Seatt

Seatt Biometric Data Policy

Last updated: 2 August 2026

This is the publicly available written policy that the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) requires any private entity in possession of biometric identifiers to publish. It also serves as the written notice required by 15(b). It is written to be read, not to be survived.

In one paragraph

If you choose to verify your profile, Seatt asks you to record a short video selfie. That video is used for two things and nothing else: to confirm a live human being is holding the phone, and to confirm that person is the one in your profile photos. Verification is optional. You can use every part of Seatt without it. The video and every image derived from it are permanently destroyed as soon as the check finishes, normally within seconds. What we keep is a single word: verified, or not.

1. What we collect

Only if you tap Confirm your ID and give consent:

We do not collect fingerprints, voiceprints, retina or iris scans, hand scans, or facial geometry from your ordinary profile photos.

2. Why we collect it

Two purposes, both of which end the moment the check finishes:

  1. Liveness, to establish that a real person is present, rather than a photograph, a screen recording, a mask, or a synthetic video.
  2. Comparison, to establish that the person present is the same person as in the first photo on your Seatt profile.

The result earns a checkmark on your profile. That is the entire product purpose. We do not use your face to identify you across sessions, to build a profile of you, to train models, to target advertising, or for any purpose you have not been told about here.

3. How long we keep it: the retention schedule

Biometric identifiers and biometric information are destroyed immediately upon satisfaction of the purpose in section 2. In ordinary operation, within seconds of the check completing, and in every case within 24 hours.

Specifically:

WhatWhere it livesDestroyed
Video streamNever stored by Seatt; streamed directly to Amazon RekognitionNot retained
Reference and audit imagesHeld by Amazon Rekognition for the sessionSession expires and images are deleted; Seatt never writes them to storage
Facial geometry measurementComputed in memory during comparisonNever written to disk; discarded when the request ends
The resultSeatt's databaseRetained while your account exists (see §5)

We do not operate a face collection. We never call any API that enrols a face template for later search, which means there is no stored biometric identifier to leak, subpoena, or sell. This is a deliberate architectural choice.

This schedule is stricter than the three-year outer limit BIPA permits. Where this policy and the statutory maximum differ, this policy governs.

4. Who we share it with

Nobody, other than the processor that performs the check.

We do not and will not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information. We will not disclose them to anyone else unless you give separate written consent, or a valid warrant or subpoena requires it, and we will tell you if that happens unless we are legally forbidden from doing so.

5. What we keep afterwards

After the check, your record holds:

None of these are biometric data. They are deleted when you delete your account.

6. Your choices

7. Security

Biometric data is transmitted over TLS to Amazon Rekognition and is never written to Seatt's storage. We protect it using the reasonable standard of care in our industry, and in a manner at least as protective as we use for other confidential and sensitive information.

8. Jurisdiction-specific notes

9. Contact

privacy@seatt.app