Seatt Biometric Data Policy
Last updated: 2 August 2026
This is the publicly available written policy that the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) requires any private entity in possession of biometric identifiers to publish. It also serves as the written notice required by 15(b). It is written to be read, not to be survived.
In one paragraph
If you choose to verify your profile, Seatt asks you to record a short video selfie. That video is used for two things and nothing else: to confirm a live human being is holding the phone, and to confirm that person is the one in your profile photos. Verification is optional. You can use every part of Seatt without it. The video and every image derived from it are permanently destroyed as soon as the check finishes, normally within seconds. What we keep is a single word: verified, or not.
1. What we collect
Only if you tap Confirm your ID and give consent:
- A short video of your face, recorded by your device's front camera.
- Images extracted from that video by Amazon Rekognition Face Liveness (a "reference image" and a small number of "audit images").
- A numerical measurement of facial geometry, computed in memory during the comparison.
We do not collect fingerprints, voiceprints, retina or iris scans, hand scans, or facial geometry from your ordinary profile photos.
2. Why we collect it
Two purposes, both of which end the moment the check finishes:
- Liveness, to establish that a real person is present, rather than a photograph, a screen recording, a mask, or a synthetic video.
- Comparison, to establish that the person present is the same person as in the first photo on your Seatt profile.
The result earns a checkmark on your profile. That is the entire product purpose. We do not use your face to identify you across sessions, to build a profile of you, to train models, to target advertising, or for any purpose you have not been told about here.
3. How long we keep it: the retention schedule
Biometric identifiers and biometric information are destroyed immediately upon satisfaction of the purpose in section 2. In ordinary operation, within seconds of the check completing, and in every case within 24 hours.
Specifically:
| What | Where it lives | Destroyed |
|---|---|---|
| Video stream | Never stored by Seatt; streamed directly to Amazon Rekognition | Not retained |
| Reference and audit images | Held by Amazon Rekognition for the session | Session expires and images are deleted; Seatt never writes them to storage |
| Facial geometry measurement | Computed in memory during comparison | Never written to disk; discarded when the request ends |
| The result | Seatt's database | Retained while your account exists (see §5) |
We do not operate a face collection. We never call any API that enrols a face template for later search, which means there is no stored biometric identifier to leak, subpoena, or sell. This is a deliberate architectural choice.
This schedule is stricter than the three-year outer limit BIPA permits. Where this policy and the statutory maximum differ, this policy governs.
4. Who we share it with
Nobody, other than the processor that performs the check.
- Amazon Web Services (Amazon Rekognition), acting as our processor under a written agreement, performs the liveness detection and the comparison. AWS does not receive the right to use it for its own purposes.
We do not and will not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information. We will not disclose them to anyone else unless you give separate written consent, or a valid warrant or subpoena requires it, and we will tell you if that happens unless we are legally forbidden from doing so.
5. What we keep afterwards
After the check, your record holds:
verificationStatus:VERIFIEDorUNVERIFIED.verifiedAt: the date it passed.- A session identifier, so we can investigate a disputed result.
None of these are biometric data. They are deleted when you delete your account.
6. Your choices
- Verification is optional. Nothing on Seatt is withheld from an unverified account. You can post, ask for seats, message and meet without it.
- You can decline at the consent screen, and you can close the camera at any point before the check completes. Nothing is retained if you stop.
- You can delete your account from Settings at any time, which removes the verification result along with everything else.
- You can withdraw consent by emailing privacy@seatt.app. Because we retain no biometric data, withdrawal removes the checkmark rather than triggering a deletion. There is nothing left to delete.
7. Security
Biometric data is transmitted over TLS to Amazon Rekognition and is never written to Seatt's storage. We protect it using the reasonable standard of care in our industry, and in a manner at least as protective as we use for other confidential and sensitive information.
8. Jurisdiction-specific notes
- Illinois (BIPA): this document is our §15(a) written policy and our §15(b) written notice. The consent screen in the app obtains the written release §15(b)(3) requires.
- Texas (CUBI) and Washington (HB 1493): notice and consent are obtained the same way; our destruction schedule is well inside both statutes.
- Canada (PIPEDA) and Quebec (Law 25): a face scan is sensitive personal information requiring express consent, which the consent screen obtains. Our processing takes place in AWS
us-east-1(United States); see the Privacy Policy for the cross-border transfer disclosure. - EU/UK (GDPR Art. 9): Seatt is not offered in the EU or UK at this time.
9. Contact
privacy@seatt.app