Security & Privacy

How UniFace Verify Handles Your Data

A plain description of what happens during a verification, what we store, and what we do not claim.

1. Liveness check

During a verification session your browser tracks face presence, a blink and head movement. The captured frame is then analysed on our server with the UniFace face-analysis library. A session expires after a short time limit and can only be completed while it is active.

This is a basic liveness check. It is not certified presentation-attack detection and should not be treated as protection against all spoofing techniques.

2. Face embeddings and duplicate detection

When a verification succeeds we store a numerical face embedding with your verification record. New verification attempts are compared against stored embeddings using cosine similarity. If the similarity meets the configured threshold, the attempt is rejected as a possible duplicate, which limits one person holding several verified identities.

Embeddings are not shown publicly and are never returned by the API.

3. What the public can see

  • Looking up a UnifaceID shows verification status, verification date and the verified name.
  • Email, phone, country and gender are only returned after a paid detail unlock or to an authenticated API key.

4. Developer API keys

  • Keys are generated with a cryptographically secure random generator and prefixed uf_.
  • The full key is shown once after creation; afterwards only a masked version appears in the dashboard.
  • You can revoke a key at any time and it stops working immediately.
  • Send keys only from your server, never from browser or mobile code.
Not a legal identity document. UniFace Verify confirms a live human completed our verification. It is not a government identity credential, passport or financial KYC check.