LEGAL · PRIVACY
VerifyHuman Privacy Policy
Last updated: May 24, 2026
VerifyHuman confirms that a survey respondent is a live, unique human and screens out bots, click farms, and repeat-takers — a check that runs in the respondent’s own browser in about five seconds, before a survey begins. We never store images or video of anyone’s face, and we never learn a respondent’s name. This policy describes, in plain terms, the limited personal information we do process, why, and the rights you have over it.
The honest summary. Most of the work happens on the respondent’s device and nothing about it is stored. But “private by design” is not the same as “no personal data at all.” Face geometry is biometric information, and we also process technical signals such as a device fingerprint and IP address to detect fraud. We treat all of this as personal information, we minimize it, we delete the most sensitive parts within 24 hours, and we never sell it.
1. The two roles we play
Your rights, and who is responsible, depend on which of two roles we are in:
- RIWI as a controller (we decide the “why” and “how”). This covers people who hold or use a VerifyHuman account — our customers and their team members — and visitors to our marketing site. This Policy governs that information directly.
- RIWI as a processor (we act on a customer’s instructions). When a respondent goes through a VerifyHuman check inside a customer’s survey, the customer is the controller of that verification data. We process it on their behalf under our data processing terms, which we make available to customers on request. If you are a respondent, the organization that asked you to verify is your first point of contact, and their privacy notice governs the survey itself.
To improve fraud detection and our own product, we also process de-identified and aggregated signals for our own purposes. Where we do, we act as a controller, only on data that cannot reasonably be linked to an identifiable person.
2. Information we collect as a controller (accounts & website)
When you create or use a VerifyHuman account or visit our site, we collect:
| Category | Examples | Source |
|---|---|---|
| Account identifiers | Name, work email, the organizations/projects you belong to, your role | You; Auth0 |
| Authentication data | Auth0 user identifier, login/MFA events; for legacy accounts a salted bcrypt password hash (never the password) | You; Auth0 |
| Billing data | Billing email, subscription tier/status, Stripe customer/subscription IDs, tax IDs. We never store full card numbers | You; Stripe |
| Usage & device data | IP address, browser/user-agent, dashboard actions, API request metadata, cookies | Automatically |
| Support | Messages you send us and our replies | You |
| Audit data | Security events (logins, key rotations, billing changes, data-rights requests) with actor, time, IP, user-agent | Automatically |
We use this to provide and secure the Service, authenticate you, bill you, provide support, send service and (where permitted) product communications, run product analytics, and meet our legal and accounting obligations.
3. Information processed during a verification (as a processor)
A VerifyHuman check runs client-side, in the respondent’s browser. What happens to data is best understood in three tiers:
3a. Camera images never leave the device
- Camera video and images. The webcam feed is analyzed in the browser and is never uploaded, transmitted, or stored. No photo or video of a face ever reaches our servers.
- Raw facial landmark frames (numeric coordinate samples, not images) may be transmitted transiently during the check for replay/plausibility validation. They are processed in memory and discarded immediately — never written to storage.
3b. Derived signals sent to our servers and stored briefly
| Data | What it is |
|---|---|
| Geometric fingerprint | A compact numeric vector derived from facial geometry, used to detect whether the same person already took a study. It is biometric information (Section 4) and cannot be turned back into a face image. |
| Liveness & quality signals | Scores/flags from passive checks (eye movement, blink, micro-expressions, depth) and any active challenges. |
| Demographic estimates (beta) | Estimated age range, gender, and skin-tone/luminance inferred on the device. Estimates, not identity (Section 5). |
| Device fingerprint | Hashes/signatures of the device/browser (canvas, WebGL, audio, screen, hardware, user-agent, timezone) used to detect bots and duplicate devices. |
| Network data | The respondent’s IP address, for security, rate-limiting, fraud signals, and approximate (country/region) geolocation. |
| Session & verdict metadata | Session ID, timing, the verdict (pass/fail/challenge), failure reasons, fraud signals. |
3c. What we return to the customer
The customer receives the verdict and scores (and, where enabled, demographic estimates, duplicate-match indicators, and fraud signals) through their dashboard and webhooks. They do not receive any image, video, or raw biometric template.
Respondent notice (plain language). When you complete a VerifyHuman check: we use your camera only in your own browser; no image or video of you is recorded, sent, or stored; we never learn your name; we create a numeric “geometry signature” to check you haven’t already taken this study; and we process some technical signals (device characteristics, IP address) to confirm you’re a real person and not a bot. Before any camera-based biometric step, you are asked to consent. You can decline — ask the organization running the survey about alternatives.
4. Biometric information
We want to be straightforward about this, because biometric data is specially regulated under the EU GDPR (Article 9), Illinois’ Biometric Information Privacy Act (BIPA), and similar laws.
- What we treat as biometric. The geometry of a respondent’s face, and the numeric geometric fingerprint derived from it.
- What we never do. We never store images or video of a face; never use the fingerprint to identify who a person is, build a named profile, or surveil; and we do not sell or rent biometric information.
- Consent. Before the camera step, the widget displays a biometric-use disclosure — “Your camera analyzes facial geometry on your device to confirm you are human. No photos or video are stored.” — and records the respondent’s acknowledgement with the verification. The organization running the survey is responsible for presenting any affirmative consent control its jurisdiction requires and for obtaining and recording that consent (see the Terms of Use).
- Retention. Raw biometric inputs are deleted on a same-day (24-hour) schedule — never longer than needed for verification and duplicate-checking, and well within applicable biometric-law limits (Section 11).
5. Demographic estimates (beta)
Where a customer enables it, the check estimates an age range, gender, and a skin-tone/luminance value from facial geometry, on the device. These are probabilistic estimates, not statements of identity, intended only as a signal a customer can compare against what a respondent claimed (e.g., to catch quota fraud). Because this is a beta feature and an inference, it can be wrong and should never be the sole basis for a consequential decision. Customers who enable it must disclose it to respondents.
6. Cookies and similar technologies
We use a small number of cookies. The VerifyHuman widget itself sets no cookies and performs no cross-site tracking — it only checks whether browser storage is available. We do not use advertising or cross-site tracking cookies. The cookies we use are:
| Cookie | Where | Purpose | Type | Duration |
|---|---|---|---|---|
| Auth0 session | Dashboard (vhuman.riwi.com) | Keeps you signed in; HTTP-only | Strictly necessary | Session |
vh_verified | Marketing (verifyhuman.riwi.com) | Remembers you recently completed the demo check, so you are not re-prompted | Functional | 7 days |
You can control or delete cookies in your browser; blocking strictly necessary cookies may stop parts of the dashboard from working. We honour Global Privacy Control (GPC) signals where applicable. For cookies on RIWI’s corporate website, see RIWI’s Cookie Policy at riwi.com/legal-documents.
7. How and why we use information
We process personal information to: confirm a respondent is a live, unique human and detect fraud; provide, secure, and operate accounts and the dashboard; bill subscriptions and meet tax/accounting duties; improve our product using de-identified/aggregated data; maintain security and audit logs; communicate with you; and comply with law. Where the GDPR/UK GDPR applies, our legal bases are performance of contract, legitimate interests, legal obligation, and — for biometric and demographic processing — explicit consent (Art. 9(2)(a)). Where Canadian law (PIPEDA, Quebec Law 25) applies, we rely on consent or another lawful basis as permitted.
For fraud prevention, we may check the IP address associated with a verification against third-party IP-reputation and geolocation services (Section 9). Verification never hard-fails solely because such a check is unavailable.
8. Automated processing and the right to a human review
A VerifyHuman verdict (pass / fail / challenge) is produced automatically. We design the system to fail open — if a check cannot complete, it returns a flagged result for the customer to review rather than silently rejecting a respondent. The customer makes the ultimate accept/reject decision; VerifyHuman is a signal, not a final adjudicator. Where the GDPR/UK GDPR applies and a solely-automated decision would have legal or similarly significant effects, you have the right to human intervention, to express your view, and to contest the decision. Such requests are normally directed to the customer (the controller); we assist as their processor. You may also contact us at [email protected].
9. When we disclose information, and to whom
We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as defined under California law. We disclose information only: to the customer who deployed the check (the verdict, scores, and enabled signals); to the service providers / subprocessors below, under contracts that restrict their use; for legal, safety, and compliance reasons; and in a corporate transaction, subject to this Policy.
Our current subprocessors (maintained at verifyhuman.riwi.com/legal/subprocessors.json):
| Subprocessor | Purpose | Region |
|---|---|---|
| Auth0 (Okta, Inc.) | Account login / identity | United States |
| Stripe, Inc. | Payments, subscription billing, tax, invoices | US, Ireland |
| DigitalOcean, LLC | Hosting & managed Postgres (non-biometric records at rest) | US (NYC); EU (Frankfurt) not yet GA |
| Cloudflare, Inc. | Edge CDN, DDoS mitigation, TLS | Global edge |
| Resend, Inc. | Transactional email | United States |
| Zilliz, Inc. (Milvus) | Vector DB for anonymous duplicate-detection | EU (AWS eu-central-1, Frankfurt) |
| Sentry (Functional Software, Inc.) | Error monitoring (PII scrubbing on) | United States |
Where enabled for an organization, we may also use IP-reputation and geolocation providers (e.g., IPQualityScore, MaxMind) to evaluate the IP address associated with a verification. We give customers 30 days’ notice of subprocessor changes via the URL above and by email to account owners.
10. International data transfers
RIWI is based in Canada. By default the Service is hosted in the United States (DigitalOcean, New York); an EU data-residency option (Frankfurt) is available for eligible organizations. Your information may be processed in Canada, the US, the EU, and other countries. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the Standard Contractual Clauses (and the UK Addendum) and, where applicable, the EU-U.S. Data Privacy Framework. Request a copy from [email protected].
11. Data retention
| Data | Retention |
|---|---|
| Raw biometric inputs (landmark / fingerprint data as received) | 24 hours (same-day deletion) |
| Derived features for fraud/uniqueness scoring; verification logs | 90 days |
| Session & challenge metadata; webhook delivery records | 2 years |
| Security audit logs; data-rights request records | 7 years |
| Stripe billing-event deduplication records | 30 days |
| Account & billing records | Life of the account + as required for tax/legal |
Customers may configure shorter retention for their own verification data where the Service supports it. After an account closes, we delete or de-identify personal data within a commercially reasonable period, except where retention is legally required.
12. How we protect information
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including: encryption in transit (TLS) and of sensitive material at rest (envelope encryption with rotating keys); row-level isolation between customer tenants; hashed-only storage of API keys and password credentials; signed, short-lived tokens; role-based access controls; brute-force and rate-limiting protections; and an immutable security audit log. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify affected parties and regulators of a breach as required by law.
13. Your privacy rights
Depending on where you live, you may have some or all of these rights:
- Canada (PIPEDA / Quebec Law 25): access and correct your information, know how it is used/disclosed, withdraw consent (subject to limits), data portability, and challenge our compliance with the Privacy Officer below.
- EU / UK (GDPR): access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to your supervisory authority.
- California (CCPA/CPRA): know, access, delete, correct; opt out of “sale”/“sharing” (we do neither); limit use of sensitive personal information; and non-discrimination.
- Illinois & other biometric-law states: the disclosures and retention schedule in Sections 4 and 11; we do not sell or profit from biometric information.
How to exercise your rights. Account holders can email [email protected]. Respondents: because the organization that ran the survey is the controller of your verification data, please contact that organization first; if you contact us, we will help route your request to them as their processor. We verify requests and respond within the timeframes required by law.
14. Children
VerifyHuman is a business tool and is not directed to children. Customers must not deploy the Service to collect data from children below the age of consent in the applicable jurisdiction without the consent legally required from a parent or guardian.
15. Changes to this Policy
We may update this Policy. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice (e.g., email to account owners). Continued use after an update takes effect constitutes acceptance where permitted by law.
16. Contact us
Privacy Officer (Chief Privacy Officer): Neil Seeman
Email: [email protected] · Tel: 416.205.9984
Mail: RIWI Corp, Attn: Privacy Officer, 33 Bloor Street East, 5th Floor, Toronto, Ontario M4W 3H1, Canada
For legal and contractual notices, see the Terms of Use (Attn: Travis Campbell, Corporate Secretary). General inquiries: [email protected].