BioAuth Terms of Service
FaceIn.id LLC · Effective October 15, 2026
BioAuth Terms of Service
FaceIn.id LLC · Effective October 15, 2026
1. The Agreement
These Terms of Service (“Terms”) are a binding agreement between FaceIn.id LLC, a Georgia limited liability company based in Atlanta, Georgia, USA (“FaceIn.id,” “we,” “us,” or “our”), and the person or organization that accepts them (“Customer” or “you”). They govern your access to and use of BioAuth: our websites, developer dashboard, APIs, software development kit (currently distributed as @pieauth/sdk), biometric authentication, account recovery, liveness and human-authorization features, signed authorization receipts, documentation, and related services (together, the “Service”).
By creating an account, clicking to accept, or using the Service, you accept these Terms. If you use the Service on behalf of an organization, you represent that you have authority to bind it, and “you” means that organization. If you have signed an order form, enterprise agreement, data processing addendum, or service-level agreement with us, that signed document controls over these Terms to the extent they conflict.
2. Eligibility and Developer Approval
You must be at least 18 years old and able to form a binding contract. You must provide accurate and complete application and account information and keep it current. Access to production (“live”) features requires our approval, which we may grant, condition, or withhold at our discretion based on use case, security, legal, risk, or capacity considerations. Sandbox access does not guarantee live approval.
3. Accounts, Credentials, and Recovery
You are responsible for all activity under your accounts and API keys. API keys and other secrets are confidential: do not expose them in client-side code, public repositories, URLs, logs, screenshots, or support messages, and rotate any key you suspect is compromised immediately. Notify us at security@bioauth.ai promptly if you suspect unauthorized access.
BioAuth does not provide a password fallback or an emailed reset link for protected accounts. You must use the supported enrollment, authentication, and recovery procedures described in the documentation. You must not create or represent the existence of any bypass, and you acknowledge that FaceIn.id personnel cannot override production authentication for you.
4. License and Restrictions
Subject to these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license during your subscription term to access the Service and to integrate the SDK and APIs into your own applications for your internal business purposes and for providing your applications to your end users.
You must not: (a) resell, sublicense, or offer the Service as a standalone identity or authentication service to third parties; (b) reverse engineer, decompile, or attempt to derive the source code or non-public design of any non-open-source component of the Service; (c) circumvent usage limits, rate limits, origin restrictions, liveness or presence controls, or security measures; (d) access non-public systems or data; (e) remove or alter proprietary notices; (f) use the Service to build a competing product; or (g) use our confidential information for any purpose other than evaluating or using the Service. Open-source components included in the SDK remain subject to their own licenses.
5. Your Responsibilities
You will:
- use the Service only for lawful purposes and in compliance with all applicable laws, including privacy, biometric-privacy, consumer-protection, export-control, and anti-discrimination laws;
- provide your end users with all legally required privacy notices and obtain all legally required consents for your use of biometric authentication, liveness checks, and authorization records;
- choose enrollment, authentication, liveness, recovery, and authorization policies that are appropriate to the risk of the actions you protect;
- validate BioAuth responses and receipts using the methods described in the documentation, and enforce scope, expiry, and authority in your own systems before acting;
- protect the identifiers, tokens, receipts, logs, and other personal or security information you receive from the Service;
- maintain an incident-response process and promptly report suspected compromise;
- honor your end users’ rights and deletion requests as the law requires, and instruct us where our assistance is needed;
- keep your integration and SDK version reasonably current; and
- ensure that your personnel, contractors, applications, and software agents comply with these Terms.
You must not send raw face images, fingerprint images, device biometric templates, or any other biometric identifier to BioAuth. The Service is designed to refuse such data, and sending it is a material breach of these Terms.
6. Authentication, Liveness, and Recovery
BioAuth helps you use device-native biometric authentication, continuous liveness and human-presence checks, human authorization of agent actions, and account recovery without stored secrets. The assurance any of these provides depends on the end user’s device and platform, your configuration, the released version of the Service, your integration, network conditions, and the threat model you face.
No authentication, liveness, anti-spoofing, recovery, or fraud-prevention control eliminates every attack. You must apply additional controls appropriate to the consequences of unauthorized access — such as transaction limits, monitoring, manual review, and escalation — and you are solely responsible for the decisions your systems make based on BioAuth results.
Technical details of our authentication, liveness, recovery, and receipt mechanisms are confidential and, where indicated, patent-pending. We may provide them to approved customers, evaluators, auditors, or advisers only under appropriate restrictions.
7. Signed Authorization Receipts
For supported events, the Service generates a cryptographically signed receipt describing an authorization decision, and a separate signed receipt when the action is completed. A receipt is evidence of what the Service determined, based on the information and configuration available to it at the moment of signing, and it never asserts more than the evidence bound to it supports. A receipt is not a guarantee that: the underlying action was lawful, prudent, error-free, or permitted by any third party’s policy; the person had legal capacity or authority beyond what the receipt represents; every device, application, agent, or external system involved was uncompromised; or the receipt will satisfy any particular evidentiary, regulatory, audit, or industry requirement.
You must verify each receipt’s signature against our published public keys, check its contents against the action you are about to take, enforce scope and expiry, preserve relevant context, and protect receipt data and receipt identifiers. Anyone holding a receipt identifier can retrieve that receipt; treat identifiers as credentials.
Receipts are immutable once signed. We retain receipts as immutable records to support verification. If you direct delivery of receipts to your own endpoint or storage, you are responsible for the security, retention, access control, export, and deletion of those copies. Any receipt-storage, retention-tier, or custody features we may offer are described in the documentation and in your order form, and are available only as and when released.
8. Software Agents and Delegated Authority
Where released and enabled, BioAuth lets you associate a software agent’s actions with scoped, time-limited, revocable authority granted by a provably present human, and records that grant in a signed receipt. You remain solely responsible for deciding which agents may act and for whom; for defining and enforcing scope, duration, transaction limits, and approval thresholds; for validating receipts and current authority before executing any action; for monitoring agent behavior and maintaining a stop and revocation process; and for complying with all laws and third-party terms that apply to automated actions. BioAuth does not make, and does not advise on, the underlying business, legal, financial, medical, employment, or other substantive decision.
9. Acceptable Use
You must not use the Service to:
- violate any law or the rights of any person;
- impersonate, deceive, surveil, stalk, harass, discriminate against, or harm any person;
- collect, build, or contribute to an unauthorized biometric or identity database;
- bypass or weaken security, liveness, enrollment, consent, recovery, rate, origin, or authorization controls;
- transmit malware or interfere with the integrity or performance of the Service;
- access data, accounts, or systems without authorization;
- use receipts or verification results to make false, misleading, or unsupported claims;
- test production systems destructively or with data you are not authorized to use; or
- facilitate activity that is prohibited by law or by an order form or policy that applies to you.
We may investigate suspected violations and may suspend or restrict access where reasonably necessary to protect the Service, our users, our customers, or third parties, giving notice where practicable.
10. Privacy and Data Processing
Our Privacy Policy, available at https://bioauth.ai/privacy, describes how we process personal information and is incorporated into these Terms. Where we process personal information on your behalf, we do so only on your documented instructions, we do not sell or share it, and we apply the safeguards described in the Privacy Policy. Enterprise customers may request a data processing addendum, including standard contractual clauses for international transfers, by writing to legal@bioauth.ai. You are responsible for your own privacy notices, lawful basis, consents, data minimization, retention choices, and end-user requests.
11. Fees, Billing, and Taxes
You will pay the fees stated in your order form or, if none, the fees published at https://bioauth.ai/pricing at the time of use. Fees may be based on monthly active users, receipts issued, environments, or other metrics stated there. Usage-based fees are calculated from our systems’ measurements, which are authoritative absent manifest error. Fees are billed monthly in arrears (or as stated in your order form) through our payment processor, are due on receipt of invoice, and are non-refundable except as expressly stated or required by law.
Subscriptions renew automatically for successive terms of the same length unless either party gives notice of non-renewal before the renewal date. We may change published fees on at least 30 days’ notice; changes take effect at your next renewal. If you dispute an invoice in good faith, notify us in writing before it is due and pay the undisputed portion; we will work with you to resolve the dispute promptly. We may suspend the Service for non-payment after 15 days’ written notice. You are responsible for all taxes, duties, and withholdings other than taxes on our net income.
12. Confidentiality
Each party may receive non-public information of the other that is marked confidential or that a reasonable person would understand to be confidential (“Confidential Information”). The receiving party will use Confidential Information only to perform or evaluate this agreement, protect it with at least reasonable care, and disclose it only to its personnel and advisers who need to know it and are bound by obligations at least as protective. Confidential Information does not include information that is or becomes public without breach, was rightfully known to the recipient without restriction, was independently developed, or was rightfully received from a third party without restriction. Disclosure compelled by law is permitted after notice to the other party where lawful. Our security, recovery, liveness, receipt, and architecture materials are our Confidential Information unless we expressly designate them for public release. These obligations survive for three years after termination, and indefinitely for trade secrets and security information.
13. Intellectual Property, Brand, and Feedback
We and our licensors own all right, title, and interest in the Service, including its software, documentation, designs, logos, and all related intellectual property, and all improvements to them. BioAuth is our product brand; FaceIn.id LLC is the provider. The SDK is currently distributed under the package name @pieauth/sdk for compatibility, and we may publish it under an additional name in the future. Aspects of the Service are patent-pending. No rights are granted except those expressly stated in these Terms.
You retain all rights in your applications and your data. You grant us the limited rights necessary to provide, secure, support, and improve the Service and to comply with law. If you give us feedback or suggestions, we may use them without restriction or compensation, but we will not identify you publicly as their source without your permission.
14. Preview and Beta Features
We may offer features labeled preview, beta, sandbox, or early access. Such features are provided for evaluation, may be changed or withdrawn at any time, are excluded from any service-level or support commitment, and are provided “as is” without warranty of any kind. Announced roadmap items and dates are not commitments unless stated in a signed order form.
15. Changes, Availability, and Support
We may update the Service and documentation, add or remove features, and deprecate versions. We will give reasonable notice of changes that materially reduce core functionality, and at least 90 days’ notice before retiring a supported SDK major version, except where security or law requires faster action. We aim for high availability but do not guarantee it; availability and support commitments are only those stated in your plan or a signed service-level agreement.
16. Term, Suspension, and Termination
These Terms apply from the date you accept them until your account is closed. Either party may terminate for convenience on 30 days’ written notice (subject to any committed term in an order form). Either party may terminate immediately on written notice if the other party materially breaches these Terms and fails to cure within 15 days of notice, or becomes insolvent. We may suspend access immediately where reasonably necessary for security, unlawful use, material breach, non-payment (after the notice in Section 11), legal compliance, or the protection of the Service or others, and we will restore access when the cause is resolved.
On termination, your license ends, you must stop using the Service and destroy our Confidential Information, and fees accrued through the termination date remain payable. For 30 days after termination we will make your account data available for export on request, after which we may delete it in accordance with the Privacy Policy. Sections that by their nature should survive termination (including fees owed, confidentiality, intellectual property, disclaimers, indemnification, limitation of liability, and dispute resolution) survive.
17. Warranties and Disclaimers
Each party represents that it has the authority to enter into this agreement. We warrant that the Service will perform materially in accordance with its then-current documentation; your exclusive remedy for breach of this warranty is for us to use reasonable efforts to correct the non-conformity or, if we cannot, to terminate the affected Service and refund prepaid fees for the unused portion of the term.
EXCEPT AS EXPRESSLY STATED IN THESE TERMS OR A SIGNED AGREEMENT, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR IMMUNE TO ATTACK. NO AUTHENTICATION, LIVENESS, RECOVERY, OR RECEIPT MECHANISM IS INFALLIBLE, AND YOU ASSUME RESPONSIBILITY FOR THE ACTIONS YOUR SYSTEMS TAKE IN RELIANCE ON THE SERVICE.
18. Indemnification
You will defend, indemnify, and hold harmless FaceIn.id and its members, managers, employees, and agents from and against all claims, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to: (a) your applications, your data, or your end users; (b) your use of the Service in violation of these Terms or applicable law, including any biometric-privacy or consumer-protection law; (c) any actual or alleged failure to provide notices or obtain consents required for your use of the Service; (d) actions taken by you or your software agents in reliance on the Service; or (e) any dispute between you and your end users.
We will defend, indemnify, and hold you harmless from and against third-party claims alleging that the Service, as provided by us and used in accordance with these Terms, infringes a United States patent, copyright, or trademark or misappropriates a trade secret, and we will pay resulting damages and costs finally awarded or agreed in settlement. This obligation does not apply to claims arising from your applications or data, modifications not made by us, combination with items not provided by us, use after we have offered a non-infringing alternative, or use in breach of these Terms. If the Service is or may become subject to such a claim, we may modify or replace it, procure the right for you to continue using it, or terminate the affected Service and refund prepaid fees for the unused term. This Section states our entire liability for infringement claims.
The indemnified party must give prompt written notice of the claim, allow the indemnifying party sole control of the defense and settlement (provided no settlement imposes obligations on the indemnified party without its consent), and provide reasonable cooperation at the indemnifying party’s expense.
19. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY’S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE FEES PAID OR PAYABLE BY YOU TO US FOR THE SERVICE IN THE TWELVE (12) MONTHS IMMEDIATELY BEFORE THE EVENT GIVING RISE TO THE CLAIM (OR ONE HUNDRED US DOLLARS, IF GREATER).
These limitations do not apply to a party’s indemnification obligations, a party’s breach of Section 12 (Confidentiality), your breach of Section 4 (License and Restrictions) or Section 9 (Acceptable Use), your payment obligations, a party’s gross negligence or willful misconduct, or any liability that cannot be limited under applicable law. The parties agree that these limitations are an essential basis of the bargain and will apply even if a limited remedy fails of its essential purpose.
20. Governing Law and Dispute Resolution
These Terms are governed by the laws of the State of Georgia, USA, without regard to its conflict-of-laws rules, and the United Nations Convention on Contracts for the International Sale of Goods does not apply.
Before starting any formal proceeding, the party raising a dispute will send written notice describing it to the other party (to us at legal@bioauth.ai), and the parties will attempt in good faith to resolve it through direct discussion for at least 30 days.
Any dispute not resolved informally will be finally resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before a single arbitrator, seated in Atlanta, Georgia, conducted in English. The arbitrator may award any relief a court could award to an individual party. Judgment on the award may be entered in any court of competent jurisdiction. Either party may seek temporary injunctive relief in court to protect its intellectual property or Confidential Information pending arbitration. For any matter that proceeds in court, the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Fulton County, Georgia.
Each party may bring claims against the other only in its individual capacity and not as a plaintiff or class member in any purported class, collective, or representative proceeding, and the arbitrator may not consolidate claims of more than one party. If this class-action waiver is found unenforceable as to a particular claim, that claim will proceed in court under the venue clause above, and the waiver remains effective for all other claims.
21. General Terms
Assignment. Neither party may assign this agreement without the other’s written consent, except that either party may assign it in connection with a merger, reorganization, or sale of all or substantially all of the relevant assets, on notice to the other. Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control. Notices. Legal notices to us must be sent to legal@bioauth.ai; notices to you will be sent to the email address on your account, and are effective when sent. Export. You will comply with United States export-control and sanctions laws and will not use the Service in, or provide it to, any embargoed country or prohibited party. Independent contractors. The parties are independent contractors. Severability; waiver. If any provision is unenforceable, it will be enforced to the maximum extent permissible and the rest remains in effect; a party’s failure to enforce a provision is not a waiver. Entire agreement. These Terms, the Privacy Policy, the documentation, and any signed order form are the entire agreement on their subject and supersede all prior agreements and communications. Changes. We may update these Terms by posting a revised version at bioauth.ai with a new effective date; material changes take effect 30 days after we notify developer account holders by email, and your continued use after that date is acceptance. Order of precedence. A signed order form or enterprise agreement, then these Terms, then the documentation.
22. Contact
FaceIn.id LLC, Atlanta, Georgia, USA. Legal notices: legal@bioauth.ai. Security: security@bioauth.ai. Privacy: privacy@bioauth.ai. Website: https://bioauth.ai.
© 2026 FaceIn.id LLC. BioAuth is a product of FaceIn.id LLC.