Legal
Biometric Data Retention & Destruction Schedule
How Saathum collects, stores, and destroys biometric identifiers used to verify that Saathum users are real people.
Last updated August 28, 2026
This schedule is published under the Illinois Biometric Information Privacy Act
(740 ILCS 14/15(a)) and applies to all users of Saathum worldwide. It supplements our Privacy Policy.
1. What we collect
Before you post publicly on Saathum for the first time, we ask you to complete a short liveness check using your device camera. This produces a scan of facial geometry — a biometric identifier — together with a short
video or set of images of your face.
We collect this only with your prior, explicit, written consent, given by
ticking a box before the camera opens. The box is never pre-ticked. If you decline, nothing
is captured, and you may continue to use Saathum to browse, read, and watch.
2. Why we collect it
There are exactly two purposes. We use it for nothing else.
- To confirm you are a real, living person before you can post publicly,
list an item, go live, message someone you have never messaged, post in a group, or upload
media to a public part of Saathum.
- Safety and lawful-request response. Tying each account to a liveness check
helps keep Saathum a safe community and deters misuse, and allows us to respond if we are
lawfully compelled by a court or law enforcement to do so.
We do not sell, lease, trade, or profit from your biometric data. We do not
use it for advertising, for facial recognition, to identify you in photographs or videos, or
to match you against any database of other people. We cannot identify you from your face; we
can only confirm that a live person completed the check.
3. Who else sees it
The liveness check is performed by our verification provider, Didit, acting
on our instructions. We do not disclose your biometric data to anyone else, except where we
are required to by a subpoena, court order, warrant, or other lawful process, or where
disclosure is required by law.
4. How long we keep it
While your account is open
We retain your liveness record for as long as your account remains open, because the check is
renewed periodically (currently every 90 days) and the record establishes when you were last
verified.
After you delete your account
What happens then depends on where you live. Two tracks:
| Track | Who | Face scan & video | Verification record |
| Protective | Residents of Illinois and Texas, and anyone whose state of residence we do not know | Permanently destroyed when you delete your account | Kept 256 days, then permanently destroyed |
| Standard | All other users | Kept 256 days, then permanently destroyed | Kept 256 days, then permanently destroyed |
If we are unsure which track applies to you, we apply the Protective track and
destroy the face scan immediately. We do not infer your residence from your IP address or
device location; we rely on the state you tell us.
The verification record retained in either case contains no biometric data. It is a
timestamp of when you were verified, how, a one-way hash of your email address, and your
account identifier — enough to answer a lawful request about whether an account existed and
when it was checked, and nothing more.
Accounts subject to a legal hold
If material has been reported on your account that we are legally required to preserve — most
notably suspected child sexual abuse material — we are obliged by law to retain the relevant
content and records, and we will do so notwithstanding any deletion request, for as long as the
law requires. We will not destroy evidence we are required to keep.
5. When we destroy it
Biometric identifiers are permanently destroyed at the earliest of:
- the date the purpose for collecting them has been satisfied;
- 256 days after you delete your account (or immediately on deletion, under
the Protective track above);
- three years after your last interaction with Saathum; or
- the date you withdraw consent, unless a legal hold applies.
Destruction is performed by an automated process that runs continuously. Once destroyed,
biometric data cannot be recovered by us or by anyone else.
6. Withdrawing consent
You may withdraw your consent at any time by deleting your account, or by contacting us at [email protected]. Withdrawing consent means you will no
longer be able to post publicly on Saathum. Your biometric data will be destroyed in accordance
with the schedule above.
7. How it is protected
Biometric data is stored encrypted at rest, in access-restricted storage separate from your
profile, using a reasonable standard of care that is the same as or more protective than the
manner in which we store other confidential and sensitive information.
8. Changes to this schedule
If we change the periods stated above, we will publish the updated schedule here and ask you to
give consent again before any further biometric data is collected. Consent you gave to a
previous version does not carry over to a new one.
9. Contact
Ava Global International, Inc. — Delaware, United States
[email protected]