BioAuth Privacy Policy
FaceIn.id LLC · Effective October 15, 2026
BioAuth Privacy Policy
FaceIn.id LLC · Effective October 15, 2026
1. Who We Are
FaceIn.id LLC, a Georgia limited liability company based in Atlanta, Georgia, USA (“FaceIn.id,” “we,” “us,” or “our”), provides BioAuth, a developer platform for biometric login, account recovery without passwords or reset links, continuous liveness and human-authorization checks, and cryptographically signed authorization receipts. BioAuth includes our websites (including bioauth.ai and bioauth.bot), the developer dashboard, our application programming interfaces, our software development kit (currently distributed under the package name @pieauth/sdk), and related documentation and support (together, the “Service”).
This Privacy Policy explains how we handle personal information when developers apply for and use the Service, when customer applications use BioAuth for their end users, and when people visit our websites or contact us. If you do not agree with this Policy, please do not use the Service.
2. Our Roles
For developer accounts, billing, website visits, security, and support, we decide how and why personal information is processed. In privacy-law terms, we are the “business” or “controller” for that information.
For personal information that a customer’s application submits to BioAuth or causes BioAuth to process about the customer’s own end users, the customer decides how and why it is processed and we process it only to provide the Service to that customer. In privacy-law terms, we are the customer’s “service provider” or “processor,” and we act on the customer’s documented instructions under our agreement with the customer.
Customers are responsible for their own privacy notices, for choosing a lawful basis and obtaining any consent their use requires, for configuring the Service appropriately, for responding to their end users’ requests, and for using BioAuth only for lawful purposes.
3. Information We Process
Depending on how the Service is used, we process the following categories of information:
- Developer application and account information: name, work email address, company, website, project description, expected usage, platform, use case, approval status, account settings, and communications with us.
- Application configuration: application name, allowed origins or domains, identifiers, integration settings, API-key metadata (never the secret itself in readable form), webhook configuration, and environment information.
- End-user authentication information: the pseudonymous user identifier assigned by the customer’s application (we do not receive end users’ names or email addresses through the SDK); registered device or authenticator identifiers and public-key material; and the outcomes, timestamps, status, and error information of authentication, recovery, liveness, and authorization events.
- Signed receipt information: receipt identifiers and the contents described in Section 9.
- Security and operational information: IP address, browser and device information, logs, diagnostics, rate-limit and abuse signals, session and token metadata, and incident records.
- Billing information: plan, usage, invoices, payment status, and transaction references. Our payment processor collects payment-card information directly; we do not store full card numbers.
- Support and communications: messages, attachments, and records needed to resolve a request.
- Website information: pages viewed, referring page, approximate location derived from IP address, and the essential cookies described in Section 15.
4. Biometric Information — What We Do and Do Not Do
BioAuth is designed so that we never receive your face, your fingerprint, or any biometric template. Biometric login uses the WebAuthn standard: the biometric check happens on the user’s own device, inside the device’s secure hardware, and the device sends us only a cryptographic signature proving that the check succeeded. We receive and store the public half of the device credential and the result of the check — never the biometric itself.
We do not collect, store, buy, or build a database of face images, fingerprints, voiceprints, iris scans, or biometric templates, and we do not use biometric information to identify people across services. Customers must not send raw biometric data to BioAuth, and our systems are built to refuse it: every signed receipt is scanned before signing and will not be issued if it contains raw biometric or sensor data.
Liveness and human-presence features process the types of signals that supported a decision (for example, that a device-native biometric check passed, or that a live presence session was active) and the outcomes of those checks. They do not process camera images, sensor streams, or biometric templates on our servers.
Because we do not receive biometric identifiers, we do not retain or destroy them. Customers whose own applications collect biometric information are responsible for complying with the biometric-privacy laws that apply to them.
5. How We Use Information
We use personal information to:
- review developer applications and administer approved accounts;
- provide, secure, maintain, troubleshoot, and improve the Service;
- register authenticators and process authentication, recovery, liveness, and authorization events;
- generate, deliver, store, and allow verification of signed authorization receipts;
- enforce application, origin, scope, rate, and security controls, and prevent abuse, fraud, unauthorized access, and service disruption;
- provide support and send service-related communications, such as verification emails, security notices, and billing notices;
- measure usage, administer plans, invoice customers, and keep required business records;
- comply with law, respond to lawful requests, and protect the rights, safety, and property of our users, our customers, and us; and
- develop new features using information that has been aggregated or de-identified so that it no longer identifies any person.
6. We Do Not Sell or Share Personal Information
We do not sell personal information, and we never will. We do not share personal information for cross-context behavioral advertising, and we never will. We do not run advertising on our Service, we do not place third-party advertising or tracking cookies on our websites, and we do not allow any vendor to use personal information we hold for its own advertising or marketing.
Because we do not sell or share personal information, there is no need for a “Do Not Sell or Share My Personal Information” opt-out; there is nothing to opt out of. We also do not use or disclose sensitive personal information for any purpose other than providing the Service you asked for, securing it, and complying with law.
7. How We Disclose Information
We disclose personal information only in the following circumstances:
- To service providers that process information on our behalf under written contracts that restrict them to providing services to us and prohibit them from using the information for their own purposes. Our current service providers are: Amazon Web Services (cloud hosting, database, storage, and cryptographic key management, in the United States); Stripe (payment processing and invoicing); Resend (transactional email delivery, such as verification and security emails); and an IP-geolocation lookup service used to derive approximate country from the IP address of a developer application, for fraud and abuse prevention only.
- To the customer whose application initiated an event. When you use a customer’s application, that customer receives the authentication outcomes and receipts relating to you.
- To destinations that a customer or user directs us to use, such as a customer-selected endpoint for receipt delivery.
- To professional advisers, auditors, and insurers under duties of confidentiality.
- To government authorities or other parties when required by law, subpoena, or court order, or when we believe disclosure is necessary to protect the rights, safety, or property of our users, our customers, the public, or us, or to investigate fraud or security incidents. We will notify affected customers of legal demands for their end-user data where the law allows.
- To a successor in connection with a merger, financing, reorganization, or sale of all or part of our business, under this Policy or one at least as protective.
8. Legal Bases (where applicable)
Where the law requires a legal basis for processing, we rely on: performance of our contract with you (to provide the Service); our legitimate interests in operating, securing, and improving the Service and preventing abuse, balanced against your interests; compliance with our legal obligations; and your consent where the law requires it, which you may withdraw at any time without affecting processing that has already occurred.
9. Signed Authorization Receipts
A signed receipt is a small, tamper-evident record that a human authorized (or was required to be present for) an action taken by an application or a software agent. Each receipt contains: the issuer, a unique receipt identifier, the time of signing, the customer application identifier, the pseudonymous user identifier assigned by the customer’s application, the agent identifier, the action (service and type), the decision, the required and current presence levels, timestamps, the basis of authorization, the policy in force, and the types of evidence that supported the decision. A completion receipt references the decision receipt it completes. Receipts never contain names, email addresses, images, or biometric information.
Receipts are signed with a private key held in a hardware-backed key-management service and never present in our application servers. Anyone can verify a receipt against our published public keys — available at the address given in our documentation at bioauth.ai — without contacting us or trusting us.
Receipts can be retrieved by anyone who holds the receipt identifier. The identifier is a randomly generated value that cannot be guessed, and possession of it is the only key to retrieval. Customers and users must protect receipt identifiers as they would protect any other credential.
Receipts are immutable by design: once signed, a receipt is never edited or re-signed, because its value as evidence depends on that. We retain receipts as immutable records for as long as needed to allow verification and to meet security, billing, dispute-resolution, and legal obligations. Customers receive their own copies of receipts and are responsible for the security, retention, and lawful use of the copies they hold or direct us to deliver elsewhere.
10. Retention
We keep personal information only as long as reasonably necessary for the purposes described in this Policy. In general: developer account information is kept for the life of the account and deleted or de-identified within a reasonable period after closure; end-user authentication records are kept while the customer’s application is active and the credential remains registered; security logs are kept for a limited period appropriate to incident investigation; billing records are kept as required by tax and accounting law; and signed receipts are kept as described in Section 9.
Deleting information from our active systems may not immediately remove it from encrypted backups, security logs, legal holds, or destinations that a customer controls. Backups are overwritten on a rolling schedule.
11. Security
We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity, including encryption in transit and at rest, hardware-backed key management for signing keys, least-privilege access controls, logging and monitoring, change management, and incident response procedures. We design the Service so that the most sensitive information — biometrics — never reaches us at all.
No system is perfectly secure. Customers must protect their API keys, administrator accounts, sessions, receipt destinations, and integration code, and must promptly report any suspected compromise to security@bioauth.ai. If we discover a breach affecting personal information, we will notify affected customers and individuals as required by law.
12. International Processing
We are located in the United States and process personal information there, using Amazon Web Services facilities in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States. Where the law of your country requires a specific mechanism for that transfer, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) and on supplementary safeguards, and we will make those terms available to customers on request.
13. Your Privacy Rights
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to receive a copy of it in a portable format, to restrict or object to certain processing, to withdraw consent, to appeal a decision we make about your request, and to complain to a data-protection regulator. We will not discriminate against you for exercising any of these rights.
If you are an end user of a customer’s application, please direct your request to that customer first; the customer controls your relationship with its application, and we will assist the customer as our agreement and the law require. If you are a developer account holder or a website visitor, contact us directly at privacy@bioauth.ai. We may need to verify your identity before acting on a request, and we will respond within the time the applicable law requires (and in any event within 45 days for requests under United States state privacy laws, extendable once where permitted).
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have the rights above to the extent those laws apply. Because we do not sell or share personal information and do not use it for targeted advertising or profiling with legal effects, no opt-out is needed. You may designate an authorized agent to make a request on your behalf; we will require proof of the agent’s authority.
14. Age Requirement
The Service is for businesses and their adult users. You must be at least 18 years old to create a developer account or to enroll in biometric authentication through BioAuth. The Service is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, contact privacy@bioauth.ai and we will delete it.
15. Cookies
Our websites use only cookies that are strictly necessary to operate the site and keep you signed in to the developer dashboard, such as session and security cookies. We do not use third-party advertising, tracking, or cross-site analytics cookies. If we ever adopt website analytics, it will be privacy-respecting, first-party measurement that does not track you across other websites, and we will update this Policy first.
16. Changes to This Policy
We may update this Policy as the Service, the law, or our practices change. We will post the updated Policy at bioauth.ai with a new effective date, and if a change materially reduces your rights or changes how we use personal information we have already collected, we will notify developer account holders by email before the change takes effect.
17. Contact Us
FaceIn.id LLC, Atlanta, Georgia, USA. Privacy inquiries and requests: privacy@bioauth.ai. Security reports: security@bioauth.ai. Legal notices: legal@bioauth.ai. Website: https://bioauth.ai.
© 2026 FaceIn.id LLC. BioAuth is a product of FaceIn.id LLC.