Operate
Data handling
What a session stores, how it is protected, and how and when it is erased.
This page lists what KYCVerify keeps about the people it verifies, so you can write an accurate privacy notice and answer a security review.
What is stored
| Data | Where | Protection | Erased by purge |
|---|---|---|---|
| Document images and portrait crop, selfie, liveness frames, PAN card photo, Aadhaar ZIP and photo | data/files | AES-256-GCM, file id as associated data | Yes |
| Face embeddings (numeric vectors) | Database | Never returned by the API | Yes |
| Identity (name, birth date, nationality, address) | Database | Console and API key access only | Yes |
| Document number | Database | Masked (first half kept), plus a keyed HMAC-SHA256 fingerprint for duplicate detection | Yes |
| Aadhaar number | Database (Aadhaar card OCR only) | Offline formats carry only the last four digits. A photographed Aadhaar card is read in full to validate it, then kept masked plus a keyed fingerprint; the encrypted card image shows the full number until purge | Yes |
| Contact email and one-time codes | Database | Codes stored hashed, expire in 10 minutes | Yes |
| IP address, user agent, flow progress | Database | Scoped to the app | Yes |
| Check results | Database | Scoped to the app | Status, score and reason kept; measured data removed |
| Session row (status, timestamps, vendor_data) | Database | Scoped to the app | Kept as a tombstone with purged_at |
Encryption of uploads
data/files/ses_…/fil_01JD….bin
Key
The service's master key: 32 bytes, kept outside the database
Associated data
the file id (fil_…): a file moved or swapped on disk fails to decrypt
Served
only to signed-in console users, decrypted per request, private, no-store
Uploads are limited to 10 MB, identified by their content, encrypted before they are written and decrypted only when a signed-in console user opens them, with cache-control: private, no-store. They are never served publicly and the API never returns them.
Retention
Each app has retention_days, 1 to 3,650, default 90. Every 10 minutes the retention worker purges sessions older than that, up to 500 per pass. Shorter is safer: keep the decision your business needs and let the evidence go.
Erasure on request
- API:
DELETE /v1/sessions/{id}returns204. - Console: an admin can purge a session from its page.
- Both remove files, embeddings and identity at once, and are audited as
session.purged.
What leaves the server
- Webhooks to your URL, carrying the decision (identity included) for final statuses.
- One-time code emails from
no-reply@kycverify.me, if the email step is on. - Downloads of the OFAC and UN lists. No personal data is sent to them; screening runs locally.
Nothing else: no analytics, no telemetry, no model calls to a third party.