, if your account is still open, is kept as an account record with its image reference removed; on account deletion it is deleted with the rest.
If any step fails, the account is flagged and the job retries it daily. A face check whose data was destroyed on the inactivity schedule also loses its verification at the same moment, so that no account can vote on the strength of a face that the duplicate check can no longer see.
Independently of the schedule above, the same daily job removes every facial vector that is no longer linked to an account, so that nothing survives in the collection by accident.
4. Images looked at on request
If your face matches another account, verification is refused automatically and no person sees the images. You can ask us to have a person look at that decision; the Privacy Policy sets out how. If you do ask, that person opens the reference image from your check and the one held for the account it matched — only where both still exist, since either may already have been destroyed on the schedule above. They are the same reference images described above, they are destroyed on the same schedule, and no copy is kept once the person has looked.
5. Service providers
AWS stores and processes biometric data on our behalf and on our instructions, as described in the Privacy Policy. Our face-check sessions are configured so that AWS keeps no audit images from them.
We designed an escalation to a second provider, Didit, for an identity-document check where the face check refuses someone in error. That escalation is not offered. The Service has no screen that starts such a check, and the request that would start one is always refused. Didit holds no biometric or identity data of ours. Every check made while the escalation was briefly available in mid-2026 was deleted from Didit in September 2026, so there is nothing at Didit for an account deletion to reach and nothing at Didit to ask about.
If the escalation is ever offered again, the Privacy Policy will state the terms on which Didit may hold your data and must delete it, and this policy will state how the destruction schedule in Section 2 applies to that data. We will publish both of those changes before any such check is taken.
6. Changes to this policy
If we change the retention period or the destruction method, we will publish the change on this page and revise the "Last updated" date above before the change takes effect. This page is the only notice we can give: we hold no email address, no telephone number and no postal address for you, and there is no banner or message in the Service — Section 13 of the Privacy Policy explains why. A shorter retention period may be applied at once. A longer retention period is not applied to data we already hold until the change has been published on this page for 30 days.
This policy is written in English, and we publish it in other languages. The version that applies to you is the version in the language the Service showed you. Where that version and the English text differ, the meaning that is better for you applies.
7. Contact
Questions about this policy and requests concerning your biometric data go to the contact address in the Privacy Policy.