Privacy policy
What we collect when you authenticate, where it is processed, and what we do not keep.
Last updated July 2026
What we collect
Authentication requires very little, and we take nothing beyond it.
- Facial imagery, transiently. When you authenticate, your browser captures a short burst of frames and sends them to our verification engine over TLS. They are analysed and discarded — we do not write them to disk and we do not retain them after the assessment completes.
- A biometric template. If you enrol, we derive a mathematical vector from your face and store it. It is a set of numbers used for comparison; it is not an image and cannot be viewed as one.
- Account details. Your name and email address, supplied during registration.
- Device and session data. Browser, operating system, device type, IP address and a device key cookie, used to recognise a device you have previously approved and to detect anomalous sign-ins.
- Verification scores. The derived measurements from each assessment — liveness confidence, match confidence and the per-engine results. Numbers only.
Visiting this website
The list above covers signing in. Simply reading this site is separate and much smaller: we count the visit, using a tool that sets no cookie, stores nothing on your device and keeps no identifier that can be traced back to you or linked from one day to the next. The cookie policy sets out exactly what is recorded and for how long.
Where it is processed
Verification runs on infrastructure we operate. Facial frames are transmitted to our servers for analysis; they are not processed entirely on your device. We say this plainly because the distinction matters and is often blurred.
- Frames travel over TLS 1.3 and exist only in memory during the assessment.
- Biometric templates are held in a dedicated vector database, separate from your account record.
- Our servers are located in India, and all verification and storage happens there today. We do not currently offer processing in a specific region on request. If your organisation requires data to remain within a particular jurisdiction, tell us before you integrate and we will be straight with you about whether we can meet it.
How long we keep it
- Facial frames — not retained. Discarded once the assessment finishes.
- Biometric template — kept while your account is active, deleted when you delete your account.
- Verification scores — retained briefly so a result can be shown back to you, then removed automatically.
- Account and device records — kept while your account is active. When you delete your account, your biometric template is destroyed immediately and the remaining account and device records are purged after thirty days. The delay exists only so an accidental deletion can be reversed; after it, the data is gone and cannot be recovered.
What we never do
- We do not sell, rent or trade personal data.
- We do not share your facial template with the applications you sign in to. They receive a token and the profile fields you consented to — never biometric data.
- We do not use your biometric data to train models for anyone else.
- We do not track you across other websites.
Your rights
You can ask us to do any of the following, and we will respond within the period your jurisdiction requires.
- Access the personal data we hold about you.
- Correct anything inaccurate.
- Delete your account, which deletes your biometric template.
- Export your data in a portable format.
- Withdraw consent for biometric processing — after which passwordless sign-in will no longer work for your account.
Contact
Write to privacy@quekey.com for anything on this page, including a data access or deletion request.