Biometric Data Notice

Effective date: March 1, 2026 · Last updated: March 1, 2026

PersonaForge ("we," "us," or "our"), operated by M3T Labs, takes the privacy and security of your biometric data seriously. This policy describes how we collect, use, store, protect, and delete biometric identifiers and biometric information ("biometric data") in connection with our AI persona creation platform, in compliance with the Illinois Biometric Information Privacy Act (740 ILCS 14) ("BIPA") and similar state laws.

What We Collect

PersonaForge will collect the following biometric data:

  • Facial geometry extracted from your photos
  • Voice characteristics (voiceprint) from your audio recording
  • We also store the raw source files you upload — your photos and voice recordings — from which these biometric identifiers are derived.

    Purpose

    This data will be used solely to generate your AI persona's avatar appearance and cloned voice. We do not use your biometric data to identify you across services, to build advertising profiles, or to train our own or any third party's models, and we never sell, lease, or trade it.

    Who Processes Your Data

    To provide the service we share your biometric data with carefully selected service providers ("subprocessors") who process it only on our instructions, under a Data Processing Agreement, and never to train their own models:

  • Cloudflare R2 — object storage for the raw biometric source files you upload (your photos and voice recordings)
  • Our avatar provider (Avatar SDK / MetaPerson) — receives your photos and derived facial geometry to build your 3D avatar
  • ElevenLabs — receives your voice recordings and the derived voiceprint for voice cloning and speech synthesis
  • Supabase — database, authentication, and fallback storage for uploaded photos and audio
  • Our LLM provider — receives your persona personality data and conversation content (not raw biometric files)
  • Resend (transactional email), Sentry (error monitoring, identifiers removed), PostHog (product analytics — no raw biometric data), and Trigger.dev (background job orchestration — biometric-derived identifiers such as persona/asset IDs, not raw biometric files)
  • All subprocessors are located in the United States. The current list is maintained in our Privacy Policy; we will notify you and obtain your renewed consent before disclosing your biometric data to any new recipient.

    Retention

    Your raw biometric source files (photos, audio) — stored in Cloudflare R2 — and the derived biometric artifacts (facial geometry held with our avatar provider, voiceprint held by ElevenLabs) are retained while your persona is active. They are permanently destroyed at the FIRST of these to occur: (1) you revoke the corresponding biometric consent; (2) your persona or account is deleted; or (3) 3 years pass since your last interaction with the persona (740 ILCS 14/15(a)).

    Destruction

    When a destruction trigger occurs, the corresponding biometric data — including the raw files in Cloudflare R2, the facial geometry held with our avatar provider, and any voiceprint held by ElevenLabs, together with the underlying recordings and photos — is permanently destroyed using secure deletion methods. Erasure triggered by revoking your consent begins without undue delay (target within 72 hours) and completes no later than 30 days. Destruction triggered by deletion or by the 3-year inactivity limit completes within 30 days.

    Your Rights

    You may revoke any biometric consent at any time, independently for each type (voice or face). Revoking a consent disables that capability and triggers erasure of that biometric type — including the raw source files in Cloudflare R2, the subprocessor-held facial geometry or voiceprint, and the source recordings or photos — without undue delay. Your persona is retained; the revoked capability stays disabled unless you consent again. You may also request access to or a copy of your data, ask us to delete it, or delete your persona or account entirely.

    Consent

    Before collecting any biometric data, we will obtain your informed, written consent through our persona creation wizard. You will be presented with this disclosure and asked to affirmatively consent to the collection and use of your biometric data for the specific purposes described above.

    Security

    We protect biometric data using industry-standard security measures including encryption at rest and in transit, access controls, and audit logging. Biometric data is stored separately from other personal information and access is limited to authorized personnel and systems required for persona generation.

    Third-Party Likeness

    If you are creating a persona using another person's likeness, you must provide that person's name and email address. We will contact them to obtain their independent, informed consent before processing their biometric data. No biometric data from a third party will be processed until their consent is confirmed.

    Contact

    If you have questions about this biometric data policy, or if you wish to exercise your rights regarding your biometric data, please contact us at: privacy@persona-forge.ai

    © 2026 M3T Labs. All rights reserved.

    Biometric Data Policy | PersonaForge