Privacy Policy
Last updated: July 20, 2026
1. Overview
Caracal provides identity verification and liveness detection infrastructure through developer APIs (the "Service"). This Privacy Policy explains how we collect, use, store, and protect information processed through the Service.
When you submit images or other data to the Service, you do so on behalf of yourself or the individuals whose data you are authorized to process.
2. Information We Collect
We collect and process the following categories of information:
Account Information
- Email address
- Authentication credentials
- API keys
- Basic account metadata
Biometric and Image Data
- Images submitted to the API for face verification or liveness detection
- Derived biometric embeddings generated from submitted images
- Associated technical metadata (timestamps, request identifiers)
Under certain laws, submitted images and derived embeddings may constitute biometric data or biometric identifiers.
Usage Data
- API request logs
- Timestamps
- Error logs
- Performance metrics
Billing Information
Payments are processed by Stripe. Caracal does not store full payment card details. Stripe processes payment information under its own privacy policy.
3. How We Use Information
We process information solely to:
- Provide identity verification and liveness detection results
- Generate and compare biometric embeddings
- Maintain compatibility when deploying updated model versions
- Authenticate and manage accounts
- Bill subscriptions
- Detect abuse, fraud, or misuse of the Service
- Troubleshoot errors and maintain system reliability
We do not sell personal data.
We do not use submitted images for advertising.
4. Storage and Model Updates
If images are registered for ongoing verification workflows, we store:
- The original submitted image
- Derived biometric embeddings
We may reprocess stored images and embeddings when new versions of our models are deployed in order to:
- Maintain compatibility
- Improve accuracy within your account
- Ensure continued operation of the Service
Such reprocessing occurs only within the context of your account.
We do not use your stored images to train unrelated third‑party systems.
5. Administrative Access
Authorized personnel may access stored images, embeddings, or metadata strictly for:
- Troubleshooting
- Security review
- Fraud prevention
- Service maintenance
Access is limited and subject to internal safeguards.
6. Data Retention
Every gallery has a retention period, set at creation — 30 days by default. Registered images and derived embeddings are automatically, permanently deleted once that period elapses, unless you delete them sooner through available controls. Indefinite retention is available but requires an explicit choice at gallery creation — it is never the default.
Full details, including how customer-initiated deletion works, live in our Data Retention Policy.
Upon account termination, stored biometric data will be deleted within a commercially reasonable period, except where retention is required by law.
7. Data Processing Role
When you submit images or biometric data to the Service, Caracal acts as a service provider or data processor on your behalf.
You are responsible for determining the lawful basis for processing such data and for obtaining any required notices or consents from individuals whose data you submit.
8. Security
We implement reasonable technical and organizational measures designed to protect personal data processed through the Service. However, no system can guarantee absolute security.
9. Your Rights
You may request:
- Access to your account data
- Correction of inaccurate account information
- Deletion of stored data
Requests may be submitted via our contact page.
10. Changes
We may update this Privacy Policy from time to time. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
11. Contact
Questions about this Privacy Policy? Contact us through the contact page on our website.