Skip to content

Operate

Data handling

What a session stores, how it is protected, and how and when it is erased.

This page lists what KYCVerify keeps about the people it verifies, so you can write an accurate privacy notice and answer a security review.

What is stored

DataWhereProtectionErased by purge
Document images and portrait crop, selfie, liveness frames, PAN card photo, Aadhaar ZIP and photodata/filesAES-256-GCM, file id as associated dataYes
Face embeddings (numeric vectors)DatabaseNever returned by the APIYes
Identity (name, birth date, nationality, address)DatabaseConsole and API key access onlyYes
Document numberDatabaseMasked (first half kept), plus a keyed HMAC-SHA256 fingerprint for duplicate detectionYes
Aadhaar numberDatabase (Aadhaar card OCR only)Offline formats carry only the last four digits. A photographed Aadhaar card is read in full to validate it, then kept masked plus a keyed fingerprint; the encrypted card image shows the full number until purgeYes
Contact email and one-time codesDatabaseCodes stored hashed, expire in 10 minutesYes
IP address, user agent, flow progressDatabaseScoped to the appYes
Check resultsDatabaseScoped to the appStatus, score and reason kept; measured data removed
Session row (status, timestamps, vendor_data)DatabaseScoped to the appKept as a tombstone with purged_at

Encryption of uploads

data/files/ses_…/fil_01JD….bin

Key

The service's master key: 32 bytes, kept outside the database

Associated data

the file id (fil_…): a file moved or swapped on disk fails to decrypt

Served

only to signed-in console users, decrypted per request, private, no-store

Each upload on disk: a random nonce, the AES-256-GCM ciphertext and its tag, bound to its file id.

Uploads are limited to 10 MB, identified by their content, encrypted before they are written and decrypted only when a signed-in console user opens them, with cache-control: private, no-store. They are never served publicly and the API never returns them.

Retention

Each app has retention_days, 1 to 3,650, default 90. Every 10 minutes the retention worker purges sessions older than that, up to 500 per pass. Shorter is safer: keep the decision your business needs and let the evidence go.

Erasure on request

  • API: DELETE /v1/sessions/{id} returns 204.
  • Console: an admin can purge a session from its page.
  • Both remove files, embeddings and identity at once, and are audited as session.purged.

What leaves the server

  • Webhooks to your URL, carrying the decision (identity included) for final statuses.
  • One-time code emails from no-reply@kycverify.me, if the email step is on.
  • Downloads of the OFAC and UN lists. No personal data is sent to them; screening runs locally.

Nothing else: no analytics, no telemetry, no model calls to a third party.