← Back

Biometric Privacy Policy

Version 1.1 · Effective 2026-09-30 · Last updated September 30, 2026

Biometric Privacy Policy

Version: 1.1  |  Effective Date: September 30, 2026

DateSteady is operated by HoopFrog Inc. ("we", "us", "our"). This policy is adopted pursuant to the Illinois Biometric Information Privacy Act, 740 ILCS 14/15(a) (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington’s H.B. 1493, and, for data subjects located in the European Union or United Kingdom, GDPR Article 9 and UK DPA 2018 requirements relating to special-category data.

1. Purpose of Collection

We collect facial geometry scores during our selfie checks to:

  • Prevent fraudulent signups (bots, catfish accounts, account takeovers);
  • Support age-assurance where the law (UK Online Safety Act 2023, EU DSA, US state laws) requires users to be 18 or over. The age check itself is performed separately by an independent age-assurance provider, not derived from your facial geometry;
  • Protect our community from impersonation by comparing a live selfie with the profile photos you upload.

Facial geometry scores are mathematical representations of the spatial relationships between facial landmarks. They are not photographs and cannot be used to recreate your image.

2. Processors and International Transfers

The following sub-processors may process biometric identifiers on our behalf (PhotoDNA excepted , it receives only image hashes and no facial-geometry data). Each is bound by a Data Processing Agreement and, where applicable, Standard Contractual Clauses (SCCs) for cross-border transfers:

  • VerifyMy (United Kingdom) , third-party age-assurance provider. Covered by UK GDPR and the EU→UK adequacy decision. SCCs in place for onward transfers.
  • Amazon Web Services , Rekognition (EU , Ireland, eu-west-1) , face-matching and image-quality/anti-spoofing checks for the photo selfie check, and AWS Face Liveness for the live selfie check, which streams a short video from your device straight to AWS and compares one frame from it with your main approved public profile photo. Processed under the AWS Data Processing Addendum, with SCCs for any onward transfer, and excluded from AWS AI/ML training through an AI-services opt-out that covers our whole AWS organization.
  • Microsoft PhotoDNA (United States) , image hash matching for illegal-content (CSAM) screening. Covered by SCCs. PhotoDNA receives only image hashes for CSAM matching; it does not receive facial-geometry biometric data.

No biometric identifier is sold, leased, traded, or otherwise profited from. We do not use biometric data for advertising or analytics.

3. Retention Schedule

Biometric identifiers (facial geometry scores) are destroyed when the initial purpose for collection is satisfied (i.e., verification outcome recorded) OR within three (3) years of the individual’s last interaction with the Service, whichever occurs sooner. This complies with BIPA 15(a) "whichever is sooner" standard.

Failed, rejected, or expired verification attempts are purged within 90 days via an automated daily cron job.

Photo selfie check: for a successful verification we keep the outcome, the scores from the check (for example how closely the selfie resembled your profile photo, and image-quality scores) and which photo it was compared with, for your most recent successful check only; these are numbers about the check, not measurements of your face. The selfie image itself is deleted after processing and is not stored.

Live selfie check: we do not store the video, the frame or any face template. We keep the outcome and two scores (how confident AWS was that a live person was present, and how closely the frame resembled your photo); these are numbers about the check, not measurements of your face. Results of checks that did not pass are deleted 90 days after the check, and results of passed checks 3 years after the check, unless we are legally required to preserve them. They are erased with your account when you delete it.

4. Destruction Process

When retention limits are reached, or at user request:

  • We delete all copies from our own storage (database rows and any derived artifacts).
  • Face-matching uses stateless Rekognition with no face collection, so AWS retains no facial geometry to delete; the selfie exists only transiently and is erased immediately after matching. The live selfie check also uses no face collection: its video goes from your device straight to AWS and is processed under the AWS service terms, and we do not store it. We delete our own database records and log the deletion event. On full account deletion we issue a VerifyMy erasure request where a data-subject-request endpoint is configured. PhotoDNA holds no biometric data (image hashes only), so there is nothing biometric to delete there.
  • We retain an audit record of the deletion event (without the biometric data itself) to demonstrate compliance.

5. Legal Basis

  • GDPR / UK GDPR: Article 9(2)(a) , your explicit consent. For the photo selfie check, for most members this is the sensitive-data consent, which covers facial geometry, given when they create their account; if we do not hold it, we ask for it on the Biometric Consent Release screen before selfie capture begins. For the live selfie check, we ask for your explicit consent on a separate screen the first time you start it, and again if you have withdrawn it; we do not rely on the consent given at sign-up for it.
  • BIPA (Illinois): 740 ILCS 14/15(b) , informed written release signed by the data subject, with full disclosure of purpose and retention schedule.
  • Texas CUBI § 503.001 / Washington H.B. 1493: Informed disclosure and consent at the time of collection.
  • PIPEDA (Canada): Meaningful consent under Principle 4.3.

6. Your Rights

You may at any time:

  • Revoke your consent. Go to Settings → Privacy → Revoke biometric consent. Upon revocation we will delete retained facial geometry from our storage and instruct processors to do the same within 7 days. Note: withdrawing consent does not retroactively invalidate lawful processing that occurred prior to withdrawal. Results of earlier live selfie checks (the outcome and two scores, no images) are kept for the periods in Section 3.
  • Request access to any biometric record we hold about you (GDPR Art. 15, BIPA 15(d)).
  • Request deletion. You may request deletion at any time, independent of consent withdrawal.
  • Request portability of your verification outcome (pass/fail flag) , though the raw facial geometry score is not portable under current sub-processor APIs.

7. Security Safeguards

Biometric identifiers in transit are protected by TLS 1.3. At rest, they are encrypted using AES-256 inside each processor’s infrastructure. Access is restricted to the narrow automated pipeline that performs the face match; no human operator at HoopFrog Inc. views raw biometric data in the ordinary course of business.

8. Contact

Questions, access requests, or consent revocations relating to biometric data:

HoopFrog Inc.
Attn: Privacy Officer (Biometric Requests)
3-11 Bellerose Drive, Suite 312
St. Albert, AB T8N 5C9, Canada
Email: support@datesteady.com

9. Changes to This Policy

If we materially change this policy , for example by adding a new sub-processor or extending retention , we will increment the version number and re-prompt affected users for consent before continuing to process their biometric data under the new terms.