Biometric information privacy聽notice.
Effective: 10 June 2026 路 Last updated: 7 September 2026
This Notice explains how Kyndrify (operated by Through The Glass Creatives Global - FZCO) collects, uses, stores, protects, and destroys biometric information when you create or verify a Digital Twin, or build a cloned voice. It supplements our Privacy Policy. The rights and obligations that apply can vary by location; where applicable law provides stronger protection, that law controls.
1. What we mean by "biometric聽information"
Information derived from your face or your voice that can be used to identify you:
- a mathematical representation of your facial geometry (a "face template" or embedding) computed from the photos and consent recording you provide, and
- a voiceprint, meaning the reference recording of your voice and the speaker model derived from it that we create when you build a cloned voice.
It does not include the photo or video itself (which we treat as your content). We do not derive any health, emotion, or demographic inference from your face or voice.
2. Why we collect it聽(purpose)
- Identity verification: to confirm that the person who gives consent is the person shown in the Twin, and that each new photo or pose you add is the same, already-consented person.
- Abuse prevention: to stop someone from building a Twin of a person who has not consented (e.g., a stolen photo).
- Voice generation: to build and run the cloned voice you ask for. The voiceprint exists only to make your voice speak your scripts.
We do not use your biometric information for advertising, and Kyndrify does not use it to train, fine-tune, or improve a Kyndrify model.
3. How little we store (data聽minimization)
We are deliberately minimal about what we keep, because the safest biometric data is the data we never store:
- Comparison measurements are temporary. When you add identity-gated media, we derive face measurements for the comparison and do not intentionally retain the individual frame-by-frame measurements as separate customer records. We may keep a numeric match score, media hashes, timestamps, and a record that the check happened.
- Encrypted template evidence may be retained with the active identity, consent evidence, and verification record so future checks can be tied to the exact verified source.
- Your consent recording and Twin photo are your content (your likeness, which is the product itself); they are stored encrypted and governed by our Privacy Policy.
4. Retention schedule and聽destruction
This is our retention schedule for biometric identifiers:
- Comparison-only face measurements: removed when the identity check finishes. They are not retained as separate customer records after a check completes.
- Active face templates: retained while the consented Digital Twin exists. When you delete the Twin, delete your account, or consent is withdrawn, the template is removed from our active systems promptly, and encrypted backups are overwritten as they age out of our backup-retention cycle.
- Voiceprints (the voice reference recording and the derived speaker model): retained while the cloned voice exists. When you delete the voice or your account, the reference recording is erased and the derived model is removed once nothing else in your workspace uses it.
- Statutory outer limits: in any event, we destroy biometric identifiers when the purpose for collecting them has been satisfied or within three (3) years of your last interaction with Kyndrify, whichever comes first. For Texas residents, destruction occurs no later than one (1) year after the purpose for collection ends. We email the workspace owner, or the first member we can reach, about 60 days before a scheduled destruction, so a twin that is still in use can be kept.
- The consent recording is your content (a video, not a derived template) and sits outside this schedule: it may be retained after withdrawal or deletion where needed to document that consent was given or to meet a legal obligation, as described in our Terms and Privacy Policy. Access remains restricted during that period.
5. Your consent
We collect and store biometric information only after you give explicit, written consent through a separate step shown to you at the time of collection, distinct from accepting our general Terms. That step states what we collect, why, how long we keep it, and that we may store and destroy it as described here. For cloned voices, the consent step is the agreement you accept in the voice-creation flow before any recording is used. You may withdraw consent at any time by deleting the Digital Twin or the voice, or by contacting us. Withdrawal blocks future rendering and removes the active reference template; limited verification evidence may remain as described above.
6. We never sell or lease聽it
We do not sell, lease, trade, or otherwise profit from your biometric information, and we do not disclose it for advertising. We share it only with service providers needed to operate identity verification. Kyndrify does not authorize unrelated use; provider handling is governed by applicable contracts, service terms, and this Notice.
7. Security
We protect biometric information with the same or greater care than other confidential information: encryption in transit and at rest, strict access controls, and applicable contractual safeguards.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your information, to withdraw consent, and to object to processing. To exercise any of these, email privacy@kyndrify.com. This Notice does not limit rights you may have under laws such as the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, Washington's biometric law, the EU/UK GDPR, or the UAE Personal Data Protection Law.
Contact
Questions about this Notice or our biometric practices: privacy@kyndrify.com.