Privacy Policy
Last updated: May 2026
This Privacy Policy describes how Orzyn ("we", "us") collects, uses, and protects information when you use our Service. We have built the Service to minimize data collection and to never store biometric identifiers.
1. No Biometric Storage
Orzyn does not store biometric data and does not create a facial recognition profile. When you complete a verification:
- Your camera feed is processed in your browser, in-session;
- Facial landmark and expression detection happens client-side using on-device computation;
- We do not transmit, retain, or store your camera feed, facial geometry, face templates, or any other biometric identifiers on our servers;
- What we store: a record that a verification attempt occurred, the randomized challenge sequence we issued, which prompts you completed (as labels, not as image data), the result (verified / failed), the confidence score, the risk band, a hashed device fingerprint, and a hashed IP address.
2. Biometric Law Notice (BIPA, CUBI, Washington, and similar)
Even though we do not store biometric identifiers, the in-session processing of facial movements may be considered "biometric processing" under laws including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington's biometric statute, and similar state and international laws. By consenting to verification at signup, you provide informed written consent to in-session biometric processing strictly for the purpose of confirming human presence.
If you are a resident of Illinois, Texas, or Washington and wish to revoke your consent or request deletion of any associated metadata, contact privacy@orzyn.ai.
3. Information We Collect
- Account info: email address and a hashed password (managed by Supabase Auth).
- Consent records: timestamps confirming you accepted the Terms and granted biometric processing consent.
- Verification metadata: result, score, risk band, challenge sequence, duration, browser user-agent, hashed device fingerprint.
- Credential records: issuance time, expiration time, and a public credential ID with HMAC signature.
- Diagnostic data: server logs, including hashed IP addresses, used for security and abuse prevention.
4. How We Use Information
- To operate and improve the Service;
- To detect and prevent fraud, abuse, and bot activity;
- To compute and issue trust signals;
- To respond to support requests and meet legal obligations.
5. Data Retention
- Verification metadata is retained for up to 24 months for fraud analysis, then deleted.
- Credential records are retained until expiration plus 90 days, then deleted.
- Account records are retained until you delete your account.
- You can request earlier deletion at any time at privacy@orzyn.ai.
6. Sharing
We share trust signals (status, score, risk band) only with B2B partners and end users you authorize by sharing your credential URL. We do not sell personal information.
7. Children
The Service is not intended for and may not be used by anyone under 18 years of age. We do not knowingly collect information from anyone under 18, and we comply with the Children's Online Privacy Protection Act (COPPA) by gating the Service to adults.
8. Security
We use cryptographic signing for credentials and HMAC for public badge URLs. Data is stored in encrypted, access-controlled databases (Supabase / Postgres). No system is perfectly secure; please report vulnerabilities to security@orzyn.ai.
9. Your Rights
Depending on your jurisdiction (GDPR, CCPA, BIPA, CUBI, etc.), you may have the right to access, correct, port, or delete your personal information, and to revoke consent. Contact privacy@orzyn.ai to exercise these rights.
10. Changes
We may update this Privacy Policy. Material changes will be communicated via the Service.
11. Contact
privacy@orzyn.ai