CaracalCaracal

Data Retention Policy

Last updated: July 24, 2026

1. What This Policy Covers

Caracal processes and stores, on your behalf:

  • Biometric templates ("face embeddings") derived from submitted images
  • Face crop images associated with each registration
  • A customer-supplied opaque identifier (your own person_id) — we never see names or other personal data unless you choose to submit them as your own identifier

This data is processed solely to provide identity verification and recognition services, as described in our Privacy Policy.

2. Default Retention

Every gallery has a retention period, set when it's created. The default is 30 days — biometric templates and face crops registered into that gallery are automatically, permanently removed 30 days after registration unless you delete them sooner.

Indefinite retention is available, but is a deliberate, explicit choice at gallery creation — it is never the default. We made this the default specifically because indefinite retention of biometric data carries real regulatory exposure, for you and for us.

3. Customer-Defined Retention

You choose the retention period, in hours, for each gallery at creation time.

When a gallery's retention period elapses for a given registration:

  • Its face crop images are permanently deleted from active systems
  • Its biometric template (embedding) is permanently and irreversibly removed from the searchable index

Re-registering the same person after expiry creates a fresh registration — expired data is never reused or resurrected.

4. Customer-Initiated Deletion

You may delete data at any time, before its retention period expires, via the dashboard or API:

  • A single registration — removes that person's biometric template from the searchable index immediately.
  • An entire gallery — removes every registration in it, and the gallery's underlying vector collection, immediately.

Deletion through these controls takes effect immediately and is irreversible once processed — there is no undo, and no soft-delete window during which a removed template can be recovered.

5. Infrastructure Backups

Where the underlying infrastructure is backed up for disaster-recovery purposes, those backups are subject to the same access controls as production systems and are never accessible through the API, dashboard, or any customer-facing surface. We are actively formalizing a fixed backup retention window as part of our ongoing security work; until that is published here, treat deletion via the dashboard/API as removing data from every system we operate on your behalf.

6. Account Termination

Upon account termination, all associated biometric templates and face crop images are deleted within a commercially reasonable period, following the same mechanisms described above, except where retention is required by law.

7. Contact

Questions about this policy, or about deleting data on behalf of an end user? Contact us.