How UniFace Verify Handles Your Data
A plain description of what happens during a verification, what we store, and what we do not claim.
1. Liveness check
During a verification session your browser tracks face presence, a blink and head movement. The captured frame is then analysed on our server with the UniFace face-analysis library. A session expires after a short time limit and can only be completed while it is active.
This is a basic liveness check. It is not certified presentation-attack detection and should not be treated as protection against all spoofing techniques.
2. Face embeddings and duplicate detection
When a verification succeeds we store a numerical face embedding with your verification record. New verification attempts are compared against stored embeddings using cosine similarity. If the similarity meets the configured threshold, the attempt is rejected as a possible duplicate, which limits one person holding several verified identities.
Embeddings are not shown publicly and are never returned by the API.
3. What the public can see
- Looking up a UnifaceID shows verification status, verification date and the verified name.
- Email, phone, country and gender are only returned after a paid detail unlock or to an authenticated API key.
4. Developer API keys
- Keys are generated with a cryptographically secure random generator and prefixed
uf_. - The full key is shown once after creation; afterwards only a masked version appears in the dashboard.
- You can revoke a key at any time and it stops working immediately.
- Send keys only from your server, never from browser or mobile code.