Biometric Privacy Notice
Last updated:
1.Scope of This Notice
This Biometric Privacy Notice describes how PolitiMind, Inc. ("PolitiMind") collects, uses, stores, and destroys biometric identifiers and biometric information in connection with identity verification on the Services.
It supplements our Privacy Policy and is written to the strictest applicable standard, including the Illinois Biometric Information Privacy Act (740 ILCS 14, "BIPA"), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001, "CUBI"), and the Washington My Health My Data Act ("MHMD-A"), as well as parallel state laws.
2.What We Collect
- Facial geometry / face-match vectors: a mathematical representation derived from a selfie and a government-issued ID photo, used solely to confirm the two depict the same person.
- Liveness signals: short video or frame sequences used to confirm a live human is present and defeat presentation attacks.
- Document images: images of a government-issued identity document. Document images are identity data, not biometric identifiers, but are covered here because they are captured in the same flow.
3.Why We Collect It
PolitiMind's entire value proposition is one verified human, one voice. Biometric verification exists for a single purpose: to establish that an account belongs to a unique, living person located in the United States, and to prevent sybil attacks, duplicate accounts, and coordinated manipulation of poll results.
We do not use biometric data for advertising, profiling, political targeting, surveillance, emotion inference, or any secondary purpose. We do not use it to deanonymize how you voted. Ever.
4.Written Consent
Before any biometric capture occurs, we present this Notice and obtain your affirmative, written (electronic) consent. Consent is logged with a timestamp, the notice version you accepted, and the account identifier.
Consent is voluntary. You may decline. Declining means you cannot complete identity verification and cannot access verified-participant features or token rewards; unverified public participation remains available.
5.Verification Sub-Processor
Biometric capture and matching are performed by our identity-verification vendor (Persona Identities, Inc.) acting as a service provider under written contract. The vendor is contractually prohibited from selling, leasing, trading, or otherwise profiting from your biometric data, and from using it for any purpose other than performing verification for PolitiMind. PolitiMind receives a pass/fail result and limited metadata — not raw biometric templates.
6.No Sale, No Disclosure
- We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
- We do not disclose biometric data except: (a) to the verification sub-processor named above; (b) with your separate written consent; (c) to complete a financial transaction you requested and authorized; or (d) where required by a valid warrant, subpoena, or applicable law.
- We do not disclose biometric data to campaigns, PACs, media buyers, advocacy groups, or any commercial customer of PolitiMind — under any circumstances.
7.Retention & Destruction Schedule
Our written retention schedule, as required by BIPA § 15(a):
- Biometric templates and liveness media: destroyed by the sub-processor when the verification purpose is satisfied, and in all cases no later than 30 days after the verification decision.
- Identity-document images: retained no longer than 12 months, or the shortest period required by applicable anti-fraud or recordkeeping obligations, whichever is shorter.
- Verification outcome metadata (pass/fail, timestamp, notice version, sub-processor reference ID): retained for the life of the account plus 3 years for audit and dispute defense. This metadata contains no biometric identifiers.
- Account deletion: all remaining biometric-adjacent records are destroyed within 30 days of a verified deletion request, except where retention is legally required.
8.Standard of Care
We store and transmit biometric-adjacent data using a reasonable standard of care within our industry, and in a manner at least as protective as the manner in which we handle other confidential and sensitive information. Controls include TLS 1.2+ in transit, AES-256 at rest, row-level security, security-definer access functions, zero-trust PII handling, and least-privilege staff access with audit logging.
9.State-Specific Rights
- Illinois (BIPA): we maintain this publicly available written policy, obtain written release before collection, and follow the destruction schedule above. Illinois residents have a private right of action under 740 ILCS 14/20.
- Texas (CUBI): we provide notice and obtain consent before capture, do not sell biometric identifiers, and destroy them within a reasonable time and no later than one year after the purpose expires.
- Washington (MHMD-A / RCW 19.375): we treat biometric data as consumer health data where the statute applies, obtain separate consent, and honor deletion requests. See our State & Regional Privacy Rights Notice.
- California (CPRA): biometric data is sensitive personal information. You may limit its use to what is necessary to perform the service.
- EU/UK (GDPR Art. 9): processed only on the basis of your explicit consent, which you may withdraw at any time.
10.Exercising Your Rights
To withdraw consent, request deletion, or ask what biometric-adjacent records exist for your account, submit a request through our Data Rights Request form or email chris@politimind.com. Withdrawing consent revokes verified status prospectively; it does not invalidate polls you already participated in.
11.Changes to This Notice
Material changes are versioned and dated. We will not apply a materially different biometric practice to previously collected data without obtaining fresh written consent.
