Privacy,in plain language.

Two separate questions, answered separately: what this website collects about you for reading it, and what the product retains after it verifies someone. The second one is the harder answer, so it is the longer section.

Editorial note — not yet reviewed by counsel

This page is a plain-language summary written by the founders. It is accurate as a description of how the site and the product behave, and it is not a legal agreement, a privacy notice drafted to a statute, or a data processing addendum. The binding legal text still needs review by counsel, and that review has not happened. Until it does, a contractual commitment comes from a signed agreement with us, not from this page.

What this website collects.

As little as we could manage. A site that sells structural privacy and then loads an advertising network is arguing against itself, so this one does not.

What is not here

  • No third-party analytics or product-analytics script.
  • No advertising cookies, no retargeting pixel, no conversion tag, no social-network embed.
  • No cross-site identifier, no fingerprinting, no session recording or heatmap tool.
  • No cookie banner, because there is no cookie to ask you about. The site sets none.
  • No third-party font request. The typefaces are served from this same origin, so reading the page does not announce you to anyone else.

What does happen

The pages are served over HTTPS by a hosting provider, which keeps ordinary server request logs — the sort of operational record any web host keeps in order to serve a page and absorb abuse. We do not join those logs to anything, and we do not build a profile from them.

If you submit the contact form, we receive exactly the fields you filled in — your name, your email address, and optionally a company, a volume figure and your message — and we use them to reply to you and to keep track of the conversation. We do not sell them, and we do not add you to a marketing list you did not ask for. Writing to contact@jerix.co reaches the same two people and leaves the same record.

Nothing on this site reads your camera, your microphone or your location. The site asks the browser to refuse those capabilities outright, which is a thing you can verify from the response headers rather than take on trust.

What the product retains, and what it never does.

This section describes a verification performed through JERIX, not your visit to this page. It is written for the person whose job is to find the overclaim, so the correct claim is stated precisely: zero retention on images and biometrics, verified on disk. That is a narrower sentence than “we keep nothing”, and the difference is the point. We do keep something, it is named below, and no part of it is an image or a biometric template.

Per verification — what is retained and for how long
DataRetentionDetail
Face imagesNever retainedThe selfie and every frame of the capture. Zero retention on images, verified on disk.
Document imagesNever retainedPhotographs of the document, front and back, including the OCR source image.
Face embeddings and templatesNever retainedNo biometric template is stored, which is why there is none to steal and none to re-use against the person elsewhere.
Chip dataNever retainedThe signed data groups read from a passport chip, including the state-signed photograph the match is made against.
Two face-derived hashes30 days / 7 daysOne-way values used for cross-operator lockout. They expire on those clocks. They are not images and they are not templates, and we name them here rather than let “zero retention on biometrics” quietly cover them.
Name, national ID, date of birthRetained, encrypted — indefinitelyEncrypted at rest. Today there is no deletion clock on these three fields, and indefinite is the honest word for that.

The retention policy itself

Deletion of images and biometrics is not a setting. There is no retention window to configure and no toggle to get wrong, because there is nothing retained for a window to hold open. That part is structural.

The three encrypted text fields are the opposite: they persist, and there is no written policy putting a lifetime on them yet.

Not shippedA data-retention policy — a defined lifetime per field, a deletion job that enforces it, and counsel review against a regulated client’s own retention duty. Until that exists, retention of the encrypted name, national ID and date of birth is indefinite, and this page will say so.

What a client ever learns about a person.

A platform integrating JERIX does not receive a name, an ID number, a date of birth or an image unless a wider field set has been configured for it deliberately. The integration running in production today takes three fields and nothing else.

The fields the live integration receives
FieldWhat it answers
verifiedWhether the verification succeeded at the assurance level the client declared.
meets_ageWhether the person is above the gate, as a true or false.
age_gate_minThe gate the client asked us to test against.

Two clients cannot compare notes

Tokens are isolated per client. Two platforms verifying the same person receive different tokens and cannot use them to discover that they share a user. Privacy here is a property of the design rather than a promise about conduct — there is no agreement between us not to correlate, because correlating is not available.

Questions, and requests about your own data.

Write to contact@jerix.co. One of the two founders answers. If you were verified through a platform that uses JERIX, say which platform, because your relationship on the data runs through them and we will need to work with them to act on it.

If something on this page contradicts what you find in the product, the page is wrong and we want to hear about it. That is a short email and a correction, not a dispute.