Biometric Data Policy

Effective Date: August 11, 2026

Read This Before Uploading A Photo
Face Monitoring works by creating a mathematical representation of a face — a biometric identifier — from a photo you upload. Several laws treat that as a special category of personal data with its own consent and destruction rules. This policy exists as a separate document, rather than a paragraph inside our Privacy Policy, so that you can read it in full before you decide. We do not collect any biometric data until you have read this policy and given us your written consent.

1. Scope of This Policy

This Biometric Data Policy governs Erasely AI's collection, use, storage, disclosure and destruction of biometric identifiers and biometric information. It supplements our Privacy Policy and our Terms of Service. Where this policy and the Privacy Policy differ on the handling of biometric data, this policy controls.

This policy applies only to our Face Monitoring service. Our DMCA letter generator, disposable email addresses and one-time-passcode phone numbers do not collect or process biometric data.

2. What We Collect

Face Monitoring involves two distinct categories of biometric data, and they are treated differently.

2.1 The Face You Ask Us To Monitor

  • The photograph you upload, stored in our database and on our servers
  • A face template — a numerical encoding of facial geometry derived from that photograph, used to find visually similar faces
  • Derived facial attributes returned by the search process, such as estimated age range and image quality signals
  • The name or label you assign to the monitored person

2.2 Faces Found In Search Results

When a search returns a possible match, we store a thumbnail image of the matched face and the address of the page it appeared on, so that you can review the result and decide whether it is genuinely you.

Please understand what this means. Search results can include images of people who are not you and who have not agreed to anything. We keep those thumbnails only as long as needed for you to review the match, we never build a searchable index from them, and we never use them to identify anyone. Section 6 sets out exactly how long they are kept.

3. Why We Collect It

We collect biometric data for one purpose, and one purpose only:

  • To search public sources for images that appear to show the face you asked us to monitor, and to alert you when a new one is found

We do not, under any circumstances:

  • Sell, lease, trade or otherwise profit from biometric data
  • Use biometric data to train, tune or improve any facial recognition model
  • Use biometric data for advertising, profiling or scoring
  • Provide a service for looking up strangers, and we terminate accounts that attempt it

4. Consent

We collect biometric data only after you have given express written consent, captured as an affirmative action — a checkbox you tick yourself. Consent is requested twice: once when you create an account, and again each time you upload a face for monitoring. Consent is never bundled into a general acceptance of our Terms, and it is never inferred from continued use of the site.

We record, for each consent you give: the account it belongs to, the date and time, and the version of this policy in force at that moment.

4.1 You Must Have The Right To Upload The Face

By giving consent you confirm that either:

  • The face in the photograph is your own; or
  • You are the parent or legal guardian of the person shown, or otherwise hold documented legal authority to act for them, and that person has consented

Uploading a third party's face without that authority is a serious violation of this policy and of our Terms of Service. It may also be unlawful. We will terminate accounts that do it.

4.2 Withdrawing Consent

You may withdraw consent at any time by deleting the relevant alert, by closing your account, or by writing to Contact@Erasely.AI. Withdrawal stops all further searching immediately and triggers destruction under Section 6. Withdrawing consent does not undo processing that already, lawfully, took place.

5. Disclosure

We do not sell, lease, trade or otherwise profit from your biometric data.

We disclose it in only three situations:

  • To our face search provider. Performing the search requires transmitting your uploaded image to a specialist third-party search provider that operates the underlying image index. This is unavoidable — it is how the service works — and it is covered by the consent described in Section 4. The provider is contractually restricted to performing the search we request.
  • To you. Search results are returned to your account and to the email address on it.
  • Where the law requires it, in response to a valid warrant, subpoena or court order, or where disclosure is necessary to comply with a legal obligation.

We do not disclose biometric data to advertisers, data brokers, analytics providers or any other commercial recipient.

6. Retention And Destruction Schedule

This is the schedule we are bound by. Biometric data is destroyed on whichever of the following comes first.

Data Destroyed
Your uploaded photograph and face template Within 30 days of you deleting the alert, withdrawing consent, or closing your account
Thumbnails of faces found in search results Within 90 days of the match being found, and immediately when the parent alert is deleted
Derived facial attributes With the alert they belong to
Biometric data on a dormant alert Within 1 year of the last time that alert was searched, regardless of anything above
Record that consent was given Retained after destruction as proof of lawful processing. Contains no biometric data.

Destruction means permanent deletion of the image data, the derived template and the stored file — not merely hiding the record from your dashboard. The only exception is where a specific legal hold, active litigation or a valid court order requires us to preserve data; in that case we destroy it as soon as the obligation ends.

A note on backups. Deleted data may persist in encrypted backups for a short period after destruction. Backups are not searchable, are not used to serve the product, and roll off on their own schedule.

7. How It Is Stored And Protected

  • Encrypted in transit using TLS
  • Stored on access-controlled servers, using at least the same standard of care we apply to other confidential information, and never a lesser standard
  • Stored images are served only through an authenticated endpoint — they are not reachable by guessing a URL
  • Access is limited to personnel who need it to operate or support the Service

No system is perfectly secure. We do not claim otherwise. If a breach affects biometric data we will notify affected users and regulators as required by law.

8. Your Rights

Regardless of where you live, you may:

  • Ask what biometric data we hold about you
  • Obtain a copy of it
  • Have it corrected
  • Have it destroyed, and withdraw consent
  • Object to the processing, which in practice means ending the service

Write to Contact@Erasely.AI. We respond within 30 days. We will not discriminate against you, degrade your service or charge you more for exercising any of these rights.

8.1 If You Are Not Our Customer

If your face appears in another user's search results and you want the stored thumbnail destroyed, write to Contact@Erasely.AI with enough detail for us to locate it. We will destroy it. You do not need an account, and there is no charge.

9. State-Specific Rights

9.1 Illinois

The Illinois Biometric Information Privacy Act (740 ILCS 14) requires that we publish a written retention and destruction schedule, give written notice of collection, and obtain a written release before collecting biometric identifiers. Section 6 is that schedule, this document is that notice, and the consent described in Section 4 is that release. We do not sell or profit from biometric identifiers.

9.2 Texas

Texas Business and Commerce Code § 503.001 (CUBI) requires notice and consent before capturing a biometric identifier for a commercial purpose, prohibits sale, and requires destruction within a reasonable time. Our schedule in Section 6 is designed to meet that requirement.

9.3 Washington

Washington RCW 19.375 requires notice and consent before enrolling a biometric identifier in a database for a commercial purpose. We obtain both.

9.4 Other Jurisdictions

Under the GDPR and UK GDPR, biometric data processed to uniquely identify a person is special category data under Article 9. Our lawful basis is your explicit consent under Article 9(2)(a). Colorado, Connecticut and other state privacy laws treat biometric data as sensitive data requiring opt-in consent, which is what we collect.

10. Age Requirement

Face Monitoring is available only to people 18 or older. We do not knowingly collect biometric data from anyone under 18. If we learn that we have, we destroy it and close the account. If you believe a child's biometric data has been submitted, contact us and we will act on it promptly.

11. Changes To This Policy

If we make a material change to how we handle biometric data, we will notify account holders by email and ask for fresh consent before the change applies to them. We will not apply a materially different practice to data already collected under an earlier version of this policy.