Skip to Content
DocsData retention

Data retention

What each class of data a Valyd integration touches is retained for. Two rows are fixed by Valyd’s documented Data & trust policy — submitted images are processing-only, and the face biometric exists only as an irreversible vector held until the account is unlinked or deleted. Retention windows for the remaining data classes are not published here — contact support@valyd.id for the current retention schedule.

Retention matrix

Data classWhat it isRetained
ID document imageFront/back photo submitted to an ID or KYC checkTransient / processing-only — processed for the check that received it and not retrievable from a Valyd account afterward (Data & trust)
Selfie imageLiveness / face-match captureTransient / processing-only — same handling as ID images (Data & trust)
Biometric vector (face template)Irreversible one-way vector derived from an enrolled selfieUntil the account is unlinked or deleted — stored only as a vector, never an image, and never exposed through any API (Data & trust)
Verification decision & proofsSession decision (APPROVED / DECLINED / IN_REVIEW) and durable proofs (id_verified, license badges, age bands)Available on request — contact support@valyd.id for the current retention schedule
Webhook delivery logRecord of signed events POSTed to your endpointAvailable on request — contact support@valyd.id for the current retention schedule
Application / request logsOperational logs keyed by X-Request-IdAvailable on request — contact support@valyd.id for the current retention schedule
Audit & billing recordsAccount, usage, and billing historyRetained per applicable legal, tax, and accounting requirements — contact support@valyd.id for the current schedule

Deletion

  • Biometric vectors are held until the account is unlinked from your app or the account is deleted. Account deletion behavior surfaces in the error catalog via user_deleted (410) — a device linked to a deleted account must clear local data and re-register.
  • Submitted images are never persisted to an account, so there is nothing to delete after a check completes — they exist only for the duration of processing.
  • End-user erasure requests / right-to-be-forgotten — deleting or unlinking a Valyd account clears the stored biometric vector (a device linked to a deleted account re-registers, surfaced as user_deleted (410)). For a formal erasure request or the completion timeline, contact support@valyd.id.

See also

Last updated on