TL;DR: Age-verification laws tell a website to check age. Third-party vendors do the checking, and their published policies do not agree on what happens next. k-ID says its facial estimation never sends an image off the device. VerifyMy deletes the derived face template immediately and the raw image after 28 days. Veriff reserves the right to keep data for its own purposes regardless of its schedule. AU10TIX says it keeps biometric data as an independent controller once a check ends. Nothing on a verification screen tells a visitor which of these applies.

The Layer the Laws Created

Statutes set the requirement. They rarely name a method and never name a company. That gap is filled by a small set of vendors now sitting between a person and a lawful website: Yoti, Veriff, Incode, AU10TIX, k-ID, VerifyMy and others. The statutory side is covered in the companion guide on age-verification laws by state [20]. This guide covers the companies doing the work.

The method menu is wider than most people expect. Yoti's privacy notice for its Age Verification Service lists roughly a dozen, among them facial age estimation, document verification, a digital ID app, a credit card check, a mobile provider check, an email address check and reusable age tokens [1]. Each leaves a different data trail, and the visitor does not pick which one runs.

What Each Vendor Says It Keeps

Every entry below is the vendor's own published text. None of these retention claims has been independently audited.

Vendor Methods offered What it says it retains, and for how long On-device or server-side Claim status
Yoti Facial age estimation, ID document verification, digital ID app, credit card check, mobile provider check, database check, email address check, reusable age tokens Selfie deleted as soon as an age estimate is given. Document images deleted as soon as an age is given by default, 28 days where the client configures manual review. Under Yoti's separate US Biometrics Policy, the image and digital map may be stored up to three years where the client sets that. Check results kept 6 months on the client's behalf. Server-side, described as Yoti servers in Yoti data centres Vendor-stated [1][2]
Veriff Identity verification, age estimation, biometric authentication, proof of address, business verification Default 90 days in the service, then 3 years in archive, covering session media and biometric face embeddings. FaceBlock fraud-list embeddings and photo kept 3 years. Sessions for US-geolocated users estimated under 13 are assigned for deletion. Veriff reserves the right to retain data for its own purposes regardless of the schedule. Server-side, no on-device option stated Vendor-stated [3][4]
Incode Identity verification, age estimation, biometric identity Biometric data kept until the purpose is satisfied or three years after the last interaction, whichever comes first. Other data kept as long as necessary, or per customer instruction where Incode acts as processor. Both, on-device processing offered for certain services Vendor-stated [5][6]
AU10TIX Document verification, biometric face-match, reusable digital ID, age assurance Biometric data kept until the first of: the purpose being satisfied, a legally prescribed period lapsing, or a deletion instruction. No fixed numeric ceiling appears in the pages checked. AU10TIX states it retains biometric data as an independent data controller once verification finishes. Server-side, no on-device option stated Vendor-stated [7][8]
k-ID Compliance orchestration routing to named third-party providers, plus facial age estimation licensed from Privately Stores the pass or fail result only, not the proof submitted. Trusted-adult email deleted after 14 days unless an account is created. Accounts deleted after 6 years of inactivity. Session data kept as long as customers indicate. On-device for facial age estimation, images never uploaded to a remote server. Other methods handled by third-party subprocessors Vendor-stated, covers k-ID's own layer only [9]
VerifyMy ID document verification, facial age estimation, soft credit look-up, mobile phone check, email address check 28 days from last verification for name, date of birth, address, email, phone, the facial image and ID document images. The derived face map is destroyed immediately once the check completes. IP address deleted immediately. A hashed email kept 24 months if used to create an account. Immediate deletion of everything in three named cases. Server-side, data stored within the EEA Vendor-stated [10]

The Deletion Promise and Its Exceptions

Yoti makes the strongest short deletion claim in the set: for facial age estimation, "Yoti deletes the selfie image as soon as an age estimate is given" [1]. The same notice describes what happens when the check is not a face scan. For US email address checks, Yoti may share the address with Versium, which checks marketing databases for the advertising segments it is linked to, listed in Yoti's own text as including "Home Own or Rent", "Credit Card Holder Bank" and "Household Income" [1]. For global email checks the recipient is Equifax, and Yoti writes that "Equifax, acts as an independent controller of the email address and re-uses pseudonymised data to enrich their consumer insights and other fraud identity products" [1]. In that configuration an age check becomes an input to a credit bureau's identity graph.

Yoti's US Biometrics Policy, written for Illinois, Texas and Washington, sets a different ceiling for identity verification: the image and digital map "are stored for a maximum of three years after the date the image was collected as set by the Client" [2]. Both statements are Yoti's own. What separates them is which party configures the retention.

Veriff publishes a detailed schedule, then a clause that governs all of it: "Veriff may retain the Personal Data for its own purposes irrespective of the retention schedule implemented for the Service provision" [4]. The schedule underneath is specific, with 90 days of active storage followed by three years of archive as the default for identity verification and age estimation alike, biometric face embeddings included [4].

AU10TIX states the most unusual position of the six. Its biometric policy says that once verification finishes, "the Company will retain your Biometric Data and process it as a 'data controller'" [8]. Retention is condition-triggered rather than time-bound, with no fixed numeric maximum for biometric data in the pages checked for this guide [8]. A separate notice discloses that the company processes personal data purchased from third parties which may include face images, and, in a distinct passage, that data it licenses to improve its age-assurance services "may include data about individuals under the age of 13, where permitted by applicable law" [7]. Those are two separate disclosures and should not be read as one.

The Variation Runs the Other Way Too

k-ID publishes the strongest architectural claim found. Its policy says "we at k-ID do NOT store the information that you provide to prove your age. All we store is the result of the verification process", and for the facial estimation option licensed from a company called Privately, that "the facial images that are processed via this solution are never uploaded to a remote server" [9]. Two caveats apply: it describes k-ID's own layer and not the subprocessors that handle document scans, and it has not been independently audited.

VerifyMy publishes the most granular retention table of the six, and draws a distinction most vendors do not. The raw facial image is held 28 days from the date of last verification. The face map, the biometric template computed from that image, is "Destroyed/Deleted immediately once check is complete" [10]. IP addresses go immediately as well. Three named cases override the 28-day default with immediate deletion of everything, one of them where the person fails the check and is believed to be a minor [10].

Incode occupies the middle. Its privacy policy says "Incode offers on-device processing which allows collection and processing of biometric identifiers to occur on your device", scoped to certain services without saying which [5]. Its biometric policy caps biometric retention at three years after the last interaction, but defines biometric identifiers to include scans of face geometry while excluding plain photographs, so a stored photograph never run through geometry scanning may fall outside that cap [6].

That spread is the finding. Between an image that never leaves the phone and biometric data held by an independent controller with no stated ceiling, there is no industry norm, and nothing in a verification screen tells a visitor where on that range they are.

What the Independent Testing Actually Measured

The one body producing independent numbers here is NIST, through its Face Analysis Technology Evaluation on age estimation and verification, published as NISTIR 8525 with updates as of July 31, 2026 [11]. Reading it correctly means keeping several statistics apart. Mean absolute error, NIST's primary accuracy measure, is the mean difference between actual and estimated ages, and it is not a pass rate [11]. Overall accuracy is defined separately as "the proportion of test images for which the absolute error is below a threshold, T" [11]. A figure quoted without saying which statistic it is, and on which image set, cannot be checked.

The threshold matters as much as the algorithm. Under a Challenge-25 policy a person must appear at least 25 to pass without a further check; Challenge-28 raises that bar. In NIST's Challenge-25 table for Application images, the false positive rate listed for the yoti-004 submission at actual age 20 is 16.4 percent. In the Challenge-28 table, same algorithm and same dataset, the figure at actual age 20 is 3.7 percent [11]. Those tables span ages 14 through 20, covering both minors and legal adults, so the numbers should not be recast as a rate at which adults get turned away. NIST also notes that its headline under-18 false positive rate is not a flat average: "The reported FPR is actually a weighted sum over subjects who are 17, 16, 15 and 14." [11], weighted toward 17-year-olds as the group most likely to try to defeat a check.

Dataset choice moves results too. NIST's measured mean absolute error for yoti-004 on subjects aged 18 to 24 runs from 1.9 to 3.8 years depending on whether the images come from its mugshot, border, application or visa collections [11]. Vendor marketing figures use different age bands and different image sources, and measure something other than what these tables measure. NIST additionally reports a median absolute error to handle outliers such as people who "might look naturally young or prematurely very old", and borrows the Gini coefficient from economics to quantify how unevenly accuracy falls across demographic groups [11].

Trade analysis of the same public data, published by Biometric Update and labelled by that outlet as its own analysis rather than NIST prose, reports that raising the threshold reduces false acceptance but pushes more legitimate adults into supplemental checks, and that at age 24 under Challenge-25 on Application images, average acceptance across algorithms ranges from roughly 51 percent for Eastern European females to 70 percent for Eastern African males [12]. The same outlet reports directional bias, meaning systematic over-estimation of teenagers' ages by leading algorithms [12]. NIST's own directional-error tables were not read for this guide, so that finding is secondary analysis here, not independently verified measurement.

What Has Already Gone Wrong, and to Whom

In June 2024, EFF reported on a 404 Media investigation into AU10TIX, in which a researcher reached the company's logging platform through credentials left exposed for over a year. EFF's account describes access to links containing "the person's name, date of birth, nationality, identification number, and the type of document uploaded such as a drivers' license", along with images of those documents, and names TikTok and X among the platforms reportedly using AU10TIX [15]. AU10TIX said the exposure did not lead to exposure beyond what the researcher had shown was possible, as relayed by EFF [15].

The second incident is frequently misdescribed. EFF's February 2026 write-up states that "attackers accessed roughly 70,000 users' government IDs, selfies, and other sensitive information after compromising Discord's third-party customer support system" [16]. The vector was a general support ticketing tool Discord had been using to route ID uploads, not an age-assurance vendor's pipeline. Discord has since stopped using that system and moved to dedicated vendors, k-ID globally and, for a period, Persona for some users in the United Kingdom [16]. Discord says uploaded IDs will be deleted and facial scans will never leave the user's device; EFF answers that platforms are closed-source and audits limited, and that "Users are being asked to simply trust that this time will be different." [16]

A third failure is of a different kind. In February 2026, 404 Media reported that "A newly released tool claims it can bypass Discord's age verification system by allowing users to control a 3D model of a computer-generated man in their browser instead of scanning their real face", alongside its earlier reporting that children were defeating the check in the VR game Gorilla Tag, which uses k-ID, by holding up photographs [19]. That is the check failing, not the data behind it leaking.

The Case For Age Assurance, Made Properly

The strongest version of the pro-verification argument does not come from vendors. 5Rights Foundation, a children's rights organisation, published a risk-based framework in February 2026 arguing that age assurance can "support a safe-by-design, children's rights approach", explicitly "not as a tool for exclusion, but as a means of enabling age-appropriate services, safer defaults and proportionate protections" [14]. The same page criticises the status quo in terms a privacy reader would recognise, describing children as left exposed to "harmful features, excessive data collection and design choices that prioritise commercial interests over their rights", and concludes that age assurance "should be risk-based, privacy-preserving and calibrated to the harms a service or feature poses" [14]. That is a position against blanket ID collection and for proportionate checks, and it is not answered by pointing at vendor retention policies.

Australia's government-funded Age Assurance Technology Trial, which tested more than 48 providers and 60 technologies, reached broadly supportive headline findings: that age assurance can be done "privately, efficiently and effectively", that there are "No substantial technological limitations preventing its implementation to meet policy goals", and that providers' practice statements at higher technology-readiness levels "fairly reflected the technological capabilities of their products, processes or services" [13]. On fairness it reported "no substantial difference in the outcomes for First Nations and Torres Strait Islander Peoples and other multi-cultural communities" [13], and it found separating age assurance services from the sites relying on them useful, because those providers "more clearly only used data for the necessary and consented purpose of providing an age assurance result" [13].

The same trial supplies the sharpest criticism in this guide, from neither a vendor nor an advocacy group. Under a finding on unnecessary data retention it reported that "Some providers were found to be building tools to enable regulators, law enforcement or Coroners to retrace the actions taken by individuals to verify their age which could lead to increased risk of privacy breaches due to unnecessary and disproportionate collection and retention of data" [13]. No law required that tooling. On security it found systems "generally secure and consistent with information security standards" but concluded they "cannot be considered infallible" [13]. Only the trial's own summary page was read for this guide, not the underlying ten-part report, so these are the project's condensed characterisations of its own results.

EFF states the opposing structural case directly: "In the final analysis, age verification systems are surveillance systems" [15], and, on its resource hub, that "there is no technology available that is entirely privacy-protective, fully accurate, and that guarantees complete coverage of the population" [18]. It also warns about function creep, arguing a company already running face-scan infrastructure could use the same scan with a different algorithm to guess a name or other demographics, since some firms operate in both age estimation and face identification [17].

What This Comparison Does Not Settle

Policy text for Persona and Jumio could not be retrieved for this guide, so neither vendor's retention posture is characterised here; Persona appears only as a vendor Discord used for some UK users, per EFF [16]. k-ID's list of named subprocessors was not examined, so its no-storage claim is documented for its own layer and open for the rest of the chain [9]. VerifyMy's separate biometric data policy was not read; the figures here come from the retention table in its main privacy policy [10]. No confirmed regulatory enforcement action against an age-assurance vendor, as distinct from a platform, was found in the checks made for this guide, which is not the same as establishing that none exists.

Everything in the vendor table is what a company says about itself. The one independently measured element in this field, NIST's evaluation, covers accuracy rather than retention, and no equivalent public test verifies whether a deletion promise is kept. That asymmetry is the practical point for anyone facing a check: the accuracy of the guess can be measured by an outside lab, and the fate of the image cannot.

Sources

  1. Yoti Ltd: "Age Verification Privacy Policy" (last updated 23/02/2026)
  2. Yoti Ltd: "Yoti US Biometrics Policy"
  3. Veriff: "Veriff's Privacy Notice"
  4. Veriff: "Data Retention in Veriff's Service" (ver-vdr-2301)
  5. Incode Technologies Inc.: "Privacy Policy"
  6. Incode Technologies Inc.: "Biometric Data Policy and Notice"
  7. AU10TIX: "Notice at Collection and Privacy Notice"
  8. AU10TIX: "AU10TIX Biometric Data Policy"
  9. k-ID: "Privacy Policy"
  10. VerifyMy: "Privacy Policy"
  11. NIST, NISTIR 8525: "Face Analysis Technology Evaluation: Age Estimation and Verification" by Kayee Hanaoka, Mei Ngan, Joyce Yang, George W. Quinn, Austin Hom and Patrick Grother (includes updates as of July 31, 2026)
  12. Biometric Update: "Beyond accuracy: What NIST's latest age estimation results mean for age assurance" by Ashok Singal (August 14, 2026)
  13. Age Assurance Technology Trial: report landing page and 12 key findings, delivered by the Age Check Certification Scheme and funded by the Australian Government
  14. 5Rights Foundation, EU Affairs Team: "Age Assurance as a Spectrum: A risk-based approach from a European perspective" (February 10, 2026)
  15. Electronic Frontier Foundation: "Hack of Age Verification Company Shows Privacy Danger of Social Media Laws" by Jason Kelley (June 26, 2024)
  16. Electronic Frontier Foundation: "Discord Voluntarily Pushes Mandatory Age Verification Despite Recent Data Breach" by Rindala Alajaji and Samantha Baldwin (February 12, 2026, updated February 25, 2026)
  17. Electronic Frontier Foundation: "Face Scans to Estimate Our Age: Harmful and Creepy AF" by Adam Schwartz (January 23, 2025)
  18. Electronic Frontier Foundation: "Age Verification Systems Are Surveillance Systems" (resource hub)
  19. 404 Media: "Free Tool Says it Can Bypass Discord's Age Verification Check With a 3D Model" by Joseph Cox (February 11, 2026)
  20. State of Surveillance: Age Verification Laws by State (companion guide on the statutory side)