GDPR & Privacy

GDPR & Privacy

VeriSelf is designed with privacy-by-default principles. This guide explains what data is collected, how long it is kept, and what rights users have.

What Data Is Collected

DataWhenHow LongPurpose
Estimated ageEvery verificationUser meta + logAge check
GenderEvery verificationUser meta + logProfile data
RaceEvery verificationUser meta + logOptional analytics
GPS coordinatesIf GPS enabledStored in logJurisdiction compliance
IP addressEvery verificationStored in logFraud scoring, rate limiting
PhotoDebug Mode ON onlyAuto-deleted after retentionTroubleshooting
Consent flagIf consent mandatoryUser metaLegal compliance
TimestampEvery verificationPermanent in logAudit trail

What Is NOT Collected

  • No raw photos in production (unless Debug Mode is explicitly enabled)
  • No cookies for tracking or advertising
  • No third-party analytics
  • No data sold or shared

User Rights

  • Right to access — Admin can export a user’s log entries
  • Right to deletion
    purges all user data
  • Right to object — Users can decline camera access (verification will fail)

For Data Processors

If you are a data processor under GDPR (e.g., running the plugin on behalf of clients):

  • Ensure your privacy policy describes the AI verification process
  • Enable the consent checkbox if required by your DPA
  • Set debug retention to the minimum needed
  • Use self-hosted Ollama (PRO) to keep images entirely within your infrastructure