Kind

Biometric Data Policy

Effective August 19, 2026 · Version 2.1

Kind’s photo verification briefly processes a measurement of facial geometry to check that a live capture matches a reference photo. This is our written retention and destruction policy for that data, published as required by the biometric privacy laws of Illinois, Texas, and Washington.

The short version: nothing from verification is ever stored, no human ever sees your photos, we never sell or disclose biometric data to anyone, and we ask for your agreement before the camera opens.

1. Why This Policy Exists

Kind, operated by Subtxt LLC, operates a photo verification check that briefly processes a measurement of facial geometry. Several laws — including the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001), and Washington RCW 19.375 — require a company that does this to publish a written policy setting out how long it keeps biometric information and how it destroys it. This is that policy. It forms part of our Terms of Service and our Privacy Policy.

2. What We Collect and How Verification Works

Verification is required to join

Every Kind member verifies. That is what makes the badge worth anything, and it is one of the main defences against catfishing on a platform where members are sharing health information. If you do not want facial geometry processed, do not complete verification — you will not be able to finish creating an account, and you can email us to confirm that anything already entered has been deleted. You are never charged before verification, and no profile is created until it succeeds.

When you verify, this is exactly what happens:

  1. You pick a private reference photo of your face from your device. It is not published on your profile.
  2. You take a live capture with the front camera, inside the app.
  3. Both images are sent to our server over an encrypted connection and held only in server memory.
  4. Face-detection software locates a face in each image. If it cannot find one, verification fails immediately and nothing further happens.
  5. Each detected face is converted into a numeric vector describing facial geometry — a "face template". The template is a list of numbers. It is not a picture and cannot be turned back into one.
  6. The two templates are compared to produce a single similarity score.
  7. The score is compared against a threshold to produce a pass or fail result.
  8. Both images and both templates are then deleted from memory. Only the result, the score, and a time stamp are saved.

The biometric identifier we process is a scan of face geometry, and the biometric information we derive from it is the face template. These are the only categories of biometric data Kind handles. We do not collect fingerprints, voiceprints, retina or iris scans, hand or face geometry for any other purpose, or DNA. Voice notes are recordings you publish on your own profile; we do not analyse them to identify anyone and we do not create voiceprints.

3. Retention Schedule

Our retention period for biometric data is zero

Kind does not store biometric identifiers or biometric information. The reference photo, the live capture, and both face templates exist only in volatile server memory for the duration of a single comparison — a few seconds — and are destroyed as soon as it completes. They are never written to disk, to a database, to object storage, to a log, or to a backup. No employee, contractor, or human reviewer ever sees them.

ItemWhere it livesRetention
Reference photoServer memory onlyDestroyed immediately after the comparison
Live capture imageServer memory onlyDestroyed immediately after the comparison
Face templates (both)Server memory onlyDestroyed immediately after the comparison
Similarity score, pass/fail result, time stampDatabaseLife of the account, then up to 12 months as an anti-fraud record
Verified badge statusDatabaseLife of the account

The similarity score and result are not biometric identifiers or biometric information. They are a numeric outcome from which no facial geometry can be reconstructed. We keep them so that we can show your verified badge, detect repeated fraudulent verification attempts, and answer support questions.

Even so, and for the avoidance of any doubt: if Kind ever did come into possession of a biometric identifier or biometric information, we would permanently destroy it at the earlier of (a) the moment the purpose for collecting it was satisfied, or (b) one year after your last interaction with Kind — well inside the three-year outer limit set by the Illinois Biometric Information Privacy Act — and in any event promptly upon your request.

4. Destruction Guidelines

  • Image bytes and template vectors are held in local variables scoped to a single request and are explicitly released when the comparison ends, including when it ends in an error.
  • The verification code path writes no image or template to disk, to object storage, to a database column, or to any cache.
  • Application logs record only the outcome, the score, and non-identifying diagnostics. Image bytes and template values are never logged.
  • Because nothing is persisted, nothing enters a backup or a replica, so no biometric data can survive in a backup.
  • These controls are part of the verification service itself, so they apply on every attempt, including failed and abandoned ones.
  • If a future change to Kind ever required storing biometric data, we would first update this policy, publish the new retention and destruction schedule, and obtain fresh written consent before collecting anything.

6. We Never Sell or Disclose Biometric Data

Absolute commitments

Kind does not and will not sell, lease, trade, or otherwise profit from any biometric identifier or biometric information. Kind does not disclose, redisclose, or otherwise disseminate biometric data to any third party — not to advertisers, not to data brokers, not to affiliates, and not to service providers.

The face-detection and face-embedding models run on our own servers. Your images are never sent to a third-party face recognition service, and the model providers receive nothing from us. The only circumstances in which biometric data could ever be disclosed are those the law does not let us refuse — a valid warrant or subpoena, or a court order — and because we store no biometric data, there would be nothing to produce.

7. Safeguards

We protect biometric data using the reasonable standard of care for our industry, and at least as protectively as we protect other confidential and sensitive information. Images travel only over encrypted HTTPS/TLS connections. Processing happens in an isolated server process. Nothing is persisted. Access to the production environment requires multi-factor authentication and is logged.

8. Rights by State

Illinois

If you are an Illinois resident, the Biometric Information Privacy Act gives you the right to be told in writing that biometric data is being collected and why, to be told how long it will be kept, and to give or withhold written consent before collection. This policy and the in-app consent screen provide that notice. You may withdraw consent, and you may ask us to confirm what biometric data we hold about you — the answer will be none.

Texas

If you are a Texas resident, we inform you before capturing a biometric identifier and obtain your consent, we do not sell or disclose it, and we destroy it within a reasonable time and in any event within one year of the purpose ending — in practice, within seconds.

Washington

If you are a Washington resident, we give notice and obtain consent before enrolling any biometric identifier in a database for a commercial purpose. We do not enrol, sell, lease, or disclose biometric identifiers. See also our Consumer Health Data Privacy Policy.

Other states

Biometric data is "sensitive data" or "sensitive personal information" under the privacy laws of California, Colorado, Connecticut, Virginia, and other states. We process it only with your consent and only for the verification purpose described here, and you may exercise the rights set out in our Privacy Policy.

9. What Verification Does Not Mean

A verified badge is not an identity guarantee

Verification is an automated, best-effort signal that a live capture plausibly resembles a reference photo. It is not identity verification, an age check, a background check, a criminal records search, or a sex offender registry search, and it is not a warranty of anyone’s identity, honesty, health status, or safety. Automated matching produces false positives and false negatives. Never let a badge substitute for your own judgement — see the safety guidance in Section 6 of our Terms of Service.

10. Questions and Requests

Email info@kind.date with "Biometric Policy" in the subject line. Subtxt LLC is a Wyoming limited liability company operating remotely, so email is how we receive these requests. We will respond within 45 days.

We will post any change to this policy here with a new effective date and version number, and we will give notice in the app before a material change takes effect.