Biometric Data Policy

Effective date: May 31, 2026 · Last updated: September 19, 2026

PersonaForge (operated by M3T Labs) creates AI personas that may incorporate biometric identifiers — facial geometry derived from photos and voiceprints derived from voice recordings. This policy describes how we collect, use, store, protect, and delete biometric identifiers and biometric information ("biometric data") in compliance with the Illinois Biometric Information Privacy Act (740 ILCS 14) ("BIPA"), the Texas Capture or Use of Biometric Identifier statute, and other state biometric privacy laws.

This page sits alongside our BIPA Disclosure and our Privacy Policy.

1. What we collect

When you upload photos or voice recordings to build a persona, we generate biometric identifiers (facial geometry templates and voiceprints) used solely to power the avatar render and voice synthesis attached to that persona. We do not use biometric data to identify individuals across services or to build advertising profiles.

2. Purpose

Biometric data is processed for the explicit purpose of creating the persona you requested and rendering its 3D avatar and voice within PersonaForge. We do not use biometric data to identify individuals across services, build advertising profiles, or train our own or any third party's models, and we never sell, lease, or trade it. We share biometric data only with the service providers strictly necessary to deliver the service, each under a Data Processing Agreement: our cloud hosting and object-storage providers store the raw biometric source files you upload (your photos and voice recordings); our avatar provider receives your photos and derived facial geometry to build your 3D avatar; and our voice-cloning provider receives your voice recordings and the derived voiceprint. All of them are located in the United States. Some of our service providers may keep copies of data they process for us under their own terms. Where a provider may still hold a copy of your biometric data after a destruction trigger, we take all steps available to us to request deletion by that provider, but we cannot guarantee that the provider completes deletion within the timeframes in this policy. The categories of service provider we use are listed in our Privacy Policy, and you can ask us who they are by emailing legal@persona-forge.ai. Except where a valid warrant, a subpoena issued by a court of competent jurisdiction, or a law requires disclosure, we will notify you and obtain your renewed consent before disclosing your biometric data to any new recipient.

3. Consent

Before any biometric data is generated, we obtain your written informed consent through an in-product disclosure and acknowledgement step. We keep a record of each consent for six (6) years after the biometric data it covers is destroyed, or longer if a legal obligation described in section 4 requires it, so we can show that consent was lawfully obtained. The record shows the account and persona the consent was given for, when it was given, what it covered, which version of our notice was shown, how it was given (the in-product step used, a keyed one-way hash of the IP address, and the browser's user-agent string), and when and how the data was destroyed. It is only a record of the consent: it never contains your biometric data, which is destroyed as described in section 4. The record does not include your account email address, so after your account is deleted we may not be able to match it to you unless you give us details that let us do so, such as your former account or persona ID. If the consent was given for another person whose likeness was used, the record also keeps the email address we sent their verification request to.

4. Retention & destruction

Biometric data is retained for as long as your persona is active. When you delete a persona you can restore it for 7 days, and when you delete your account you can cancel for 14 days. After that, we permanently destroy the biometric data we hold and instruct our voice-cloning provider to delete your voiceprint, completing destruction within 30 days of your deletion request unless a legal obligation described below requires us to preserve it. Encrypted backups may keep copies until they expire on their regular schedule. BIPA-mandated destruction occurs no later than three (3) years after your last interaction with PersonaForge. If a warrant, court order, government preservation request or another legal obligation requires us to preserve data, we pause destruction of the affected persona or account until that obligation ends. We disclose biometric data to law enforcement only when a valid warrant or a subpoena issued by a court requires it, or when a law requires us to report it.

5. Storage & security

Your raw biometric source files (photos and voice recordings) are stored by our object-storage provider in the United States under a Data Processing Agreement; account, persona and consent records are held by our cloud database provider (also United States), which additionally serves as a storage fallback for uploaded files. All biometric data is encrypted at rest and in transit using industry-standard strong encryption, with least-privilege access controls and audit logging on every read.

6. Your rights

You may request access to, correction of, or deletion of your biometric data at any time by emailing privacy@persona-forge.ai. We will honor verified requests within 30 days.

7. Contact

Questions about this policy? Reach us at privacy@persona-forge.ai.

M3T Labs · PersonaForge

© 2026 M3T Labs. All rights reserved.

Biometric Data Policy | PersonaForge