Biometric Data Policy

Effective date: May 31, 2026 · Last updated: May 31, 2026

PersonaForge (operated by M3T Labs) creates AI personas that may incorporate biometric identifiers — facial geometry derived from photos and voiceprints derived from voice recordings. This policy describes how we collect, use, store, protect, and delete biometric identifiers and biometric information ("biometric data") in compliance with the Illinois Biometric Information Privacy Act (740 ILCS 14) ("BIPA"), the Texas Capture or Use of Biometric Identifier statute, and other state biometric privacy laws.

This page sits alongside our BIPA Disclosure and our Privacy Policy.

1. What we collect

When you upload photos or voice recordings to build a persona, we generate biometric identifiers (facial geometry templates and voiceprints) used solely to power the avatar render and voice synthesis attached to that persona. We do not use biometric data to identify individuals across services or to build advertising profiles.

2. Purpose

Biometric data is processed for the explicit purpose of creating the persona you requested and rendering its 3D avatar and voice within PersonaForge. We do not use biometric data to identify individuals across services, build advertising profiles, or train our own or any third party's models, and we never sell, lease, or trade it. We share biometric data only with service providers strictly necessary to deliver the service, each under a Data Processing Agreement: Cloudflare R2 stores the raw biometric source files you upload (your photos and voice recordings); our avatar provider (Avatar SDK / MetaPerson) receives your photos and derived facial geometry to build your 3D avatar; and ElevenLabs receives your voice recordings and the derived voiceprint for voice cloning. The full, current list of subprocessors is maintained in our Privacy Policy. We will notify you and obtain your renewed consent before disclosing your biometric data to any new recipient.

3. Consent

Before any biometric data is generated, we obtain your written informed consent through an in-product disclosure and acknowledgement step. Consent records are retained alongside your account for the duration of the persona's lifetime.

4. Retention & destruction

Biometric data is retained for as long as your persona is active. When you delete a persona or your account, the underlying biometric identifiers are permanently destroyed within 30 days. BIPA-mandated destruction occurs no later than three (3) years after your last interaction with PersonaForge.

5. Storage & security

Your raw biometric source files (photos and voice recordings) are stored by Cloudflare R2, our object-storage subprocessor, in the United States, under a Data Processing Agreement; account, persona, and consent records are held in Supabase (also United States), which additionally serves as a storage fallback for uploaded files. All biometric data is encrypted at rest and in transit using the same controls applied to other sensitive data: AES-256 at rest, TLS 1.2+ in transit, access scoped to least-privilege service roles, and audit logging on every read.

6. Your rights

You may request access to, correction of, or deletion of your biometric data at any time by emailing privacy@persona-forge.ai. We will honor verified requests within 30 days.

7. Contact

Questions about this policy? Reach us at privacy@persona-forge.ai.

M3T Labs · PersonaForge

© 2026 M3T Labs. All rights reserved.

Biometric Data Policy | PersonaForge