Draft — not legal advice — version 0.1, 22/09/2026
Kesem — Biometric Data Policy
This policy covers how Kesem collects, uses, keeps and destroys biometric data. It adds to the Privacy Policy. Kesem is operated by Yosef Haim Davidovitz, Israel (131 Lachish Boulevard, Kiryat Gat, Southern District 8204857, Israel). Privacy contact: [email protected].
BIO-1 · What we scan and what we keep
During registration, and whenever we ask you to verify again, the app runs a live face scan (a "liveness check"). From it we keep:
- a face template: a mathematical representation of your face geometry;
- the scan image: the reference image taken during the live scan;
- the result of the liveness check (passed or failed, and a confidence score).
We do not collect fingerprints, voiceprints, iris or retina scans, or hand geometry. Your ordinary profile photos are not biometric data in themselves, but they are compared with your face template (see BIO-2).
BIO-2 · Why (the only three purposes)
- To confirm that every account belongs to a real, live person (against fake accounts and bots).
- To check that the photos on your profile show you. If a photo has a face, it must match your scan. Your first photo must clearly show your face.
- To stop people we have permanently banned for serious violations from registering again.
We do not use biometric data for advertising, profiling, emotion recognition or any other purpose. We do not sell, lease or trade it, or otherwise profit from it.
BIO-3 · Why the scan is required
The face scan is a condition of using Kesem. Verifying that each member is a real person, and that the photos are theirs, is the core safety promise of the service. It protects members from impersonation, catfishing and romance scams. We could not offer that promise without it. We have documented this assessment in our data protection impact assessment. You can withdraw your consent at any time (BIO-7). If you refuse the scan at registration, registration stops, and you can come back later.
BIO-4 · Who processes it and who can see it
- Amazon Web Services (Amazon Rekognition and Face Liveness) processes the scan in the EU (Ireland) as our processor, under a data processing agreement. AWS is opted out of using this content to improve its services.
- Scan images are encrypted with a dedicated key (AWS KMS, Ireland) and stored in the EU (Frankfurt).
- The app can never read biometric data back.
- Staff access: only the owner or an administrator can view a scan image. They must enter a reason first, and every view is recorded in two logs (the biometric access log and the staff audit log). Moderators cannot see scan images.
- We disclose biometric data only (a) to the processor above, (b) with your consent, or (c) when the law or a valid legal process requires it.
BIO-5 · How long we keep it
We permanently destroy biometric data at the earliest of these events:
| Event | Destruction |
|---|---|
| You leave registration unfinished after the scan | 7 days after the scan |
| You withdraw your biometric consent | At once (a backup deletion job makes sure it is gone within 30 days) |
| You delete your account | 30 days after the request (the restoration window) |
| Two years pass since the scan | 2 years after the scan (we may ask you to scan again) |
| In any case | No later than 3 years after your last activity on Kesem |
Permanently banned accounts. To stop a banned person from registering again, the face template of a permanently banned account is kept in a separate, restricted list for 3 years from the ban, and then destroyed. A match with this list is always reviewed by a person. It never leads to an automatic ban.
BIO-6 · How we destroy it
We delete it from the database, from the AWS face collection and from encrypted storage. Every access, comparison and deletion is logged, without the biometric data itself. The logs are kept for 3 years. Encrypted backups roll over within 30 days.
BIO-7 · Withdrawing consent
Go to Settings → Privacy → "Withdraw face scan consent". Then:
- your face template and scan image are deleted at once;
- your account is no longer "verified", and your profile is hidden from discovery until you scan again, with new consent;
- your matches and chats stay;
- a record that you gave consent, and then withdrew it, is kept as evidence while your account exists.
BIO-8 · Places where we collect no new biometric data
We do not accept new registrations from Illinois, Texas or Washington (USA). We check this at the location step, before any consent or scan. In that check we save no location and no biometric data. If an existing account is located in one of these states, no new face scan and no new photo upload takes place there. If a new verification is needed, the profile is hidden from discovery until the account leaves the state, and chats and matches continue. Existing data is not deleted because of this. Kesem is also not offered in the EU, the EEA or the United Kingdom.
BIO-9 · Security
We protect biometric data at least as carefully as our most sensitive data. It is encrypted in transit and at rest, with a separate encryption key. Only named roles have access. Every access is logged.
BIO-10 · Contact
Questions or requests: [email protected], or the in-app support form (category "Privacy and data").
Sources
No third-party template text was used.
- Illinois BIPA, 740 ILCS 14/15 (written retention policy, consent, no profiting). Used as a benchmark, although registration from Illinois is blocked: https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
- Texas Bus. & Com. Code §503.001 (CUBI): https://statutes.capitol.texas.gov/Docs/BC/htm/BC.503.htm
- EDPB, Guidelines 05/2020 on consent (explicit consent; "freely given"): https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en (checked 22/09/2026)
- Israel Privacy Protection Authority (Amendment 13: biometric data as "information of special sensitivity"): https://www.gov.il/he/departments/the_privacy_protection_authority (gov.il blocks automated fetching; verify manually)
- AWS Data Processing Addendum: https://d1.awsstatic.com/legal/aws-dpa/aws-dpa.pdf
- Internal:
legal/BIOMETRIC-POLICY.mdPart 1 and Part 2 (checked againstsystem_settings),legal/BIOMETRIC-CONSENT.md,legal/DPIA.md; DECISIONS T-20, T-28, T-32, T-44, T-63, T-64, T-72, T-73, T-84, T-87