1. Introduction
At VerifEye, your privacy and security come first.
VerifEye is an AI-powered tool operated by Realeyes OÜ, registry code 11730664, Vahe 15, 11615 Tallinn, Estonia (“Realeyes,” “we,” “us,” or “our”). The service helps online platforms anonymously verify that you are a real person and, where required by law or platform policy, that you meet a specified minimum age.
We design VerifEye to use the least possible amount of personal data. The process involves a short, live visual input (for example, a brief selfie video) that is analyzed in real time to estimate your probable age and confirm human presence. We never request or store identity documents, and all data is processed in accordance with the GDPR, UK GDPR, CCPA/CPRA, and other applicable privacy laws.
This Privacy Policy explains how we handle your information, what rights you have, and how to contact us.
2. Who is Responsible for Your Data
Realeyes OÜ operates VerifEye in collaboration with its business customers (“Business Customers”)—for example, websites or apps that use VerifEye to confirm that users meet an age or authenticity threshold.
- Business Customer as Data Controller.
The Business Customer decides why and how your personal data is processed (for example, to comply with an age-assurance rule).
Realeyes acts on the Business Customer’s behalf to perform the technical analysis and return only a verification result such as “18 or over” or “human verified.” - Realeyes as Data Processor.
In most cases, Realeyes processes your data strictly under the instructions of the Business Customer and never uses that data for its own independent purposes. - Realeyes as Independent Controller (limited cases).
In certain narrow circumstances, Realeyes may process anonymized or pseudonymized data independently to maintain and improve the accuracy, security, and fairness of its AI systems. This processing never produces decisions about you personally and is carried out under Realeyes’ legitimate interests and applicable data protection safeguards. Such processing never involves identifying individuals or linking results back to specific verification sessions. - Allocation for uniqueness and re-authentication. Where the Business Customer enables uniqueness verification or returning-user re-authentication, the Business Customer remains the Data Controller and defines the scope of the user population against which matching occurs. Realeyes operates the underlying gallery of facial embeddings as Data Processor on the Controller’s instructions and applies the technical and organisational safeguards described in this Policy.
3. Applicability of This Privacy Policy
This Privacy Policy applies exclusively to the processing of personal data carried out through the VerifEye Service, including:
- the verification process you complete when a Business Customer uses VerifEye on its website or app; and
- any communication you have directly with Realeyes in connection with that process (for example, support requests).
This Policy does not apply to:
- the Business Customer’s own website, platform, or services, which are governed by their own privacy terms;
- Realeyes’ corporate website or marketing activities, which are subject to a separate corporate privacy notice; or
- any third-party services not controlled by Realeyes.
By using VerifEye, you acknowledge that your data will be processed in accordance with this Privacy Policy and applicable law.
4. Key Definitions
For clarity, the following terms have the meanings below:
- End User / You – a natural person who uses VerifEye to verify their age or human status.
- Business Customer – the entity integrating VerifEye into its platform to confirm users’ age or authenticity; the Data Controller for such processing.
- End User Data – the personal data (such as brief visual input or metadata) processed by VerifEye to generate a verification result.
- Verification Result – the outcome of the analysis (for example, “18 or over,” “under 18,” “human verified,” or “unable to estimate”).
- Third-Party Provider – a trusted vendor engaged by Realeyes to supply technical components of the Service (e.g., cloud hosting, liveness detection) under strict contractual safeguards.
- Personal Data – any information relating to an identified or identifiable person as defined under applicable data-protection laws.
5. What Data We Process
VerifEye is designed according to the principle of data minimization. We collect and process only the information required to estimate your age and verify that you are a real person.
Depending on how a Business Customer integrates the Service, VerifEye may process the following categories of data:
- Visual input: a short live video or camera frames showing your face, used only for real-time analysis. The visual input is processed in memory only for the duration of the verification session and deleted automatically and irreversibly within minutes after the result is produced.
- Derived technical data: numerical representations (embeddings) or signals created by the AI model. Embeddings used solely for age and liveness estimation are processed transiently. Where the Business Customer has enabled uniqueness verification or returning-user re-authentication, a face embedding may be retained as a persistent identity template, separately from any visual input,
- Device and session data: limited technical metadata such as device type, browser, session ID, and connection status.
- Verification result: the non-identifying outcome shared with the Business Customer (e.g., “18 or over,” “under 18,” “human verified”).
VerifEye does not request or store identity documents, financial information, or government-issued IDs.
6. Why and How We Use Your Data
We process your data exclusively for the following purposes:
- Age and human verification – to confirm whether you appear to meet the age threshold defined by the Business Customer and to verify that you are a live, real person.
- Fraud and abuse prevention – to detect automated submissions, repeated misuse, or presentation attacks.
- Security and service reliability – to monitor system performance and prevent unauthorized access.
- Model improvement (anonymized form) – to maintain the accuracy, fairness, and robustness of VerifEye’s AI models.
- Uniqueness verification – where enabled by the Business Customer, to determine whether you have previously enrolled, participated in an activity, or maintain another account on their platform.
- Returning-user re-authentication – where enabled by the Business Customer, to recognise you as a returning user by comparing a fresh capture against your previously stored face embedding.
All processing takes place within secure, controlled environments and follows the documented instructions of the relevant Business Customer.
7. Legal Basis for Processing
Your data is processed under one or more of the following lawful bases:
- Consent – where required by law, for example when biometric data (facial imagery) is processed, you are asked to give explicit consent before starting the verification.
- Contractual necessity – processing may be necessary for the Business Customer to provide its service to you when age assurance or human verification is a condition of access.
- Legitimate interests – Realeyes may process anonymized or pseudonymized data independently to ensure the safety and reliability of its AI technology, without producing decisions about you personally.
You may withdraw your consent at any time before or during the verification by cancelling the process. Doing so may prevent you from accessing the content or service that requires verification.
8. Data Sharing and Recipients
We never sell or share your personal data in the sense prohibited by the CCPA/CPRA.
Your data may be disclosed only to the following categories of recipients:
- Business Customers, who receive only the Verification Result.
- Trusted Third-Party Providers, such as secure cloud-hosting or liveness-analysis partners, engaged under written contracts that impose data-protection and confidentiality obligations equivalent to the GDPR and UK GDPR standards. These providers may process limited data solely to support VerifEye’s operation and are regularly reviewed for compliance.
- Regulators or authorities, where disclosure is required by law, court order, or competent authority, limited to the minimum necessary.
Where data is processed by Third-Party Providers outside your jurisdiction, Realeyes applies appropriate transfer safeguards (see below).
9. International Data Transfers
VerifEye’s infrastructure is primarily located within the EU / EEA and United Kingdom.
If data is transferred to other jurisdictions, we rely on lawful transfer mechanisms such as:
- the EU Standard Contractual Clauses (SCCs) and UK Addendum;
- adequacy decisions recognized by the European Commission or UK authorities; and
- additional technical and organizational safeguards, including encryption and access controls.
These measures ensure an equivalent level of protection wherever your data is processed.
10. Data Retention
We retain your data only for as long as strictly necessary to perform the verification and ensure system integrity. Raw visual data (e.g., video frames) is automatically deleted within seconds after the verification result is produced. Pseudonymized or aggregated technical data may be stored for a short, limited period for security auditing, fraud detection, or performance monitoring. After these periods, the data is securely deleted or anonymized in accordance with Realeyes’ internal retention policy and applicable law.
Where the Business Customer has enabled uniqueness verification or returning-user re-authentication, the associated face embedding is retained as a persistent identity template for as long as necessary to fulfil the matching purpose — typically until you withdraw consent, your account with the Business Customer is closed, the Business Customer instructs deletion, or a defined period of inactivity has elapsed, whichever occurs first. Retention parameters are configured by the Business Customer in accordance with applicable law, and Realeyes will delete or anonymise the embedding promptly thereafter.
11. Automated Processing and Human Oversight
VerifEye’s analysis uses automated AI models to estimate probable age and detect liveness signals. These automated processes do not make legally or similarly significant decisions about you, are limited to returning a categorical verification result and are subject to ongoing testing for accuracy and demographic fairness. Where required, Business Customers can request a human review if an automated result prevents access and you believe it may be incorrect.
12. Your Rights and How We Support Them
Depending on your location and applicable privacy laws (for example, the GDPR, UK GDPR, or CCPA/CPRA), you have the following rights concerning your personal data:
- Access – to know whether VerifEye processes your data and to obtain a copy.
- Rectification – to request correction of inaccurate or incomplete information.
- Erasure (“Right to be forgotten”) – to request deletion of your data when it is no longer needed or when you withdraw consent.
- Restriction – to request limitation of processing under certain conditions (for instance, if accuracy is contested).
- Objection – to object to processing carried out on legitimate-interest grounds, such as pseudonymized model-improvement activities.
- Data portability – to receive your data in a structured, machine-readable format, where legally applicable.
- Withdraw consent – to withdraw your consent for biometric or other consent-based processing at any time before or during the verification.
Realeyes’ role in consent and rights management:
- Realeyes is responsible for recording consent whenever it is legally required—particularly where biometric data is processed during the VerifEye session.
- Realeyes also supports Business Customers in fulfilling data-subject rights requests that relate to the VerifEye verification process. When a request is addressed to a Business Customer, Realeyes provides the necessary technical and organizational assistance to ensure it is fulfilled properly and within legal deadlines.
If you wish to exercise your rights directly or inquire about your consent record, you can contact Realeyes at verifeye@realeyes.ai
You may also contact the Business Customer that requested your verification, as they remain the Data Controller responsible for determining the purpose of processing.
You have the right to lodge a complaint with your local data-protection authority if you believe your data has been processed unlawfully.
13. Security Measures
Realeyes applies strict technical and organizational measures to protect your data, including:
- encryption of data in transit and at rest;
- secure EU/UK data-centre environments;
- multi-factor authentication and role-based access control;
- continuous monitoring, vulnerability management, and penetration testing; and
- regular staff training and confidentiality undertakings.
These measures are designed to prevent unauthorized access, loss, or misuse of your personal data and to maintain the integrity of VerifEye’s verification process.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, or our Service. The “Last updated” date at the top of this document shows the latest version. If updates materially affect your rights, we will make reasonable efforts to notify you through the verification interface or our website before the new version takes effect. Your continued use of VerifEye after an update means you accept the revised Policy.
15. Additional Information for U.S. State Residents
15.1 Additional Information for Individuals Residing in Certain U.S. States
If you reside in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia, this section applies to you and supplements the rest of this Privacy Policy. It also serves as our California “notice at collection.” If there is any conflict between this section and another part of this Policy, this section controls for residents of these states with respect to the matters it addresses.
In most cases, Realeyes processes End User Data as a Data Processor / service provider on behalf of a Business Customer, who is the Data Controller (see Section 2). Where Realeyes acts only as a service provider, the rights described below may be directed to, and fulfilled by, the relevant Business Customer; Realeyes will provide reasonable assistance as described in Section 12.
Additional Disclosures
This Policy explains how we collect (see Section 5), use (see Section 6), retain (see Section 10), and disclose (see Section 8) personal information about you. The provisions below restate that information using the categories required by these state privacy laws.
- Categories of personal information we collect. In providing the VerifEye Service we may collect: identifiers (e.g., a session ID and limited device/online identifiers); biometric information (facial geometry derived from a brief live visual input, and, where the Business Customer enables uniqueness verification or returning-user re-authentication, a facial embedding used as an identity template); internet or other electronic network activity information (e.g., device type, browser, connection status); and sensitive personal information (the biometric information described above). We do not collect or store identity documents, government-issued IDs, financial information, Social Security numbers, precise geolocation, or audio recordings through the verification process. The Verification Result returned to the Business Customer (e.g., “18 or over,” “human verified”) is designed to be non-identifying.
- Sources of personal information. We collect personal information (i) directly from you when you complete the verification flow (the live visual input); (ii) automatically from your device during the session (technical/session metadata); and (iii) from the Business Customer, which configures the verification and its parameters.
- Purposes of collection and use. We collect and use personal information for the business and commercial purposes described in Section 6 — namely age and human verification, fraud and abuse prevention, security and service reliability, anonymized model improvement, and (where enabled by the Business Customer) uniqueness verification and returning-user re-authentication.
- Disclosure of personal information. We disclose personal information for the business purposes described in Section 8 to the following categories of recipients: (a) the Business Customer, which receives only the Verification Result and never your biometric data; (b) trusted third-party providers / sub-processors (e.g., secure cloud hosting and liveness-analysis partners) engaged under written contracts that restrict their use of the data to providing the Service on our behalf; and (c) regulators, courts or authorities, where disclosure is required by law, limited to the minimum necessary.
- We retain personal information as described in Section 10. Raw visual input is deleted automatically and irreversibly within a short period after the result is produced. Facial embeddings retained for uniqueness verification or re-authentication are kept only for as long as necessary to fulfil the matching purpose configured by the Business Customer (and, for Illinois and Texas residents, no longer than the statutory periods in Section 15.2).
- No sale, no sharing, no targeted advertising. We do not sell your personal information, “share” it for cross-context behavioral advertising, or use it for “targeted advertising,” as those terms are defined under these state privacy laws, in the course of providing the VerifEye verification Service. We do not sell or share sensitive personal information, including biometric information. We also do not knowingly sell or share the personal information of consumers under the age of 16 (or any higher age required by applicable law).
- Sensitive personal information. We process sensitive personal information (including biometric information) only as a service provider/processor, for the limited purposes of providing the Service and permitted, anonymized service improvement. We do not use sensitive personal information to infer characteristics about you or for any purpose other than those disclosed here. Where a Business Customer determines additional purposes, please contact that Business Customer directly.
Your Privacy Rights Under State Privacy Laws
Subject to the conditions and exceptions in these laws, you may have the right to:
- Know / Access – confirm whether we process your personal information and obtain a copy, including in a portable format where applicable;
- Delete – request deletion of your personal information;
- Correct – request correction of inaccurate personal information;
- Opt out – opt out of any “sale,” “sharing,” targeted advertising, or certain profiling. As noted above, we do not engage in these activities through the verification Service, so no opt-out is required for it;
- Limit use of sensitive personal information – we already limit our use of sensitive personal information to the permitted purposes described above;
- Non-discrimination – not receive discriminatory treatment for exercising any of these rights;
- Appeal – appeal a denial of your request (see below).
To exercise these rights, contact us at verifeye@realeyes.ai. We will verify your request as described in Section 12 before responding. You may also use an authorized agent to submit a request on your behalf, subject to verification of the agent’s authority. Because Realeyes typically acts as a service provider, you may also contact the Business Customer that requested your verification, which remains the Data Controller.
If we deny your request, you may appeal by contacting us at verifeye@realeyes.ai. If you have concerns about the outcome of an appeal, you may contact the attorney general in the state where you reside.
15.2 Notice to Residents of the State of Illinois and the State of Texas
- The Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq. (“BIPA”), and the Texas Capture or Use of Biometric Identifiers Act, Tex. Bus. & Com. Code § 503.001 (“CUBI”), regulate the collection, storage, use, and retention of “biometric identifiers” and “biometric information.” A “biometric identifier” means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color. “Biometric information” means any information, regardless of how it is captured, converted, stored, or shared, based on an individual’s biometric identifier and used to identify an individual.
- Realeyes collects certain biometric identifiers and biometric information — namely facial geometry information (a scan of face geometry derived from a brief live visual input, and information based on it) — during the VerifEye process. Realeyes collects and uses this information to estimate your probable age, confirm that you are a live, real person, and, where the Business Customer enables it, to verify uniqueness or re-authenticate you as a returning user. Realeyes does not collect identity documents and returns only a non-identifying Verification Result to the Business Customer.
- Illinois retention and destruction. For Illinois residents, we will permanently destroy biometric identifiers and biometric information when the initial purpose for collecting or obtaining them has been satisfied, or within three (3) years of the individual’s last interaction with Realeyes, whichever occurs first.
- Texas retention and destruction. For Texas residents, we will destroy biometric identifiers within a reasonable time, and not later than the first anniversary of the date the purpose for collecting the identifier expires; or, where the identifier is used in connection with an instrument or document that another law requires be retained for a longer period, within a reasonable time but not later than one (1) year after that retention obligation ends.
- No sale; limited disclosure. Realeyes does not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information. Except where disclosure is required or permitted by law, your biometric data is accessible only to Realeyes and our service providers, which process it solely on our behalf to provide the Service. We do not disclose your biometric data to any other third parties, and the Business Customer on whose behalf we process your data does not receive your biometric data — only the Verification Result.
- Before the verification or authentication process begins, you are presented with the relevant disclosures and asked to choose whether to continue. By acknowledging those disclosures and choosing to continue, you voluntarily consent to Realeyes’ collection, storage, retention, use, and disclosure of your data, including your biometric data, as described in this Policy. You may decline or withdraw consent at any time before or during the verification by cancelling the process; doing so may prevent you from accessing the content or service that requires verification.
- Realeyes uses the reasonable standard of care within its industry to store, transmit, and protect your biometric data from disclosure, in a manner that is the same as or more protective than the manner in which it stores, transmits, and protects other confidential and sensitive information (see Section 13).
- Our role. In providing biometric verification, Realeyes generally acts as a Data Processor on behalf of the Business Customer, which determines the purpose of the verification. Questions about a Business Customer’s own use of your data should be directed to that Business Customer.
16. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact:
Realeyes OÜ
Vahe 15, 11615 Tallinn, Estonia
Email: verifeye@realeyes.ai
17. Relationship to Other Legal Documents
This Privacy Policy forms part of the broader legal framework governing your use of VerifEye.
Please also review:
- the VerifEye Terms and Conditions for Users, and
- our Cookies Policy explains how cookies and similar technologies are used.
Together, these documents describe how VerifEye operates and how your personal data is collected, used, and protected.
Last updated: 1st June 2026