Skip to main content

How long data is kept

After the images are deleted, their urls in the API are null and downloading them answers 404. The decision stays, so you can still show why a person was approved or declined. This scheduled deletion is not an erasure: the verification’s erasure field stays null.

Erasing a person’s data

When a person asks you to delete their data, or you no longer need it, erase it:
  • on the verification’s page in the console, with Erase Personal Data;
  • or through the MCP server, with prepare-purge-personal-data and confirm-purge-personal-data.
You pick why: the person asked (data_subject_request), your company asked (customer_request), retention, test data, or other. Erasure removes the images, the document fields, the analysis results and the device data. The status, the reason, the dates and the audit trail stay, and so does the fact of the erasure. Erasure cannot be undone. Administrators and support specialists can erase; developers cannot.

After erasure

The verification’s erasure field says when the data was erased, why, and whether your team or ProofAge did it. Document fields read null and images answer 404. See Data models. ProofAge processes this data for you under our Data Processing Agreement. How the data is protected is on Security and data protection.