Sensitive data

Biometric Data Policy

Our publicly available written policy on facial recognition in photo galleries: what we collect, with what consent, how long we keep it, and how we destroy it. It also serves as our Consumer Health Data Privacy Policy.

1. What facial recognition does

Galleries from graduation events can hold thousands of photos. When you turn on facial recognition, you can find the photos you appear in without scrolling through all of them. That is its only purpose.

Your search selfie

Processed in memory to build a temporary numeric template, compared with the gallery, and discarded within seconds. It is never written to disk, databases, backups, or logs.

The gallery index

Face templates computed from the official event photos, so that matches can be found. They are mathematical vectors and cannot be turned back into a picture of your face.

We collect this biometric information (called a "biometric identifier" or "biometric information" under Illinois law, and "face geometry" in other laws) only in these two forms.

  • Before we collect or use any biometric data, we tell you in writing that it is being collected, the specific purpose, and how long it will be kept.
  • We ask for your written release (an electronic signature, such as an unchecked box you check yourself, counts) in a separate step. We never bundle it with other terms.
  • For a minor, the release must come from a parent or legal guardian.
  • Facial recognition is always optional. Every gallery works without it.
  • You can withdraw consent at any time in the app or through the request form.

When a studio or graduation company indexes a gallery through Partiu, it is responsible for obtaining these releases, and our contract requires it to do so before indexing. We act only on its instructions.

3. Retention schedule and destruction

We permanently destroy biometric data on the earliest of these dates:

DataDestroyed
Search selfie and its temporary templateImmediately after the search, within seconds.
Gallery index linked to you Within 30 days after you withdraw consent, close your account, or the gallery is taken down, and in any case no later than 1 year after the purpose of the gallery ends, or 3 years after your last interaction with us, whichever comes first.
BackupsOverwritten on the normal backup cycle, within 35 days of deletion from production.

We review stored biometric data at least once a year and delete anything no longer needed. Destruction means deleting the templates from our databases and indexes so they cannot be recovered. The only exception is a valid warrant or subpoena, and in that case we keep only what the order requires, only for as long as it requires.

4. How we protect it

  • We never sell, lease, trade, or otherwise profit from biometric data.
  • We do not disclose it to anyone, except our service providers acting on our instructions, or when you consent, or when the law requires it (such as a valid warrant or subpoena).
  • We do not use it for surveillance, advertising, profiling, or any decision about you.
  • We store and transmit it with at least the same care we use for our most sensitive data: encryption in transit and at rest, least-privilege access, and audit trails.

5. State and provincial laws

This policy is designed to comply with, among others:

Illinois BIPA

Biometric Information Privacy Act (740 ILCS 14): public written policy, retention schedule, written release, no profiting, and destruction within 3 years of the last interaction at the latest.

Texas CUBI

Capture or Use of Biometric Identifier Act (Bus. & Com. Code § 503.001): notice and consent, no sale, and destruction within 1 year after the purpose ends.

Washington

RCW 19.375 on biometric identifiers, and the My Health My Data Act (RCW 19.373) for consumer health data.

Colorado

Colorado Privacy Act biometric rules (C.R.S. 6-1-1314): written policy, retention schedule, annual review, and incident response.

Other U.S. states

Biometric data is sensitive data under every comprehensive state privacy law, so we only process it with opt-in consent.

Quebec

Biometric identity verification needs express consent and is declared in advance to the Commission d'accès à l'information.

6. Consumer Health Data Privacy Policy

Washington's My Health My Data Act (RCW 19.373) and Nevada's SB 370 treat biometric data as "consumer health data". Partiu does not collect information about anyone's health. The only data we hold that falls under these laws is the facial recognition data described on this page.

  • Categories collected: face templates (biometric data) and search selfies processed in memory.
  • Purpose and use: helping you find your own photos in an event gallery. Nothing else.
  • Sources: you (search selfies) and official event photos provided by the studio or graduation company.
  • Sharing: only with service providers (processors) that host our systems and act on our instructions. No third party receives it for its own use, and we never sell it.
  • Consent: we collect it only with your separate consent, and we would need a second, separate consent before sharing it for any other reason.
  • Your rights: confirm whether we collect, share, or sell your consumer health data; access it and get a list of third parties and affiliates that received it; withdraw consent; and have it deleted, including from our processors. Use the request form or email privacidade@partiuformatura.app. We answer within 45 days and you can appeal a refusal.
  • Geofencing: we do not use geofences around health care facilities.

Last updated: September 21, 2026