Biometric Retention and Destruction Policy

Last updated: September 2026

This is the written biometric retention and destruction schedule that our Privacy Policy refers to. It applies to everyone who starts the face check in the World Republic Service, wherever they are. It is published so that you can hold us to it, and so that the laws that require a public schedule of this kind are met.

1. What this policy covers

The face check creates two kinds of biometric data, both held by Amazon Web Services (AWS) in its EU (Ireland) region on our behalf:

  • A reference facial image from your face-check session, stored in Amazon S3.
  • A facial vector (template) derived from that image, stored in an Amazon Rekognition collection and linked to your account. The collection is what lets us check that the same face is not used to verify a second account.

"Biometric data" in this policy means both of these, together with the internal records in our database that point at them (the session records of your face checks).

It does not cover the outcome of a check. Whether your account is verified, and the record that your face matched another account and verification was refused (which account, and the similarity score), are ordinary account records and are handled as described in the Privacy Policy.

2. When biometric data is destroyed

We keep biometric data only as long as it is needed to verify that you are a unique, live person and to prevent duplicate voting accounts. It is permanently destroyed at the earliest of the following:

  1. When you delete your account. Deletion in the Service destroys your reference images and your facial vector as part of the deletion itself — at once, or, if a test election you voted in is still open, when that election closes and never more than fourteen days later; the reason is set out in the Privacy Policy, section 4.5. If the destruction cannot be completed at that moment, your account is still deleted and the destruction is recorded as owed and retried automatically every day until it succeeds.
  2. When you withdraw consent or ask us to delete it. Requests to the contact in the Privacy Policy are handled the same way, with one difference: if a held destruction has not yet run and you complete a new face check, the new check is a new consent and the held destruction is cancelled. A deletion is never cancelled this way.
  3. Three years after your last interaction with the Service. Three years after the last interaction our records show — a vote, a WDD movement, a verification attempt, an edit to a party you founded, a basic-income claim, accepting an updated Terms of Service or Privacy Policy when you sign in, or a session that is still signed in — an automated job destroys your biometric data and removes your verification. Signing in and out on its own is otherwise not recorded. Your account, balance and past votes are not affected. If you come back, you can verify again with a new face check.
  4. Earlier if the law requires it.

We do not keep biometric data longer than three years after your last interaction.

3. How destruction works

Destruction means deleting the data, not marking it as unused:

  • The reference images are deleted from Amazon S3, under every face-check session of yours.
  • The facial vector is deleted from the Amazon Rekognition collection, and the account's entry in that collection is removed with it.
  • The internal records that pointed at them are deleted from our database. The one exception is the record that your face matched another account and verification was refused (which account, and the similarity score), which, if your account is still open, is kept as an account record with its image reference removed; on account deletion it is deleted with the rest.

If any step fails, the account is flagged and the job retries it daily. A face check whose data was destroyed on the inactivity schedule also loses its verification at the same moment, so that no account can vote on the strength of a face that the duplicate check can no longer see.

Independently of the schedule above, the same daily job removes every facial vector that is no longer linked to an account, so that nothing survives in the collection by accident.

4. Images looked at on request

If your face matches another account, verification is refused automatically and no person sees the images. You can ask us to have a person look at that decision; the Privacy Policy sets out how. If you do ask, that person opens the reference image from your check and the one held for the account it matched — only where both still exist, since either may already have been destroyed on the schedule above. They are the same reference images described above, they are destroyed on the same schedule, and no copy is kept once the person has looked.

5. Service providers

AWS stores and processes biometric data on our behalf and on our instructions, as described in the Privacy Policy. Our face-check sessions are configured so that AWS keeps no audit images from them.

Where an identity-document check with our escalation provider (Didit) has been used, Didit holds the data it processes under its own retention terms, which are named in the Privacy Policy. Deleting your account in the Service does not currently send a deletion instruction to Didit; requests about data held by Didit go through the contact address in section 7.

6. Changes to this policy

If we change the retention period or the destruction method, we will update this page and the "Last updated" date above before the change takes effect. A shorter period may be applied immediately; a longer one will not be applied to data already collected without notice.

This policy is written in English. Where we publish a translation, it is provided for convenience; if a translation and the English text differ, the English text prevails.

7. Contact

Questions about this policy and requests concerning your biometric data go to the contact address in the Privacy Policy.