FaceLock Authenticator for Elevated MFA — Privacy Policy

Last Updated: July 3, 2026

Authoritative version: facelock.id/privacy-policy/authenticator

FaceLock ("we", "us", or "our") is committed to protecting the privacy and security of all individuals who use the FaceLock Authenticator mobile application (the "App") for elevated multi-factor authentication ("MFA"). This Privacy Policy explains how we collect, use, disclose, store, and protect information when you enroll a device, respond to MFA challenges, and use related FaceLock services powered by FaceLock.API.ZeroProof. We design our systems in accordance with privacy-first principles, including those advanced by the No Phone Home initiative.

Critical Privacy Statement: The App uses the FaceTec Device SDK for 3D liveness detection during enrollment and verification. Biometric data is captured on your device, processed into a secure template representation ("facemap"), and transmitted to FaceLock's secure servers solely for identity verification and fraud prevention as part of elevated multi-factor authentication. Raw FaceTec capture never leaves your device. We do not use biometric data or Face Data for advertising, marketing, profiling, or any unrelated purpose whatsoever. Facial biometrics are used exclusively to provide the authentication functionality of this App.

The App connects to FaceLock's ZeroProof MFA service, which integrates with your organization's identity provider (for example, Microsoft Entra ID via OpenID Connect) to deliver push-based elevated MFA. The service supports device registration, push notification dispatch, liveness verification, and challenge reporting.

The App supports three types of MFA activities:

  • Enrollment — Your organization registers your device and binds your face to your account through a one-time liveness check.
  • Sign-in verification — You receive a push notification to approve elevated sign-in requests (for example, from Microsoft Entra ID via OIDC).
  • Ad-hoc verification — Your organization's administrator initiates a liveness challenge for a specific business purpose (for example, confirming a sensitive account change).

Face Data Summary (TL;DR)

  • Collected: 3D face geometry + liveness data captured on your device only via the FaceTec SDK. Raw images never leave the device.
  • Used for: Solely to create a secure facemap template and match it for elevated MFA (enrollment, sign-in verification, or admin ad-hoc challenges).
  • Never used for: Advertising, marketing, profiling, targeting, or any other purpose.
  • Shared with: Never with advertisers, data brokers, or for marketing. Facemaps are sent only to FaceLock's systems for matching using FaceTec's licensed technology. FaceTec, Inc. receives only limited anonymized usage data required for licensing and billing of the technology; it does not receive biometric templates (facemaps) for its own use.
  • Retention: Deleted when you unenroll or upon valid request.

Full details appear in the section immediately below and in "3. Biometric Data Handling".

Face Data and Compliance with Apple's Developer Program License Agreement

The FaceLock Authenticator processes images of the user's face (and derived biometric templates) using the FaceTec 3D Liveness SDK. This processing occurs only to deliver the elevated multi-factor authentication service provided by the App — a function directly relevant to the Application.

In accordance with the requirements of the Apple Developer Program License Agreement regarding "Face Data" (including the provisions set forth under section 3.3.52 and related clauses in the Data and Privacy section):

  • Face Data and biometric templates are accessed and used solely to provide the authentication and identity verification functionality of this App.
  • We do not use Face Data for advertising, marketing purposes, or to otherwise target an end-user in any manner.
  • We do not use Face Data to build a user profile or to attempt to identify anonymous users or reconstruct profiles.
  • We do not transfer, share, sell, or otherwise provide Face Data to advertising platforms, analytics providers, data brokers, information resellers, or similar parties.
  • Raw facial captures and intermediate biometric artifacts never leave the user's device. Only a secure, one-way derived template ("facemap") is transmitted to FaceLock's servers — and only for the narrow purpose of matching against the user's previously enrolled template during an MFA challenge for which the user (or their organization) has initiated or consented to the verification.

During enrollment and prior to each liveness session, users are presented with clear notices and must affirmatively proceed, providing the informed consent required for collection and use of Face Data for this specific, limited purpose.

Our Privacy Philosophy

FaceLock's founder is a signer of the No Phone Home initiative (nophonehome.com), a public effort to ensure digital identity systems are designed without latent capabilities for covert tracking or surveillance. This commitment shapes how we build: biometric data is collected with explicit purpose limitation, stored only as long as necessary for the consented authentication relationship, and never repurposed for advertising, marketing, analytics, or secondary uses.

We believe strong authentication should protect privacy, not compromise it.

1. Information We Collect

We collect only the information necessary to provide secure elevated MFA, maintain auditability, and support your organization's compliance requirements.

Device and Registration Information

  • Device identifiers, push notification tokens (APNS or FCM), platform, device name, bundle ID, and registration timestamps.
  • Enrollment codes, authentication method keys, and deviceKey values used to register your device with FaceLock ZeroProof servers.
  • Tenant and profile association data so you can enroll with one or more organizations.

MFA Challenge and OIDC Context

  • Challenge metadata including reference identifiers, operation type, challenge status, and timestamps.
  • OIDC context from your organization's identity provider (for example, Entra ID sign-in session references) used to correlate MFA approvals with sign-in requests.
  • Ad-hoc challenge purpose text when provided by your organization's administrator.
  • Push notification dispatch records (delivery status, not message content beyond the approval prompt).

Biometric and Liveness Information (via FaceTec SDK)

  • Face geometry and liveness data captured via the FaceTec Device SDK during enrollment and verification challenges. This constitutes "Face Data" for purposes of Apple's Developer Program License Agreement when processed in connection with iOS applications.
  • This data is processed on your device to create a facemap (secure template representation). Raw FaceTec capture never leaves your device.
  • The facemap is transmitted to FaceLock's secure backend servers for matching against your enrolled template using FaceTecServerVerifyService (server-side verification technology).
  • FaceTec Data Practices: Per the FaceTec Device SDK License and Privacy Policy (dev.facetec.com/privacy-site and related terms), FaceTec may collect certain anonymized technical and usage data from the SDK (e.g., IP address, device model, OS version, SDK version, timestamps) solely for licensing, billing, and operational purposes. FaceTec does not receive raw captures or biometric templates (facemaps) from production Authenticator flows. All processing of user facemaps occurs within FaceLock's systems using FaceTec's licensed technology.
  • Biometric data and Face Data are used solely for identity verification and fraud prevention in support of elevated MFA. They are never used for advertising, marketing, or profiling. Data is deleted according to our retention policies and your valid requests.

Usage and Activity Information

  • Logs of authentication events, liveness challenges (success/failure), enrollment activities, and challenge metadata.
  • Append-only temporal usage logs for billing, security auditing, and chain-of-custody (each record includes EffectiveDate and EffectiveStatus; prior versions are retained for historical integrity).
  • Activity records associated with your organization's tenant for security, auditing, and billing.
  • These records support the Activity History feature in the App and your organization's compliance requirements.

Other Information

  • IP address and network information during API calls.
  • App version, build information, and diagnostic data when you use Help & Support or send diagnostics.
  • Location data (when enabled) captured during liveness checks to provide enhanced security and audit information ("who + where"). Location is optional and disclosed at the time of permission request on your device.

We do not collect unnecessary personal information.

2. How We Use Your Information

We use collected information solely to:

  • Provide and secure the ZeroProof elevated MFA service (device registration, push delivery via APNS/FCM, liveness verification, and challenge reporting).
  • Correlate MFA approvals with your organization's OIDC sign-in flows (for example, Entra ID elevated authentication).
  • Prevent fraud and ensure only authorized enrolled devices can approve sign-in and verification requests.
  • Maintain append-only audit logs for security, chain-of-custody, and temporal integrity as required by your organization.
  • Support customer service, troubleshooting, and security incident response.
  • Comply with legal obligations and enforce our Terms of Use.

We do not use facial images, facemaps, biometric templates, or any other Face Data for advertising, marketing, profiling, personalization of ads, or any purpose other than authentication and fraud prevention within the App. We do not sell or monetize biometric data in any form.

3. Biometric Data Handling

FaceLock Authenticator uses biometric liveness verification to bind your identity to MFA approvals. All biometric processing is performed in strict accordance with the limited purpose of providing authentication within this Application, as described in the Face Data compliance section above.

  • Biometric capture occurs through the FaceTec Device SDK on your device during enrollment and each verification challenge.
  • Raw selfies and intermediate biometric artifacts from FaceTec capture never leave your device.
  • A facemap (a secure, derived biometric template) is transmitted to FaceLock servers for matching against your enrolled template via FaceTecServerVerifyService. No raw images or Face Data (as defined by Apple) are sent off-device.
  • Biometric templates (facemaps) are stored only for the duration of your enrollment with the applicable organization, unless a longer retention period is required by law.
  • Biometric templates are deleted upon unenrollment or per your valid deletion request (subject to legal holds).
  • Face Data is never used for advertising, marketing, or targeting. It is used exclusively for the authentication service you (or your organization) have requested.

Data Processing Roles

  • Your organization (tenant) acts as the data controller for workforce MFA data, including decisions about which users must enroll and how verification outcomes are used internally.
  • FaceLock acts as a data processor for the ZeroProof MFA service, processing data on your organization's instructions to provide secure authentication infrastructure.
  • FaceTec provides the licensed 3D liveness technology. FaceTec, Inc. receives only limited anonymized usage and technical data necessary for the operation and billing of the licensed software. It does not receive or retain biometric templates (facemaps) from the Authenticator service.
  • Microsoft (Entra ID) and other identity providers are separate controllers for sign-in and directory data; FaceLock receives only the OIDC context necessary to deliver MFA challenges.
  • Your organization may have its own privacy notices governing your use of corporate authentication tools.

4. Sharing of Information

We do not sell, rent, or trade personal information. We may share information only:

  • With FaceTec: Limited anonymized SDK usage data (e.g., session counts) as required by the FaceTec license for licensing and billing. FaceTec does not receive raw biometric data or biometric templates (facemaps) from production Authenticator flows. Facemaps are processed exclusively within FaceLock's systems using FaceTec's licensed server technology. FaceTec has no independent rights to the data.
  • With your organization (tenant): Activity logs and verification outcomes associated with your tenant for compliance, auditing, and security monitoring.
  • With service providers (for example, Microsoft Azure hosting, Apple APNS, Google FCM) under strict data processing agreements. Service providers are contractually prohibited from using Face Data for any purpose other than the specific service they provide to FaceLock.
  • To comply with legal requirements, court orders, or to protect rights and safety.
  • In connection with business transfers (for example, merger or acquisition), with notice where feasible.

Face Data and biometric templates are never shared with advertising networks, data brokers, analytics providers for marketing purposes, or any party for advertising or marketing.

5. Data Storage, Security, and Retention

  • Data is hosted in Azure SQL databases with encryption at rest and in transit.
  • We implement industry-standard security measures including access controls, audit logging, and append-only temporal modeling for historical integrity.
  • Device registration data: Retained while your device is enrolled or as required for security and audit purposes.
  • Biometric templates (facemaps): Retained for the duration of your enrollment with the tenant. Deleted upon unenrollment or per your valid request (subject to legal holds).
  • Usage logs: Stored as append-only temporal records (EffectiveDate and EffectiveStatus per version; prior versions retained for audit and chain-of-custody). Retained for auditing and billing purposes (typically 1–7 years per compliance needs).
  • Diagnostic data: Deleted after resolution.

You can request deletion by unenrolling your device in the App or contacting us.

6. International Data Transfers

Data may be processed in the United States or other jurisdictions where FaceLock or its service providers operate. Where required (for example, GDPR), we implement appropriate safeguards such as Standard Contractual Clauses.

7. Your Rights and Choices

You may:

  • Unenroll your device and revoke MFA binding via Settings → Manage Tenants → Unenroll.
  • Access, correct, or delete your personal information by contacting privacy@facelock.id or support@facelock.id. Include your deviceKey and tenant name in deletion requests so we can locate your records promptly.
  • Exercise biometric rights under laws such as Illinois BIPA, Texas biometric laws, or GDPR (where applicable).
  • Manage push notifications in your device settings or via the App's Notifications section (including Quiet Hours).
  • Disable location for liveness audit by revoking location permission in your device settings (where supported).

For EU/UK/Swiss residents: You may have additional GDPR rights (access, rectification, erasure, restriction, portability, objection, and withdrawal of consent).

California residents: You may have CCPA/CPRA rights (know, delete, correct). We do not "sell" personal information as defined by CCPA.

For workforce users, your organization may also provide an internal process for privacy requests.

8. Security

We use industry-standard security measures including encryption in transit and at rest, access controls, and secure processing environments. However, no system is completely secure.

9. Children's Privacy

The App is not directed to children under 13 (or 16 in some jurisdictions). We do not knowingly collect information from children.

10. Third-Party Technology

  • The App uses the FaceTec Device SDK for 3D liveness detection. FaceTec's data practices are described in their Privacy Policy at dev.facetec.com/privacy-site and their SDK License.
  • Push notifications are delivered via Apple APNS (iOS) or Google FCM (Android).
  • MFA challenges are coordinated with your organization's identity provider (for example, Microsoft Entra ID via OIDC).
  • We are not responsible for third-party privacy practices outside our control. FaceTec provides the licensed 3D liveness technology; it receives only limited anonymized usage data for licensing and billing and does not receive or retain user biometric templates from the Authenticator. All facemaps are processed exclusively by FaceLock using FaceTec's licensed components.

11. Changes to This Privacy Policy

We may update this policy to reflect changes in practices or law. Significant changes will be notified via the App, push notification, or email where appropriate. Continued use constitutes acceptance of updates.

The authoritative version of this policy is always available at facelock.id/privacy-policy/authenticator.

12. Contact Us

For privacy questions, contact:

FaceLock Privacy Team 1800 City Farm Dr, Bldg 1B Baton Rouge, LA 70806 United States Email: privacy@facelock.id or privacy@envoc.com

For FaceTec-specific inquiries, refer to their Privacy Policy at dev.facetec.com/privacy-site or contact privacy@facetec.com. FaceTec does not use or receive raw biometric captures from FaceLock's production Authenticator flows for its own purposes.

Trademarks

"FaceTec" is a trademark of FaceTec, Inc. and is registered in the United States. FaceLock is a product of Envoc.

© 2026 FaceLock. All rights reserved.