Privacy policy
Last updated: 29 July 2026
Who we are
ComVis is a learning / demo product for visual identity verification. It helps a person prove they are present and match a document photo using closed local models and a controlled server API.
What we collect
Account data you provide (such as email and name), session outcomes (pass/fail, timestamps, step results), and optional company workspace data (members, client ids, webhook settings). During a live session we process camera frames in the browser and may receive derived face metrics and short-lived capture images needed to complete the check.
Technologies we use
Verification relies on:
- On-device / in-browser face landmarking (MediaPipe Tasks) for liveness challenges.
- Server-side face detection and embedding (OpenCV YuNet + SFace ONNX) for selfie and document face match.
- Optional OCR on document images when a company enables it — best-effort field extraction, not a permanent document archive.
- Authentication via Better Auth (email/password and optional Google sign-in).
Documents and biometrics
We do not keep copies of identity documents as a gallery or share document images with third parties for advertising or resale. Document frames are processed to produce a face imprint for comparison against the selfie, then discarded. A selfie JPEG may be stored so you and authorized operators can review the enrolled face; you can ask an operator to remove associated face data where the product supports it. Liveness anti-spoof peeks are processed in memory and are not persisted as media.
Sharing
We do not sell personal data. Infrastructure providers (for example hosting and database) process data only to run the service. Company workspaces receive verification outcomes for their own clients (including webhooks they configure). Legal requests may require disclosure where mandatory.
Retention & security
Account and session records are kept while the service is operated and as needed for abuse prevention. Use HTTPS in production. This is not a banking-grade KYC product — treat it as a privacy-minded prototype and review your own compliance needs before production use.
Contact
Questions about this policy: contact the operator of your ComVis deployment (the account that hosts the instance you are using).